Cyber Security and Resilience (Network and Information Systems) Bill 2024-26


Make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.

What is this Bill?

The Cyber Security and Resilience (Network and Information Systems) Bill is a Government Bill tabled by a Minister of the Crown.

Is this Bill currently before Parliament?

Yes. This Bill was introduced on 12 November 2025 and is currently before Parliament.

Whose idea is this Bill?

Government Bills implement the legislative agenda of the Government. This agenda, and the Bills that will implement it, are outlined in the Queen's Speech at the Session's State Opening of Parliament.

What type of Bill is this?

Government Bills are technically Presentation Bills, but the Government can use its legislative time to ensure the schedule of debates to scrutinise the Bill.

So is this going to become a law?

Though the Bill can be amended from its original form, the Bill will almost certainly be enacted in law before the end of the Session, or will be carried over to the subsequent Session.

How can I find out exactly what this Bill does?

The most straightforward information is contained in the initial Explanatory Notes for the Bill.

Would you like to know more?

See these Glossary articles for more information: Government Bills, Process of a Bill

Official Bill Page Initial Explanatory Notes Initial Briefing papers Ministerial Extracts from Debates All Bill Debates

Next Event: Tuesday 1st September 2026 - Committee stage

Last Event: Tuesday 14th July 2026 - 2nd reading: Minutes of Proceedings (Lords)

191 Amendments have been proposed for this Bill
View Amendments

Bill Progession through Parliament

Commons Completed
Lords - 60%

Timeline of Bill Documents and Stages

9th September 2026
Committee stage (Lords)
7th September 2026
Committee stage (Lords)
3rd September 2026
Committee stage (Lords)
1st September 2026
Committee stage (Lords)
23rd July 2026
Amendment Paper
HL Bill 32 Running list of amendments – 23 July 2026
Baroness Kidron (XB)
Tabled: 23 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 7, page 6, line 31, after “engine” insert “, an AI product or service”

22nd July 2026
Amendment Paper
HL Bill 32 Running list of amendments – 22 July 2026
Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 8, page 7, line 36, at end insert— “(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 9, page 9, line 13, at end insert— “(3E) A person does not provide a managed service for the purposes of paragraph (3B) where the service provided consists only of— (a) the provision of advice, consultancy, training or professional services that does not involve the person, or a person acting on the person’s behalf, connecting to or otherwise obtaining privileged access to the network and information systems of the customer, (b) the development, licensing, sale or support of software, where that support does not involve ongoing privileged administrative access to the customer’s network and information systems, or (c) the provision of a help desk or user-support service that does not include the active administration or management of the customer’s network and information systems. (3F) In paragraph (3E), “privileged access” means access which enables the person to alter the configuration of, install software on, or exercise administrative control over, the customer’s network and information systems.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 24, insert the following new Clause— “Services to support political parties to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify that an activity carried out for the primary purpose of the operation of a registered political party be an essential activity. (2) In this section “registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000. (3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the specified activities.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 35, insert the following new Clause— “Office for Cyber Resilience (1) There is to be a body corporate known as the Office for Cyber Resilience (“the OCR”). (2) The OCR is to be— (a) the single regulatory authority for the purposes of this Act, and (b) the single designated competent authority for the purposes of the NIS Regulations. (3) The Secretary of State must by regulations— (a) provide for the transfer to the OCR of the functions of— (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment. (4) Regulations under subsection (3) must in particular make provision about the OCR’s constitution, membership, staffing, funding, governance and accountability to Parliament. (5) In exercising its functions the OCR must— (a) act in a way that is proportionate, consistent, transparent and targeted only at cases in which action is needed, (b) have regard to differences in the nature, scale and risk profile of the sectors and persons it regulates, and (c) maintain arrangements for co-operation with the National Cyber Security Centre, the Information Commission and other relevant persons. (6) The Secretary of State must, before the OCR assumes any function, lay before Parliament a report setting out— (a) how the OCR will be resourced and staffed to discharge its functions across all regulated sectors, and (b) the arrangements for maintaining sector-specific technical expertise within the OCR.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 37, insert the following new Clause— “Consultation before issue of codes of practice and regulations (1) Before preparing, issuing, amending or revising a code of practice under Chapter 4 of this Part, the Secretary of State must carry out an open public consultation. (2) Before making regulations under section 24 or Chapter 3 of this Part, or giving a direction under Part 4 that applies to a description of regulated persons generally, the Secretary of State must carry out an open public consultation. (3) A consultation under this section must— (a) be open to any person providing, or proposing to provide, services of a kind regulated under this Act or the NIS Regulations, and to any other interested person, (b) be published in a manner that is readily accessible, including to small and medium-sized enterprises, (c) last for a period of not less than eight weeks, except where the Secretary of State reasonably considers that a shorter period is justified by urgency and publishes the reasons for that decision, and (d) invite representations on the likely costs, benefits and practical effects of the proposal. (4) The Secretary of State must publish a response to the consultation, setting out how the representations received have been taken into account, before the code of practice, regulations or direction take effect. (5) This section does not apply to a direction given under Part 4 in respect of a specific regulated person for national security purposes.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 39, insert the following new Clause— “Presumption of conformity with recognised standards (1) A regulated person who demonstrates compliance with a designated standard in relation to a matter is to be presumed, in relation to that matter, to have complied with the corresponding duty under this Act or the NIS Regulations to which the designated standard relates. (2) The Secretary of State must by regulations designate for the purposes of subsection (1) one or more internationally or nationally recognised cyber security standards or frameworks, which must include— (a) the standard published as ISO/IEC 27001 (information security management systems), and (b) the Cyber Essentials Plus certification scheme operated under the authority of the National Cyber Security Centre. (3) When designating a standard the Secretary of State must specify the duty or duties under this Act or the NIS Regulations to which the presumption in subsection (1) applies. (4) The presumption in subsection (1)— (a) applies only to the extent that the scope of the designated standard covers the network and information systems to which the duty relates, and (b) may be rebutted by a regulatory authority where it has reasonable grounds to believe that, despite compliance with the designated standard, the regulated person has not met the duty in question. (5) The Secretary of State must review the designated standards at least once in every three-year period and update them to reflect current best practice.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 40, page 63, line 27, leave out “5” and insert “3”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 42, page 65, line 36, at end insert— “(aa) which is made under section (Office for Cyber Resilience), or”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

Clause 42, page 65, line 36, at end— “(aa) which is made under section (Presumption of conformity with recognised standards), or”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Computer Misuse Act 1990: statutory defence for cyber security activities (1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities. (2) The review under subsection (1) must consider, in particular— (a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith, (b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and (c) the approaches taken in other jurisdictions. (3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out— (a) the findings and conclusions of the review, and (b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Annual report on incident volumes (1) The Secretary of State must, for each calendar year, prepare and lay before Parliament a report on the volume of incidents reported under the NIS Regulations and under regulations made under this Act during that year. (2) A report under this section must include, so far as is consistent with national security— (a) the number of incidents reported, broken down by regulated sector and subsector, (b) the number of incidents reported by each description of regulated person, (c) the number of incidents that were significant incidents, and (d) a summary of the principal types and causes of the incidents reported. (3) A report under this section must be laid before Parliament within four months of the end of the calendar year to which it relates. (4) This section does not require the disclosure of information which would, in the opinion of the Secretary of State, be prejudicial to national security or which would identify a particular regulated person without its consent.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Digital Sovereignty Strategy (1) The Secretary of State must, within 12 months of the day on which this Act is passed, publish a strategy (“the Digital Sovereignty Strategy”) setting out the Government’s approach to maintaining the security and resilience of relevant network and information systems by assessing, managing and mitigating risks— (a) associated with foreign interference, and (b) arising from reliance on foreign-supplied technologies. (2) The Digital Sovereignty Strategy must— (a) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on the security and resilience of government digital procurement, detailing how the Government intends to reduce strategic dependencies on foreign-owned suppliers and on the hardware and software of hostile states so as to mitigate the risk of systemic disruption; (c) include a commitment to prioritise, where appropriate, the use of secure technologies developed in the United Kingdom by United Kingdom organisations in relevant network and information systems; (d) set out how the Government intends to address any risks identified under subsection (1), including by supporting the use of sovereign and domestic technologies or systems. (3) The Secretary of State must review and, if necessary, revise the Digital Sovereignty Strategy at least once in every three-year period. (4) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 23 July 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Board oversight and accountability: security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of the arrangements relating to the security and resilience of the body’s network and information systems. (2) In exercising that oversight, the management body must— (a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems, and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for a failure by the body to comply with its duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks to, and assess appropriate risk-management practices for, the body’s network and information systems. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

14th July 2026
2nd reading: Minutes of Proceedings (Lords)
14th July 2026
2nd reading (Lords)
1st July 2026
Select Committee report
3rd Report from the Select Committee on the Constitution
23rd June 2026
Briefing papers
Cyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026–27
19th June 2026
Delegated Powers Memorandum
Delegated Powers Memorandum
17th June 2026
Bill
HL Bill 32 (as brought from the Commons)
17th June 2026
1st reading: Minutes of Proceedings (Lords)
17th June 2026
1st reading (Lords)
17th June 2026
Explanatory Notes
HL Bill 32 Explanatory Notes
17th June 2026
Keeling schedules
Keeling text (schedules) prepared by the Department for Science, Innovation and Technology to show changes to the Network and Information Systems Regulations 2018 proposed by the Bill as introduced to the House of Lords on 17 June 2026
16th June 2026
3rd reading (Commons)
16th June 2026
Report stage (Commons)
16th June 2026
Amendment Paper
Consideration of Bill Amendments as at 16 June 2025
16th June 2026
Bill proceedings: Commons
Report Stage Proceedings as at 16 June 2026
16th June 2026
Selection of amendments: Commons
Speaker’s provisional grouping and selection of Amendments
15th June 2026
Amendment Paper
Notices of Amendments as at 15 June 2026
12th June 2026
Amendment Paper
Notices of Amendments as at 12 June 2026
11th June 2026
Amendment Paper
Notices of Amendments as at 11 June 2026

NC21

Matt Western (Lab)
Iqbal Mohamed (Ind)
Tabled: 11 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Food supply chain to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— “Food supply Food supply chain The Secretary of State for Environment, Food and Rural Affairs (United Kingdom)” (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert— “The food supply chain subsector 12 — (1) This paragraph describes the threshold requirements which apply to essential services in the food supply chain subsector. (2) For the essential service of the food supply chain in the United Kingdom the threshold requirement is that the person is in the food supply chain and does not qualify as small or a micro-entity (or is excluded) within the meaning of Part 15 of the Companies Act 2006. (3) For the purposes of this paragraph— (a) a “food supply chain” is a supply chain for providing individuals with items of food or drink for personal consumption, where the items consist of or include, or have been produced to any extent using— (i) anything grown or otherwise produced in carrying on agriculture, or (ii) anything taken, grown or otherwise produced in carrying on fishing or aquaculture; (b) a person is “in” a food supply chain if that person is a producer or an intermediary in a food supply chain. (4) In paragraph (3)(b)— (a) “producer” means a person who is carrying on agriculture, fishing or aquaculture; (b) “intermediary” means a person in the food supply chain between a producer and the individuals referred to in paragraph (3)(a). (5) In this paragraph— “agriculture” includes any growing of plants, and any keeping of animals, for the production of food or drink; “aquaculture” means the breeding, rearing, growing or cultivation of— (a) any fish or other aquatic animal, (b) seaweed or any other aquatic plant, or (c) any other aquatic organism. “plants” includes fungi. (6) In regulation 8A of the NIS Regulations (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert— “(c) provides an essential service of a kind referred to in paragraph 12 of Schedule 2 (food supply chain sector) within the United Kingdom.””

28

Matt Western (Lab)
Iqbal Mohamed (Ind)
Tabled: 11 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

Clause 10, page 9, line 33, at end insert— “(2A) The measures taken by an RMSP under paragraph (1) must ensure that the number of customers to whom the RMSP provides services does not exceed the critical risk threshold. (2B) In paragraph (2A), the “critical risk threshold” is the number of customers within a sector or subsector where an incident affecting the provision of services to those customers by the RMSP would result in disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom. (2C) Paragraph (2D) applies where the number of customers to whom an RMSP provides services exceeds the critical risk threshold by virtue of contracts entered into before the coming into force of section 10 of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (2D) The RMSP must take steps to reduce the number of customers to below the critical risk threshold, including exercising any right to terminate a contract or vary the terms of a contract.”

10th June 2026
Amendment Paper
Notices of Amendments as at 10 June 2026

NC19

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Review of risks posed by foreign state ownership or control of providers of cellular Internet of Things modules (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by foreign state ownership or control of providers of cellular Internet of Things modules. (2) For the purposes of this section– “cellular Internet of Things modules” means devices that communicate over public mobile networks for the purposes of enabling autonomous machine to machine communication;”

NC20

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Specification of retail commerce as an essential activity (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify as an essential activity retail commerce carried out by companies with an annual turnover in excess of £12 billion. (2) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector.”

7

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 38, line 33, leave out first “and” and insert “or”

8

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 38, line 35, leave out “and” and insert “or”

9

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 39, leave out lines 15 to 17

10

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 39, line 42, leave out from “paragraph (1)” to end of line 2 on page 40

11

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 12, leave out “(1)(c)” and insert “(1)(b)”

12

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 24, leave out from “regulation 6(1)” to “, or” in line 26

13

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 31, leave out from “regulation 6(1)” to end of line 33

14

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 41, line 4, at end insert— “(4A) A disclosure of information under any provision of regulation 6 or this regulation must be limited to information which is relevant and proportionate to the purpose for which the disclosure is being made.”

15

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 41, line 23, at end insert— “(1A) A disclosure of information under paragraph (1) must be limited to information which is relevant and proportionate to the purpose for which the disclosure is being made.”

16

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 20, page 44, line 15, at end insert— “(da) assesing the security or resilience of network and information systems relied on by a person regulated by the designated competent authority; (db) establishing whether any incident has occurred that the designated competent authority believes could have had, has had, is having or is likely to have, an adverse effect on the security or resilience of network and information systems relied on by a person regulated by the authority, and the nature and impact of any such incident; (dc) assessing the implementation of measures taken under regulation 10 to manage risks and to prevent and minimise the impact of incidents, including as a result of any inspection conducted under regulation 16; (dd) identifying a failure of a person to comply with any duty imposed by these Regulations;”

17

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 20, page 44, line 28, at end insert— “(da) assessing the security or resilience of network and information systems relied on by a person regulated by the Information Commission; (db) establishing whether any incident has occurred that the Information Commission believes could have had, has had, is having or is likely to have, an adverse effect on the security or resilience of network and information systems relied on by a person regulated by the Commission, and the nature and impact of any such incident; (dc) assessing the implementation of measures taken under regulation 12 or 14B to manage risks and to prevent and minimise the impact of incidents, including as a result of any inspection conducted under regulation 16; (dd) identifying a failure of a person to comply with any duty imposed by these Regulations;”

18

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 16, leave out “or notice” and insert “, notice, notification or decision”

19

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 20, at end insert— “(1A) Where a regulated person has— (a) appointed a representative to act on their behalf, and (b) notified a regulatory authority of the appointment, a direction, notice, notification or decision under this Part may be given to that representative instead of the regulated person, by any of the methods mentioned in subsection (1). (1B) Any direction, notice, notification or decision given to a representative by virtue of subsection (1A) is to be treated as having been given to the regulated person.”

20

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 22, leave out “or notice” and insert “, notice, notification or decision”

21

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 23, leave out “or notice” and insert “, notice, notification or decision”

22

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 25, leave out “or notice” and insert “, notice, notification or decision”

23

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 28, leave out “or notice” and insert “, notice, notification or decision”

24

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 5, leave out “or notice” and insert “, notice, notification or decision”

25

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 14, leave out “or notice” and insert “, notice, notification or decision”

26

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 17, leave out “or notice” and insert “, notice, notification or decision”

27

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Schedule 1, page 90, line 3, after “sub-paragraph (e)” insert “(including the “or” at the end)”

4th June 2026
Amendment Paper
Notices of Amendments as at 4 June 2026

NC17

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Withdrawn

To move the following Clause—"Specification of retail commerce carried out by UK-owned companies as an essential activity (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify retail commerce carried out by UK-owned companies as an essential activity. (2) For the purposes of this section, “UK owned companies” means companies incorporated in the United Kingdom and not controlled by non UK persons or entities. (3) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector."

NC18

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause—"Review of the number of bodies providing cloud computing services (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services. (2) For the purposes of this section, “cloud computing services” has the meaning given in paragraph 1 of the NIS Regulations."

6

Iqbal Mohamed (Ind)
Neil Duncan-Jordan (Lab)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

Clause 18, page 40, line 12, at end insert—"(8A) Where the CSIRT receives notification of an incident under regulation 11, 11A, 12A or 14E which it considers to materially involve autonomous or adaptive systems based on machine learning, the CSIRT must share relevant technical information with the relevant body within 72 hours. (8B) For the purposes of this regulation, a “relevant body” means the Al Security Institute or any successor or replacement body designated by the Secretary of State."

22nd May 2026
Amendment Paper
Notices of Amendments as at 22 May 2026
20th May 2026
Amendment Paper
Notices of Amendments as at 20 May 2026

4

Graeme Downie (Lab)
Luke Akehurst (Lab)
Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Christine Jardine (LD)
Tabled: 20 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 29, page 54, line 9, at end insert “, including the risks arising from the use of embedded communications components manufactured outside the UK;

5

Graeme Downie (Lab)
Luke Akehurst (Lab)
Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Christine Jardine (LD)
Tabled: 20 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 43, page 66, line 18, at end insert—"(i) a requirement relating to embedded communications components manufactured outside the UK."

19th May 2026
Amendment Paper
Notices of Amendments as at 19 May 2026
15th May 2026
Amendment Paper
Notices of Amendments as at 15 May 2026

NC2

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Withdrawn After Debate
View the speech made in the House

To move the following Clause—"Cyber security support service for SMEs (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems. (2) For the purposes of this section, a relevant SME is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A support service established under this section must provide- (a) advice and technical assistance to SMEs following a cyber incident; and (b) guidance on recovery and remediation."

NC3

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Review of high-risk bodies (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies. (2) A review under this section must assess- (a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise; (b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and (c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities. (3) In this section—"relevant body" means- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. "foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest; "network and information systems" has the meaning given by section 24(1)."

NC5

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Critical manufacturing and retail sectors (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities- (a) the manufacture of critical transport equipment; (b) the industrial production and processing of food products; and (c) the retail sale of food and essential goods via large-scale distribution chains. (2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors."

NC4

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Local authorities to be regulated as essential services (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—"Local Government Local Government The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The Local Government Sector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector. (2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register. (3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records. (4) In this paragraph "local authority means"— (a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly; (b) in Wales, a county council or a county borough council; (c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994; (d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.""

NC6

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Computer Misuse Act 1990: security and resilience of network and information systems (1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities. (2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines— (a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review; (b) the review's conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and (c) the Government's intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”

NC7

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Consultation on resourcing of regulatory authorities and regulated persons (1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing- (a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and (b) whether further government support is needed. (2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1)"

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Electoral infrastructure to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—"Elections Electoral infrastructure The Electoral Commission" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The electoral infrastructure subsector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector. (2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to- (a) maintain a register of electors containing more than 50,000 entries; (b) issue, receive, or process postal ballots for a parliamentary or local government election; or (c) count or aggregate votes cast in a parliamentary, mayoral or local government election. (3) In this paragraph—"parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom; "network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—"(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.""

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Political parties to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—"Government Political parties The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The political parties subsector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector. (2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons. (3) In this paragraph—"registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.""

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Board oversight of security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body's network and information systems. (2) In exercising oversight, the management body must- (a) approve the approach taken by the body to the management of risks to the security and resilience of the body's network and information systems; and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Requirement for regular testing of network and information systems (1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services. (2) Testing undertaken in accordance with this section must- (a) be proportionate, having regard to the size, nature and risk profile of the business; and (b) be conducted periodically, at intervals that are appropriate to the risks identified by the body. (3) A relevant body must document- (a) the outcomes of testing undertaken in accordance with this section; and (b) any remedial actions required or taken in response to the testing. (4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC12

Alex Sobel (Lab)
Brian Leishman (Lab)
John Whitby (Lab)
Samantha Niblett (Lab)
Neil Duncan-Jordan (Lab)
Dawn Butler (Lab)
Chris Bloore (Lab)
John McDonnell (Lab)
Ben Lake (PC)
George Freeman (Con)
Desmond Swayne (Con)
Iqbal Mohamed (Ind)
Melanie Ward (Lab)
Jess Asato (Lab)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—""Last-resort" powers in respect of data centres and Al models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of- (a) data centres, or (b) Al systems used or deployed by a data centre, in the event of an Al security or operational emergency. (2) For the purposes of this section—"data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); "Al system" means a machine-based system that, from the input it receives, can infer how to- (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "used or deployed” means made available to— (a) a substantial number of individuals within the United Kingdom; or (b) providers and operators of essential services; "Al security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an Al system used or deployed by a data centre, whether through autonomous or non-autonomous means; and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to- (a) large-scale disruption to critical infrastructure or essential services; (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or (c) severe, large-scale harm to human life; "data centre operator” means a person who operates a data centre; (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the direction and the reasons for it; and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, including relating to- (a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers; (b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers; (c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and (d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including- (i) incident reporting; and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4). (6) Regulations relating to last-resort powers may- (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to— (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must— (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and (b) inform the operator or provider of their right to apply to the High Court for relief. (8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including- (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of Al security or operational emergencies and lay a copy of the report before Parliament. (12) The causes and potential causes of Al security or operational emergencies considered in any report under subsection (11) must include- (a) adversarial uses of Al systems by state and non-state actors; (b) the capabilities for cyber-attacks by autonomous Al systems; and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent Al”.”

NC13

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Iqbal Mohamed (Ind)
Caroline Voaden (LD) - Liberal Democrat Spokesperson (Schools)
Steve Darling (LD) - Liberal Democrat Spokesperson (Work and Pensions)
Mike Martin (LD)
Vikki Slade (LD)
Lisa Smart (LD) - Liberal Democrat Spokesperson (Cabinet Office)
Danny Chambers (LD) - Liberal Democrat Spokesperson (Mental Health)
Ian Sollom (LD) - Liberal Democrat Spokesperson (Universities and Skills)
Adrian Ramsay (Green) - Green Spokesperson (Treasury)
Liz Jarvis (LD)
Adam Dance (LD)
Cameron Thomas (LD)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Sarah Olney (LD) - Liberal Democrat Spokesperson (Business)
Pippa Heylings (LD) - Liberal Democrat Spokesperson (Energy Security and Net Zero)
Steff Aquarone (LD)
Bobby Dean (LD) - Liberal Democrat Shadow Leader of the House of Commons
Clive Lewis (Lab)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

To move the following Clause—"Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies (1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy ("a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by- (a) assessing, managing and mitigating risks— (i) associated with foreign interference, (ii) arising from reliance on foreign-supplied technologies, and (b) preventing over-reliance on foreign providers by building domestic capacity. (2) For the purposes of this section, a “relevant network and information system" is a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A Digital Sovereignty Strategy published under this section must— (a) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption; (c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and (d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems."

NC14

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Alison Griffiths (Con)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

To move the following Clause—"Register of foreign powers for the purposes of Part 4 (1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom's critical network and information systems. (2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups. (3) Regulations under this section are subject to the affirmative resolution procedure. (4) In this section, “foreign power” means— (a) the sovereign or other head of a foreign state in their public capacity; (b) a foreign government, or part of a foreign government; (c) an agency or authority of a foreign government, or of part of a foreign government; (d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or (e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government- (i) hold those posts as a result of, or in the course of, their membership of the party, or (ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”

NC15

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Alison Griffiths (Con)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Review of the cyber security risk posed by foreign powers (1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers. (2) A review under this section must identify whether any risk arises from— (a) activities undertaken outside of the UK, or (b) foreign owned or controlled infrastructure or locations within the UK. (3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups. (4) Within three months of each review under subsection (1), the Secretary of State must- (a) lay before Parliament a report containing the findings and conclusions of the review; and (b) where information is not included in a report on the grounds of being prejudicial to the UK's national security, send such information to the Intelligence and Security Committee of Parliament.”

NC16

Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy ("the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to— (i) dependence on hardware, software, or digital services that may be subject to foreign interference; (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers; (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities; (b) technological developments, market concentration, or strategic dependencies that may affect the security and resilience of relevant network and information systems; (c) set out the Government's approach to mitigating the risks identified under subsection (2); and (d) include an assessment of- (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems; (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems; (iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems; (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems; (v) options for international collaboration in the production of open source components used in relevant network and information systems; (vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (5) In this section—"relevant network and information system” means a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the Network and Information Systems Regulations 2018; "digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access and control over the hardware, software, data, and digital services on which relevant network and information systems depend; "open source” has the meaning given to it in the definition published by the Open Source Initiative.”

1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 8, page 7, line 36, at end insert—"(1A) In paragraph (1), after "risks” insert “, including risks arising from fraud,””

3

Iain Duncan Smith (Con)
Sarah Owen (Lab)
Alex Sobel (Lab)
Rachael Maskell (Lab)
Marie Rimmer (Lab)
Emily Darlington (Lab)
Nadia Whittome (Lab)
Mark Sewards (Lab)
Christine Jardine (LD)
Chris Law (SNP) - Shadow SNP Spokesperson (Business)
Layla Moran (LD)
Alistair Carmichael (LD)
Desmond Swayne (Con)
Charlie Dewhirst (Con)
Greg Smith (Con) - Shadow Parliamentary Under Secretary (Energy Security and Net Zero)
Julian Lewis (Con)
Bradley Thomas (Con)
Bob Blackman (Con)
Tom Tugendhat (Con)
Alicia Kearns (Con) - Opposition Whip (Commons)
Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Peter Bedford (Con)
Jack Rankin (Con)
Danny Kruger (RUK)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

Clause 18, page 41, line 15, at end insert—"Exemption from disclosure: right to a fair trial 6AB.-(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that- (a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or (b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial. (2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of— (a) subject matter experts, and (b) competent civil society groups. (3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months."

14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - html
14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - xml
14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - pdf
14th May 2026
Bill reintroduced
14th May 2026
Impact Assessments
Impact Assessment from the Department for Science, Innovation and Technology
14th May 2026
Explanatory Notes
Bill 002 EN 2026-27 - pdf
30th April 2026
Amendment Paper
Notices of Amendments as at 30 April 2026
29th April 2026
Amendment Paper
Notices of Amendments as at 29 April 2026
28th April 2026
Amendment Paper
Notices of Amendments as at 28 April 2026
16th April 2026
Amendment Paper
Notices of Amendments as at 16 April 2026
14th April 2026
Amendment Paper
Notices of Amendments as at 14 April 2026
10th April 2026
Amendment Paper
Notices of Amendments as at 10 April 2026
27th March 2026
Amendment Paper
Notices of Amendments as at 27 March 2026

NC16

Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Tabled: 27 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy ("the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to— (i) dependence on hardware, software, or digital services that may be subject to foreign interference; (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers; (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities; (b) technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems; set out the Government's approach to mitigating the risks identified under subsection (2); and (c) include an assessment of- (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems; (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems; (iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems; (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems; (v) options for international collaboration in the production of open source components used in relevant network and information systems; (vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (5) In this section— "relevant network and information system" means a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the Network and Information Systems Regulations 2018; "digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; "open source” has the meaning given to it in definition published by the Open Source Initiative."

26th March 2026
Amendment Paper
Notices of Amendments as at 26 March 2026

NC14

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Register of foreign powers for the purposes of Part 4 (1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom's critical network and information systems. (2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups. (3) Regulations under this section are subject to the affirmative resolution procedure. (4) In this section, "foreign power” means— (a) the sovereign or other head of a foreign state in their public capacity; (b) a foreign government, or part of a foreign government; (c) an agency or authority of a foreign government, or of part of a foreign government; (d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or (e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government- (i) hold those posts as a result of, or in the course of, their membership of the party, or (ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party."

NC15

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Review of the cyber security risk posed by foreign powers (1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers. (2) A review under this section must identify whether any risk arises from- (a) activities undertaken outside of the UK, or (b) foreign owned or controlled infrastructure or locations within the UK. (3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups. (4) Within three months of each review under subsection (1), the Secretary of State must- (a) lay before Parliament a report containing the findings and conclusions of the review; and (b) where information is not included in a report on the grounds of being prejudicial to the UK's national security, send such information to the Intelligence and Security Committee of Parliament.”

3

Iain Duncan Smith (Con)
Sarah Owen (Lab)
Alex Sobel (Lab)
Rachael Maskell (Lab)
Marie Rimmer (Lab)
Emily Darlington (Lab)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

Page 41, Clause 18, line 15, at end insert— "Exemption from disclosure: right to a fair trial 6AB.—(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that- (a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or (b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial. (2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of— (a) subject matter experts, and (b) competent civil society groups. (3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months."

25th March 2026
Amendment Paper
Notices of Amendments as at 25 March 2026

NC12

Alex Sobel (Lab)
Brian Leishman (Lab)
John Whitby (Lab)
Tabled: 25 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— ""Last-resort” powers in respect of data centres and Al models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of- (a) data centres, or (b) Al systems used or deployed by a data centre, in the event of an Al security or operational emergency. (2) For the purposes of this section— "data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); "Al system” means a machine-based system that, from the input it receives, can infer how to- (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "used or deployed” means made available to- (a) a substantial number of individuals within the United Kingdom; or (b) providers and operators of essential services; "Al security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an Al system used or deployed by a data centre, whether through autonomous or non-autonomous means; and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to— (a) large-scale disruption to critical infrastructure or essential services; (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or (c) severe, large-scale harm to human life; "data centre operator” means a person who operates a data centre; (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the direction and the reasons for it; and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, including relating to- (a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers; (b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers; (c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and (d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including- (i) incident reporting; and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4). (6) Regulations relating to last-resort powers may- (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to— (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must— (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and (b) inform the operator or provider of their right to apply to the High Court for relief. (8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including- (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of Al security or operational emergencies and lay a copy of the report before Parliament. (12) The causes and potential causes of Al security or operational emergencies considered in any report under subsection (11) must include- (a) adversarial uses of Al systems by state and non-state actors; (b) the capabilities for cyber-attacks by autonomous Al systems; and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent Al”.”

NC13

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Iqbal Mohamed (Ind)
Caroline Voaden (LD) - Liberal Democrat Spokesperson (Schools)
Steve Darling (LD) - Liberal Democrat Spokesperson (Work and Pensions)
Mike Martin (LD)
Vikki Slade (LD)
Lisa Smart (LD) - Liberal Democrat Spokesperson (Cabinet Office)
Danny Chambers (LD) - Liberal Democrat Spokesperson (Mental Health)
Ian Sollom (LD) - Liberal Democrat Spokesperson (Universities and Skills)
Adrian Ramsay (Green) - Green Spokesperson (Treasury)
Liz Jarvis (LD)
Adam Dance (LD)
Cameron Thomas (LD)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Sarah Olney (LD) - Liberal Democrat Spokesperson (Business)
Pippa Heylings (LD) - Liberal Democrat Spokesperson (Energy Security and Net Zero)
Steff Aquarone (LD)
Bobby Dean (LD) - Liberal Democrat Shadow Leader of the House of Commons
Tabled: 25 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies (1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy ("a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by- (a) assessing, managing and mitigating risks- (i) associated with foreign interference, (ii) arising from reliance on foreign-supplied technologies, and (b) preventing over-reliance on foreign providers by building domestic capacity. (2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A Digital Sovereignty Strategy published under this section must- (a) include risks associated with- (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption; (c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and (d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems."

18th March 2026
Amendment Paper
Notices of Amendments as at 18 March 2026
10th March 2026
Amendment Paper
Notices of Amendments as at 10 March 2026
2nd March 2026
Amendment Paper
Notices of Amendments as at 2 March 2026

NC1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was Withdrawn

To move the following Clause— "Statement on risks posed to systems by foreign interference (1) The Secretary of State must, within 12 months of the passing of this Act, publish a statement of the Government's plans in relation to risks to the security and resilience of relevant network and information systems arising from foreign interference. (2) For the purposes of this section, a “relevant network and information system" is a network and information system belonging to— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) Any statement under this section must— (a) set out the Government's intentions to assess, manage and mitigate the risks posed, or which could potentially be posed, to the security and resilience of relevant network and information systems by foreign interference in such systems; (b) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, (iv) procurement processes, and (v) the use of, or reliance on foreign technologies or systems; (c) include a specific focus on government digital procurement processes; (d) where risks are identified under (2)(b)(v), state whether the Government intends to address these risks by encouraging or supporting the use of domestic technologies or systems."

NC2

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Cyber security support service for SMEs (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems. (2) For the purposes of this section, a relevant SME is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A support service established under this section must provide— (a) advice and technical assistance to SMEs following a cyber incident; and (b) guidance on recovery and remediation."

NC3

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Review of high-risk bodies (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies. (2) A review under this section must assess— (a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise; (b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and (c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities. (3) In this section— "relevant body" means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. "foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest; "network and information systems" has the meaning given by section 24(1)."

NC4

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Critical manufacturing and retail sectors (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities— (a) the manufacture of critical transport equipment; (b) the industrial production and processing of food products; and (c) the retail sale of food and essential goods via large-scale distribution chains. (2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors."

NC5

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Local authorities to be regulated as essential services (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert— "Local Government Local Government The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The Local Government Sector 12- (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector. (2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register. (3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records. (4) In this paragraph "local authority means" (a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly; (b) in Wales, a county council or a county borough council; (c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994; (d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.""

NC6

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Computer Misuse Act 1990: security and resilience of network and information systems (1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities. (2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines– (a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review; (b) the review's conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and (c) the Government's intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”

NC7

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Consultation on resourcing of regulatory authorities and regulated persons (1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing- (a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and (b) whether further government support is needed. (2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1)"

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Electoral infrastructure to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— "Elections Electoral infrastructure The Electoral Commission" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The electoral infrastructure subsector 12- (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector. (2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to- (a) maintain a register of electors containing more than 50,000 entries; (b) issue, receive, or process postal ballots for a parliamentary or local government election; or (c) count or aggregate votes cast in a parliamentary, mayoral or local government election. (3) In this paragraph- "parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom; "network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert— "(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.""

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Political parties to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— "Government Political parties The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The political parties subsector 12 - (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector. (2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons. (3) In this paragraph- "registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.""

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Board oversight of security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body's network and information systems. (2) In exercising oversight, the management body must— (a) approve the approach taken by the body to the management of risks to the security and resilience of the body's network and information systems; and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Requirement for regular testing of network and information systems (1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services. (2) Testing undertaken in accordance with this section must— (a) be proportionate, having regard to the size, nature and risk profile of the business; and (b) be conducted periodically, at intervals that are appropriate to the risks identified by the body. (3) A relevant body must document – (a) the outcomes of testing undertaken in accordance with this section; and (b) any remedial actions required or taken in response to the testing. (4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request. (5) For the purposes of this section, a relevant body is one which is – (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

Clause 8, page 7, line 36, at end insert- "(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,””

26th February 2026
Committee stage (Commons)
25th February 2026
Bill
Bill 385 2024-26 (as amended in committee) - xml
25th February 2026
Bill
Bill 385 2024-26 (as amended in committee)
25th February 2026
Amendment Paper
Notices of Amendments as at 25 February 2026

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Local authorities to be regulated as essential services
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—

“Local Government

Local Government

The Secretary of State for Housing, Communities and Local Government”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The Local Government Sector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector.
(2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register.
(3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records.
(4) In this paragraph “local authority means” —
(a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly;
(b) in Wales, a county council or a county borough council;
(c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994;
(d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.””


Explanatory Text

This new clause would bring local authorities within the scope of the NIS Regulations as operators of essential services in relation to their functions managing electoral rolls and social care records. This ensures that public sector bodies holding sensitive data such as electoral rolls and social care records are subject to the same statutory protections as other critical infrastructure.

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Critical manufacturing and retail sectors
(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities—
(a) the manufacture of critical transport equipment;
(b) the industrial production and processing of food products; and
(c) the retail sale of food and essential goods via large-scale distribution chains.
(2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors.”


Explanatory Text

This new clause would require the Secretary of State to designate the manufacturing of critical transport equipment and retail of food and essential goods (when part of a large-scale distribution chain) as essential activities, bringing them within the scope of Part 3 of the Bill.

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Consultation on resourcing of regulatory authorities and regulated persons
(1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing—
(a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and
(b) whether further government support is needed.
(2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1).”


Explanatory Text

This new clause would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations, and whether additional government support is required.

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Electoral infrastructure to be regulated as an essential service
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Elections

Electoral infrastructure

The Electoral Commission”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The electoral infrastructure subsector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector.
(2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to—
(a) maintain a register of electors containing more than 50,000 entries;
(b) issue, receive, or process postal ballots for a parliamentary or local government election; or
(c) count or aggregate votes cast in a parliamentary, mayoral or local government election.
(3) In this paragraph—
“parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom;
“network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026.
(4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—
“(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.”


Explanatory Text

This new clause would designate the administration of elections and maintenance of voter registers as an “essential service” within the meaning of the NIS Regulations.

NC12

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Political parties to be regulated as an essential service
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Government

Political parties

The Secretary of State for Housing, Communities and Local Government”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The political parties subsector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector.
(2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons
(3) In this paragraph—
“registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.”””


Explanatory Text

This new clause would designate political parties as providing essential services for the purposes of cyber security.

NC13

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Statement on risks posed to systems by foreign interference
(1) The Secretary of State must, within 12 months of the passing of this Act, publish a statement of the Government’s plans in relation to risks to the security and resilience of network and information systems arising from foreign interference.
(2) Any statement under this section must—
(a) set out the Government’s intentions to assess, manage and mitigate the risks posed, or which could potentially be posed, to the security and resilience of network and information systems by foreign interference in such systems;
(b) include risks associated with—
(i) hardware,
(ii) software,
(iii) supply chains,
(iv) procurement processes, and
(v) the use of, or reliance on, foreign technologies or systems;
(c) include a specific focus on government digital procurement processes.
(d) where risks are identified under (2)(b)(v), state whether the Government intends to address these risks by encouraging or supporting the use of domestic technologies or systems.”


Explanatory Text

This new clause would require the Government to publish a statement of how it intends to address and mitigate any risks to network and information systems posed by foreign interference.

NC14

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Cyber security support service for SMEs
(1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems.
(2) For the purposes of this section, a relevant SME is one which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.
(3) A support service established under this section must provide—
(a) advice and technical assistance to SMEs following a cyber incident; and
(b) guidance on recovery and remediation.”


Explanatory Text

This new clause would require the Secretary of State to establish a cyber security support service for relevant SMEs.

NC15

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Review of high-risk bodies
(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies.
(2) A review under this section must assess—
(a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise;
(b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and
(c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities.
(3) In this section—
“relevant body” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.
“foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest;
“network and information systems” has the meaning given by section 24(1).”


Explanatory Text

This new clause would require the Government to review the security risks posed by critical suppliers and essential service providers linked to foreign states and evaluate whether current powers are sufficient to address these threats.

NC16

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Board oversight of security and resilience of network and information systems
(1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body’s network and information systems.
(2) In exercising oversight, the management body must—
(a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems; and
(b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks.
(3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems.
(4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices.
(5) For the purposes of this section, a relevant body is one which is –
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require active board oversight of, and accountability for, security and resilience measures, where a relevant body is governed by a board or similar body.

NC17

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Requirement for regular testing of network and information systems
(1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services.
(2) Testing undertaken in accordance with this section must –
(a) be proportionate, having regard to the size, nature and risk profile of the business; and
(b) be conducted periodically, at intervals that are appropriate to the risks identified by the body.
(3) A relevant body must document –
(a) the outcomes of testing undertaken in accordance with this section; and
(b) any remedial actions required or taken in response to the testing.
(4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request.
(5) For the purposes of this section, a relevant body is one which is –
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require bodies to carry out proportionate, periodic testing of the security and resilience of their network and information systems and provide the results to regulatory bodies upon request.

NC18

Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Withdrawn

To move the following Clause—
“Computer Misuse Act 1990: security and resilience of network and information systems
(1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities.
(2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines–
(a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review;
(b) the review’s conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and
(c) the Government’s intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”


Explanatory Text

This new clause would require the Secretary of State to review, within 12 months, whether amending the Computer Misuse Act 1990 could improve the resilience of network and information systems, and to report the government’s intentions to Parliament.

24th February 2026
Committee stage: 7th sitting (Commons)
24th February 2026
Written evidence
Written evidence submitted by Microsoft (CSRB39)
24th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 24 February 2026
24th February 2026
Bill proceedings: Commons
All proceedings up to 24 February 2026
24th February 2026
Written evidence
Written evidence submitted by Capita (CSRB33)
24th February 2026
Amendment Paper
Public Bill Committee Amendments as at 24 February 2026
24th February 2026
Written evidence
Written evidence submitted by the Regulatory Policy Committee (RPC) (CSRB34)
24th February 2026
Written evidence
Further written evidence submitted by iProov (CSRB35)
24th February 2026
Written evidence
Supplementary written evidence submitted by techUK (CSRB37)
24th February 2026
Written evidence
Written evidence submitted by National Grid (CSRB40)
24th February 2026
Written evidence
Written evidence submitted by Cloudflare (CSRB38)
12th February 2026
Amendment Paper
Notices of Amendments as at 12 February 2026
11th February 2026
Amendment Paper
Notices of Amendments as at 11 February 2026
10th February 2026
Committee stage: 6th sitting (Commons)
10th February 2026
Committee stage: 5th sitting (Commons)
10th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 10 February 2026
10th February 2026
Written evidence
Supplementary written evidence submitted by the NCC Group (CSRB29)
10th February 2026
Written evidence
Written evidence submitted by VIRTUS Data Centres (CSRB31)
10th February 2026
Amendment Paper
Public Bill Committee Amendments as at 10 February 2026
10th February 2026
Written evidence
Written evidence submitted by the UK Cyber Security Council (CSRB32)
10th February 2026
Written evidence
Written evidence submitted by CrowdStrike (CSRB30)
9th February 2026
Amendment Paper
Notices of Amendments as at 9 February 2026
6th February 2026
Amendment Paper
Notices of Amendments as at 6 February 2026
5th February 2026
Committee stage: 4th sitting (Commons)
5th February 2026
Committee stage: 3rd sitting (Commons)
5th February 2026
Amendment Paper
Public Bill Committee Amendments as at 5 February 2026
5th February 2026
Written evidence
Written evidence submitted by the British Insurance Brokers' Association (BIBA) (CSRB28)
5th February 2026
Written evidence
Written evidence submitted by Dr Aine MacDermott, Liverpool John Moores University (CSRB24)
5th February 2026
Written evidence
Written evidence submitted by The ABI (CSRB23)
5th February 2026
Written evidence
Written evidence submitted by the Internet Services Providers' Association (ISPA) (CSRB22)
5th February 2026
Written evidence
Written evidence submitted by Shoosmiths LLP (CSRB27)
5th February 2026
Written evidence
Written evidence submitted by the Online Safety Act Network (CSRB26)
5th February 2026
Written evidence
Written evidence submitted by Rob Wright, Chief Commercial Officer, Hexiosec, Ambassador for Software Security for DSIT (CSRB25)
5th February 2026
Written evidence
Written evidence submitted by BCS, The Chartered Institute for IT (CSRB21)
4th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 5 February 2026
4th February 2026
Amendment Paper
Notices of Amendments as at 4 February 2026
3rd February 2026
Committee stage: 2nd sitting (Commons)
3rd February 2026
Committee stage:Commitee Debate: 1st sitting (Commons)
3rd February 2026
Written evidence
Written evidence submitted by Rob Newby (on the Energy sector) (CSRB01A)
3rd February 2026
Written evidence
Written evidence submitted by ISACA (CSRB05)
3rd February 2026
Written evidence
Written evidence submitted by the UK Cyber Security Council (UK CSC) (CSRB06)
3rd February 2026
Written evidence
Written evidence submitted by Richard Holland (CSRB07)
3rd February 2026
Written evidence
Written evidence submitted by PauseAI UK (CSRB09)
3rd February 2026
Amendment Paper
Public Bill Committee Amendments as at 3 February 2026
3rd February 2026
Written evidence
Written evidence submitted by ISC2 (CSRB10)
3rd February 2026
Written evidence
Written evidence submitted by the CyberUp Campaign (CSRB18)
3rd February 2026
Written evidence
Written evidence submitted by iProov (CSRB17)
3rd February 2026
Written evidence
Written evidence submitted by UK Finance (CSRB14)
3rd February 2026
Written evidence
Written evidence submitted by Zurich UK (CSRB12)
3rd February 2026
Written evidence
Written evidence submitted by Rik Ferguson (CSRB02)
3rd February 2026
Written evidence
Written evidence submitted by National Gas (CSRB20)
3rd February 2026
Written evidence
Written evidence submitted by Infoblox (CSRB19)
3rd February 2026
Written evidence
Written evidence submitted by Liberty and Privacy International (CSRB16)
3rd February 2026
Written evidence
Written evidence submitted by the Cybersecurity Business Network (CSRB15)
3rd February 2026
Written evidence
Written evidence submitted by Philip Virgo (CSRB13)
3rd February 2026
Written evidence
Written evidence submitted by Doctors Lam and Seifert (CSRB11)
3rd February 2026
Written evidence
Written evidence submitted by the Institution of Engineering and Technology (IET) (CSRB08)
3rd February 2026
Written evidence
Written evidence submitted by Open Rights Group (CSRB04)
3rd February 2026
Written evidence
Written evidence submitted by Fortaegis (CSRB03)
3rd February 2026
Written evidence
Written evidence submitted by Rob Newby (on the Retail sector) (CSRB01B)
30th January 2026
Amendment Paper
Notices of Amendments as at 30 January 2026
29th January 2026
Amendment Paper
Notices of Amendments as at 29 January 2026
28th January 2026
Amendment Paper
Notices of Amendments as at 28 January 2026
27th January 2026
Amendment Paper
Notices of Amendments as at 27 January 2026
22nd January 2026
Keeling schedules
The Network and Information Systems Regulations 2018 - 22 January 2026
7th January 2026
Press notices
Cyber Security and Resilience (Network and Information Systems) Bill
6th January 2026
2nd reading2nd Reading Commons Hansard Link (Commons)
6th January 2026
Carry-over motion
6th January 2026
Programme motion
6th January 2026
Ways and Means resolution
6th January 2026
Money resolution
17th December 2025
Briefing papers
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26
12th November 2025
Bill
Bill 329 2024-26 (as introduced)
12th November 2025
Bill
Bill 329 2024-26 (as introduced) - xml download
12th November 2025
1st reading (Commons)
12th November 2025
Delegated Powers Memorandum
Memorandum from the Department of Science, Innovation and Technology
12th November 2025
Explanatory Notes
Bill 329 EN 2024-26
12th November 2025
Impact Assessments
Impact Assessment from the Department for Science, Innovation and Technology