Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

UK data centres face Ofcom oversight as Cyber Security and Resilience Bill advances

The May 2025 request for Ofcom to prepare for data-centre oversight has advanced into a Bill that would regulate qualifying UK facilities from 1MW of rated IT load, with a 10MW threshold for enterprise data centres. The regime is proposed, phased and not yet fully in force.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ofcom is preparing to become the UK’s operational regulator for qualifying data centres, but the new regime is not yet fully in force. The May 2025 disclosure that DSIT minister Chris Bryant had asked Ofcom whether it could expand its remit has developed into the Cyber Security and Resilience (Network and Information Systems) Bill. Government factsheets updated on 30 June 2026 propose bringing data-centre services into the NIS framework, generally from 1MW of rated IT load, or 10MW for enterprise data centres.

As at 18 August 2026, the Bill had not become a completed, fully commenced Act. Detailed duties, reporting thresholds, commencement dates and guidance remain to be settled.

What Ofcom was asked to do in 2025

Ofcom disclosed in parliamentary evidence in May 2025 that DSIT had asked whether it would be willing to take on data-centre regulation. The request came from DSIT minister Chris Bryant. Ofcom described the proposed responsibility as a substantial expansion, but also as a natural extension of its existing work on communications security and resilience. The original development was reported by Computer Weekly.

Ofcom subsequently began engaging with operators and preparing its capability. This was preparation for a possible statutory role, not evidence that every UK data centre had already become subject to new Ofcom duties.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the position changed

Date Development
September 2024 The government designated data centres as critical national infrastructure, citing their importance to public services, financial systems, communications, cloud computing and AI.
1 April 2025 DSIT published its policy statement for the Cyber Security and Resilience Bill.
28 May 2025 Ofcom’s request to prepare for a possible data-centre remit was reported.
12 November 2025 The Bill was introduced to Parliament.
3 February 2026 Ofcom told the Public Bill Committee that it had been visiting facilities, building relationships and gathering industry views.
17 June 2026 A House of Lords version, HL Bill 32 of 2026–27, was introduced.
30 June 2026 Government data-centre and summary factsheets were updated, identifying Ofcom as the operational regulator and describing phased implementation after enactment.

The Bill’s parliamentary progress is recorded in the government Bill collection. Its proposed commencement is phased: becoming an Act would not automatically make every detailed obligation effective on the same day.

What the Bill would change

The Bill would add data infrastructure as a relevant sector under the NIS framework and classify qualifying data-centre services as an essential service. Operators would be expected to manage cyber and resilience risks, provide information to the regulator, report significant incidents and cooperate with supervision. Detailed requirements would be set through secondary legislation and regulatory guidance.

The government’s rationale is that a compromise or outage at a data centre can cascade into services used by government, businesses and households. The policy statement also argues that, although operators already maintain extensive security and availability controls, there has not been a consistent NIS baseline with equivalent regulatory oversight across the sector.

The designation is not a guarantee against outages. It is intended to improve risk management, visibility and accountability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which facilities are likely to be covered?

Category Proposed threshold Important qualification
Standard UK data-centre services At least 1MW Measured by rated IT load.
Enterprise data centres At least 10MW Facilities operated solely for the IT needs of their owning organisation.

The Bill refers to rated IT load, not automatically to a site’s total grid connection, maximum utility import or entire building capacity. Operators should therefore avoid classifying a facility solely from its electricity-supply contract. The threshold provisions appear in the published Bill text and the government data-centres factsheet.

Questions that still need rules

  • Whether a threshold is assessed per building, site, campus, service or operator.
  • How multi-building campuses and distributed capacity are aggregated.
  • How mixed colocation, cloud and enterprise arrangements are classified.
  • How edge, modular, temporary and rapidly deployable facilities are measured.
  • How changing rated IT load affects registration and status.
  • Whether a facility serving one corporate group is an enterprise data centre for the higher threshold.

The available Bill and policy documents do not finally answer these boundary questions. They are matters for secondary legislation, Ofcom processes and guidance.

What operators should expect to do

The policy materials indicate that qualifying operators will have to notify or provide information to the regulator, maintain appropriate and proportionate risk-management measures, report significant incidents and support regulatory oversight. Operators may also have to comply with additional duties created by secondary legislation and retain evidence that their controls work.

Practical control areas

These are preparation priorities, not a final legal checklist:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Maintain an accurate inventory of IT, power, cooling, network and building-management assets.
  • Map dependencies, single points of failure and customer-critical services.
  • Control privileged access and remote administration with strong authentication and segregation.
  • Review vulnerability, patching, backup, restoration and recovery testing.
  • Secure operational technology, environmental controls and building-management systems.
  • Assess suppliers including cloud platforms, carriers, hardware vendors, managed-service providers and physical-security contractors.
  • Define incident detection, escalation, customer communication and regulator-notification processes.
  • Retain policies, test results, approvals, incident records and remediation evidence in an auditable repository.
  • Assign executive ownership for resilience and regulatory engagement.

Cyber security, operational resilience, physical resilience and availability overlap but are not identical. A fire, flood, cooling failure or power outage is not automatically a cyber incident; it may nevertheless become relevant if it disrupts an essential service, exposes a systemic dependency or follows compromise of operational technology.

How Ofcom, DSIT and the NCSC fit together

Ofcom

The June 2026 factsheet identifies Ofcom as the operational regulator. Its expected functions include registration or notification, supervision, information gathering and enforcement once the framework is commenced. Ofcom told Parliament in February 2026 that it was using the lead-in period to understand the sector rather than starting from zero. Its evidence is available in the Hansard record.

DSIT

DSIT is responsible for government policy and the Bill. It will also shape secondary legislation and the strategic framework. Earlier explanatory material used “joint regulators” language for Ofcom and DSIT, while the later factsheet uses “operational regulator” for Ofcom. The later formulation should be treated as the current government description, without assuming every institutional detail is settled.

NCSC and other regulators

The National Cyber Security Centre remains the UK’s technical cyber-security authority and a source of threat intelligence and guidance. Incidents may also intersect with obligations involving telecommunications, energy, privacy, financial services, law enforcement or public-sector contracting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Implementation issues operators and investors should watch

Proportionality

A 1MW threshold could include regional colocation facilities as well as much larger campuses. The eventual rules will need to distinguish risk and capability without creating an unmanageable burden for smaller providers.

Enterprise boundary

The 10MW enterprise threshold means an internally operated facility could be treated differently from a commercial facility at the same load. Ownership alone does not determine the consequences of an outage, so the classification test will matter.

Multiple reporting channels

Operators may already notify customers, insurers, the NCSC, police, carriers and sector regulators. Ofcom has acknowledged the need to clarify what must be reported, where and when, so that one incident does not create contradictory or duplicative reporting burdens.

Confidential information

Regulatory visibility must be balanced against customer privacy, security-sensitive architecture, vulnerability information and national-security considerations. Operators will want clear rules on handling, sharing and retaining sensitive submissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Supply-chain exposure

Risk does not stop at the facility perimeter. Cloud services, telecommunications, software, hardware, managed services, security contractors and building systems can all create dependencies. The government’s wider programme also emphasises critical-supplier visibility.

International operators

The proposed regime concerns data-centre services provided in the UK. A foreign-owned operator with UK facilities may therefore be affected for those UK services; that does not mean every service delivered by its overseas parent is automatically regulated by the UK regime.

Commercial and financial consequences

Direct compliance spending is only one possible effect. Operators may need additional audits, monitoring, incident-response retainers, evidence systems, staff and capital investment in cyber and operational technology. Customers, insurers and lenders may also tighten questionnaires, contractual controls and assurance requirements.

For investors, stronger oversight could improve confidence in operators that can demonstrate mature governance and tested recovery. Conversely, smaller providers may face proportionally higher costs, potentially affecting consolidation, market entry and colocation pricing. None of these outcomes is guaranteed; they depend on the final duties, regulator approach and implementation timetable.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What operators can do before commencement

  1. Measure rated IT load accurately. Keep the engineering basis and calculation method, not just the utility connection figure.
  2. Classify each facility. Record whether it is commercial, enterprise, hybrid, campus-based or distributed, and document assumptions.
  3. Map dependencies. Include power, cooling, carriers, cloud platforms, suppliers, building systems and customer-critical services.
  4. Rehearse incidents. Test detection, executive escalation, customer communications, recovery and restoration.
  5. Review access and remote management. Focus on privileged accounts, third parties, multifactor authentication and segregation.
  6. Check contracts. Identify notification, audit, information-sharing and resilience commitments with customers and suppliers.
  7. Create an evidence repository. Preserve risk assessments, test results, approvals, incidents and remediation decisions.
  8. Track implementation material. Monitor DSIT, Ofcom and NCSC publications and assign an accountable executive.

What remains unresolved

  • When the Bill will receive Royal Assent and when each provision will commence.
  • The final definition and treatment of campuses, hybrid sites, edge facilities and changing IT loads.
  • Incident significance and reporting deadlines.
  • Ofcom’s registration process, fees, inspection model and detailed enforcement powers.
  • The final relationship between Ofcom, DSIT, the NCSC and other regulators.
  • How sensitive technical and customer information will be protected.
  • The detailed content of secondary legislation and Ofcom guidance.

The May 2025 story was about Ofcom preparing for a possible new remit. By August 2026, that preparation sits inside a progressing Bill that would make Ofcom the operational regulator for qualifying UK data centres. The legal duties still depend on the Bill’s passage, commencement and subsequent rules.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.