The UK Cyber Security and Resilience Bill Will Change Your Incident Response Obligations. Here Is What You Need to Know Before It Passes

The Cyber Security and Resilience Bill was introduced to the House of Commons in November 2025 and completed its committee stage in February 2026. Report stage and third reading are scheduled for June 2026 and Royal Assent is expected before the end of the year. The bill is the most significant reform of UK cybersecurity legislation in nearly a decade and its passage will fundamentally change what regulated organisations are required to do when they discover an incident.

The core change is a dual reporting obligation. Organisations must issue an early warning to both their sector regulator and the NCSC within 24 hours of becoming aware of a significant incident. This must be followed by a full incident report within 72 hours. The current NIS Regulations 2018 required notification to the sector regulator only, with no specific 24-hour early warning obligation. The new dual notification to both regulator and NCSC is a material change that requires a different kind of incident classification process.

The bill also substantially expands the scope of regulated organisations. Managed service providers, data centres and designated critical suppliers are brought within the framework for the first time. These categories contain a large number of organisations that have not historically operated under a cybersecurity regulatory obligation and many of them are not currently aware that the bill is likely to apply to them.

The Compliance Obligation Flow

The diagram below maps the key obligations under the bill from initial scope determination through to enforcement. The ransomware payment rules shown in the callout on the right are among the most operationally significant provisions and apply regardless of whether an organisation is a critical infrastructure operator.

Diagram 1: UK Cyber Security and Resilience Bill key obligations flow from scope determination to enforcement

The 24-Hour Requirement in Practice

The 24-hour early warning obligation is the provision that will cause the most operational difficulty for organisations that do not prepare in advance. Twenty four hours from becoming aware of a significant incident is a very short window in which to classify the incident, determine whether it meets the reporting threshold, identify the correct sector regulator contacts and NCSC notification channel and submit a coherent early warning.

Most organisations that have tested this process in tabletop exercises find that their current incident response playbooks do not have a clear decision point for regulatory reporting. The incident is triaged, contained and investigated before anyone thinks about whether a regulator needs to be told. Under the new regime that sequence needs to be reversed. Regulatory reporting classification should happen in parallel with technical response from the first hour.

The NCSC’s early warning system, which the government has been urging organisations to join ahead of the bill’s passage, provides the technical channel for the 24-hour notification. Organisations that are not already registered should register now. The registration process is straightforward and being on the system before an incident significantly simplifies the notification process during one.

Comparing the New Bill Against Current NIS Obligations

Obligation AreaCurrent NIS Regulations 2018New Cyber Security and Resilience Bill
Incident reporting timelineWithout undue delay to sector regulator24-hour early warning plus 72-hour full report to both sector regulator and NCSC
Notification recipientsSector regulator onlySector regulator AND NCSC (dual notification mandatory)
Scope of regulated entitiesEssential service operators and relevant digital service providersAdds managed service providers, data centres and designated critical suppliers
Customer notificationNot requiredMandatory where relevant customers may be affected by the incident
Maximum penalty£17 million under existing framework£10 million or 2 percent of turnover for standard; £17 million or 4 percent for serious; £100,000 per day ongoing
Ransomware reportingNo specific requirementMandatory for all organisations; payment banned for CNI and public sector
Supply chain obligationsLimitedDesignated Critical Supplier mechanism creates formal requirements for high-risk suppliers

Steps to Take Before Royal Assent

The first step is scope determination. If your organisation provides managed IT services, operates a data centre or supplies critical digital infrastructure to an essential service operator, you should assume you will be in scope and begin preparing accordingly. Waiting for the final text and implementing guidance to be published before starting will leave insufficient time.

The second step is to review and update your incident response playbook to include a regulatory reporting decision point within the first hour of incident detection. This decision point should specify who is responsible for making the reporting determination, what the reporting threshold criteria are and how the notification will be submitted.

The third step is to register with the NCSC early warning system if you have not already done so and to identify your primary sector regulator contact. Having both channels established before an incident is the difference between a stressful but manageable process and a chaotic one.

Leave a Reply

Your email address will not be published.