The latest Parliamentary position is that the Cyber Security and Resilience (Network and Information Systems) Bill (current copy as attached) has completed all Commons stages and is now in the House of Lords.
Please follow this link to monitor the bills progress https://bills.parliament.uk/bills/4035
Latest reading
- House of Lords – Second Reading: 14 July 2026 (yesterday). This is the latest formal Parliamentary stage scheduled for the Bill.
- House of Lords – First Reading: 17 June 2026.
- House of Commons – Third Reading: 16 June 2026, after which the Bill moved to the Lords.
What happens next?
Following Second Reading in the Lords, the Bill will normally proceed through:
- Lords Committee Stage
- Lords Report Stage
- Lords Third Reading
- Consideration of any amendments between Commons and Lords
- Royal Assent
The Bill has not yet reached Royal Assent, but this is expected in late 2026 unless there are significant amendments or delays in the House of Lords.
Why it matters for BSIA members
The Bill significantly expands the UK's cyber security regime beyond the existing NIS Regulations by bringing Managed Service Providers (MSPs), Data Centres and Critical Suppliers into scope, while strengthening incident reporting, regulatory oversight and enforcement powers. It creates new statutory obligations for organisations to manage cyber risks, report significant incidents within 24 hours (initial notification) and 72 hours (full notification), and notify affected customers where relevant.
The Bill also introduces stronger supply-chain assurance requirements, enhanced powers for regulators and government, and substantial financial penalties for non-compliance. It provides a framework for future sector-specific cyber resilience regulations and national security directions. The Bill remains in the House of Lords and has not yet received Royal Assent.
Business Impacts & Risks
- More security sector suppliers, MSPs and technology providers may fall within regulatory scope.
- Mandatory incident reporting (24hr/72hr) will require mature cyber monitoring and response capabilities.
- Supply-chain scrutiny will increase, including designation of 'critical suppliers'.
- Enhanced regulator powers to request information, inspect systems and investigate incidents.
- Board-level accountability for cyber resilience and risk management will increase.
- Potential penalties up to £17m or 4% of global turnover under NIS provisions.
- Future regulations could impose additional security controls and reporting requirements.
- Misalignment between UK and EU cyber requirements may create compliance complexity for manufacturers operating in both markets.
Recommended Next Steps & Deadlines
- Monitor House of Lords passage and Royal Assent timetable.
- Conduct gap analysis against incident reporting, governance and supply-chain controls.
- Identify whether your organisation could be classed as an MSP, critical supplier or regulated entity.
- Prepare incident response processes capable of meeting 24-hour and 72-hour reporting obligations.
- Review third-party supplier assurance and contractual cyber obligations.
- Track secondary legislation and regulatory guidance expected following Royal Assent.
- For BSIA members, begin alignment with CRA, NIS principles and relevant cyber assurance schemes such as The BSIA CySPAG Scheme; https://www.cyspag.co.uk/
The BSIA welcome your feedback via technical@bsia.co.uk on the above points and any additional observations you may have on this important subject.