Cyber Security and Resilience (Network and Information Systems) Bill
A Bill to Make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.
- Introduced by
- Liz Kendall · Labour · Leicester West
- Originating house
- Commons
- Introduced
- 12 November 2025
- Last updated
- 16 September 2026
What this bill does
Currently at Committee stage in the Lords.
Expands UK cyber rules to cover more services and gives ministers stronger powers.
This bill is now in its later parliamentary form and would widen the UK’s cyber security rules to cover more organisations, including data centres, managed service providers and some load controllers. It also strengthens incident reporting, customer notification, information sharing, inspections and financial penalties. At the same time, it gives the Secretary of State broader powers to set priorities, make further rules and direct action for national security reasons.
- Expand the scope of the NIS Regulations to include data centre services, managed services, critical suppliers and large load controllers
- Create new duties for relevant digital service providers and relevant managed service providers to manage cyber risks, report incidents and notify affected customers
- Require certain operators of data centre services, digital service providers and managed service providers to register and provide updated information to the Information Commission or competent authorities
- Allow regulators to gather information, issue guidance, recover costs through charges, impose financial penalties and take enforcement action
- Give the Secretary of State powers to designate strategic statements, issue a code of practice, require reports on the legislation, and make regulations about cyber security and resilience
- Allow the Secretary of State to give directions to regulated persons and regulatory authorities where a cyber threat poses a risk to national security, including secrecy requirements in some cases
The stage line is the same Parliament bill record as the heading. The summary is AI-generated and not independently reviewed. Report an error.
Progress
- 1st reading · Commons
- 2nd reading · Commons
- Programme motion · Commons
- Money resolution · Commons
- Ways and Means resolution · Commons
- Carry-over motion · Commons
- Committee stage · Commons
- Bill reintroduced · Commons
- Report stage · Commons
- 3rd reading · Commons
- 1st reading · Lords
- 2nd reading · Lords
- Committee stage · Lords
- Report stage · Lords