The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Ofcom is preparing to become the UK’s operational regulator for qualifying data centres, but the new regime is not yet fully in force. The May 2025 disclosure that DSIT minister Chris Bryant had asked Ofcom whether it could expand its remit has developed into the Cyber Security and Resilience (Network and Information Systems) Bill. Government factsheets updated on 30 June 2026 propose bringing data-centre services into the NIS framework, generally from 1MW of rated IT load, or 10MW for enterprise data centres.
As at 18 August 2026, the Bill had not become a completed, fully commenced Act. Detailed duties, reporting thresholds, commencement dates and guidance remain to be settled.
What Ofcom was asked to do in 2025
Ofcom disclosed in parliamentary evidence in May 2025 that DSIT had asked whether it would be willing to take on data-centre regulation. The request came from DSIT minister Chris Bryant. Ofcom described the proposed responsibility as a substantial expansion, but also as a natural extension of its existing work on communications security and resilience. The original development was reported by Computer Weekly.
Ofcom subsequently began engaging with operators and preparing its capability. This was preparation for a possible statutory role, not evidence that every UK data centre had already become subject to new Ofcom duties.
#1 Best Overall
How the position changed
| Date | Development |
|---|---|
| September 2024 | The government designated data centres as critical national infrastructure, citing their importance to public services, financial systems, communications, cloud computing and AI. |
| 1 April 2025 | DSIT published its policy statement for the Cyber Security and Resilience Bill. |
| 28 May 2025 | Ofcom’s request to prepare for a possible data-centre remit was reported. |
| 12 November 2025 | The Bill was introduced to Parliament. |
| 3 February 2026 | Ofcom told the Public Bill Committee that it had been visiting facilities, building relationships and gathering industry views. |
| 17 June 2026 | A House of Lords version, HL Bill 32 of 2026–27, was introduced. |
| 30 June 2026 | Government data-centre and summary factsheets were updated, identifying Ofcom as the operational regulator and describing phased implementation after enactment. |
The Bill’s parliamentary progress is recorded in the government Bill collection. Its proposed commencement is phased: becoming an Act would not automatically make every detailed obligation effective on the same day.
What the Bill would change
The Bill would add data infrastructure as a relevant sector under the NIS framework and classify qualifying data-centre services as an essential service. Operators would be expected to manage cyber and resilience risks, provide information to the regulator, report significant incidents and cooperate with supervision. Detailed requirements would be set through secondary legislation and regulatory guidance.
The government’s rationale is that a compromise or outage at a data centre can cascade into services used by government, businesses and households. The policy statement also argues that, although operators already maintain extensive security and availability controls, there has not been a consistent NIS baseline with equivalent regulatory oversight across the sector.
The designation is not a guarantee against outages. It is intended to improve risk management, visibility and accountability.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWhich facilities are likely to be covered?
| Category | Proposed threshold | Important qualification |
|---|---|---|
| Standard UK data-centre services | At least 1MW | Measured by rated IT load. |
| Enterprise data centres | At least 10MW | Facilities operated solely for the IT needs of their owning organisation. |
The Bill refers to rated IT load, not automatically to a site’s total grid connection, maximum utility import or entire building capacity. Operators should therefore avoid classifying a facility solely from its electricity-supply contract. The threshold provisions appear in the published Bill text and the government data-centres factsheet.
Questions that still need rules
- Whether a threshold is assessed per building, site, campus, service or operator.
- How multi-building campuses and distributed capacity are aggregated.
- How mixed colocation, cloud and enterprise arrangements are classified.
- How edge, modular, temporary and rapidly deployable facilities are measured.
- How changing rated IT load affects registration and status.
- Whether a facility serving one corporate group is an enterprise data centre for the higher threshold.
The available Bill and policy documents do not finally answer these boundary questions. They are matters for secondary legislation, Ofcom processes and guidance.
What operators should expect to do
The policy materials indicate that qualifying operators will have to notify or provide information to the regulator, maintain appropriate and proportionate risk-management measures, report significant incidents and support regulatory oversight. Operators may also have to comply with additional duties created by secondary legislation and retain evidence that their controls work.
Practical control areas
These are preparation priorities, not a final legal checklist:
Rank #3
- Maintain an accurate inventory of IT, power, cooling, network and building-management assets.
- Map dependencies, single points of failure and customer-critical services.
- Control privileged access and remote administration with strong authentication and segregation.
- Review vulnerability, patching, backup, restoration and recovery testing.
- Secure operational technology, environmental controls and building-management systems.
- Assess suppliers including cloud platforms, carriers, hardware vendors, managed-service providers and physical-security contractors.
- Define incident detection, escalation, customer communication and regulator-notification processes.
- Retain policies, test results, approvals, incident records and remediation evidence in an auditable repository.
- Assign executive ownership for resilience and regulatory engagement.
Cyber security, operational resilience, physical resilience and availability overlap but are not identical. A fire, flood, cooling failure or power outage is not automatically a cyber incident; it may nevertheless become relevant if it disrupts an essential service, exposes a systemic dependency or follows compromise of operational technology.
How Ofcom, DSIT and the NCSC fit together
Ofcom
The June 2026 factsheet identifies Ofcom as the operational regulator. Its expected functions include registration or notification, supervision, information gathering and enforcement once the framework is commenced. Ofcom told Parliament in February 2026 that it was using the lead-in period to understand the sector rather than starting from zero. Its evidence is available in the Hansard record.
DSIT
DSIT is responsible for government policy and the Bill. It will also shape secondary legislation and the strategic framework. Earlier explanatory material used “joint regulators” language for Ofcom and DSIT, while the later factsheet uses “operational regulator” for Ofcom. The later formulation should be treated as the current government description, without assuming every institutional detail is settled.
NCSC and other regulators
The National Cyber Security Centre remains the UK’s technical cyber-security authority and a source of threat intelligence and guidance. Incidents may also intersect with obligations involving telecommunications, energy, privacy, financial services, law enforcement or public-sector contracting.
Rank #4
Implementation issues operators and investors should watch
Proportionality
A 1MW threshold could include regional colocation facilities as well as much larger campuses. The eventual rules will need to distinguish risk and capability without creating an unmanageable burden for smaller providers.
Enterprise boundary
The 10MW enterprise threshold means an internally operated facility could be treated differently from a commercial facility at the same load. Ownership alone does not determine the consequences of an outage, so the classification test will matter.
Multiple reporting channels
Operators may already notify customers, insurers, the NCSC, police, carriers and sector regulators. Ofcom has acknowledged the need to clarify what must be reported, where and when, so that one incident does not create contradictory or duplicative reporting burdens.
Confidential information
Regulatory visibility must be balanced against customer privacy, security-sensitive architecture, vulnerability information and national-security considerations. Operators will want clear rules on handling, sharing and retaining sensitive submissions.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Best Value
Supply-chain exposure
Risk does not stop at the facility perimeter. Cloud services, telecommunications, software, hardware, managed services, security contractors and building systems can all create dependencies. The government’s wider programme also emphasises critical-supplier visibility.
International operators
The proposed regime concerns data-centre services provided in the UK. A foreign-owned operator with UK facilities may therefore be affected for those UK services; that does not mean every service delivered by its overseas parent is automatically regulated by the UK regime.
Commercial and financial consequences
Direct compliance spending is only one possible effect. Operators may need additional audits, monitoring, incident-response retainers, evidence systems, staff and capital investment in cyber and operational technology. Customers, insurers and lenders may also tighten questionnaires, contractual controls and assurance requirements.
For investors, stronger oversight could improve confidence in operators that can demonstrate mature governance and tested recovery. Conversely, smaller providers may face proportionally higher costs, potentially affecting consolidation, market entry and colocation pricing. None of these outcomes is guaranteed; they depend on the final duties, regulator approach and implementation timetable.
Free tools Windows power users keep installed
One-click scans. No signup required.
What operators can do before commencement
- Measure rated IT load accurately. Keep the engineering basis and calculation method, not just the utility connection figure.
- Classify each facility. Record whether it is commercial, enterprise, hybrid, campus-based or distributed, and document assumptions.
- Map dependencies. Include power, cooling, carriers, cloud platforms, suppliers, building systems and customer-critical services.
- Rehearse incidents. Test detection, executive escalation, customer communications, recovery and restoration.
- Review access and remote management. Focus on privileged accounts, third parties, multifactor authentication and segregation.
- Check contracts. Identify notification, audit, information-sharing and resilience commitments with customers and suppliers.
- Create an evidence repository. Preserve risk assessments, test results, approvals, incidents and remediation decisions.
- Track implementation material. Monitor DSIT, Ofcom and NCSC publications and assign an accountable executive.
What remains unresolved
- When the Bill will receive Royal Assent and when each provision will commence.
- The final definition and treatment of campuses, hybrid sites, edge facilities and changing IT loads.
- Incident significance and reporting deadlines.
- Ofcom’s registration process, fees, inspection model and detailed enforcement powers.
- The final relationship between Ofcom, DSIT, the NCSC and other regulators.
- How sensitive technical and customer information will be protected.
- The detailed content of secondary legislation and Ofcom guidance.
The May 2025 story was about Ofcom preparing for a possible new remit. By August 2026, that preparation sits inside a progressing Bill that would make Ofcom the operational regulator for qualifying UK data centres. The legal duties still depend on the Bill’s passage, commencement and subsequent rules.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




