24 November 2025
The UK government has outlined significant changes to its national cyber security framework with the introduction of the Cyber Security & Resilience Bill, expected to become law in 2026. The legislation is intended to strengthen national security, align UK policy with the EU’s NIS2 Directive, and expand obligations for organisations operating across the digital economy.
The new Bill widens the definition of Critical National Infrastructure (CNI) to reflect the increased importance of digital services and supply chains in delivering essential operations. Currently, CNI regulation covers Operators of Essential Services (OES) — healthcare, water, energy, transport, banking, and digital infrastructure — and Relevant Digital Service Providers (RDSPs) such as online marketplaces, search engines, and cloud platforms.
Under the new framework, the scope will broaden considerably to include additional high-impact sectors and their supply chains. Organisations involved in public administration, postal and courier services, waste management, space, manufacturing and distribution of chemicals, food production and logistics, research and development, financial services, and Managed Service Providers (MSPs) will now be brought into scope.
A major change is the formal inclusion of Managed Service Providers supporting CNI organisations, recognising the critical role MSPs play in operational resilience. The Information Commissioner’s Office (ICO) will act as the regulator for MSPs, overseeing compliance and registration requirements.
The Bill introduces mandatory significant incident reporting for all regulated entities. Updates to the NCSC Cyber Assessment Framework will introduce stricter controls and a new two-step incident reporting process:
Additional provisions encourage greater transparency across digital infrastructure and data centres, with streamlined reporting mechanisms designed to strengthen national response capabilities.
The ICO will receive expanded powers to enforce compliance. Penalties may be imposed for failing to meet reporting obligations, non-compliance with security standards, or failing to register as a CNI entity or supplier. Regulators will also gain authority to charge registration fees, helping fund oversight.
The ICO is expected to adopt an intelligence-led approach to preventing cyber incidents. Organisations providing digital services may be required to share information proactively, supported by:
For technology firms, digital service providers, and MSPs, the Cyber Security & Resilience Bill marks a substantial shift in accountability. Organisations will need to adapt governance, supply chain risk management, and incident response processes to comply with new requirements.
As digital ecosystems continue to underpin national infrastructure, the Bill aims to build a more resilient and responsive cyber landscape, ensuring that critical operations remain secure in an increasingly complex threat environment.
If your business is looking to meet the new standards set by the Bill, or needs expert guidance in transitioning, then please get in touch here.