Blog

The Cyber Security and Resilience Bill – and what it means for you

Long gone are the days when cyberattacks were an occasional and remote threat. Today, they’re an everyday reality for businesses of all sizes and in every sector, and they’re growing more technically sophisticated all the time.

In response, the UK Government is preparing to introduce its impending Cyber Security and Resilience (CS&R) Bill, which is expected to be introduced to Parliament before the end of this year. The new legislation aims to strengthen national cyber defences and ensure organisations are better protected against emerging threats; it represents a significant shift in how these risks are managed.

For businesses, the CS&R Bill indicates a need to take proactive steps to tighten cybersecurity, prepare for closer oversight and rethink how resilience is built into their operations. Let’s take a closer look at what the legislation means and what organisations can do to prepare for it.

What is the Cyber Security and Resilience Bill?

The CS&R Bill updates and expands existing frameworks to address modern cybersecurity threats, particularly those facing critical national infrastructure and public services. The Bill essentially updates and expands the Network and Information Systems Regulations of 2018.

First announced in the King’s Speech of July 2024, a policy statement outlining the Bill’s scope and impact was published in April 2025. It is expected that the Bill will be tabled in Parliament later this year, where it will be subject to scrutiny and potential amendments. Assuming it is passed into law, the legislation’s implementation appears likely to be phased in gradually sometime in 2026.

Once it is implemented, the Bill will apply to primarily to operators of essential services (OES, e.g. health, energy, transport and water) and relevant digital service providers (RDSPs), which include cloud computing services, search engines and online marketplaces.

Firms providing core IT services and infrastructure to OES or RDSPs will also fall under scope of the CS&R Bill. This is expected to include managed service providers, cybersecurity providers and data centre operators.

Furthermore, the Bill will extend obligations to key supply chain partners (referred to as designated critical suppliers, or DCPs) that provide essential goods and services to these sectors. This reflects a recognition on the part of the government that attackers are increasingly targeting suppliers as a way to access larger, high-value targets, including those with potential implications for national security.

The main themes of the new legislation thus include:

  • Broader regulatory scope: More digital services and supply chain providers working with key national infrastructure and utilities will be subject to regulatory oversight, closing gaps that currently leave critical organisations vulnerable.
  • Stronger regulatory powers: Regulators will be empowered to investigate vulnerabilities proactively and recover costs so that they have the resources to enforce continual compliance.
  • Mandatory reporting: Organisations within the scope of the Bill will be required to disclose a wider range of cyber incidents, including ransomware attacks, thereby providing the government with more detailed intelligence to identify patterns and pre-empt potential threats.

 

What the bill means for businesses

While we are still awaiting the final details, it’s important to recognise from the outset that the CS&R Bill represents more than just another compliance exercise. What it actually represents is a broader recognition that cyber resilience underpins both business continuity and national security. Failure to adapt accordingly could mean not just regulatory penalties and financial losses but lasting reputational damage.

One of the most significant implications of the new legislation is its focus on supply chains. More attackers are now targeting third parties as a way into larger organisations, so regulators want proof that suppliers for key public services and infrastructure are also following robust security practices. As a result, organisations will be expected to conduct more rigorous supplier due diligence.

The Bill’s reporting requirements are also notable. In particular, organisations classed as “regulated entities” under the Bill will be required to inform the National Cyber Security Centre (NCSC) of any significant cyber incident no more than 24 hours after becoming aware of it, and to provide a detailed report within 72 hours.

How Sentis can help

Building cyber resilience into your day-to-day operations involves strategic investment. At Sentis, we help organisations develop this resilience with a range of services that both provide stronger protection against cyberattacks and also reduce the risk of serious disruption when they do occur.

Our security assessments can identify vulnerabilities across systems, networks and supply chains, giving businesses a clearer view of the risks they face. We also provide ongoing threat detection and response, helping organisations spot risks before they escalate, and our expertise in regulatory compliance helps our clients demonstrate compliance with the standards expected by regulators.

The Cyber Security and Resilience Bill marks a pivotal moment for cybersecurity in the UK. It is both a challenge to raise standards and also an opportunity to bolster trust. Those organisations that act swiftly will not only be better prepared for the new regulations the Bill entails, but will also be better equipped to protect their operations, assets and people.

Sentis delivers the expertise and support to help businesses strengthen their cyber resilience and protect themselves against online security threats. Contact our team of specialists today and let’s discuss what we can do for your organisation.