What stage is the Bill actually at?
| Stage | Date |
|---|---|
| Commons introduction | 12 November 2025 |
| All Commons stages | Completed |
| Lords first reading (HL Bill 32) | 17 June 2026 |
| Lords second reading | 14 July 2026 |
| Current stage | Lords committee |
| Royal Assent | None |
The Bill amends the Network and Information Systems Regulations 2018; it does not replace them. The 2018 Regulations remain the operative law and continue to cover energy, transport, health, drinking water, digital infrastructure and some digital services. If you are regulated for network and information systems in the UK today, you are regulated under the 2018 Regulations in their existing form.
A Bill at committee stage in the second House is still capable of change. That is a reason to track it, not a reason to build a control programme against its current text.
Who comes into scope that was not before?
The scope expansion is the genuinely useful part of the Bill, because it reaches organisations that do not think of themselves as critical infrastructure:
- Data centres — medium, large and enterprise.
- Managed service providers — medium and large.
- Large load controllers.
- Designated critical suppliers.
The last category is the one most likely to catch people unprepared. A critical supplier is brought into scope by designation — that is, by another organisation's dependency on you and a regulator's decision, not by your own read of your sector. A firm that supplies a niche component or a single piece of software to a regulated operator can find itself inside a regime it never considered relevant.
Managed service providers sit in a similar position. An MSP that runs a client's identity estate, backup or endpoint management does not usually describe itself as national infrastructure. In the Bill's terms, the concentration of privileged access across many clients is precisely the point.
What will the duties be?
The core obligation is to take appropriate and proportionate security measures, on an all-hazards basis — so not only cyber attack, but power failure, physical events and supply chain disruption. Twelve sector regulators oversee the regime, with cost recovery so that regulators can charge for supervision, and higher maximum penalties than the 2018 Regulations allow.
Incident reporting is the part with hard numbers:
- Initial notification within 24 hours.
- Full report within 72 hours.
- The NCSC informed at the same time as the regulator — one reporting event, two recipients.
- Relevant digital service providers, managed service providers and data centre operators must also identify and notify affected customers.
When do the duties actually bite?
This is the nuance that most published UK commentary gets wrong.
| Commencement point | What starts |
|---|---|
| At Royal Assent | Future-proofing powers; post-implementation review |
| Month 2 | Strategic priorities; information sharing |
| Secondary legislation, timing TBD | Data centres; managed service providers; critical suppliers; expanded incident reporting; cost recovery |
Royal Assent will produce headlines and, in a fair amount of vendor content, a wave of claims that new duties have landed. They will not have. The obligations that change what an organisation must do are in the third row, and the third row has no date.
How does the UK compare with Germany, Denmark, Belgium and Norway?
| Jurisdiction | Status | In force | Reporting clock | Management liability |
|---|---|---|---|---|
| United Kingdom | Bill, Lords committee stage | Not in force | 24h / 72h (proposed) | No distinct personal duty in the Bill |
| Germany | NIS2UmsuCG; new BSIG | 6 December 2025 | 24h / 72h / 1 month | BSIG § 38 — management must umsetzen und überwachen; liability to the entity under company law; mandatory training |
| Denmark | NIS 2-loven (LOV nr 434 af 06/05/2025) | 1 July 2025 | 24h / 72h / 1 month | § 7 — management body approves measures and undergoes training; for væsentlige enheder only, the authority may temporarily bar an individual from management functions |
| Belgium | NIS2 law of 26 April 2024 | 18 October 2024 | NIS2 timescales | Regulator: Centre for Cybersecurity Belgium (CCB) |
| Norway | NIS2 does not apply; digitalsikkerhetsloven implements NIS1 | 1 October 2025 | 24h to NSM | No NIS2 management-liability regime |
Belgium was among the first movers, in force within a year of the directive. Germany's fines reach €10m or 2% of turnover for besonders wichtige Einrichtungen and €7m or 1.4% for wichtige Einrichtungen. Denmark's regime has been operating since mid-2025, and the personal dimension of it is the sharpest in this group — see the Danish management-liability treatment.
Against that, the UK is the laggard. Norway is an outlier for a different reason: NIS2 has not been incorporated into the EEA Agreement and does not apply there at all. A Norwegian entity in a group otherwise governed by NIS2 sits under a materially lighter, NIS1-based regime. Do not read EEA membership as implying NIS2 coverage; several group-wide compliance programmes have.
Why is 24 hours the hard part?
The clock is the same in every regime above and in the UK Bill, and it deserves more attention than the scope debate. Twenty-four hours is not long to establish what happened. It is long enough to know that something happened, and often not long enough to know what it was.
Automation makes this materially worse. Where automated systems or agents have taken a series of actions, the first-day question is not only "was there an intrusion" but "which of these actions were authorised". If you cannot answer that within the first day, you report on an uncertain basis — and the quality of that early notification depends directly on how fast you can reconstruct an ordered event sequence. That is a records capability, not an incident-response one, and it has to exist before the incident. See the treatment of audit trails for AI agents.
The 72-hour report is where the 24-hour notification gets corrected. A correction that changes the character of the incident — from contained to not contained, from internal error to intrusion — is a considerably worse conversation with a regulator than an accurate but incomplete first notification would have been.
For MSPs and data centre operators there is a second clock running in parallel: the duty to identify and notify affected customers. That presupposes a current, accurate mapping of customers to systems. Most organisations discover the state of that mapping during the incident.
What is worth doing now, given it is not law?
- Establish whether you fall into a new category — MSP, data centre operator, large load controller, or a plausible candidate for critical supplier designation.
- Do not build a UK compliance programme against a Bill still in committee in the Lords. The text can change.
- Do the reporting-readiness work regardless. Anyone with EU operations or EU customers is already inside the German, Danish or Belgian regimes, and those already require it.
- Test event reconstruction against the clock: can you produce an ordered sequence of what your systems did, within 24 hours, on a weekend?
- Fix incident classification: who decides that an incident is notifiable, at what threshold, and out of hours.
- For MSPs and data centres, build the customer-notification list now and keep it current.
- Track the secondary legislation, not Royal Assent. Assent is the news event; the statutory instruments are the obligation.
In the meantime, the UK obligations that actually bind come from the 2018 Regulations, sector regulators, and data protection law — including the automated decision-making regime introduced by the DUAA, which is in force and does apply.
Frequently asked questions
Is the Bill law?
No. It is at Lords committee stage as HL Bill 32 and has been carried over into the 2026-27 session. There has been no Royal Assent.
What applies to UK operators today?
The NIS Regulations 2018, unamended. The Bill amends them; it does not replace them.
Will managed service providers be in scope?
Yes — medium and large MSPs, along with data centres, large load controllers and designated critical suppliers. That scope arrives via secondary legislation, not at Royal Assent.
What are the reporting deadlines?
Initial notification within 24 hours, full report within 72 hours, NCSC informed at the same time as the regulator. RDSPs, MSPs and data centre operators must also notify affected customers.
Is the UK regime equivalent to NIS2?
Similar in shape, later in time. The 24h/72h clock and the all-hazards duty are recognisable, but Germany, Denmark and Belgium have been operating theirs for months or years.
Does NIS2 apply in Norway?
No. It has not been incorporated into the EEA Agreement. Norway's digitalsikkerhetsloven implements NIS1 and requires 24-hour reporting to NSM.
Related
- AI agent governance — the complete guide
- How to build an audit trail for AI agents
- Automated decision-making after the DUAA
- NIS 2-loven: management liability in Denmark
BarzelVault records what each automated action was, who or what authorised it and on what policy version, before it executes — which is the material a 24-hour notification has to be assembled from, and the difference between reconstructing a sequence and guessing at one.
In practice
Contain the incident first, prove what happened second — inside the reporting window.
Reporting clocks run in hours, and management liability turns on whether controls were implemented and supervised, not merely approved. Barzel isolates credentials, cuts an agent off in one action and keeps signed receipts of what ran — the material a notification and a board report are written from.
Cyber Security and Resilience Bill: Lords committee stage
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Sources
- Cyber Security and Resilience (Network and Information Systems) Bill, HL Bill 32 — UK Parliament bill stages.
- DSIT factsheets on the Cyber Security and Resilience Bill, updated 30 June 2026.
- The Network and Information Systems Regulations 2018.
- Germany: NIS2UmsuCG; BSIG (new), in force 6 December 2025, § 38.
- Denmark: NIS 2-loven, LOV nr 434 af 06/05/2025, §§ 7 and 13.
- Belgium: NIS2 law of 26 April 2024, in force 18 October 2024; Centre for Cybersecurity Belgium.
- Norway: digitalsikkerhetsloven, in force 1 October 2025; NSM incident reporting.
This article is for information and does not constitute legal advice. Position as at 2 September 2026.