Cyber Security and Resilience (Network and Information Systems) Bill Contents

Third Report

Cyber Security and Resilience (Network and Information Systems) Bill

Introduction

1.The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the House of Commons on 12 November 2025. It was carried over at the end of the 2024–26 session, completing its passage through the House on 16 June 2026. It was introduced in the House of Lords on 17 June and is scheduled to receive its Second Reading on 14 July.

2.The Bill has two broad objectives. First, the Bill will update the Network and Information Systems Regulations 2018 (the NIS regulations)—“the UK’s only cross-sector cyber regulations”1—by extending their reach to additional bodies and providing regulators with powers to discharge their obligations under the regulations. Second, the Bill will “provide the Government with power to amend and add to the NIS regulations in the future and respond to imminent and actual threats to … national security.”2

3.The NIS regulations were initially introduced in 2016 following an EU Directive on cyber security and were supplemented by an EU Regulation in 2018. In the light of increased and more sophisticated hostile cyber activity—and that, in a fast-moving sphere, the 2018 Regulations are now dated—the Government argues that the Bill is required to “address the vulnerabilities in our cyber defences to minimise the impact of attacks and improve the resilience of our critical infrastructure, services and digital economy.”3 The Bill is necessary as, following the UK’s exit from the EU, “there are no appropriate powers currently available to update these regulations.”4

4.The Bill raises issues of constitutional significance regarding the Secretary of State’s power to issue directions and parliamentary scrutiny.

Compliance with directions issued by the Secretary of State

5.In Part 4 of the Bill, clause 43 provides the Secretary of State with the power to issue directions to regulated persons requiring that specific actions be taken, or not taken, on national security grounds. A direction may be issued where a security or operational compromise in relation to a relevant network and information system, or the threat of such a compromise, creates a risk to national security and the giving of a direction is necessary and proportionate in the interests of national security. Clause 44(6) states that directions by the Secretary of State must be complied with, and clauses 50–51 state that failure to comply with a direction can result in the imposition of a significant financial penalty.

6.Clause 44(1)–(2) states that if the Secretary of State considers that it is not reasonably practicable for the regulated person to comply with a requirement of a direction imposed under clause 43 and “another requirement of a regulatory nature imposed under or by virtue of any enactment”, then the duty to comply with the conflicting requirement will not apply. This means that a power of direction under clause 43 can displace a statutory requirement.

7.Furthermore, while the Secretary of State is required by clause 55 to lay copies of directions given before Parliament, this will only take place after their issue, and clause 55(2) states that the requirement “does not apply” if the Secretary of State considers that it would be contrary to the interests of national security to do so.

8.We acknowledge the need to provide for a responsive legislative means of addressing cyber security threats and the necessity for the Government to have the means to protect national security. Nevertheless, the provision of a power effectively to supplant the requirements of statute by way of ministerial direction is of constitutional significance. Given that details of the Secretary of State’s directions can also be withheld from Parliament on national security grounds, the clause also presents a challenge to the rule of law obligation that the requirements of the law be publicly accessible. We therefore draw this provision to the attention of the House.

Penalties under Part 4 of the Bill

9.Contravention of a requirement of a direction issued by the Secretary of State can incur a significant financial penalty, up to a maximum of £17 million. A financial penalty can be imposed if the enforcement authority “is satisfied” that a contravention has occurred. Penalty regimes in recent Bills such as the Commercial Payments Bill have made provision for an appeals process. This Bill provides for no appeals process. Instead, the Bill’s explanatory notes state that a “penalty decision may only be appealed by judicial review heard in the High Court.”5 A judicial review action is not equivalent to an appeal, and allows only for the review of a decision on specific and more limited grounds.

10.We recommend that Part 4 of the Bill be amended to provide an appeals process where contravention of a requirement of a direction issued by the Secretary of State has resulted in the imposition of a financial penalty.

Delegated powers

11.The Bill makes extensive use of delegated powers. In particular, the regulation-making power in clause 29(1) and the Bill’s subsequent provisions are central to the Bill’s scheme. Clause 29(1) provides for the making of regulations for the purposes of, or in connection with, “the identification, management and reduction of risks of security or operational compromises in relation to relevant network and information systems” and/or “the mitigation of adverse impacts resulting from such security or operational compromises.” The Bill’s subsequent clauses indicate that these provisions can, for instance, be used to impose requirements on those regulated by the Bill, can confer functions on regulators, can provide for the imposition of financial penalties, and can provide for the recovery of costs by regulators. The Government has indicated that the Bill’s delegated powers are designed to “enable the Government to update the NIS regulations without requiring an Act of Parliament.”6

12.We draw the House’s attention to the extensive use of delegated powers in the Bill. However, we note that this reflects the technical nature of this area of law, the fact that the security of network and information systems was previously governed primary by EU laws, and the need for a regime that is responsive to a fast-moving field.

Parliamentary oversight of the cyber security and resilience regime

13.Clause 28 places the Secretary of State under an obligation to report to Parliament at 12-monthly intervals on regulatory authorities’ compliance with their duties, and planned activities in relation to compliance, under the Government’s statement of strategic priorities set out in clause 12.

14.In addition, clause 40 requires the Secretary of State to report to Parliament “at least once every five years” on the operation and effectiveness of NIS regulations, Parts 3 and 4 of the Bill and regulations passed under Part 3 of the Bill.

15.Given that this is a fast-moving area of law and the significant powers granted to the Secretary of State under the Bill, we recommend that the requirement in clause 40 for the Secretary of State to report to Parliament at least once every five years should be strengthened to require more regular reporting.

Human rights

16.Baroness Lloyd of Effra, the Minister for Digital Economy, has issued a statement of compliance under s.19(1)(a) of the Human Rights Act 1998. However, a full European Convention on Human Rights memorandum has not been published.

17.The failure to publish a full European Convention on Human Rights memorandum setting out the reasoning by which the Government reached its view on compatibility inhibits parliamentary scrutiny of the Bill.


1 Explanatory Notes to the Cyber Security and Resilience (Network and Information Systems) Bill [Bill 2 (2026–27)-EN], para 1

2 Ibid., paras 1–2

3 Department for Science, Information and Technology, Cyber Security and Resilience Policy Statement, CP 1299, 9 April 2025

4 Explanatory Notes to the Cyber Security and Resilience (Network and Information Systems) Bill [Bill 2 (2026–27)-EN], para 20

5 Ibid., para 314

6 Ibid., para 20




© Parliamentary copyright 2026