The Cyber Security and Resilience Bill was introduced to the House of Commons in November 2025 and completed its committee stage in February 2026. Report stage and third reading are scheduled for June 2026 and Royal Assent is expected before the end of the year. The bill is the most significant reform of UK cybersecurity legislation in nearly a decade and its passage will fundamentally change what regulated organisations are required to do when they discover an incident.
The core change is a dual reporting obligation. Organisations must issue an early warning to both their sector regulator and the NCSC within 24 hours of becoming aware of a significant incident. This must be followed by a full incident report within 72 hours. The current NIS Regulations 2018 required notification to the sector regulator only, with no specific 24-hour early warning obligation. The new dual notification to both regulator and NCSC is a material change that requires a different kind of incident classification process.
The bill also substantially expands the scope of regulated organisations. Managed service providers, data centres and designated critical suppliers are brought within the framework for the first time. These categories contain a large number of organisations that have not historically operated under a cybersecurity regulatory obligation and many of them are not currently aware that the bill is likely to apply to them.
The Compliance Obligation Flow
The diagram below maps the key obligations under the bill from initial scope determination through to enforcement. The ransomware payment rules shown in the callout on the right are among the most operationally significant provisions and apply regardless of whether an organisation is a critical infrastructure operator.

Diagram 1: UK Cyber Security and Resilience Bill key obligations flow from scope determination to enforcement
The 24-Hour Requirement in Practice
The 24-hour early warning obligation is the provision that will cause the most operational difficulty for organisations that do not prepare in advance. Twenty four hours from becoming aware of a significant incident is a very short window in which to classify the incident, determine whether it meets the reporting threshold, identify the correct sector regulator contacts and NCSC notification channel and submit a coherent early warning.
Most organisations that have tested this process in tabletop exercises find that their current incident response playbooks do not have a clear decision point for regulatory reporting. The incident is triaged, contained and investigated before anyone thinks about whether a regulator needs to be told. Under the new regime that sequence needs to be reversed. Regulatory reporting classification should happen in parallel with technical response from the first hour.
The NCSC’s early warning system, which the government has been urging organisations to join ahead of the bill’s passage, provides the technical channel for the 24-hour notification. Organisations that are not already registered should register now. The registration process is straightforward and being on the system before an incident significantly simplifies the notification process during one.
Comparing the New Bill Against Current NIS Obligations
| Obligation Area | Current NIS Regulations 2018 | New Cyber Security and Resilience Bill |
| Incident reporting timeline | Without undue delay to sector regulator | 24-hour early warning plus 72-hour full report to both sector regulator and NCSC |
| Notification recipients | Sector regulator only | Sector regulator AND NCSC (dual notification mandatory) |
| Scope of regulated entities | Essential service operators and relevant digital service providers | Adds managed service providers, data centres and designated critical suppliers |
| Customer notification | Not required | Mandatory where relevant customers may be affected by the incident |
| Maximum penalty | £17 million under existing framework | £10 million or 2 percent of turnover for standard; £17 million or 4 percent for serious; £100,000 per day ongoing |
| Ransomware reporting | No specific requirement | Mandatory for all organisations; payment banned for CNI and public sector |
| Supply chain obligations | Limited | Designated Critical Supplier mechanism creates formal requirements for high-risk suppliers |
Steps to Take Before Royal Assent
The first step is scope determination. If your organisation provides managed IT services, operates a data centre or supplies critical digital infrastructure to an essential service operator, you should assume you will be in scope and begin preparing accordingly. Waiting for the final text and implementing guidance to be published before starting will leave insufficient time.
The second step is to review and update your incident response playbook to include a regulatory reporting decision point within the first hour of incident detection. This decision point should specify who is responsible for making the reporting determination, what the reporting threshold criteria are and how the notification will be submitted.
The third step is to register with the NCSC early warning system if you have not already done so and to identify your primary sector regulator contact. Having both channels established before an incident is the difference between a stressful but manageable process and a chaotic one.

Leave a Reply