Legislative tracker

Cyber Security and Resilience Bill: the legislative timeline

Where is the Cyber Security and Resilience Bill up to? This is a live tracker of its progress through Parliament, from the King's Speech announcement to the duties that will follow Royal Assent. We update it at each stage.

Last reviewed 14 July 2026 · all sources linked in the text

Stage Timing Status What it means
King's Speech announcement July 2024 Done The government announced the Cyber Security and Resilience Bill in the King's Speech, setting out its intention to strengthen the UK's cyber resilience and to update and expand the Network and Information Systems (NIS) Regulations 2018.
Policy statement published 2025 Done The government published a policy statement on gov.uk describing the intended scope and measures, including bringing more organisations into scope such as managed service providers, strengthening incident reporting and giving regulators stronger powers.
Introduction to Parliament (First Reading) Expected Expected The Bill is formally introduced to Parliament and given its First Reading, at which point the Bill text is published and can be read in full.
Second Reading Expected Expected The first full debate on the general principles of the Bill in the House where it is introduced.
Committee stage Expected Expected Detailed, line-by-line scrutiny of the Bill, where amendments are proposed and considered.
Report stage and Lords stages Expected Expected Further consideration and amendment, then the same stages in the second House, before both Houses agree the final text.
Royal Assent Expected Expected The point at which the Bill becomes an Act. This has not happened yet, and no date is confirmed. Statutory duties and deadlines begin to take shape from this stage onward.
Secondary legislation and statutory instruments Expected (after Royal Assent) Expected The detailed rules that set the in-scope entities, duties and deadlines are made through secondary legislation after Royal Assent. Each statutory instrument fills in part of the picture.
Duties commence Expected (after secondary legislation) Expected In-scope organisations, including managed service providers, must meet the new requirements. This is the point at which preparation done early pays off.

Status is drawn from the government's published position and Parliament's own record. The announcement and policy statement sit on the gov.uk Cyber Security and Resilience Bill collection, and the Bill's progress through Parliament is recorded on bills.parliament.uk. We re-verify this page at each stage and whenever the government or Parliament publishes.

Reading the tracker

What matters in practice

3D illustration of tracking the Bill as it moves through its stages

A live tracker

This page is updated at each stage of the Bill's journey through Parliament, from introduction and Second Reading to the Lords stages and Royal Assent. Check back for the current status rather than relying on a snapshot.

3D illustration showing that no legal duties apply until the Bill becomes law

No duties yet

The Bill has not received Royal Assent, so there are no statutory duties or deadlines to comply with today. The right stance now is to understand the direction of travel and prepare early, not to try to comply with rules that are not yet law.

3D illustration of the milestone of Royal Assent for the Bill

What Royal Assent changes

Royal Assent turns the Bill into an Act, and the secondary legislation that follows sets the in-scope entities, duties and deadlines. That is when readiness work moves from optional to time-sensitive for in-scope organisations.

For the background to the Bill, read what the Bill is, see who is in scope, or compare it with the EU regime on our NIS2 and the UK Bill page.

3D rocket illustration for booking a free discovery call about the Bill

Prepare early, not in a panic

Get ahead of the timeline

Book a discovery call to understand your likely exposure and start preparing before Royal Assent sets the duties and deadlines.