Most writing about the Cyber Security and Resilience Bill comes
from law firms (accurate, rarely practical) or vendors
(practical, rarely complete). CyPro sits in the gap: a UK cyber
security consultancy that is itself an in-scope managed service
provider, tracking the Bill for its clients and for its own
business. That gives it a practitioner's view of what the Bill is
likely to require, and which preparations are worth starting now.
Every fact on this site traces to a primary source: the Bill, the
government policy statement, gov.uk and Parliament publications,
NCSC guidance and the NIS Regulations 2018 the Bill updates.
Pages carry a last-reviewed date, and we update them when the
government or Parliament publish. The Bill has not yet received
Royal Assent, so much remains to be settled, and where that is
the case we say so rather than rounding it off.
To be clear about independence: this is a commercial site run by
a consultancy that helps organisations prepare for cyber
regulation. It is not government guidance, and it never replaces
reading the Bill or taking legal advice on the hard scoping
questions. What it does is make the coming regime genuinely
navigable, so you can prepare early rather than react late.