Skip to content
You can now search across every topic, entity and event.What's new
Cyber Security and Resilience Bill
LegislationGB

Cyber Security and Resilience Bill

Cyber Security and Resilience Bill

By 23 July 2026 the Cyber Security and Resilience Bill's House of Lords committee paper carried a transnational-repression proposal from Lord Alton, alongside the £17m fine ceiling peers set at second reading, its progress unconfirmed.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Will the 24-hour notification clock be law before the next Trellix-scale disclosure gap occurs?

Timeline for Cyber Security and Resilience Bill

#12 22 Jul

Reached House of Lords committee stage with a 23 July amendment paper

Cybersecurity: Threats and Defences: Cyber resilience bill at Lords committee
#11 16 Jul

Mentioned in: Police press for a 'digital prison'

Cybersecurity: Threats and Defences
#10 14 Jul

UK cyber bill hits Lords with £17m cap

Cybersecurity: Threats and Defences
#8 17 Jun
#7 10 Jun

Passed report stage and third reading in the Commons on 10 June, advancing to the Lords

Cybersecurity: Threats and Defences: UK cyber bill drops payment regime
View full timeline →

Background

The Cyber Security and Resilience Bill is the UK Government's legislation to update and extend the Network and Information Systems Regulations 2018, broadening mandatory cyber-incident reporting and security obligations to a wider range of critical national infrastructure sectors, managed service providers and digital supply-chain entities. Its headline measure is a 24-hour initial-notification requirement for reportable cyber incidents. Oversight sits with DSIT and Ofcom, extending existing NIS Regulations enforcement rather than creating a new regulator.

The Bill passed its Commons report stage and third reading on 10 June 2026, dropping a proposed ransomware-payment disclosure requirement from the published text, and reached House of Lords second reading on 14 July 2026, carrying a fine ceiling of £17m or 4% of global turnover. It reached Lords committee stage by 23 July. It has not yet received Royal Assent.

The South Staffordshire Water ICO fine and the Trellix breach both give Parliament current-quarter examples of the gap the Bill's notification clause targets: the ICO is already enforcing comparable obligations under existing data-protection law, without waiting for Royal Assent.

Key Issues
Bill passage

Lords committee scrutiny leaves gaps open

Following its 14 July second reading, where peers had already brought managed service providers and data centres into critical-infrastructure scope and added a near-miss reporting duty, the Bill picked up a running amendment paper dated 23 July 2026, alongside the £17m or 4%-of-turnover fine ceiling . That paper also carries a transnational-repression proposal from Lord Alton, attached to a bill whose own subject is cyber-incident reporting; the public record does not say whether his amendment has had a hearing .

The Bill has not yet received Royal Assent. Its own text updates the Network and Information Systems Regulations 2018, adding a headline 24-hour initial-notification duty; current-quarter cases, the Trellix 21-day self-disclosure gap and South Staffordshire Water's 20-month dwell time, give peers concrete examples of the detection gap that duty targets.

Common Questions
Does the UK Cyber Security and Resilience Bill cover data centres?
Yes. At the Lords second reading on 14 July 2026, managed service providers and data centres were brought into critical-infrastructure scope for the first time, alongside a new near-miss reporting duty.Source: event
What is the fine for breaching the UK Cyber Security and Resilience Bill?
The Bill carries a fine ceiling of £17m or 4% of global turnover, set out at the House of Lords second reading on 14 July 2026.Source: event
When does the UK Cyber Security and Resilience Bill become law?
The Bill passed its Commons report stage and third reading on 10 June 2026 and reached the House of Lords second reading on 14 July 2026. It has not yet received Royal Assent.Source: event
Does the UK already have cyber laws that apply to water companies?
Yes. The ICO fined South Staffordshire Water £963,900 in May 2026 under the existing Data Protection Act 2018 and UK GDPR Article 32. The CS&R Bill will ADD further obligations, but current statute already provides enforceable baseline security requirements for CNI operators.Source: ICO
Why does the Trellix breach matter for the UK's new cyber law?
Trellix took 21 days to disclose a breach that occurred on 17 April 2026. The Cyber Security and Resilience Bill's 24-hour notification clause is designed to prevent exactly that gap.
What does the UK Cyber Security and Resilience Bill require companies to do?
The Bill proposes a 24-hour initial-notification requirement for reportable cyber incidents and extends mandatory cyber-security obligations from the NIS Regulations 2018 to more sectors, including managed service providers and data centres.
Source Material