Plain-English explainer
What is the Cyber Security and Resilience Bill?
A direct, sourced answer to the question, plus what the Bill changes, who it is likely to affect, where it is in Parliament and how it differs from the EU's NIS2 and Cyber Resilience Act.
Last reviewed 14 July 2026 · all sources linked in the text
The Cyber Security and Resilience Bill is the UK government's planned law to strengthen the cyber resilience of the country's essential and digital services.
It is widely described as the UK's NIS2-equivalent, and it updates and expands the existing Network and Information Systems (NIS) Regulations 2018, the current UK rules for operators of essential services and digital service providers. It was announced in the King's Speech in July 2024, and the government has since published a policy statement on gov.uk setting out its intended scope and measures. It is sometimes shortened to the CSR Bill or the Cyber Resilience Bill.
As things stand it has not yet received Royal Assent, so there are no statutory duties or deadlines to meet today. It is progressing through the legislative process, which is why the sensible move now is to understand it and prepare early rather than to comply now.
What it changes
An update to the existing UK cyber regime
Rather than a brand new regime, the Bill modernises and widens the rules the UK already has. Four themes run through the government's stated intentions.
It updates the NIS Regulations 2018
The Bill builds on the UK's existing Network and Information Systems Regulations 2018, the current rules for essential services and digital service providers, modernising them for today's threats rather than starting from scratch.
Wider scope, including MSPs
The government has signalled that more organisations will be brought into scope, including managed service providers, expected to follow an essential entities and important entities style categorisation similar to NIS2.
Stronger incident reporting
The Bill is expected to strengthen the duty to report significant cyber incidents, giving regulators and the wider system faster, clearer visibility of what is happening.
Stronger regulator powers
Regulators are expected to gain stronger powers to oversee and enforce cyber resilience across the sectors and organisations in scope.
What it will require
Reading the policy statement
The government's published policy statement sets out the intended direction: wider scope including managed service providers, stronger incident reporting, and stronger powers for regulators to oversee and enforce cyber resilience across essential and digital services.
These are stated intentions rather than final legal duties. The binding requirements, sectors and deadlines will be fixed by the Bill as passed and by the secondary legislation (statutory instruments) that follows, so the detail may change as the Bill progresses. The NCSC and gov.uk remain the authoritative sources as measures are confirmed.
Who it affects
More organisations, including MSPs
The Bill is expected to bring more organisations into scope than the current NIS Regulations 2018, including managed service providers, using an essential entities and important entities style categorisation. Exact definitions are set by the Bill and secondary legislation still to follow, so final scope is not confirmed. CyPro is itself an in-scope MSP, preparing for this alongside its clients.
Check who is in scopeWhere it is now
Announced in 2024, progressing through Parliament
Announced in the King's Speech in July 2024, with a policy statement published on gov.uk, the Bill is working its way through the legislative process rather than sitting in force. Statutory duties and deadlines arrive at Royal Assent and through the secondary legislation that follows. We keep the live stage on the timeline.
See the full timelineDo not confuse these
How it differs from the EU's laws
Versus the EU NIS2 directive
They share the same goal and the Bill is the UK's NIS2-equivalent, but jurisdiction and detail differ. NIS2 is EU law transposed by member states; the Bill is UK legislation that updates the NIS Regulations 2018. NIS2 does not apply directly in the UK, so the Bill is the domestic regime to plan around.
Versus the EU Cyber Resilience Act
A different law entirely, easy to confuse because both use the word resilience. The EU Cyber Resilience Act sets cyber security requirements for products with digital elements, aimed mainly at manufacturers. The UK Bill is about the resilience of services and the organisations that run them, not product security.
The full comparison, and where NIS2 language maps onto the UK Bill, is set out on the NIS2 and the UK Bill page.
How to prepare early
Understand it now, so duties do not find you starting
There are no duties to comply with yet, so preparation is about readiness, not compliance. Sensible groundwork includes identifying your critical services, reviewing your incident detection and reporting, and strengthening supply chain and access controls. Much of this aligns with established good practice and frameworks such as ISO 27001 and NCSC guidance, so the work is rarely wasted whatever the final scope turns out to be.
A discovery call with CyPro can help you understand whether the Bill is likely to apply to you and where to focus first.
Plan ahead
Prepare for the Cyber Security and Resilience Bill
Book a discovery call to understand whether the Bill is likely to apply to you, what it will probably require and how to get ready ahead of Royal Assent. Clear guidance, no scaremongering.