An independent guide, run by CyPro

The Cyber Security and Resilience Bill, explained clearly

What the UK Cyber Security and Resilience Bill is, who it will affect, where it has reached in Parliament, and how to prepare early rather than wait for the duties to land.

  • Every fact sourced to gov.uk and Parliament
  • Tracked through every legislative stage
  • Written by practitioners, not lawyers
3D illustration representing the UK Cyber Security and Resilience Bill and stronger cyber duties

Last reviewed 14 July 2026 · all sources linked in the text

The short version

What the Cyber Security and Resilience Bill is

The Cyber Security and Resilience Bill, sometimes shortened to the CSR Bill, is the UK government's planned law to strengthen the cyber resilience of essential and digital services. It is widely described as the UK's NIS2-equivalent, because it updates and expands the Network and Information Systems Regulations 2018. According to the government's policy statement on gov.uk, it is expected to bring more organisations into scope, including managed service providers, strengthen incident reporting, and give regulators stronger powers. It was announced in the King's Speech in July 2024 and is progressing through Parliament, so the duties are not in force yet.

3D illustration of the Bill as the UK equivalent of the EU NIS2 Directive

A NIS2-equivalent UK law

The Bill is widely described as the UK's answer to the EU's NIS2 directive. It updates and expands the Network and Information Systems Regulations 2018, the existing UK cyber regime for essential and digital services.

How it compares to NIS2
3D illustration of the wider scope bringing managed service providers into regulation

Wider scope, including MSPs

The government has signalled that more organisations will be brought into scope, including managed service providers, using an essential entities and important entities style categorisation.

Check if you are in scope
3D illustration of the Bill progressing through Parliament

Progressing through Parliament

Announced in the King's Speech in July 2024, with a policy statement published on gov.uk, the Bill is working its way through the legislative process rather than sitting in force.

Where the Bill is now
3D illustration of the statutory duties that begin once the Bill receives Royal Assent

Duties arrive at Royal Assent

There are no statutory duties yet. They will land at Royal Assent and through the secondary legislation that follows, which is why the sensible move now is to understand it and prepare early.

What the Bill is

One important reassurance about timing

There are no statutory duties to comply with yet. The Bill has not received Royal Assent, and the detailed obligations will be set at Assent and through the secondary legislation that follows. The value in acting now is preparing early, not panicking: understanding your likely scope and getting the fundamentals in place while there is time to do it calmly.

See where the Bill has reached
Scope explainer

Will the Bill apply to you?

A plain-English read on who the Bill is expected to reach: which organisations look like essential or important entities, and why managed service providers are being drawn in for the first time.

Check if you are in scope
3D illustration of organisations checking whether they fall within scope of the Bill

Preparing early

Three steps, in the right order

Work out if you are in scope

Essential entity or important entity? Caught directly, or reached through your role as a managed service provider or through your customers' supply chains?

Check if you are in scope

See where the Bill is now

Announced in July 2024, with a published policy statement, the Bill is progressing through Parliament. The stage it is at shapes what you can plan for and when.

The full timeline

Prepare early, evidence as you go

Map your critical services, tighten incident reporting and supply chain controls, and capture the proof as you build, so that duties at Royal Assent find you ready rather than starting.

Talk it through with CyPro

Where the Bill is now

Tracking the Bill through Parliament

The Bill was announced in the King's Speech in July 2024, and the government has published a policy statement setting out its intended scope and measures. It is progressing through the legislative process and has not yet received Royal Assent.

The full timeline

The team behind this hub has advised

az
bgi
british gas
cigna
deloitte
euroclear
jpm
kpmg
lme
m & g
ns & i
royal london
rsa
schroders
shell
ubs
virgin trains
william hill

Your experts hold

  • CIPM
  • CIPP E
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001
  • Prince2

Proof, not promises

Teams that trust CyPro

3D illustration of frequently asked questions about the Cyber Security and Resilience Bill

Good questions

Frequently asked questions

What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill is the UK government's planned law to strengthen the cyber resilience of the country's essential and digital services. It is widely described as the UK's NIS2-equivalent, and it updates and expands the existing Network and Information Systems (NIS) Regulations 2018.

It was announced in the King's Speech in July 2024, and the government has published a policy statement on gov.uk setting out its intended scope and measures. It is sometimes shortened to the CSR Bill.

The Bill explained in full

Is the Cyber Security and Resilience Bill law yet, and when does it come into force?

Not yet. As things stand it has not received Royal Assent, so there are no statutory duties or deadlines to meet today. It is progressing through the legislative process after being announced in July 2024.

Duties will begin once the Bill receives Royal Assent and the secondary legislation (statutory instruments) that sets the detail is made. Because the exact stage and dates are moving, we track the Bill's progress on the timeline rather than fixing a date here.

Where the Bill is now

Does NIS2 apply in the UK?

No, not directly. NIS2 is an EU directive and the UK is no longer an EU member state, so NIS2 does not apply to UK organisations as law. The UK's own equivalent is the Cyber Security and Resilience Bill, which builds on the Network and Information Systems Regulations 2018.

UK organisations that operate in the EU, or that supply EU essential and important entities, may still encounter NIS2 through those markets and contracts, but the domestic regime to plan around is the Bill.

NIS2 and the UK Bill compared

What is the difference between the Bill and the EU NIS2 directive?

They share the same goal, raising the cyber resilience of essential and digital services, and the Bill is widely described as the UK's NIS2-equivalent. The difference is jurisdiction and detail: NIS2 is EU law transposed by member states, while the Bill is UK legislation that updates and expands the UK's NIS Regulations 2018.

The Bill is expected to use an essential entities and important entities style categorisation, as NIS2 does, but the precise UK definitions, sectors and duties are set by the Bill and the secondary legislation that follows it, so they will not match NIS2 line for line.

NIS2 and the UK Bill compared

3D rocket illustration for booking a free discovery call about the Bill

Plan ahead

Prepare for the Cyber Security and Resilience Bill

Book a discovery call to understand whether the Bill is likely to apply to you, what it will probably require and how to get ready ahead of Royal Assent. Clear guidance, no scaremongering.