Plain-English explainer

What is the Cyber Security and Resilience Bill?

A direct, sourced answer to the question, plus what the Bill changes, who it is likely to affect, where it is in Parliament and how it differs from the EU's NIS2 and Cyber Resilience Act.

Last reviewed 14 July 2026 · all sources linked in the text

The Cyber Security and Resilience Bill is the UK government's planned law to strengthen the cyber resilience of the country's essential and digital services.

It is widely described as the UK's NIS2-equivalent, and it updates and expands the existing Network and Information Systems (NIS) Regulations 2018, the current UK rules for operators of essential services and digital service providers. It was announced in the King's Speech in July 2024, and the government has since published a policy statement on gov.uk setting out its intended scope and measures. It is sometimes shortened to the CSR Bill or the Cyber Resilience Bill.

As things stand it has not yet received Royal Assent, so there are no statutory duties or deadlines to meet today. It is progressing through the legislative process, which is why the sensible move now is to understand it and prepare early rather than to comply now.

What it changes

An update to the existing UK cyber regime

Rather than a brand new regime, the Bill modernises and widens the rules the UK already has. Four themes run through the government's stated intentions.

3D illustration of the existing NIS Regulations 2018 that the Bill updates

It updates the NIS Regulations 2018

The Bill builds on the UK's existing Network and Information Systems Regulations 2018, the current rules for essential services and digital service providers, modernising them for today's threats rather than starting from scratch.

3D illustration of managed service providers newly brought into scope by the Bill

Wider scope, including MSPs

The government has signalled that more organisations will be brought into scope, including managed service providers, expected to follow an essential entities and important entities style categorisation similar to NIS2.

3D illustration of stronger incident reporting duties under the Bill

Stronger incident reporting

The Bill is expected to strengthen the duty to report significant cyber incidents, giving regulators and the wider system faster, clearer visibility of what is happening.

3D illustration of expanded regulator powers and penalties under the Bill

Stronger regulator powers

Regulators are expected to gain stronger powers to oversee and enforce cyber resilience across the sectors and organisations in scope.

What it will require

Reading the policy statement

The government's published policy statement sets out the intended direction: wider scope including managed service providers, stronger incident reporting, and stronger powers for regulators to oversee and enforce cyber resilience across essential and digital services.

These are stated intentions rather than final legal duties. The binding requirements, sectors and deadlines will be fixed by the Bill as passed and by the secondary legislation (statutory instruments) that follows, so the detail may change as the Bill progresses. The NCSC and gov.uk remain the authoritative sources as measures are confirmed.

3D illustration of the policy and governance intent behind the Bill

Who it affects

More organisations, including MSPs

The Bill is expected to bring more organisations into scope than the current NIS Regulations 2018, including managed service providers, using an essential entities and important entities style categorisation. Exact definitions are set by the Bill and secondary legislation still to follow, so final scope is not confirmed. CyPro is itself an in-scope MSP, preparing for this alongside its clients.

Check who is in scope

Where it is now

Announced in 2024, progressing through Parliament

Announced in the King's Speech in July 2024, with a policy statement published on gov.uk, the Bill is working its way through the legislative process rather than sitting in force. Statutory duties and deadlines arrive at Royal Assent and through the secondary legislation that follows. We keep the live stage on the timeline.

See the full timeline

Do not confuse these

How it differs from the EU's laws

Versus the EU NIS2 directive

They share the same goal and the Bill is the UK's NIS2-equivalent, but jurisdiction and detail differ. NIS2 is EU law transposed by member states; the Bill is UK legislation that updates the NIS Regulations 2018. NIS2 does not apply directly in the UK, so the Bill is the domestic regime to plan around.

Versus the EU Cyber Resilience Act

A different law entirely, easy to confuse because both use the word resilience. The EU Cyber Resilience Act sets cyber security requirements for products with digital elements, aimed mainly at manufacturers. The UK Bill is about the resilience of services and the organisations that run them, not product security.

The full comparison, and where NIS2 language maps onto the UK Bill, is set out on the NIS2 and the UK Bill page.

How to prepare early

Understand it now, so duties do not find you starting

There are no duties to comply with yet, so preparation is about readiness, not compliance. Sensible groundwork includes identifying your critical services, reviewing your incident detection and reporting, and strengthening supply chain and access controls. Much of this aligns with established good practice and frameworks such as ISO 27001 and NCSC guidance, so the work is rarely wasted whatever the final scope turns out to be.

A discovery call with CyPro can help you understand whether the Bill is likely to apply to you and where to focus first.

3D rocket illustration for booking a free discovery call about the Bill

Plan ahead

Prepare for the Cyber Security and Resilience Bill

Book a discovery call to understand whether the Bill is likely to apply to you, what it will probably require and how to get ready ahead of Royal Assent. Clear guidance, no scaremongering.