Straight answers

Frequently asked questions

The questions organisations ask most about the UK Cyber Security and Resilience Bill, answered plainly and sourced to gov.uk, Parliament and the NCSC. Not covered here? Raise it on a discovery call and you will get the same direct answer.

3D illustration of common questions answered about the Cyber Security and Resilience Bill
What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill is the UK government's planned law to strengthen the cyber resilience of the country's essential and digital services. It is widely described as the UK's NIS2-equivalent, and it updates and expands the existing Network and Information Systems (NIS) Regulations 2018.

It was announced in the King's Speech in July 2024, and the government has published a policy statement on gov.uk setting out its intended scope and measures. It is sometimes shortened to the CSR Bill.

The Bill explained in full

Is the Cyber Security and Resilience Bill law yet, and when does it come into force?

Not yet. As things stand it has not received Royal Assent, so there are no statutory duties or deadlines to meet today. It is progressing through the legislative process after being announced in July 2024.

Duties will begin once the Bill receives Royal Assent and the secondary legislation (statutory instruments) that sets the detail is made. Because the exact stage and dates are moving, we track the Bill's progress on the timeline rather than fixing a date here.

Where the Bill is now

Does NIS2 apply in the UK?

No, not directly. NIS2 is an EU directive and the UK is no longer an EU member state, so NIS2 does not apply to UK organisations as law. The UK's own equivalent is the Cyber Security and Resilience Bill, which builds on the Network and Information Systems Regulations 2018.

UK organisations that operate in the EU, or that supply EU essential and important entities, may still encounter NIS2 through those markets and contracts, but the domestic regime to plan around is the Bill.

NIS2 and the UK Bill compared

What is the difference between the Bill and the EU NIS2 directive?

They share the same goal, raising the cyber resilience of essential and digital services, and the Bill is widely described as the UK's NIS2-equivalent. The difference is jurisdiction and detail: NIS2 is EU law transposed by member states, while the Bill is UK legislation that updates and expands the UK's NIS Regulations 2018.

The Bill is expected to use an essential entities and important entities style categorisation, as NIS2 does, but the precise UK definitions, sectors and duties are set by the Bill and the secondary legislation that follows it, so they will not match NIS2 line for line.

NIS2 and the UK Bill compared

Who is in scope, and will it apply to my company?

The Bill is expected to bring more organisations into scope than the current NIS Regulations 2018, including managed service providers. The government has signalled an essential entities and important entities style categorisation, similar to NIS2.

Exact in-scope definitions are set by the Bill and by secondary legislation still to follow, so final scope is not confirmed. If you operate in an essential or digital service sector, or you supply organisations that do, it is sensible to assume you may be affected and to prepare.

Check who is in scope

What must managed service providers (MSPs) do under the Bill?

Managed service providers are expected to be brought into scope for the first time, reflecting their access to clients' systems and data. The government has indicated the Bill will extend duties around security measures, incident reporting and regulator oversight to MSPs.

The specific obligations will be confirmed by the Bill and its secondary legislation. CyPro is itself an in-scope MSP, so we are preparing for this alongside our clients rather than watching from the sidelines. The practical starting points are mapping the services you run for clients, tightening incident reporting, and strengthening supply chain controls.

What in-scope means for you

How does the Bill relate to the NIS Regulations 2018?

The Network and Information Systems (NIS) Regulations 2018 are the UK's existing cyber rules for operators of essential services and relevant digital service providers. The Cyber Security and Resilience Bill updates and expands that framework rather than replacing the idea behind it.

The government has said the Bill will widen the range of organisations covered, strengthen incident reporting and give regulators stronger powers, modernising the 2018 regime for current threats.

The Bill explained in full

What will the Bill require organisations to do?

The government's published policy statement sets out the intended direction: wider scope including managed service providers, stronger incident reporting, and stronger powers for regulators to oversee and enforce cyber resilience across essential and digital services.

These are stated intentions rather than final legal duties. The binding requirements, sectors and deadlines will be fixed by the Bill as passed and by the secondary legislation that follows, so the detail may change as the Bill progresses.

What the Bill will require

What is the difference between the Bill and the EU Cyber Resilience Act?

They are different laws and easy to confuse because both use the word resilience. The EU Cyber Resilience Act sets cyber security requirements for products with digital elements, placing duties mainly on manufacturers of hardware and software sold in the EU.

The UK Cyber Security and Resilience Bill is about the resilience of essential and digital services and the organisations that run them, not product security. The Bill is sometimes shortened to the Cyber Resilience Bill, which adds to the confusion, but it is a separate UK measure from the EU Cyber Resilience Act.

The Bill explained in full

What is the difference between GDPR and the NIS regime?

They cover different things. The UK GDPR and the Data Protection Act 2018 protect personal data and privacy. The NIS regime, and the Cyber Security and Resilience Bill that updates it, focus on the security and resilience of the network and information systems behind essential and digital services.

An organisation can be subject to both at once: data protection duties for the personal data it holds, and cyber resilience duties for the services it operates. They complement each other rather than overlap.

NIS2 and the UK Bill compared

Is the CSR Bill the same as the Cyber Resilience Bill?

Yes. Cyber Security and Resilience Bill is the full and official name. It is sometimes shortened to the CSR Bill or the Cyber Resilience Bill, and the acronym CSRB occasionally appears, but the full name is the clearest way to refer to it.

Take care with Cyber Resilience Bill in particular, because it is easily mistaken for the EU Cyber Resilience Act, which is a separate product security law.

The Bill explained in full

How should we prepare now, before the Bill becomes law?

There are no statutory duties to comply with yet, so the sensible stance is to understand the Bill and prepare early rather than to comply now. Good groundwork includes identifying your critical services, reviewing your incident detection and reporting, and strengthening supply chain and access controls.

Much of this aligns with established good practice and frameworks such as ISO 27001 and NCSC guidance, so preparation is rarely wasted. A discovery call with CyPro can help you understand whether the Bill is likely to apply to you and where to focus first.

Talk it through with CyPro

3D rocket illustration for booking a free discovery call about the Bill

One question left?

Ask it on a discovery call

Book a discovery call to understand whether the Cyber Security and Resilience Bill is likely to apply to you and how to prepare early. Clear guidance, no scaremongering.