The Cyber Security and Resilience Bill just cleared a real milestone. It sits in the House of Lords as HL Bill 32, with Grand Committee scrutiny running across four sittings in September 2026. Peers have tabled dozens of amendments, including proposals on AI governance, vendor powers, and potential personal liability for company directors. Meanwhile, the reporting rules underneath it are tightening hard. NIS 2018 relied on a vague trigger: whether an incident caused an adverse effect. That’s gone now. Organisations face a strict 24-hour initial notification and a 72-hour full report once an incident meets the Bill’s reportable-incident test.
Here’s why that gap matters in practice. Consider two real examples. The 2024 Synnovis ransomware attack on an NHS pathology provider cost an estimated £32.7 million and delayed over 11,000 appointments. The 2025 Marks & Spencer breach caused reported losses up to £300 million. Under NIS 2018’s subjective ‘adverse effect’ threshold, it was far from clear that incidents of this scale had to be reported at the time. This Bill exists specifically to close this issue.
This guide covers what actually changes, where penetration testing genuinely fits, and what newly in-scope organisations should be doing right now, not after Royal Assent.
What the Bill Actually Changes vs. NIS 2018
The Bill substantially expands who counts as regulated, replacing NIS 2018’s narrower sector-based scope with categories built around actual digital dependency. In practice, that shift is the biggest change for organisations that never considered themselves critical infrastructure.
| Scope Element | NIS Regulations 2018 | Cyber Security and Resilience Bill |
|---|---|---|
| Core coverage | Operators of Essential Services (energy, transport, health, water) and Relevant Digital Service Providers | Same base categories, carried forward and expanded |
| Managed service providers | Not covered | Regulated as RMSPs under Section 9 |
| Data centres | Not covered | In scope under Section 4, at 1MW and 10MW capacity thresholds |
| Load controllers | Not covered | In scope under Section 6, at 300MW or higher |
| Supply chain | Not addressed | Critical suppliers designated under Section 12, based on who they supply |
| Incident trigger | “Adverse effect” on service, a subjective threshold | Defined 24-hour initial notification and 72-hour full report apply once an incident is assessed as reportable |
Section 12’s critical supplier route deserves particular attention. An organisation can fall into scope purely because of who it supplies, even if its own sector has nothing to do with critical infrastructure. A software vendor serving a handful of energy companies could find itself regulated for that reason alone.
Cyber Security and Resilience Bill UK Timeline: Where It Stands Now

The Bill has moved through Parliament faster than many observers expected, but the real cyber security and resilience bill timeline pressure lies in the gap between Royal Assent and enforcement. Introduced to Parliament on 12 November 2025 as Bill 329, it cleared Commons Report Stage and Third Reading on 16 June 2026, passing without division, and entered the House of Lords the next day as HL Bill 32.
Lords Second Reading was completed on 14 July 2026 with cross-party support in principle. Grand Committee scrutiny then ran across four sittings, on 1, 3, 7, and 9 September 2026. The government tabled new vendor-related direction powers over risky technology suppliers. However, it rejected amendments covering AI vendor scope, an AI “kill switch,” and Computer Misuse Act reform. One committee-stage change is worth flagging specifically. Ofcom became the sole regulator for data centres, resolving what had been an ambiguous point.
Royal Assent timing genuinely splits opinion. Most commentary through 2026 pointed to late 2026. However, a government consultation published in June 2026 suggested spring 2027 instead, subject to parliamentary progress. Either way, the government does not expect substantive obligations to take effect until around 2028. It will deliver them through secondary cybersecurity legislation following its implementation consultation. That gap between Royal Assent and enforcement is exactly why waiting for the final vote before preparing is the wrong call.
Is Penetration Testing Legally Mandated, or Practically Expected?
The Bill’s own text doesn’t contain an explicit clause requiring penetration testing on a fixed schedule. Instead, the practical testing obligation flows through version 4.0 of the NCSC’s Cyber Assessment Framework. Regulators expect to use this framework when judging whether an organisation’s technical measures are “appropriate and proportionate.”
CAF v4.0 is built around four objectives, 14 principles, and 39 Contributing Outcomes, each backed by Indicators of Good Practice. NCSC itself is explicit that it “has no regulatory responsibilities.” Because of that, organisations need to confirm with their actual regulator how CAF applies to them specifically. Even so, industry practitioner guidance already treats CAF Objective B and Objective C differently. These are the outcomes penetration testing evidence is specifically meant to support. Practitioners extend threat-led testing scope to cover Bill-regulated systems, then use the results as direct evidence against those two objectives.
Weak evidence, common in organisations treating testing as a formality:
A generic annual vulnerability scan report, with no mapping back to a specific CAF outcome and no retest confirming remediation actually worked.
CAF-aligned evidence, structured for regulatory review:
A penetration test report names the specific CAF Objective B or C outcome each finding relates to. It includes reproduction steps. It documents a retest confirming the fix held.
The practical upshot is straightforward. Nobody can point to a single Bill clause and say “this requires quarterly pentesting.” Even so, an organisation without CAF-aligned testing evidence will struggle to demonstrate proportionate technical measures once a regulator asks.
|
Regulatory Framework |
Maximum Financial Penalty |
Based on Global Turnover? |
Who It Applies To |
Penalty Approach |
| Cyber Security and Resilience Bill | £17m or 4% of global turnover for serious breaches; £10m or 2% for minor breaches. |
Yes |
Essential services, digital providers, and critical suppliers | Fines increase with company size and global turnover. |
| NIS Regulations 2018 | Up to £17 million |
No |
Organisations within the NIS regulatory scope | Fixed maximum penalty regardless of company turnover. |
| UK / EU GDPR | Up to £17.5m or 4% of global turnover, whichever is higher. |
Yes |
Organisations handling personal data under GDPR | Fines can increase based on the organisation’s global turnover. |
New Incident Reporting Rules: 24hrs, 72hrs & Mandatory Ransomware Reporting
The Bill replaces NIS 2018’s subjective adverse effect trigger with fixed, unforgiving reporting windows: 24 hours for an initial notification, and 72 hours for a full report, regardless of how severe the incident initially appears. That’s a change from a regime where an organisation could reasonably argue an incident didn’t meet the reporting bar.
Meanwhile, ransomware incidents fall squarely within the new mandatory incident reporting regime, including attacks that have not yet caused disruption but are likely to have a significant impact. The Bill also introduces “near miss” reporting duties, meaning organisations may need to report incidents that didn’t succeed but came close. Neither Synnovis nor the M&S attack triggered mandatory reporting under the current rules. Given that gap, this tightening is a direct response to incidents regulators felt should have surfaced sooner.
What Newly In-Scope Organisations Should Do Now
Waiting for Royal Assent before preparing means starting the real work only after enforcement is already close, since substantive obligations follow through secondary cybersecurity legislation roughly two years out. A few priorities matter more than others in the meantime.
Start by mapping every technology supplier used in service delivery to critical infrastructure clients. That matters because the Section 12 critical supplier route means exposure can arrive through a customer relationship. Run a gap analysis against CAF v4.0 specifically, since that’s the standard regulators are expected to reference. Build a unified incident triage process capable of meeting the 24-hour and 72-hour windows, including ransomware and near-miss scenarios, well before enforcement begins. Brief the board on the personal liability debate still playing out in the Lords, since the outcome of those 65 tabled amendments will shape governance expectations either way.
How Qualysec Supports Bill Readiness
Qualysec is a crest-accredited penetration-testing-led security firm helping with cyber security resilience that has completed 3700+ assessments across SaaS, healthcare, fintech, e‑commerce and AI environments. The organization designs its engagements to produce auditor‑ready evidence aligned to the NCSC Cyber Assessment Framework (CAF v4.0) and the Bill’s tighter reporting expectations.
CAF‑Aligned Penetration Testing
- Scopes tests to Bill‑relevant systems (apps, APIs, cloud, admin portals, critical‑client integrations).
- Maps findings to CAF Objective B and Objective C, with reproduction steps, impact analysis, and remediation guidance.
- Includes retesting and delivers reports in a format suitable for regulators and auditors.
Incident Response & Supply‑Chain Readiness
- Runs tabletop and technical IR exercises against ransomware, third‑party compromise, and near‑miss scenarios.
- Validates whether triage and escalation can meet the 24‑hour and 72‑hour reporting clocks of this UK cybersecurity legislation.
- Reviews customer and vendor dependencies to flag Section 12 critical supplier exposure.
Compliance-Focused Testing for Multi-Framework Environments
Many organisations in scope for the Bill already maintain or pursue compliance certifications such as SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR and FDA 510(k). Qualysec’s compliance practice is built around these frameworks, using penetration testing as direct audit evidence. qualysec
For CSRB readiness, this means:
- A single testing programme supports CAF alignment and existing or planned certifications, reducing duplication.
- Reports are written for both technical stakeholders (engineers, security leads) and governance stakeholders (CISO, auditors, board).
- Case studies show this model in practice across healthcare, SaaS, fintech, and e‑commerce, including work tied to HIPAA, SOC 2, and VARA compliance.
All work is tracked in Qualysec’s client dashboard for real‑time visibility and compliance‑ready reporting.
Schedule a Cyber Security and Resilience Bill readiness assessment with Qualysec.
Conclusion
The Cyber Security and Resilience Bill won’t receive Royal Assent with a penetration testing clause spelled out in black and white. Instead, it will lean on the NCSC’s Cyber Assessment Framework to define what “appropriate and proportionate” actually looks like. CAF-aligned testing evidence is already the standard practitioner guidance points toward. Add genuinely expanded scope and tighter reporting windows. Add penalties reaching £17 million or 4% of turnover. Organisations newly caught by this Bill have a real reason to start now. The two-year gap between Royal Assent and enforcement isn’t a reason to wait. It’s the only real head start anyone gets.
Contact Qualysec to prepare for Cyber Security and Resilience Bill enforcement.
FAQ
1. When will the Cyber Security and Resilience Bill become law?
The Cyber Security and Resilience Bill UK is in the House of Lords Grand Committee as of September 2026, having cleared all Commons stages without division. Most commentary expects Royal Assent in late 2026, though a June 2026 government consultation suggested spring 2027 instead, subject to parliamentary progress. Either way, substantive obligations aren’t expected to take effect until around 2028, delivered through secondary legislation.
2. Which organisations are newly in scope?
The Bill carries forward the existing Operators of Essential Services and Relevant Digital Service Providers from NIS 2018. Beyond that base, it adds four new categories. Managed service providers, regulated as RMSPs under Section 9. Data centres meeting 1MW or 10MW capacity thresholds under Section 4. Load controllers at 300MW or higher under Section 6. Critical suppliers designated under Section 12, based on who they supply rather than their own sector.
3. Does UK cyber security legislation require mandatory penetration testing?
Not explicitly in this cyber security legislation Bill’s text. Instead, the practical obligation flows through the NCSC’s Cyber Assessment Framework, version 4.0. Regulators are expected to use this framework when assessing whether an organisation’s technical measures are appropriate and proportionate. Industry guidance already treats CAF-aligned penetration testing as the standard for evidencing two of the framework’s four objectives, even without a standalone testing clause in the legislation itself.
4. How is the Bill different from the EU’s NIS2 Directive?
Both cyber security legislation in the UK aims to modernise incident reporting and expand regulatory scope, and the UK government has stated the Bill intends to reduce regulatory duplication with NIS2 where possible. However, the Bill takes a different structural approach. It amends and extends the existing UK NIS Regulations 2018, rather than replacing them wholesale. It also introduces UK-specific categories, like the Section 12 critical supplier route, that don’t map directly onto NIS2’s own scope definitions.
5. What are the incident reporting timelines?
In this cyber security and resilience bill timeline, organisations face a 24-hour initial notification requirement, followed by a 72-hour full report. This replaces NIS 2018’s subjective “adverse effect” trigger with fixed windows that apply regardless of assessed severity. The Bill also introduces mandatory ransomware reporting and new near-miss reporting duties for cyber security resilience, covering incidents that came close to succeeding.






