Legislative tracker

Cyber Security and Resilience Bill: the legislative timeline

Where is the Cyber Security and Resilience Bill up to? This is a live tracker of its progress through Parliament, from the King's Speech announcement to the duties that will follow Royal Assent. We update it at each stage.

Last reviewed 14 July 2026 · all sources linked in the text

Stage Timing Status What it means
King's Speech announcement July 2024 Done The government announced the Cyber Security and Resilience Bill in the King's Speech, setting out its intention to strengthen the UK's cyber resilience and to update and expand the Network and Information Systems (NIS) Regulations 2018.
Policy statement published 1 April 2025 Done The government published its Cyber Security and Resilience Policy Statement (Command Paper CP 1299), laid before Parliament, describing the intended scope and measures: bringing more organisations into scope including managed service providers and data centres, strengthening incident reporting and giving regulators stronger powers.
Introduction to Parliament (First Reading) 12 November 2025 Done The Bill was formally introduced to the House of Commons and given its First Reading, at which point the Bill text was published and could be read in full. Its full title is the Cyber Security and Resilience (Network and Information Systems) Bill.
Second Reading (Commons) 6 January 2026 Done The first full debate on the general principles of the Bill, held in the House of Commons.
Committee stage (Commons) February 2026 Done Detailed, line-by-line scrutiny of the Bill in the House of Commons, where amendments were proposed and considered.
Report stage and Third Reading (Commons) June 2026 Done Further consideration and amendment, then the final Commons vote. The Bill cleared all of its House of Commons stages and passed to the House of Lords.
Lords stages Second Reading 14 July 2026 In progress The Bill is now before the House of Lords, which held its Second Reading on 14 July 2026. Lords committee and report stages follow, after which both Houses must agree the final text.
Royal Assent Expected late 2026 Expected The point at which the Bill becomes an Act. This has not happened yet and no date is confirmed: late 2026 is the widely reported expectation rather than a fixed date. Statutory duties and deadlines begin to take shape from this stage onward.
Secondary legislation and statutory instruments Consultation during 2026, instruments to follow Expected The detailed rules that set the in-scope entities, duties and deadlines are made through secondary legislation after Royal Assent, covering data centres, managed service providers, large load controllers, designated critical suppliers, incident reporting and cost recovery. The government has said stakeholder consultation is planned during 2026.
Duties commence Phased from Royal Assent through to 2028 Expected Commencement is phased. Future-proofing and post-implementation review provisions apply from day one, the statement of strategic priorities and information sharing rules from around month two, and the substantive duties on in-scope organisations follow through secondary legislation, with implementation reported as running to 2028. This is the point at which preparation done early pays off.

Status is drawn from the government's published position and Parliament's own record. The announcement and policy statement sit on the gov.uk Cyber Security and Resilience Bill collection, and the Bill's progress through Parliament is recorded on bills.parliament.uk. We re-verify this page at each stage and whenever the government or Parliament publishes.

Reading the tracker

What matters in practice

3D illustration of tracking the Bill as it moves through its stages

A live tracker

This page is updated at each stage of the Bill's journey through Parliament, from introduction and Second Reading to the Lords stages and Royal Assent. Check back for the current status rather than relying on a snapshot.

3D illustration showing that no legal duties apply until the Bill becomes law

No duties yet

The Bill has not received Royal Assent, so there are no statutory duties or deadlines to comply with today. The right stance now is to understand the direction of travel and prepare early, not to try to comply with rules that are not yet law.

the milestone the Bill is working towards

What Royal Assent changes

Royal Assent turns the Bill into an Act, and the secondary legislation that follows sets the in-scope entities, duties and deadlines. That is when readiness work moves from optional to time-sensitive for in-scope organisations.

For the background to the Bill, read what the Bill is, see who is in scope, or compare it with the EU regime on our NIS2 and the UK Bill page.

3D rocket illustration for booking a free discovery call about the Bill

Prepare early, not in a panic

Get ahead of the timeline

Book a discovery call to understand your likely exposure and start preparing before Royal Assent sets the duties and deadlines.