Cyber Security and Resilience Bill: What It Means for Your Organisation
- Dec 3, 2025
- 3 min read

The UK Government is taking decisive steps to strengthen the nation’s cyber resilience with the introduction of the Cyber Security and Resilience (Network and Information Systems) Bill. This bill details significant changes that will impact organisations delivering essential services and their supply chains. Here’s what you need to know.
Why This Matters
Cyber threats are evolving at pace, and the UK’s reliance on digital infrastructure means resilience is no longer optional, it’s critical. The Bill updates the NIS Regulations 2018, expanding their scope and introducing new obligations to ensure organisations can withstand and recover from cyber incidents. This brings the UK closer in line to the NIS2 Directive within the EU.
Key Changes in Detail
Expanded Scope of Regulation
The Bill significantly broadens the range of organisations subject to NIS requirements:
Data Centres: Recognised as critical infrastructure due to their role in hosting essential services.
Managed Service Providers (MSPs): Now regulated because of their influence over client IT and OT environments.
Critical Suppliers: Organisations whose failure could disrupt essential services will face additional scrutiny.
This means businesses that previously operated outside the NIS framework may now need to comply.
2. New Security Duties
MSPs and Relevant Digital Service Providers (RDSPs) (including online marketplaces, search engines and cloud computing service providers) must adopt robust risk management practices.
Compliance will involve technical and organisational measures aligned with updated codes of practice.
The Information Commission will issue guidance to ensure consistency across sectors.
3. Mandatory Incident Reporting
Initial notification within 24 hours of detecting a significant incident.
Full report within 72 hours, detailing impact and mitigation steps.
Organisations must inform affected customers promptly after major incidents.
Failure to meet these timelines could result in regulatory action.
4. Enhanced Information Sharing
Competent authorities and CSIRTs gain greater powers to share threat intelligence across borders.
This aims to improve national and international coordination during cyber crises.
5. Cost Recovery & Compliance
Regulators can impose periodic charges to cover oversight costs.
Non-compliance penalties:
Up to £17 million or 4% of global turnover for severe breaches.
Daily fines for ongoing violations.
6. National Security Directions
The Secretary of State can issue binding directions to mitigate risks.
These may include mandatory actions, prohibitions, and inspections.
Such directions override conflicting regulatory requirements.
What Should Organisations Do Now?
Assess Your Position Are you an MSP, RDSP, or operate critical infrastructure? If so, review your compliance posture immediately. Consider the latest version of NCSC’s Cyber Assessment Framework (v4.0 at the time of writing).
Update Incident Response Plans Would your organisation be ready to report a major cyber incident within 24 hours? Ensure you can meet the new 24-hour and 72-hour reporting requirements.
Strengthen Supplier Risk Management Critical suppliers will be under scrutiny—make sure your supply chain is resilient, and expect your clients to take a more thorough look at your security. Third party risk management will be key in understanding and reducing your exposure.
Budget for Compliance Factor in potential regulatory charges and penalties for non-compliance. Regulators will be able to introduce charges to cover the costs of monitoring compliance, conducting audits, investigations and inspections and enduring that incident reporting obligations are met.
How Sapphire Can Help
At Sapphire, we specialise in helping organisations align with evolving regulatory standards. From gap analysis to managed detection and response, we provide the expertise and tools to keep you compliant and resilient.
Want to understand how this Bill impacts your organisation?
Don’t wait until regulations catch you off-guard - contact our team today or explore our Cyber Resilience Services.





