An independent guide, run by CyPro
The Cyber Security and Resilience Bill, explained clearly
What the UK Cyber Security and Resilience Bill is, who it will affect, where it has reached in Parliament, and how to prepare early rather than wait for the duties to land.
- Every fact sourced to gov.uk and Parliament
- Tracked through every legislative stage
- Written by practitioners, not lawyers
Last reviewed 14 July 2026 · all sources linked in the text
The short version
What the Cyber Security and Resilience Bill is
The Cyber Security and Resilience Bill, sometimes shortened to the CSR Bill, is the UK government's planned law to strengthen the cyber resilience of essential and digital services. It is widely described as the UK's NIS2-equivalent, because it updates and expands the Network and Information Systems Regulations 2018. According to the government's policy statement on gov.uk, it is expected to bring more organisations into scope, including managed service providers, strengthen incident reporting, and give regulators stronger powers. It was announced in the King's Speech in July 2024 and is progressing through Parliament, so the duties are not in force yet.
A NIS2-equivalent UK law
The Bill is widely described as the UK's answer to the EU's NIS2 directive. It updates and expands the Network and Information Systems Regulations 2018, the existing UK cyber regime for essential and digital services.
How it compares to NIS2
Wider scope, including MSPs
The government has signalled that more organisations will be brought into scope, including managed service providers, using an essential entities and important entities style categorisation.
Check if you are in scope
Progressing through Parliament
Announced in the King's Speech in July 2024, with a policy statement published on gov.uk, the Bill is working its way through the legislative process rather than sitting in force.
Where the Bill is now
Duties arrive at Royal Assent
There are no statutory duties yet. They will land at Royal Assent and through the secondary legislation that follows, which is why the sensible move now is to understand it and prepare early.
What the Bill isOne important reassurance about timing
There are no statutory duties to comply with yet. The Bill has not received Royal Assent, and the detailed obligations will be set at Assent and through the secondary legislation that follows. The value in acting now is preparing early, not panicking: understanding your likely scope and getting the fundamentals in place while there is time to do it calmly.
See where the Bill has reachedWill the Bill apply to you?
A plain-English read on who the Bill is expected to reach: which organisations look like essential or important entities, and why managed service providers are being drawn in for the first time.
Check if you are in scope
Preparing early
Three steps, in the right order
Work out if you are in scope
Essential entity or important entity? Caught directly, or reached through your role as a managed service provider or through your customers' supply chains?
Check if you are in scopeSee where the Bill is now
Announced in July 2024, with a published policy statement, the Bill is progressing through Parliament. The stage it is at shapes what you can plan for and when.
The full timelinePrepare early, evidence as you go
Map your critical services, tighten incident reporting and supply chain controls, and capture the proof as you build, so that duties at Royal Assent find you ready rather than starting.
Talk it through with CyProWhere the Bill is now
Tracking the Bill through Parliament
The Bill was announced in the King's Speech in July 2024, and the government has published a policy statement setting out its intended scope and measures. It is progressing through the legislative process and has not yet received Royal Assent.
The team behind this hub has advised
Your experts hold
Proof, not promises
Teams that trust CyPro
Good questions
Frequently asked questions
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is the UK government's planned law to strengthen the cyber resilience of the country's essential and digital services. It is widely described as the UK's NIS2-equivalent, and it updates and expands the existing Network and Information Systems (NIS) Regulations 2018.
It was announced in the King's Speech in July 2024, and the government has published a policy statement on gov.uk setting out its intended scope and measures. It is sometimes shortened to the CSR Bill.
Is the Cyber Security and Resilience Bill law yet, and when does it come into force?
Not yet. As things stand it has not received Royal Assent, so there are no statutory duties or deadlines to meet today. It is progressing through the legislative process after being announced in July 2024.
Duties will begin once the Bill receives Royal Assent and the secondary legislation (statutory instruments) that sets the detail is made. Because the exact stage and dates are moving, we track the Bill's progress on the timeline rather than fixing a date here.
Does NIS2 apply in the UK?
No, not directly. NIS2 is an EU directive and the UK is no longer an EU member state, so NIS2 does not apply to UK organisations as law. The UK's own equivalent is the Cyber Security and Resilience Bill, which builds on the Network and Information Systems Regulations 2018.
UK organisations that operate in the EU, or that supply EU essential and important entities, may still encounter NIS2 through those markets and contracts, but the domestic regime to plan around is the Bill.
What is the difference between the Bill and the EU NIS2 directive?
They share the same goal, raising the cyber resilience of essential and digital services, and the Bill is widely described as the UK's NIS2-equivalent. The difference is jurisdiction and detail: NIS2 is EU law transposed by member states, while the Bill is UK legislation that updates and expands the UK's NIS Regulations 2018.
The Bill is expected to use an essential entities and important entities style categorisation, as NIS2 does, but the precise UK definitions, sectors and duties are set by the Bill and the secondary legislation that follows it, so they will not match NIS2 line for line.
Plan ahead
Prepare for the Cyber Security and Resilience Bill
Book a discovery call to understand whether the Bill is likely to apply to you, what it will probably require and how to get ready ahead of Royal Assent. Clear guidance, no scaremongering.