The Cyber Security and Resilience Bill entered Committee stage on September 1, pushing forward what experts are calling the most significant update to the UK’s cyber framework in years
It comes as the government suggested new measures aimed at shoring up supply chain security, especially in procurement.
The Bill’s proposals aim to boost resilience amid an increasing risk of cyber-attacks. What is the timeline for the Cyber Security and Resilience Bill and what should UK firms be doing now?
Big Shift
Tracey Hannan-Jones, consulting director in information security, UBDS Digital calls the Cyber Security and Resilience Bill the government’s “most significant overhaul of cyber security regulation in nearly a decade.”
Replacing the Network and Information Systems (NIS) regulations 2018, it substantially widens the scope to include managed service providers, broader digital infrastructure providers, and supply chain entities.
The key changes proposed include strengthened incident reporting obligations with shorter timeframes and a broader definition of what constitutes a reportable incident.
Proactive regulatory oversight means that the Information Commissioner’s Office (ICO) and sector-specific bodies would gain powers to inspect and audit organisations before an incident occurs.
At the same time, supply chain security duties require in-scope organisations to “actively assess and manage cyber risks from suppliers, not simply document them,” explains Hannan-Jones.
The new amendments package tabled by the government would “significantly expand minister discretion on high-risk vendors,” says Grace Carter, government affairs counsel at Elastic.
Put forward by cyber minister Liz Lloyd, the amendments introduce powers for the secretary of state to issue vendor-related directions, enabling the government to block companies operating essential services from buying products from high-risk suppliers.
These powers raise a question that organisations “will need to sit with,” says Carter. “The government is giving itself authority to mandate supplier decisions, while simultaneously expecting businesses to own their supply chain risk.”
This tension is compounded by the fact that the definition of ‘high-risk supplier’ remains undefined in statute. “Put simply, CISOs cannot easily pre-position if they don't yet know which vendors may be directed out of their stack,” she tells SC Media UK.
The Bill also raises important questions about AI accountability, says Carter. “Where frontier AI developers are not directly regulated, organisations deploying AI in critical environments may still be expected to understand and manage the risks those systems create.”
It could leave businesses “carrying responsibility for technologies whose underlying models and infrastructure they do not fully control,” she warns.
Timeline For Changes
The timeline for the Bill is clear, although it’s not set in stone. Once the Commons and Lords have agreed on any amendments, the Bill can be given Royal Assent.
However, many of the principal requirements will require secondary legislation, consultation, and an implementation period before becoming enforceable, says Daniel Nunn, managing director in the cybersecurity practice at FTI Consulting. “The overall direction is established, but some important details, particularly reporting thresholds and implementation arrangements, are still being debated.”
The government's vendor-direction powers will attract scrutiny from peers, though this is not expected to significantly delay passage beyond 2026, says Carter.
Once the Committee stage is over at the end of November, early 2027 should see the ‘report’ stage and third reading in the Commons, says Hannan-Jones. By Spring or early Summer 2027, it should reach the Lord’s stage, she predicts.
Under this timeline, it could achieve Royal Assent by the end of 2027, followed by a phased commencement.
Organisations will have a business adjustment period before the new regulatory expectations are fully in force. “We currently expect this to be by 2028 to 2029, but by no means do companies have to wait until then to start preparing,” says Louise Horton, head of UK government affairs at NCC Group
“Building resilience takes time, particularly where it involves understanding complex supply chains and critical dependencies.”
CISO Planning Time
While some measures may not take effect until 2027, organisations should not wait for every detail to be settled before preparing, agrees Carter. “CISOs should treat this as critical planning time. Building governance structures and resilience now will enable more flexibility as the UK requirements are clarified.”
She believes CISOs should also use this period to pressure-test their supplier visibility. “The vendor-direction powers mean that rapid removal or replacement of a supplier could become a regulatory requirement, not just an operational preference. Organisations that cannot quickly answer which vendors sit in critical parts of their stack, and what it would take to remove them, are carrying a risk that is now more concrete than it was before these amendments.”
Doug Jewitt, security consultant, Infinity Group agrees. He advises gaining an understanding of who has access to critical systems, validating suppliers against recognised standards such as Cyber Essentials and ensuring incident response processes are well rehearsed. “Security leaders should also ensure their organisations understand breach reporting obligations and know when and how incidents should be escalated to regulators such as the ICO."
CISOs should establish whether their organisation is likely to be in scope, map the essential services, systems and suppliers involved, and identify material gaps in security and operational resilience, says Nunn. “They should also test their ability to assess and report incidents within 24 and 72 hours, including escalation to regulators, the National Cyber Security Centre (NCSC) and affected customers. This testing should assess the depth and detail that they are able to provide, and whether additional functionality or data points are required to fully populate information requirements.”
Boards should receive a clear assessment of likely applicability, material control gaps, and remediation costs, says Nunn. “Although the final details remain subject to secondary legislation and guidance, the proposed timescales mean that it may be too difficult to build the necessary reporting, governance and operational capabilities quickly at a later stage when resources are in heavy demand.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist