The UK's Cyber Security and Resilience Bill Has Cleared the Commons
The Cyber Security and Resilience (Network and Information Systems) Bill completed all of its stages in the House of Commons on 25 June 2026 and formally entered the House of Lords. It had its Second Reading on 6 January 2026, with a committee-amended version published on 25 February 2026. Royal Assent is expected later in 2026, though phased implementation means the full regime may not be in force until 2028.
What the Bill actually does
For the first time, the Bill pulls managed service providers, data centres, and designated critical suppliers directly into a statutory security regime - not just the operators of essential services that the 2018 NIS Regulations originally targeted. It introduces fines of up to £17 million or 4% of global turnover, and an incident-reporting clock that starts within 24 hours of an organisation becoming aware of a qualifying incident.
What this means if you serve UK clients
- If your organisation is an MSP, or you rely on one, this Bill changes the regulatory conversation - MSPs move from being a vendor you trust to being a statutorily accountable part of the supply chain.
- The 24-hour reporting clock is materially tighter than many organisations' current incident response runbooks assume. Test your actual time-to-detect and time-to-declare, not just your policy's stated SLA.
- Even though full enforcement may land as late as 2028, the Bill's direction of travel - broader scope, faster reporting, larger fines - is now settled enough to plan against today rather than waiting for Royal Assent.
Gaming, fintech, and insurance firms operating in the UK typically sit downstream of several of the supplier categories this Bill newly regulates. Understanding which of your vendors will become directly accountable under the new regime is worth doing now, while there's still runway before enforcement begins.
Sources
Have a security question of your own?
Talk to a Security Expert →