Vellum Search Regulations coveredPricingAnalysis ↗ Sign in

UK Cyber Security & Resilience Bill — the verified record, live

The Cyber Security and Resilience Bill is the UK's answer to the widening gap between its inherited cyber framework — the NIS Regulations 2018 — and the threat environment that has produced disruptive attacks on health services, supply chains and major retailers. Announced in the July 2024 King's Speech and shaped by a government policy statement in April 2025, the Bill is designed to expand regulation to more of the digital economy, bringing managed service providers into scope and addressing critical suppliers and data infrastructure, while strengthening regulators' powers, modernising incident reporting with tighter timelines, and enabling faster updating of the framework as risks evolve. Enforcement would remain with existing sectoral competent authorities, including the ICO for digital services, on a cost-recovery-strengthened footing. As a Bill in passage rather than settled law, the operative detail — final scope, reporting thresholds, penalty levels and commencement — depends on the text as enacted and subsequent secondary legislation, which is precisely why organisations in and near scope are tracking it closely now.

Every document below comes from the body that published it — regulators, courts, parliaments, official registers — with its true publication date and a link to the primary source.

as of 2026-08-31 · refreshed from scheduled releases

4
Publishers represented
2018-04-19
Earliest
2026-07-01
Most recent

Latest developments

UK — Dept. for Science, Innovation & Technology · 2026-07-01

Improved family leave and flexible working to signal step change in support for women researchers

UK — Dept. for Science, Innovation & Technology · 2026-06-30

Cyber Security and Resilience (Network and Information Systems) Bill: factsheets

UK — Dept. for Science, Innovation & Technology · 2026-06-30

Person Data Standard Alpha Release

UK — Dept. for Science, Innovation & Technology · 2026-06-30

Vulnerabilities Data Standard Alpha Release

UK — Dept. for Science, Innovation & Technology · 2026-06-26

IT Reuse for Good Charter

UK — Dept. for Science, Innovation & Technology · 2026-06-24

Trialling automated vehicle technologies in public

UK — Dept. for Science, Innovation & Technology · 2026-06-19

HM Government licensing cyber security tech for a global market

UK — Dept. for Science, Innovation & Technology · 2026-06-16

AI tool to slash planning decision times as government accelerates push to build 1.5 million homes

UK — Dept. for Science, Innovation & Technology · 2026-06-16

World’s first national framework for quantum standards to boost UK leadership and trade in groundbreaking future tech

UK — Dept. for Science, Innovation & Technology · 2026-06-12

When AI Leaves the Lab: Testing Frontier Models in Government Cyber Defence

Publishing bodies represented

UK — Dept. for Science, Innovation & Technologylast update 2026-07-01

Frequently asked

Who will the Cyber Security and Resilience Bill apply to?

It builds on the NIS Regulations 2018, which cover operators of essential services in sectors such as energy, transport, water, health and digital infrastructure, plus certain digital service providers. The government has confirmed the Bill will extend scope to managed service providers and create mechanisms to address critical suppliers, with data centres also within the framework's ambit; precise boundaries depend on the final text and secondary legislation.

Who will enforce the new regime?

The existing model of sectoral competent authorities is expected to continue: regulators such as Ofcom, Ofgem and the health and transport authorities for their sectors, and the Information Commissioner's Office for relevant digital services, with the National Cyber Security Centre providing technical support rather than acting as a regulator. The Bill is intended to strengthen these regulators' information, enforcement and cost recovery powers.

How does the Bill change incident reporting?

The stated intention is a broader and faster reporting regime: notification of a wider range of significant incidents, including some that do not interrupt service, with an initial report expected within around 24 hours and a fuller report within 72 hours, and reporting to both the regulator and the NCSC. Exact triggers and timelines will be fixed in the enacted legislation and accompanying regulations.

Search the full UK Cyber Security & Resilience Bill record — free.

Free forever — 20 searches a day, and your first 14 days include full access. No card needed. The live dashboard, alerts, summaries and exports come with a plan from £49.99/mo.

Start searching free →