The Cyber Security and Resilience Bill sets a new national baseline for cyber governance, mandating rapid incident reporting, expanding regulated sectors, and imposing penalties of up to £17 million or 10% of turnover.
Get Your 'Vulnerability Management Template' FREE!
Your Vulnerability Management Template Includes:
Secure your organisation today by completing the form for your Vulnerability Management Template.
Download the, 'How to secure Microsoft Office Desktop Deployments Technical Guide' - FREE
Complete the form to download your free technical guide and secure your organisation today.
Download the Cyber Essentials Template Policy Pack - FREE
Complete the form to download your FREE Cyber Essentials Template Pack today, including:
Download the Microsoft 365 Security Guide - FREE
Complete the form to download your FREE Microsoft 365 Security Guide today, including:
Sign up on the form and receive the guide instantly.
The Cyber Security and Resilience (Network and Information Systems) Bill (CSRB) represents the most significant update to UK cyber law since 2018. It fundamentally expands regulatory scope, tightens incident response rules, and massively increases penalties.
On 12th November 2025, the Cyber Security and Resilience (Network and Information Systems) Bill (Bill 329) was formally introduced to the UK Parliament, marking a significant milestone in the UK's approach to cyber security regulation. Presented by Secretary Liz Kendall and supported by the Prime Minister and senior ministers, this comprehensive legislation represents the most substantial update to UK cyber security law since the Network and Information Systems (NIS) Regulations 2018.
The Bill’s introduction follows its announcement in the 2024 King’s Speech and the publication of a formal policy paper in April 2025. With 61 sections across 5 Parts and 2 Schedules, the legislation will fundamentally reshape how organisations manage cyber security risks, respond to incidents, and maintain operational resilience.
For thousands of UK organisations - from managed service providers and data centres to critical infrastructure operators and their supply chains—the Bill's introduction signals that compliance preparation is no longer optional. It’s time to act.
The formal introduction of the Cyber Security and Resilience Bill to Parliament on 12th November 2025 triggers the legislative process that will ultimately make these requirements law. While the Bill must still pass through both Houses of Parliament and receive Royal Assent, its introduction represents a clear statement of intent from the UK Government.
Section 60 of the Bill provides for phased commencement:
This phased approach means organisations have a window to prepare, but that window is closing. The most significant changes - expanded scope, mandatory incident reporting, and new enforcement powers - will come into effect once the Bill receives Royal Assent and the Secretary of State makes commencement regulations.
The Cyber Security and Resilience Bill introduces sweeping changes that will affect organisations across multiple sectors. Below are the most significant updates.
Section 15 introduces major changes to incident reporting expectations.
Full reports must include:
Notifications must be submitted simultaneously to:
Under Section 16 and Regulations 11C, 12C, and 14G, affected UK customers must be notified as soon as reasonably practicable after the full regulatory notification is submitted.
Notifications must explain why the customer is likely to be adversely affected.
Section 21 and Schedule 1 significantly strengthen regulator enforcement capability.
Penalties are tiered:
Section 20 introduces Regulation 15, giving regulators authority to require:
Schedule 1 strengthens Regulation 16, permitting:
Under Schedule 1 (Regulation 17), regulators may issue Enforcement Notices requiring immediate corrective action.
Failure to comply can result in civil proceedings.
Part 4 introduces unprecedented powers for national security scenarios:
Part 3 introduces new governance frameworks:
Section 17 introduces Regulations 20A–20C, allowing NIS enforcement authorities to:
Section 18 significantly expands information sharing powers:
With the Bill now introduced to Parliament, organisations should understand the timeline ahead.
Based on typical parliamentary processes for significant legislation:
However, given the Bill's significance and the government's stated priorities, the process may be accelerated. Organisations should prepare for the possibility of earlier implementation.
Section 60 provides for phased commencement, meaning different parts of the Bill will come into force at different times:
The Secretary of State will make commencement regulations specifying exact dates. Organisations should expect guidance and consultation on implementation timelines.
With the Bill now before Parliament, preparation is no longer theoretical. Here’s what organisations should do immediately.
Assess whether you fall into scope:
The 24/72-hour timelines are strict. Prepare now:
Enhanced enforcement means higher stakes:
Regulators will have extensive information powers:
Regulators can recover costs through charges:
Stay informed as the Bill progresses:
The introduction of the Cyber Security and Resilience Bill to Parliament is a clear signal that the UK is serious about raising cyber security standards across the economy.
For organisations in scope, the message is clear:
At Precursor Security, we are helping organisations prepare for the Cyber Security and Resilience Bill through:
Our team combines deep technical expertise with regulatory knowledge to help integrate compliance into your security strategy.
The Cyber Security and Resilience Bill's introduction to Parliament on 12 November 2025 marks a major shift in UK cyber regulation. Expanded scope, stricter requirements, and enhanced enforcement powers mean organisations cannot wait.
The most successful organisations will treat CSRB compliance as an opportunity to strengthen security and build trust.
Start preparing now. Assess your exposure, strengthen your capabilities, and build the governance structures needed to meet these requirements.
For organisations needing deeper guidance, we’ve published a comprehensive CSRB Readiness Assessment on the Cyber Security and Resilience Bill website, featuring detailed explanations, sector-specific implications, and practical preparation steps tailored to different types of organisations. Visit cybersecurityandresiliencebill.com to explore more.
For tailored support, explore the resources on this site or contact Precursor Security to discuss your specific needs.
Choose Precursor Security for penetration testing excellence—where industry-leading expertise, CREST accreditation, and a client-focused approach converge to fortify your digital defences with precision and reliability.

We have a CREST accredited Security Operations Centre and all of our penetration testers are CREST certified.

We are accredited to the highest of standards including CREST, ISO27001, ISO9001 and Cyber Essentials Plus.
![Experienced people icon]](https://cdn.prod.website-files.com/6569bb4bd6018f8bee273541/65c0fddfb82858785bf456d7_rating.png)
Our experts have a combined experience of over 30 years delivering security operations to sectors such as healthcare, financial services, aerospace and more.
It’s important to know what you’re getting, what’s not included and what else is available. This starts with understanding a SOC and it’s critical functions. CREST has recently published a guide to the critical functions of a SOC which aligns with the CREST SOC standard.
Enter your details here and to get the complete guide instantly sent to your inbox.
Choose Precursor Security for penetration testing excellence—where industry-leading expertise, CREST accreditation, and a client-focused approach converge to fortify your digital defences with precision and reliability.

We have a CREST accredited Security Operations Centre and all of our penetration testers are CREST certified.

We are accredited to the highest of standards including CREST, ISO27001, ISO9001 and Cyber Essentials Plus.
![Experienced people icon]](https://cdn.prod.website-files.com/6569bb4bd6018f8bee273541/65c0fddfb82858785bf456d7_rating.png)
Our experts have a combined experience of over 30 years delivering security operations to sectors such as healthcare, financial services, aerospace and more.
For more details on the partnership and the wider context of the UK's changing legislative landscape, visit the official announcements below:
Official Press Release: Axiologik & Precursor launch UK cyber resilience tool
Axiologik’s Announcement: Yorkshire tech alliance launches cyber assessment service as legislative countdown begins

Precursor Security
Welcome to Precursor Security, where the forefront of cybersecurity and penetration testing expertise meets unmatched dedication and innovation. We are the architects of robust digital defences, committed to safeguarding the online realm.