Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The UK’s Cyber Security and Resilience Bill is intended to improve protection against attacks that could disrupt essential services, but it will also impose substantial new costs on businesses. The Bill is not yet law. On the latest supplied parliamentary position, dated 18 August 2026, it had completed its Commons stages and passed its second reading in the House of Lords, with committee stage scheduled for 1 September 2026.
The government’s May 2026 impact assessment estimates a central monetised business cost of £1.186 billion over 10 years, measured in 2025 present-value terms. Its public summary describes the burden as less than £150 million a year. However, the benefits—such as attacks prevented and disruption avoided—have not been monetised, so the economic case remains dependent on benefits that are expected but difficult to quantify.
What the Bill would change
The proposed legislation would update and expand the Network and Information Systems Regulations 2018, commonly known as the NIS Regulations.
The existing regime covers essential services in areas including transport, energy, drinking water, health and digital infrastructure. It also covers some digital services, such as cloud computing, online marketplaces and online search engines. It does not cover the whole economy, and the government says it has not adapted quickly enough to changing cyber threats.
#1 Best Overall
The Bill’s central change is to widen the perimeter of regulation. It would add or strengthen obligations for:
- relevant managed service providers;
- data-centre operators;
- large load controllers in the energy sector; and
- suppliers that are important enough to be designated as critical suppliers.
It would also introduce tighter incident reporting, clearer enforcement powers, more structured regulatory cost recovery and wider powers to update the regime through secondary legislation.
That means the Bill sets the direction, but does not yet provide a single, fully specified technical standard. Much of the eventual cost and day-to-day burden will depend on regulations, thresholds, consultations and guidance that have not been finalised.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Bill status: it is not yet law
The Bill was introduced on 12 November 2025. The current Lords version is HL Bill 32, introduced on 17 June 2026. Lords second reading took place on 14 July 2026, and committee stage was scheduled to begin on 1 September 2026.
Until the Bill completes Parliament and receives Royal Assent, companies should not describe themselves as definitively regulated under the new provisions. They should, however, assess their likely exposure because implementation will require new systems, contracts, staffing and evidence—not merely a last-minute policy update.
Who is likely to be affected?
Relevant managed service providers
A relevant managed service provider, or RMSP, is broadly an organisation that provides an ongoing managed IT service to another organisation. Examples may include outsourced infrastructure management, managed networks, security operations, cloud management and continuing IT administration.
This does not mean every IT consultancy, software supplier or technology contractor will automatically be regulated. The statutory definition and thresholds matter. The explanatory notes indicate that telecommunications connectivity providers are not treated as RMSPs merely because they provide internet or telephone connectivity. Some operational-technology services, such as certain SCADA support, may also fall outside the intended category.
The government has said that small and micro-sized managed or digital service providers will generally be exempt from direct designation as regulated providers. They could nevertheless become relevant as critical suppliers if they meet the higher threshold for designation.
Data centres
The Bill would classify data centres as essential services and create a data-infrastructure sector under NIS. Medium and large data centres, including qualifying enterprise data centres, would need appropriate and proportionate security and resilience measures.
Government explanatory material identifies a 1 MW capacity threshold for the relevant data-centre infrastructure definition. That threshold and any related conditions should be checked against the final legislation and implementing regulations before a business assumes it is either inside or outside scope.
Data centres were designated as critical national infrastructure in 2024. The government says, however, that they currently do not face equivalent minimum cyber-security or operational-resilience requirements specifically tailored to their role. The proposed regime is intended to address that gap.
Large load controllers
Large load controllers would form a new energy essential service category. These are organisations able to control electricity demand at scale. They may not generate or distribute power, but compromise of their systems could affect grid stability.
This category matters as electricity systems become more dependent on flexible demand, demand-response platforms and digitally controlled assets. The government’s central estimate for bringing large load controllers into scope is £40 million over 10 years, in 2025 present-value terms.
Critical suppliers
A business may be regulated indirectly even if it does not operate critical infrastructure itself. Regulators would be able to designate a supplier of goods or services to an essential, digital or managed service provider where:
- the supplier relies on network and information systems;
- an incident could disrupt the service; and
- that disruption could significantly affect the UK economy or society.
The detailed requirements for critical suppliers will largely be set through regulations. This creates uncertainty for technology vendors, subcontractors, facilities providers and other suppliers whose failure could interrupt a regulated customer.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesWhat “higher standards” means in practice
The Bill does not establish one complete technical checklist. Its likely compliance themes include:
- cyber-risk management and board-level accountability;
- asset and network management;
- secure configuration, access control and monitoring;
- incident prevention, response and recovery;
- business continuity and operational resilience;
- supply-chain risk management;
- evidence that controls are operating effectively; and
- information sharing with regulators and relevant public authorities.
The impact assessment says future security requirements are expected to reflect elements of the Cyber Assessment Framework Basic Profile, including governance, asset management, risk management and incident response. That is an indication of the likely direction, not a statement that every CAF control is already a statutory requirement.
For data centres and some digital services, incidents may also trigger customer-notification obligations. Businesses should therefore think beyond technical security: they will need decision records, escalation procedures, tested recovery plans and contracts that allocate notification responsibilities clearly.
The proposed 24-hour and 72-hour reporting clock
The proposed model would require an initial notification within 24 hours of becoming aware of a qualifying incident, followed by a fuller report within 72 hours.
The first notification is intended to be light-touch. It is not a requirement to complete a forensic investigation, identify the full attack path or understand every affected system within one day. The priority remains containment and recovery, while the regulator receives early warning.
Rank #3
In practice, organisations will need to define what “becoming aware” means and who records that time. They may also need overnight and weekend cover. The government’s cost modelling assumes that one staff member could handle the reporting requirement and considers the need for staff availability outside normal working hours.
A realistic incident sequence
- Detection: a monitoring system, employee, customer or supplier identifies suspicious activity.
- Awareness decision: the incident team determines whether the organisation is aware of a potentially qualifying incident and records the time.
- Initial notification: a concise report is submitted within 24 hours.
- Containment: technical teams isolate systems, protect evidence and maintain essential services where possible.
- Fuller report: additional facts, impact and response details are supplied within 72 hours.
- Wider communications: customers, partners, insurers, regulators and public authorities are contacted where required.
- Remediation: the organisation documents lessons learned and tracks corrective action.
This reporting regime does not replace data-protection breach reporting, contractual notification clauses, evidence preservation or communications obligations under other laws and agreements.
How much could compliance cost?
The government’s May 2026 impact assessment provides the following central, low and high estimates. They are present-value estimates in 2025 prices over a 10-year appraisal period, not invoices that every organisation will receive.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match| Measure | Low estimate | Central estimate | High estimate |
|---|---|---|---|
| Relevant managed service providers | £552m | £796m | £1.058bn |
| Data-centre infrastructure | £118m | £149m | £214m |
| Large load controllers | £27m | £40m | £64m |
| Improved incident reporting | £58m | £201m | £384m |
The combined central estimate for business and regulator costs is £1.186 billion over 10 years, equivalent to an estimated annual direct net cost of £137.7 million. The government’s public factsheet rounds this into the simpler description of less than £150 million per year.
The annual figure can be misleading if interpreted as an evenly distributed annual bill. A newly regulated provider may incur a much larger first-year cost for:
- a gap assessment and risk review;
- new monitoring, logging, backup or recovery technology;
- network segmentation and identity improvements;
- additional staff or specialist consultants;
- external assurance and compliance evidence;
- contract renegotiation; and
- physical-security or operational-resilience upgrades.
By contrast, a mature enterprise with an established security operations centre, documented governance and tested recovery plans may face a smaller incremental cost, concentrated in evidence, reporting and regulatory engagement. A smaller MSP with weak segmentation, limited logging and no formal incident process could face a disproportionately high remediation bill.
RMSPs are the largest cost category by a considerable margin. Their central estimate of £796 million is greater than the central data-centre and large-load-controller estimates combined.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What the impact assessment does—and does not—say
The impact assessment monetises many of the expected costs but does not monetise the expected benefits. The government says it cannot reliably estimate how many attacks will be prevented or how much disruption will be avoided.
As a result, the assessment shows a central monetised net present social value of negative £1.203 billion. That does not mean the government expects the Bill to cause £1.203 billion of economic damage. It means the quantified costs exceed the quantified benefits because the likely benefits have not been assigned a monetary value.
The strongest argument for the Bill is therefore systemic resilience: preventing or limiting a cyber incident that could interrupt energy, communications, data hosting or essential public services. The weakest part of the economic case is the asymmetry between concrete estimated compliance costs and benefits that remain unmeasured.
Rank #4
Enforcement and penalties
The Bill would make the sanctions regime clearer and enable higher, more proportionate fines. The impact assessment says the current maximum fine of £17 million can represent less than 1% of annual turnover for a large regulated organisation, potentially making non-compliance cheaper than investment in security.
Free tools Windows power users keep installed
One-click scans. No signup required.
The proposed approach combines higher maximum penalties, some linkage to turnover, simplified penalty bands and clearer enforcement expectations. The maximum is not the likely fine in an individual case. The practical exposure also includes remediation directions, regulatory scrutiny, reputational damage, customer notification, contract loss and possible insurance consequences.
The assessment assumes full compliance when modelling the cost of the enforcement changes. It therefore does not provide a useful expected-fines budget for businesses. Boards should treat fines as only one part of the risk calculation.
More adaptable rules, less certainty for businesses
The Bill would allow the government to update parts of the NIS regime through secondary legislation. That should make it easier to respond to new technologies, services and threats without passing a new Act of Parliament each time.
The trade-off is that the compliance target may change after companies have invested in meeting the initial rules. Consultation is expected for implementation proposals, future costs are supposed to be assessed before secondary legislation is laid, and stakeholders are expected to receive an adjustment period. Nevertheless, thresholds, supply-chain duties, charging schemes and enforcement details remain material uncertainties.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Businesses should avoid treating the first compliance assessment as a one-off project. The proposed framework is designed to evolve.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who pays—and who may benefit?
Regulated businesses will pay directly through technology, people, assurance, reporting and potential regulatory charges.
Customers of MSPs and data centres may benefit from stronger resilience, but could also see higher service prices, stricter contract terms, more audits and tighter onboarding requirements.
Smaller providers may avoid direct RMSP designation but could still face customer-imposed security requirements or critical-supplier designation.
Recommended Free Tools
Large incumbent firms may find the fixed cost easier to absorb than smaller competitors, potentially affecting competition in managed services and hosting.
Best Value
Regulators will gain clearer powers and may recover more of their costs through charging schemes. That could improve regulatory capacity, but charges may vary between sectors.
The public and wider economy are intended to benefit from fewer severe disruptions. Those benefits are plausible, but the government has not quantified them reliably.
What organisations should do now
- Map services and customers. Identify ongoing managed IT services, data-centre capacity, flexible electricity-load activities and suppliers supporting essential or digital services.
- Determine the likely category. Assess whether each legal entity and service is an existing NIS operator, digital service provider, RMSP, data-centre operator, large load controller or potential critical supplier.
- Test the reporting clock. Define the time-of-awareness process, create an on-call rota and prepare a short initial-notification template.
- Build evidence. Keep asset inventories, risk assessments, supplier reviews, backup tests, recovery exercises and corrective actions documented.
- Review contracts. Add workable incident-notification deadlines, clarify responsibilities between providers and customers, and define audit and assurance rights.
- Check overlapping regimes. Consider the NIS Regulations, telecoms security rules, financial-services operational-resilience requirements, data-protection duties, customer contracts and, where relevant, EU regimes such as NIS2 and DORA.
- Track consultations and guidance. Budget for uncertainty, including possible regulator charging schemes and later changes made through secondary legislation.
Organisations should not buy a particular certification, platform or “Bill compliance package” solely because the Bill is not final. A proportionate starting point may be an accurate asset inventory, strong identity controls, tested and isolated backups, useful logging, supplier visibility and an incident process that has been exercised.
Where compliance can become box-ticking
A formal assessment can improve governance and evidence without materially improving resilience if privileged access remains excessive, logging is incomplete, backups remain connected to production, supplier reviews consist only of questionnaires or incident plans are never exercised.
The important distinction is between regulatory evidence and technical resilience. The Bill may require organisations to demonstrate that risks are being managed, but paperwork alone will not restore a failed service or stop a ransomware attack.
Thresholds also create a proportionality problem. A small organisation may fall outside direct regulation despite being strategically important, while a larger provider may be regulated even where its actual risk is relatively low. Critical-supplier powers partly address that gap but add uncertainty about future designation.
Conclusion
The Cyber Security and Resilience Bill is best understood as a trade-off: a broader and potentially more credible cyber baseline in exchange for higher and less predictable compliance costs.
Recommended Free Tools
Its biggest financial impact is likely to fall on relevant managed service providers, while data centres, large load controllers and important suppliers face new or expanded obligations. The government estimates the cost with reasonable detail, but cannot yet quantify the disruption and attacks the Bill may prevent.
For businesses, the sensible response is neither to assume the Bill is already law nor to wait for every detail. Map likely scope, test incident response, strengthen recovery and supplier controls, and keep budgets flexible until the final regulations and charging arrangements are known.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

