
Cyber Security and Resilience Bill
Cyber Security and Resilience Bill
By 23 July 2026 the Cyber Security and Resilience Bill's House of Lords committee paper carried a transnational-repression proposal from Lord Alton, alongside the £17m fine ceiling peers set at second reading, its progress unconfirmed.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Will the 24-hour notification clock be law before the next Trellix-scale disclosure gap occurs?
Timeline for Cyber Security and Resilience Bill
Reached House of Lords committee stage with a 23 July amendment paper
Cybersecurity: Threats and Defences: Cyber resilience bill at Lords committeeMentioned in: Police press for a 'digital prison'
Cybersecurity: Threats and DefencesUK cyber bill hits Lords with £17m cap
Cybersecurity: Threats and DefencesMentioned in: NCSC counts 200+ UK infrastructure hits
Cybersecurity: Threats and DefencesPassed report stage and third reading in the Commons on 10 June, advancing to the Lords
Cybersecurity: Threats and Defences: UK cyber bill drops payment regimeBackground
The Cyber Security and Resilience Bill is the UK Government's legislation to update and extend the Network and Information Systems Regulations 2018, broadening mandatory cyber-incident reporting and security obligations to a wider range of critical national infrastructure sectors, managed service providers and digital supply-chain entities. Its headline measure is a 24-hour initial-notification requirement for reportable cyber incidents. Oversight sits with DSIT and Ofcom, extending existing NIS Regulations enforcement rather than creating a new regulator.
The Bill passed its Commons report stage and third reading on 10 June 2026, dropping a proposed ransomware-payment disclosure requirement from the published text, and reached House of Lords second reading on 14 July 2026, carrying a fine ceiling of £17m or 4% of global turnover. It reached Lords committee stage by 23 July. It has not yet received Royal Assent.
The South Staffordshire Water ICO fine and the Trellix breach both give Parliament current-quarter examples of the gap the Bill's notification clause targets: the ICO is already enforcing comparable obligations under existing data-protection law, without waiting for Royal Assent.
Lords committee scrutiny leaves gaps open
Following its 14 July second reading, where peers had already brought managed service providers and data centres into critical-infrastructure scope and added a near-miss reporting duty, the Bill picked up a running amendment paper dated 23 July 2026, alongside the £17m or 4%-of-turnover fine ceiling . That paper also carries a transnational-repression proposal from Lord Alton, attached to a bill whose own subject is cyber-incident reporting; the public record does not say whether his amendment has had a hearing .
The Bill has not yet received Royal Assent. Its own text updates the Network and Information Systems Regulations 2018, adding a headline 24-hour initial-notification duty; current-quarter cases, the Trellix 21-day self-disclosure gap and South Staffordshire Water's 20-month dwell time, give peers concrete examples of the detection gap that duty targets.