Legislative tracker
Cyber Security and Resilience Bill: the legislative timeline
Where is the Cyber Security and Resilience Bill up to? This is a live tracker of its progress through Parliament, from the King's Speech announcement to the duties that will follow Royal Assent. We update it at each stage.
Last reviewed 14 July 2026 · all sources linked in the text
| Stage | Timing | Status | What it means |
|---|---|---|---|
| King's Speech announcement | July 2024 | Done | The government announced the Cyber Security and Resilience Bill in the King's Speech, setting out its intention to strengthen the UK's cyber resilience and to update and expand the Network and Information Systems (NIS) Regulations 2018. |
| Policy statement published | 2025 | Done | The government published a policy statement on gov.uk describing the intended scope and measures, including bringing more organisations into scope such as managed service providers, strengthening incident reporting and giving regulators stronger powers. |
| Introduction to Parliament (First Reading) | Expected | Expected | The Bill is formally introduced to Parliament and given its First Reading, at which point the Bill text is published and can be read in full. |
| Second Reading | Expected | Expected | The first full debate on the general principles of the Bill in the House where it is introduced. |
| Committee stage | Expected | Expected | Detailed, line-by-line scrutiny of the Bill, where amendments are proposed and considered. |
| Report stage and Lords stages | Expected | Expected | Further consideration and amendment, then the same stages in the second House, before both Houses agree the final text. |
| Royal Assent | Expected | Expected | The point at which the Bill becomes an Act. This has not happened yet, and no date is confirmed. Statutory duties and deadlines begin to take shape from this stage onward. |
| Secondary legislation and statutory instruments | Expected (after Royal Assent) | Expected | The detailed rules that set the in-scope entities, duties and deadlines are made through secondary legislation after Royal Assent. Each statutory instrument fills in part of the picture. |
| Duties commence | Expected (after secondary legislation) | Expected | In-scope organisations, including managed service providers, must meet the new requirements. This is the point at which preparation done early pays off. |
Status is drawn from the government's published position and Parliament's own record. The announcement and policy statement sit on the gov.uk Cyber Security and Resilience Bill collection, and the Bill's progress through Parliament is recorded on bills.parliament.uk. We re-verify this page at each stage and whenever the government or Parliament publishes.
Reading the tracker
What matters in practice
A live tracker
This page is updated at each stage of the Bill's journey through Parliament, from introduction and Second Reading to the Lords stages and Royal Assent. Check back for the current status rather than relying on a snapshot.
No duties yet
The Bill has not received Royal Assent, so there are no statutory duties or deadlines to comply with today. The right stance now is to understand the direction of travel and prepare early, not to try to comply with rules that are not yet law.
What Royal Assent changes
Royal Assent turns the Bill into an Act, and the secondary legislation that follows sets the in-scope entities, duties and deadlines. That is when readiness work moves from optional to time-sensitive for in-scope organisations.
For the background to the Bill, read what the Bill is, see who is in scope, or compare it with the EU regime on our NIS2 and the UK Bill page.
Prepare early, not in a panic
Get ahead of the timeline
Book a discovery call to understand your likely exposure and start preparing before Royal Assent sets the duties and deadlines.