News

Cyber Security and Resilience Bill: What Businesses Need to Know

Digital padlock

The UK Government's proposed Cyber Security and Resilience Bill aims to strengthen cyber security requirements that help protect the country's essential services and critical digital infrastructure.

The proposed legislation, that builds upon and reforms the existing Network and Information Systems (NIS) Regulations of 2018, is designed to improve resilience against cyber threats. The reforms are a response to the changing threat landscape and aim to reduce disruption to services that people and businesses rely on every day, including healthcare, energy, water, transport and digital infrastructure.

Who could be affected?

The Bill is expected to introduce a wider scope of regulation, including: 

  • Data centres: Certain data centres are expected to be regulated because many organisations are digital services critically depend on them.
  • Managed Service Providers (MSPs): Medium and large MSPs are expected to be regulated because a cyber-attack on one provider can disrupt many organisations at once.
  • Critical suppliers: Suppliers that provide essential products or services to critical sectors may regulated whose disruption could affect important services.

Wider implications for businesses

Even organisations that are not directly covered by the legislation may feel its impact. Customers, insurers, regulators and procurement frameworks could increasingly expect organisations to demonstrate good cyber security practices and resilience.

Now is a good time to review your cyber security arrangements and identify opportunities to strengthen your ability to prevent, respond to and recover from cyber incidents.

When will the changes take effect?

The Bill was introduced to Parliament in November 2025 and is currently progressing through the legislative process. Implementation timelines will depend on when the legislation receives Royal Assent and supporting regulations are introduced. 

Preparing for the future

Businesses should keep informed about developments and consider how new requirements could affect their operations, supply chains and digital services.

Future guidance and updates are expected to provide further information on what good cyber resilience looks like in practice and how organisations can prepare for any upcoming changes.

The Cyber Security and Resilience Bill is not yet law. This document is intended to support organisations in understanding cyber resilience. It is provided for general guidance only and does not replace legal, regulatory or professional advice tailored to your organisation's circumstances.

Find out more about cyber security support available: Cyber Security Advice and Support | Business Wales.


Business Wales Helpline

03000 6 03000

Lines are open 10am to 4pm Monday to Friday.

Rydym yn croesawu galwadau'n Gymraeg.