Cyber Security and Resilience (Network and Information Systems) Bill 2024-26


Make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.

What is this Bill?

The Cyber Security and Resilience (Network and Information Systems) Bill is a Government Bill tabled by a Minister of the Crown.

Is this Bill currently before Parliament?

Yes. This Bill was introduced on 12 November 2025 and is currently before Parliament.

Whose idea is this Bill?

Government Bills implement the legislative agenda of the Government. This agenda, and the Bills that will implement it, are outlined in the Queen's Speech at the Session's State Opening of Parliament.

What type of Bill is this?

Government Bills are technically Presentation Bills, but the Government can use its legislative time to ensure the schedule of debates to scrutinise the Bill.

So is this going to become a law?

Though the Bill can be amended from its original form, the Bill will almost certainly be enacted in law before the end of the Session, or will be carried over to the subsequent Session.

How can I find out exactly what this Bill does?

The most straightforward information is contained in the initial Explanatory Notes for the Bill.

Would you like to know more?

See these Glossary articles for more information: Government Bills, Process of a Bill

Official Bill Page Initial Explanatory Notes Initial Briefing papers Ministerial Extracts from Debates All Bill Debates

Next Event: Monday 7th September 2026 - Committee stage

Last Event: Thursday 3rd September 2026 - Committee stage: Minutes of Proceedings (Lords)

612 Amendments have been proposed for this Bill
View Amendments

Bill Progession through Parliament

Commons Completed
Lords - 60%

Timeline of Bill Documents and Stages

9th September 2026
Committee stage (Lords)
7th September 2026
Committee stage (Lords)
4th September 2026
Amendment Paper
HL Bill 32–III Third marshalled list for Grand Committee
3rd September 2026
Committee stage: Minutes of Proceedings (Lords)
3rd September 2026
Committee stage (Lords)
2nd September 2026
Amendment Paper
HL Bill 32–II(a) Amendment for Grand Committee (Supplementary to the Second Marshalled List)

148A

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 2 Sep 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 52, insert the following new Clause – "Appeals against decisions under section 50 (1) A person may appeal to the Upper Tribunal against— (a) a confirmation decision given to the person under section 50; (b) a decision under section 50 to require the person to pay a penalty; (c) the amount of a penalty which the person is required to pay under section 50. (2) An appeal under this section must be brought before the end of the period of 28 days beginning with the day on which notice of the decision appealed against was given to the person, or within such longer period as the Upper Tribunal may allow. (3) The Upper Tribunal must determine an appeal under this section on the merits and by reference to the matters before it, and not by applying the principles that would be applied by a court on an application for judicial review. (4) On an appeal under this section the Upper Tribunal may – (a) confirm, vary or cancel the decision appealed against, (b) substitute for that decision any decision that the Secretary of State could have made, or (c) remit the matter to the Secretary of State with such directions as the Upper Tribunal considers appropriate. (5) Where an appeal is brought under subsection (1)(b) or (c), the requirement to pay the penalty is suspended until the appeal is determined, withdrawn or abandoned. (6) Tribunal Procedure Rules must make provision, for the purposes of proceedings under this section, about— (a) securing that information is not disclosed where disclosure would be contrary to the interests of national security, (b) the holding of proceedings, or of parts of proceedings, in the absence of a party or a party's legal representative, and (c) the appointment of a person to represent the interests of a party in proceedings, or parts of proceedings, from which that party and that party's legal representative are excluded. (7) Nothing in this section affects any right to apply for judicial review.”

2nd September 2026
Amendment Paper
HL Bill 32-II Second marshalled list for Grand Committee

99

Baroness Northover (LD)
Tabled: 2 Sep 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 42, insert the following new Clause—
“Cyber security competence: functions of the UK Cyber Security Council
(1) The UK Cyber Security Council is to exercise the functions in subsection (2) and is accountable to the Secretary of State.
(2) The functions are—
(a) to validate and accredit professional qualifications, standards and titles for cyber security professionals employed by regulated persons,
(b) to monitor the supply of, and demand for, qualified cyber security professionals across the sectors regulated under this Act and the NIS Regulations, and
(c) to audit whether, and to what extent, regulated persons employ or have access to appropriately certified cyber security professionals.
(3) A regulatory authority must have regard to the information and standards provided by the Council under this section when exercising its functions.
(4) The Secretary of State must by regulations make further provision about the exercise of the Council’s functions under this section, including provision about its governance, funding and accountability.
(5) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament.”


Explanatory Text

This new clause would place the UK Cyber Security Council on a statutory footing under the Office for Cyber Resilience (or, absent that body, the Secretary of State), with powers to validate qualifications, to monitor the supply of and demand for cyber security professionals, and to audit whether regulated organisations employ certified professionals—a “competence mandate” for the regime.

1st September 2026
Committee stage: Minutes of Proceedings (Lords)
1st September 2026
Committee stage (Lords)
1st September 2026
Amendment Paper
HL Bill 32–I(b) Amendments for Grand Committee (Supplementary to the Marshalled List)

81B

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 1 Sep 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 24, insert the following new Clause – “Public authority activities to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify as essential activities such activities carried on by public authorities as the Secretary of State considers to be essential to the economy of the United Kingdom or any part of it, or to the day-to-day functioning of society in the United Kingdom or any part of it. (2) In complying with subsection (1) the Secretary of State must have regard in particular to activities carried on by – (a) government departments and other persons exercising functions on behalf of the Crown, (b) executive agencies and non-departmental public bodies, and (c) persons responsible for the delivery of health, social care, social security or justice services. (3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified. (4) Regulations under subsection (1) may not specify an activity so far as it is carried on– (a) by the Security Service, the Secret Intelligence Service or GCHQ, or (b) by means of a network and information system used for the storage, processing or transmission of information which is classified as “secret” or “top secret” in accordance with the policy of His Majesty's Government on the security classification of documents. (5) In this section “public authority" means a person exercising functions of a public nature in the United Kingdom.”

81C

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 1 Sep 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 24, insert the following new Clause – "Local authority functions to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the maintenance by a local authority of a register of electors, (b) the management by a local authority of social care records, and (c) the administration by a local authority of council tax, non-domestic rates or housing benefit. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified. (3) In this section “local authority" means – (a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly; (b) in Wales, a county council or a county borough council; (c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994; (d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972."

81D

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 1 Sep 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 24, insert the following new Clause- "Electoral infrastructure to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the administration of a parliamentary, mayoral or local government election, (b) the issue, receipt or processing of postal ballots for such an election, and (c) the counting or aggregation of votes cast in such an election. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified. (3) In this section “parliamentary election” means an election of a member to serve in the Parliament of the United Kingdom."

92C

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 1 Sep 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 37, page 62, line 24, leave out subsection (7)

95C

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 1 Sep 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 40, page 64, line 18, leave out subsection (5)

28th August 2026
Amendment Paper
HL Bill 32–I(a) Amendments for Grand Committee (Supplementary to the Marshalled List)

15A

Lord Arbuthnot of Edrom (Con)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 28 Aug 2026
HL Bill 32–I(a) Amendments for Grand Committee (Supplementary to the Marshalled List)
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 12, page 10, leave out lines 27 and 28 and insert— "(a) P supplies goods or services, whether directly or through one or more intermediaries, on which an OES for which the authority is the designated competent authority materially depends for the provision of an essential service,"

15B

Lord Arbuthnot of Edrom (Con)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 28 Aug 2026
HL Bill 32–I(a) Amendments for Grand Committee (Supplementary to the Marshalled List)
This amendment was Not Moved
View the speech made in the House

Clause 12, page 11, leave out line 13 and insert – "(a) P supplies goods or services, whether directly or through one or more intermediaries, on which an RDSP or an RMSP materially depends for the provision of a relevant digital service or managed service,"

81A

Baroness Berger (Lab)
Tabled: 28 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 24, insert the following new Clause– "Education sector to be specified as essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the provision of education as an essential activity. (2) Regulations under subsection (1) must, in particular, specify the following as essential activities - (a) the setting, marking or awarding of qualifications by an awarding organisation recognised by Ofqual or an equivalent regulator in Scotland, Wales or Northern Ireland; (b) the provision of higher education by a provider registered with the Office for Students or an equivalent UK regulator, including institutions which hold or have access to research, data, or intellectual property whose compromise would be likely to prejudice the national security, economic interests, or research capability of the United Kingdom; (c) the provision of further education by a provider, including sixth form colleges and providers of vocational training; (d) the operation of a centralised admissions service for higher education, including the Universities and Colleges Admissions Service (UCAS); (e) the provision of primary or secondary education by any education institution which- (i) is essential to the operation of schools in the United Kingdom, and (ii) processes or holds a significant volume of personal data relating to students or staff. (3) In specifying an activity under this section, the Secretary of State must have regard to the extent to which network and information systems relied on in connection with that activity are exposed to the risk of a security or operational compromise. (4) Regulations made under this section must designate appropriate regulatory authorities for the activities specified.”

92A

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 28 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause– “Assessment of need for further strategically important entities to be brought within scope (1) The Secretary of State must, within 12 months of the day on which this Act is passed, conduct an assessment of whether any additional strategically important entities based in the United Kingdom should be brought within the scope of the NIS Regulations. (2) For the purposes of subsection (1), a strategically important entity should be brought within the scope of the NIS Regulations where an attack on the network and information systems of the body would have such a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom that the entity should be considered to be carrying on an essential activity. (3) Following the conclusion of the assessment under subsection (1), the Secretary of State must publish a report outlining the findings and conclusions of the assessment. (4) Any report published under this section must include— (a) an overview of the criteria used to determine strategically important entities, which may include the body's- (i) turnover, (ii) number of employees, (iii) role in the supply of essential goods and services, and (iv) relevance to the viability of supply chains, (b) a summary of the reasons why a strategically important entity should be brought within the scope of the NIS Regulations, and (c) an assessment of further measures needed to address or mitigate risks to the security and resilience of the network and information systems of any strategically important entities that the report concludes should be brought within the scope of the NIS Regulations."

92B

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 28 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause– “Requirement for relevant large businesses to report on cyber security and resilience plans (1) Within six months of the day on which this Act is passed, the Secretary of State must issue statutory guidance that requires all relevant large businesses to report annually on the status of their cyber security and resilience plans. (2) A business is a relevant large business for the purposes of this section if it exceeds the thresholds for a medium-sized company set out in the Companies Act 2006 and it is - (a) a relevant body with respect to the NIS Regulations, or (b) a regulated person within the meaning of this Chapter. (3) A “relevant body with respect to the NIS Regulations” means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (4) The guidance required by subsection (1) may require the reporting of – (a) whether the business has a cyber security and resilience plan, (b) the nature of the cyber security and resilience plan, and (c) the use of the cyber security and resilience plan. (5) The guidance required by subsection (1) may require reporting— (a) within the annual accounts of large businesses, or (b) by any other means which the Secretary of State considers appropriate.”

95A

Lord Arbuthnot of Edrom (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 40, page 63, line 27, leave out “5” and insert “2”

95B

Lord Arbuthnot of Edrom (Con)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

Clause 40, page 64, line 17, at end insert- “(f) assess the impact of supply chain and third-party dependencies on the resilience of regulated persons, including where risks originating outside the regulatory perimeter may undermine the effectiveness of the regime.”

174A

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause– "Register of foreign powers for the purposes of Part 4 (1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations made by statutory instrument, and within six months of the day on which this Act is passed, establish and maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom's critical network and information systems. (2) Foreign powers designated by the Secretary of State under subsection (1) must include states - (a) which have been confirmed by GCHQ as having- (i) perpetrated, or attempted to perpetrate, a cyber attack in the UK in the preceding seven years, (ii) targeted, or intended to target, that attack at the network or information systems of one or more operators of an essential service or critical suppliers, and (iii) carried out, or intended to carry out, that attack through a state department, agency or affiliate group; (b) which GCHQ has warned pose a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers. (3) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament. (4) In this section, “foreign power” means— (a) the sovereign or other head of a foreign state in their public capacity, (b) a foreign government, or part of a foreign government, (c) an agency or authority of a foreign government, or of part of a foreign government, (d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority, or (e) a political party which is a governing political party of a foreign government. (5) A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government- (a) hold those posts as a result of, or in the course of, their membership of the party, or (b) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party."

174B

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause– “Register of foreign powers for the purposes of Part 4: review of nature of risk (1) For each foreign power added to the register established under section (Register of foreign powers for the purposes of Part 4), the Secretary of State must review the extent and nature of the risk posed to the network and information systems of operators of essential services and critical suppliers, including whether the risk arises from- (a) activities undertaken outside of the United Kingdom, or (b) foreign owned or controlled infrastructure or locations within the United Kingdom. (2) Within six months of the establishment of the register under section (Register of foreign powers for the purposes of Part 4)(1), the Secretary of State must lay before Parliament a report containing- (a) the findings and conclusions of the review conducted under subsection (1) above, and (b) the Government's plan for addressing the risks identified. (3) If the Secretary of State considers that laying a report, or any portion of a report, under subsection (2) would be contrary to the interests of national security, the Secretary of State must make a statement to Parliament confirming that- (a) a review has been conducted under subsection (1), and (b) that the report, or a portion of the report, cannot be laid before Parliament for reasons of national security.”

174C

Lord Arbuthnot of Edrom (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause- “Guidance: skills and competency requirements The Secretary of State must issue guidance setting out the skills and competencies relevant to compliance with duties under this Act relating to the security and resilience of network and information systems, including the role of recognised professional standards and independently assessed competence.”

174D

Lord Arbuthnot of Edrom (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 58, insert the following new Clause– "Strategy for developing cyber-security and resilience capability across regulated sectors under this Act (1) Within 12 months of the day on which this Act is passed, the Secretary of State must publish a strategy for developing cyber-security and resilience capability across the sectors regulated under this Act. (2) The strategy for regulated sectors published under subsection (1) must include workforce development, training and professional standards. (3) The Secretary of State must publish an updated strategy in each calendar year."

174E

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 28 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause– "Increasing resilience by reducing data retention (1) The Secretary of State must, within one month of the day on which this Act is passed, open a consultation on the potential impact of minimising data collection and increasing data anonymisation on the resilience to cyber attack of relevant public bodies. (2) In this section, "relevant public bodies" are public bodies that are operators of essential services or digital service providers under the NIS Regulations or this Act."

27th August 2026
Amendment Paper
HL Bill 32-I Marshalled list for Grand Committee

92

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
AI Security Institute: standards, inspection and enforcement powers
(1) The Secretary of State must ensure that the AI Security Institute (or any successor or replacement body designated by the Secretary of State) has power, under the circumstances described in subsection (2), to—
(a) set, and keep under review, safety standards for certain frontier AI systems,
(b) inspect certain frontier AI systems, and the practices of persons developing or deploying them, for the purpose of assessing conformity with those standards, and
(c) require a provider or operator of certain frontier AI systems to take remedial action, including suspending or restricting the provision or deployment of the system, where it fails to conform to those standards,.
(2) The powers described in subsection (1) are exercisable where a frontier AI system’s capabilities pose a material risk to the security or resilience of network and information systems used in the carrying out of essential activities, as defined in section 24, including risk of—
(a) harm to national security, or
(b) catastrophic harm,
arising from a failure or compromise of such systems.
(3) In exercising its powers under this section the AI Security Institute must have regard to the desirability of proportionate, evidence-based and transparent regulation, and to any relevant standards or guidance issued by the National Cyber Security Centre or a competent authority designated under this Act.
(4) The Secretary of State must by regulations make provision about the exercise of the powers described in subsection (1), including procedures for notice, representations, appeal and enforcement.
(5) In this section “frontier AI system” means an artificial intelligence system meeting criteria specified by the Secretary of State by regulations, by reference to the computational resources used in training, the system’s capabilities, or such other matters as the Secretary of State considers appropriate.”


Explanatory Text

This new clause would give the AI Security Institute standard-setting, inspection and enforcement powers over certain frontier AI systems, exercisable where a system poses a material risk to the security or resilience of network and information systems used in the carrying out of essential activities.

98

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 42, page 65, line 36, at end insert—
“(aa) which is made under section (AI Security Institute: standards, inspection and enforcement powers), or”

3

Baroness Kidron (XB)
Baroness Harding of Winscombe (Con)
Baroness Berger (Lab)
Baroness Morgan of Cotes (None)
Tabled: 27 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 4, page 3, line 18, at end insert- "(3A) A data centre also meets the threshold requirement in this paragraph, regardless of its rated IT load, if the Office of Communications considers that an incident affecting the data centre would be likely to have a significant impact on the economy or the day-to-day functioning of society in the United Kingdom or any part of it, having regard in particular to the data centre's customer base and level of interconnection with essential services."

15

Lord Arbuthnot of Edrom (Con)
Tabled: 27 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 10, insert the following new Clause – Workforce competence (1) The NIS Regulations are amended as follows. (2) In regulation 10 (security duties of operators of essential services), after paragraph (2) insert- "(2A) The measures taken by an operator of essential services under paragraphs (1) and (2) must include appropriate and proportionate measures to ensure that persons with responsibility for the security of the network and information systems on which its essential service relies have the skills, knowledge and competence necessary to discharge that responsibility effectively. (2B) In determining what is appropriate and proportionate for the purposes of paragraph (2A), regard must be had to- (a) the size of the operator and the nature and scale of the essential service it provides, and (b) the nature and extent of the risks to which its network and information systems are exposed." (3) In regulation 12 (relevant digital service providers), in paragraph (2), at the end insert - "(d) include appropriate and proportionate measures to ensure that persons with responsibility for the security of the network and information systems on which it relies have the skills, knowledge and competence necessary to discharge that responsibility effectively. (2A) In determining what is appropriate and proportionate for the purposes of paragraph (2)(d), regard must be had to – (a) the size of the operator and the nature and scale of the service it provides, and (b) the nature and extent of the risks to which its network and information systems are exposed." (4) In regulation 14B (inserted by section 10 of this Act), in paragraph (2), at the end insert- "(c) include appropriate and proportionate measures to ensure that persons with responsibility for the security of the network and information systems on which it relies have the skills, knowledge and competence necessary to discharge that responsibility effectively. (2A) In determining what is appropriate and proportionate for the purposes of paragraph (2)(c), regard must be had to- (a) the size of the operator and the nature and scale of the service it provides, and (b) the nature and extent of the risks to which its network and information systems are exposed."

24

Lord Ashcombe (Con) - Opposition Whip (Lords)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 33, leave out “72 hours” and insert “30 days”

32

Lord Ashcombe (Con) - Opposition Whip (Lords)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 40, leave out “72 hours” and insert “30 days”

40

Lord Ashcombe (Con) - Opposition Whip (Lords)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 15, leave out “72 hours” and insert “30 days”

48

Lord Ashcombe (Con) - Opposition Whip (Lords)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 29, leave out “72 hours” and insert “30 days"

53

Baroness Harding of Winscombe (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 32, line 39, at end insert- "(c) update customers regularly until the incident is fully resolved."

60

Baroness Harding of Winscombe (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 20, at end insert- "(c) update customers regularly until the incident is fully resolved."

67

Baroness Harding of Winscombe (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 34, line 2, at end insert - "(c) update customers regularly until the incident is fully resolved."

72

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 16, insert the following new Clause- "Notification of near misses, cyber threats and sub-threshold incidents After regulation 14G of the NIS Regulations (inserted by section 16) insert- "Notification of near misses, cyber threats and sub-threshold incidents 14GA. - (1) A regulated person must notify the designated competent authority without undue delay and in any event no later than 72 hours after becoming aware of- (a) a cyber threat, (b) a near miss, or (c) a sub-threshold incident, affecting the regulated person's network and information systems. (2) A person other than a regulated person may notify the designated competent authority on a voluntary basis of a cyber threat or a near miss or a sub-threshold incident affecting that person's network and information systems, regardless of whether that person is subject to any requirement under these Regulations. (3) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, a person who gives a notification under paragraph (1) or (2) is not, by reason only of that notification, subject to any additional duty, liability or requirement to which that person would not otherwise have been subject. (4) In this regulation- "cyber threat" means any potential circumstance, event or action that could, if it occurred, adversely affect the network and information systems of a person, or the users of a service provided by means of such systems; “near miss” means an event that could have compromised the availability, authenticity, integrity or confidentiality of data, or of a service provided by means of network and information systems, but that was prevented from having that effect or did not in fact have that effect; "regulated person” means an OES, an RDSP, an RMSP or a critical supplier; "sub-threshold incident” means an incident affecting the regulated person's network and information systems which the regulated person is not otherwise required to notify under regulation 11(2), 11A(2), 12A(1) or 14E(1) but which is close to the thresholds for notification under those regulations.”

84

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Baroness Kidron (XB)
Baroness Harding of Winscombe (Con)
Lord Hunt of Kings Heath (Lab)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 29, insert the following new Clause— ““Last-resort” powers in respect of data centres and AI models (1) Regulations under section 29(1) may confer on the Secretary of State powers (“last-resort powers”) to direct the shutdown of— (a) data centres, or (b) AI systems deployed on a substantial scale, in the event of an AI security or operational emergency. (2) For the purposes of this section— “data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); “AI system” means a machine-based system that, from the input it receives, can infer how to— (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; “deployment on a substantial scale” means AI systems made available to— (a) a substantial number of individuals within the United Kingdom, or (b) providers and operators of essential service; “AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an AI system operating from data centres or deployed on a substantial scale, whether through autonomous or non-autonomous means, and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to - (a) large-scale disruption to critical infrastructure or essential services, (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom, or (c) severe, large-scale harm to human life; "data centre operator” means a person who operates a data centre; "AI provider" means a person who deploys one or more AI systems on a substantial scale. (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the directions and the reasons for it, and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of AI systems, and on AI providers, including relating to - (a) the possession or installation of technical infrastructure necessary for those operators or providers to be able to comply with last-resort powers, (b) the provision by those operators or providers of secure communication channels for use by the Secretary of State when utilising last-resort powers, (c) the implementation by those operators or providers of regular emergency exercises to ensure that a direction under this section can be received safely and implemented, and (d) post-mortem processes to be followed by those operators or providers before a data centre operator or an Al provider is allowed to resume operations after the use of last-resort powers, including – (i) incident reporting, and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if – (a) the person is a data centre operator and fails to comply with any requirement imposed on data centre operators by regulations made under subsection (4), or (b) the person is an AI provider and fails to comply with any requirement imposed on AI providers by regulations made under subsection (4). (6) A person guilty of an offence under subsection (5) is liable – (a) on conviction on indictment, to imprisonment for a term not exceeding 2 years or a fine (or both); (b) on summary conviction, to imprisonment for a term not exceeding 6 months or a fine (or both). (7) Regulations relating to last-resort powers may (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to- (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (8) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must- (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable, and (b) inform the operator or provider of their right to apply to the High Court for relief. (9) The High Court may make any order it thinks fit on an application under subsection (7)(b), including - (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (10) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (11) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (12) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament. (13) The report must include (in particular) consideration of – (a) adversarial uses of AI systems by state and non-state actors, (b) the capabilities for cyber-attacks by autonomous AI systems, and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability (including systems described as “superintelligent AI")."

85

Lord Tarassenko (XB)
Baroness Kidron (XB)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 29, insert the following new Clause – "AI Security Institute: statutory functions and pre-deployment assessment of frontier artificial intelligence products or services (1) Regulations under section 29(1) must confer power and functions on the AI Security Institute in connection with the following objectives – (a) the identification, management and reduction of risks of security or operational compromises associated with frontier Al products or services used by relevant network and information systems; (b) the mitigation of adverse impacts resulting from such security or operational compromises, including impacts arising from- (i) autonomous orchestration or substantial acceleration of sophisticated attacks on critical infrastructure, essential services, or any other relevant network and information system in the United Kingdom, (ii) evasion of human oversight or shutdown or resistance to any action, that, at a given level of confidence, has the effect of compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data, or the related services offered by, or accessible via, relevant network and information systems, (iii) autonomous self-replication, self-improvement, unsanctioned network activity or acquiring computing or other resources to the extent that this presents a risk to the authenticity and integrity of the processed data held within relevant network and information systems, or (iv) other capabilities which are found to compromise, at a given level of confidence, the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, relevant network and information systems. (2) The powers and functions conferred under subsection (1) must include- (a) the power to take specified action for the purposes of or in connection with an objective mentioned in subsection (1); (b) powers to require comprehensive assessments of the identification, management and reduction of risks, or adverse impacts resulting from such security or operational compromises; (c) power to establish and enforce relevant mandatory AI safety training for persons who develop, deploy or make available AI products or services to users of relevant network and information systems, in connection with an objective mentioned in subsection (1); (d) the power to require the reporting of specified relevant matters, including - (i) notification of a new frontier Al product or service before deployment within relevant network and information systems in the United Kingdom, and (ii) notification of any safety breaches during the internal evaluations of a new frontier AI product or service, including safety breaches caused by an autonomous Al product or service, which could affect relevant networks and information systems in the United Kingdom; (e) a duty to make recommendations to the Secretary of State relating to the deployment of a frontier Al product or service within relevant network and information systems in the United Kingdom, including recommendations that- (i) the use of the frontier Al system in relevant network and information systems is restricted for such a period designated by the AI Security Institute until the system satisfies the objectives laid out in subsection (1)(b); (ii) the use of the frontier Al system in relevant network and information systems is prohibited if the AI Security Institute concludes that the objectives laid down in subsection (1) cannot be satisfied. (3) In this section, “frontier Al product or service” means a highly capable general-purpose artificial intelligence model, used either as a stand-alone model or within an agentic framework, that can perform a wide variety of tasks and match or exceed the capabilities present in the current most advanced AI models and agents. (4) The Secretary of State must ensure that AI Security Institute has sufficient resources and operational independence to carry out the functions conferred on it by regulations under this section, and must lay before Parliament an annual report on the exercise of those functions."

86

Lord Tarassenko (XB)
Baroness Kidron (XB)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 31, page 56, line 29, at end insert- “and must do in relation to regulations meeting the requirements in section (AI Security Institute: statutory functions and pre-deployment assessment of frontier artificial intelligence products or services).”

88

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment."

89

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience: software and platform providers (1) The OCR must establish and maintain a register of software and platform providers permitted to supply network and information system services as a relevant digital service provider in the United Kingdom to operators of essential services. (2) The OCR must require registered software and platform providers- (a) to certify their products as safe when used as directed, and (b) to inform the OCR and all affected customers within 24 hours of the discovery of a new vulnerability or breach affecting network or information services. (3) The OCR must not include in its register any software or platform providers which also supply cyber resilience audit services."

90

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 35, insert the following new Clause- "Office for Cyber Resilience: cyber resilience professionals (1) The OCR must work with the UK Cyber Security Council to- (a) ensure that relevant bodies have sufficient and appropriately qualified cyber security professionals, and (b) produce a timetable to increase the number of chartered cyber security professionals available to work on the security and resilience of network and information systems of relevant bodies. (2) In this section “relevant bodies" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

91

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 35, insert the following new Clause- "Office for Cyber Resilience: cyber resilience audit (1) Within two years of the day of the establishment of the OCR, and every 12 months thereafter, the OCR must designate which commercial companies and public sector bodies must, from that year on, conduct an annual independent audit of the cyber security and resilience of their network and information systems (“the cyber resilience audit”). (2) The OCR may designate those companies or bodies individually or with reference to any relevant categorisation (including sector, scale, or materiality). (3) Organisations designated under subsection (1) must be - (a) relevant bodies with respect to the NIS Regulations, or (b) regulated persons within the meaning of this Chapter. (4) A “relevant body with respect to the NIS Regulations” means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The results of the annual cyber resilience audit must be shared only with the company's or body's board, except where any material vulnerabilities or breaches are identified, which must be shared in confidence with the OCR."

114

Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 38, at end insert- "(3A) The Secretary of State must by regulations made by statutory instrument define what conditions must be met for a person to be considered to have expertise in relation to the security of network and information systems for the purpose of paragraph (3)(g). (3B) A statutory instrument containing regulations under subsection (3A) is subject to annulment in pursuance of a resolution of either House of Parliament."

140

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 48, page 73, line 23, after “section” insert “(Vendor-related directions) or”

141

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 48, page 73, line 24, after “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or"

142

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 8, after first “section” insert “(Vendor-related directions) or”

143

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 8, after second “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or"

145

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 25, after first “section” insert “(Vendor-related directions) or”

146

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 25, after second “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or"

148

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 52, page 78, line 24, after “section” insert “(Further provision about giving of vendor-related directions)(8),”

149

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 54, page 80, line 26, after “section” insert “(Vendor-related directions),”

150

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 54, page 81, line 5, after “section” insert “(Vendor-related directions) or"

151

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 54, insert the following new Clause- "Publication of notice of direction under section (Vendor-related directions) etc (1) Subject to subsection (3), the Secretary of State must publish, in such manner as the Secretary of State considers appropriate, notice of the fact that – (a) a direction under section (Vendor-related directions) has been given, or (b) such a direction has been varied or revoked under section 54. (2) The notice under subsection (1) must be published as soon as practicable and must- (a) state when the direction, variation or revocation comes into force, (b) state the person to which the direction, variation or revocation has been given, (c) include a summary of the direction, variation or revocation, its effect and the reasons for it, and (d) include any other information that the Secretary of State considers it appropriate to include. (3) The Secretary of State may exclude from the notice under subsection (1) anything the publication of which the Secretary of State considers (a) might harm the commercial interests of any person to an unreasonable degree, or (b) would be contrary to the interests of national security.”

152

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 54, insert the following new Clause- "Annual report in relation to directions under section (Vendor-related directions) (1) The Secretary of State must, in relation to each relevant period – (a) prepare a report in accordance with this section, and (b) lay a copy of it before each House of Parliament as soon as practicable after the end of that period. (2) Each report must provide details of – (a) the number of directions given under section (Vendor-related directions) during the relevant period, (b) the kinds of services provided by persons to which directions under section (Vendor-related directions) were given during the relevant period (including, where relevant, the sectors in which the services are provided), (c) the number of directions under section (Vendor-related directions) that have been varied during the relevant period, and (d) the number of directions under section (Vendor-related directions) that have been revoked during the relevant period. (3) "Relevant period" means - (a) the period of 12 months beginning with the day on which section (Vendor-related directions)(1) comes into force for any purpose other than the purpose of making regulations; (b) each subsequent period of 12 months.”

153

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

As an amendment to Amendment 152 After subsection (2)(d) insert - "(e) how many, and which, directions under section (Vendor-related directions) were the result of mandatory referral schemes established under section (Power to establish mandatory referral scheme), and (f) the reason that directions under section (Vendor-related directions) resulting from mandatory referral schemes established under section (Power to establish mandatory referral scheme) were given.”

154

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 55, page 81, line 26, at end insert “in respect of a direction under section 43 or 53”

157

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 23, at end insert- “essential goods or services” means goods or services without the provision of which the carrying on of a Part 4 essential activity would be at risk of disruption;"

158

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 26, at end insert- ““Part 4 essential activity” means an activity the carrying on of which the Secretary of State considers to be essential to - (a) the economy of the United Kingdom or any part of the United Kingdom, or (b) the day-to-day functioning of society in the United Kingdom or any part of the United Kingdom;"

159

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 26, at end insert- “Part 4 NIS”, in relation to a person, means a network and information system that is- (a) used or relied on by the person in connection with the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (b) associated with a system mentioned in paragraph (a) (and section 29(4) (meaning of "associated”) applies for the purposes of this paragraph as it applies for the purposes of section 29(3));"

160

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 28, after “30(2)” insert “and (5)”

162

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 34, leave out from “compromise”” to end of line 35 and insert “, in relation to a network and information system, means (a) anything that compromises the security, availability, functionality or reliability of the system, (b) any unauthorised access to, interference with or exploitation of the system or anything which enables such access, interference or exploitation, (c) anything that compromises the confidentiality, authenticity, integrity or availability of data stored on or processed, received or transmitted by the system, or (d) anything that causes data stored on or processed by the system to be lost."

163

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 58, page 84, line 35, at end insert- "(2) For the purposes of this Part – (a) a reference to the carrying on of an activity includes a reference to the provision of a service; (b) a reference to a person specified or of a description specified for the purposes of section 30(2) includes a reference to a person treated by section 30(5) as having been so specified."

164

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Arbuthnot of Edrom (Con)
Lord Holmes of Richmond (Con)
Baroness Finlay of Llandaff (XB)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause- "Computer Misuse Act 1990: statutory defence for cyber security activities (1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities. (2) The review under subsection (1) must consider, in particular – (a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith, (b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and (c) the approaches taken in other jurisdictions. (3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out- (a) the findings and conclusions of the review, and (b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”

165

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause – "Annual report on incident volumes (1) The Secretary of State must, for each calendar year, prepare and lay before Parliament a report on the volume of incidents reported under the NIS Regulations and under regulations made under this Act during that year. (2) A report under this section must include, so far as is consistent with national security— (a) the number of incidents reported, broken down by regulated sector and subsector, (b) the number of incidents reported by each description of regulated person, (c) the number of incidents that were significant incidents, and (d) a summary of the principal types and causes of the incidents reported. (3) A report under this section must be laid before Parliament within four months of the end of the calendar year to which it relates. (4) This section does not require the disclosure of information which would, in the opinion of the Secretary of State, be prejudicial to national security or which would identify a particular regulated person without its consent.”

166

Baroness Ludford (LD)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause – "Digital Sovereignty Strategy (1) The Secretary of State must, within 12 months of the day on which this Act is passed, publish a strategy (“the Digital Sovereignty Strategy") setting out the Government's approach to maintaining the security and resilience of relevant network and information systems by assessing, managing and mitigating risks – (a) associated with foreign interference, and (b) arising from reliance on foreign-supplied technologies. (2) The Digital Sovereignty Strategy must- (a) include risks associated with- (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on the security and resilience of government digital procurement, detailing how the Government intends to reduce strategic dependencies on foreign-owned suppliers and on the hardware and software of hostile states so as to mitigate the risk of systemic disruption; (c) include a commitment to prioritise, where appropriate, the use of secure technologies developed in the United Kingdom by United Kingdom organisations in relevant network and information systems; (d) set out how the Government intends to address any risks identified under subsection (1), including by supporting the use of sovereign and domestic technologies or systems. (3) The Secretary of State must review and, if necessary, revise the Digital Sovereignty Strategy at least once in every three-year period. (4) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

167

Baroness Ludford (LD)
Lord Arbuthnot of Edrom (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause- "Board oversight and accountability: security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of the arrangements relating to the security and resilience of the body's network and information systems. (2) In exercising that oversight, the management body must- (a) approve the approach taken by the body to the management of risks to the security and resilience of the body's network and information systems, and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for a failure by the body to comply with its duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks to, and assess appropriate risk-management practices for, the body's network and information systems. (5) For the purposes of this section, a relevant body is one which is - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

168

Baroness Ludford (LD)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause – "Review of the regulation of data-storing sectors (1) The Secretary of State must carry out a review of whether the NIS Regulations should be extended to persons who store or process personal data on behalf of other organisations at scale, but who are not otherwise regulated under those Regulations. (2) The review must, in particular, consider the case for extending regulation to – (a) providers of software as a service, and (b) any other sector or description of provider which the Secretary of State considers, at the time of the review, to hold personal data on behalf of other organisations at a scale or in a manner that may warrant regulation under the NIS Regulations. (3) In carrying out the review the Secretary of State must consider, in particular – (a) the number of organisations relying on any single such provider, and the number of individuals whose personal data is held; (b) the extent to which those organisations are able in practice to assess or influence the security of the network and information systems on which their data is held; (c) whether the data protection legislation is sufficient to manage the risks identified, in particular as regards the security of network and information systems and the reporting of incidents; (d) whether providers within subsection (2) could be brought within the meaning of “relevant managed service provider” or “relevant digital service provider”, or designated under regulation 14H of the NIS Regulations, and what changes (if any) to those Regulations would be needed to achieve this; (e) the effect of any such extension on organisations that are small or medium-sized enterprises, or that are charities or other voluntary organisations, whether as providers or as customers. (4) In carrying out the review the Secretary of State must consult the Information Commission, the National Cyber Security Centre, and such other persons as the Secretary of State considers appropriate. (5) The Secretary of State must lay a report on the review before Parliament within 12 months of the day on which this Act is passed. (6) In this section – "the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act); "the NIS Regulations” has the meaning given by section 1.”

169

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 58, insert the following new Clause- "Review of effect of information sharing and analysis centres (1) The Secretary of State must, within six months of the day on which this Act is passed, conduct a review of - (a) the effect of information sharing and analysis centres (ISACs) on the security and resilience of network and information systems in regulated sectors; (b) the feasibility and appropriateness of conferring enforcement powers on information sharing and analysis centres to encourage compliance with the requirements of the NIS Regulations and this Act among their members. (2) Following the conclusion of a review under subsection (1), the Secretary of State must publish and lay before Parliament a report which- (a) identifies advantages and challenges associated with the operation of information sharing and analysis centres; (b) identifies sectors in which the establishment of information sharing and analysis centres is likely to be beneficial for increasing the security and resilience of systems relied on for the provision of an essential service; (c) where the establishment of further information sharing and analysis centres is likely to be beneficial, sets out a plan for the establishment of such centres; (d) sets out a framework for conferring enforcement powers on information sharing and analysis centres, including - (i) power to conduct investigations and audits of member compliance; (ii) power to issue binding compliance directions to members; (iii) power to exclude or suspend members for serious or repeated breaches; (iv) procedures for member appeals and due process; (v) coordination mechanisms with designated competent authorities for escalation and cross-enforcement; (e) identifies any barriers to private sector ISACs exercising such enforcement powers and recommends legislative changes if necessary. (3) Following publication of the report, the Secretary of State must- (a) consult with designated competent authorities, existing information sharing and analysis centres, and regulated entities on the framework set out in subsection (2)(d); (b) within 12 months of the day on which this Act is passed, lay before Parliament revised regulations or statutory guidance providing that information sharing and analysis centres may (i) investigate suspected breaches of the NIS Regulations or this Act among their members; (ii) issue binding compliance directions requiring remedial action within a specified timeframe; (iii) exclude or suspend members who fail to comply with such directions or who commit serious breaches; (iv) escalate cases to the designated competent authority where - (A) a member fails to comply with ISAC directions, (B) the breach poses a significant risk to critical infrastructure, or (C) the ISAC considers formal regulatory enforcement necessary. (4) Regulations under subsection (3)(b) must be made by statutory instrument and include- (a) minimum standards for ISAC independence and governance to avoid conflicts of interest; (b) procedural safeguards for members facing investigation or enforcement action, including right to be heard and appeal; (c) requirements that ISACs publish annual compliance reports identifying enforcement actions taken; (d) coordination protocols requiring ISACs to notify the relevant designated competent authority of enforcement actions. (5) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament. (6) In this section – (a) "information sharing and analysis centres” means organisations – (i) whose membership is primarily comprised of entities operating within a regulated sector for the purposes of the NIS Regulations and this Act, (ii) that are independent of the designated competent authority or authorities for the relevant regulated sector, and (iii) whose aim is to increase cyber security among its membership and facilitate information sharing on threats and vulnerabilities; (b) “regulated sectors” means sectors and subsectors under the regulatory oversight of designated competent authorities as defined in regulation 3 and Schedule 1 of the NIS Regulations (as amended by this Act); (c) "designated competent authority” has the meaning given by regulation 3 of the NIS Regulations."

170

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 58, insert the following new Clause – "Duty on Secretary of State to report on the meeting of existing recommendations and implementation deadlines (1) The Secretary of State must, at least once in every 12-month period, lay before Parliament a report outlining the Government's progress towards meeting- (a) the recommendations made in the National Audit Office's report on Government Cyber Resilience of 29 January 2025, and (b) the implementation milestones set out in the Government's Cyber Action Plan of 6 January 2026, so far as they relate to the security and resilience of network and information systems relied on in connection with the carrying on of essential activities. (2) Any report under this section must, where a deadline or implementation date has not been met in relation to the matters set out in subsection (1), include - (a) an explanation for the failure to meet the deadline or implementation date; (b) a revised deadline or implementation date and a plan for meeting the new date."

171

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause- "Consultation on amnesty-based reporting of relevant ransomware attacks (1) The Secretary of State must, within six months of the day on which this Act is passed, launch a consultation on the establishment of an amnesty-based reporting scheme for ransomware attacks affecting relevant network and information systems (within the meaning established by section 29(3)). (2) The purpose of the consultation is to determine the feasibility and appropriateness of a framework which would allow organisations to report such ransomware attacks to a designated government body confidentially, without triggering- (a) mandatory incident reporting obligations under the NIS Regulations, (b) regulatory investigation or enforcement action, or (c) civil or criminal liability for the organisation or its officers. (3) The consultation must address (a) the design of a safe harbour reporting framework to incentivise organisations voluntarily to disclose such ransomware incidents to government to improve threat intelligence and cyber resilience; (b) the appropriate government department or agency to receive such reports and how reports would be used to inform law enforcement investigations and threat intelligence; (c) data protection safeguards to protect organisations making reports, including how personal data in ransomware communications would be handled; (d) the relationship between amnesty-based reporting and mandatory incident reporting under the NIS Regulations. (4) The consultation must be conducted with- (a) regulated entities, industry bodies, and businesses; (b) law enforcement and national security agencies; (c) designated competent authorities and the Information Commissioner's Office; (d) cyber security researchers and incident response providers. (5) The Secretary of State must publish a consultation response within six months of closing the consultation, setting out whether such a ransomware amnesty scheme should be established and, if so, the proposed design and implementation timeline. (6) In this section, “ransomware attack" means a cyber-attack involving malicious software which- (a) infects a victim's computer systems, and (b) prevents the victim from accessing systems or data, impairs the use of systems or data, or facilitates theft of data, and in relation to which a ransom is demanded for access to be restored or for data not to be published."

172

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause – "Impact of reporting requirements on relevant bodies (1) The Secretary of State must, within 12 months of the day on which this Act is passed, publish and lay before Parliament- (a) a review of the impact on relevant bodies of – (i) the requirements relating to the notification of incidents in Parts 3 and 4 of the NIS Regulations (as amended by this Act), and (ii) any additional incident notification requirements made by regulations under this Act; (b) proposals for the creation of a single cyber incident reporting channel for relevant bodies. (2) A review under this section must consider – (a) the costs of requirements on relevant bodies, and (b) interactions with other incident reporting regimes. (3) In this section, “relevant bodies” means operators of essential services, critical suppliers or digital service providers, as defined by the NIS Regulations."

173

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 58, insert the following new Clause- "Publication of relevant elements of the National Cyber Action Plan The Secretary of State must- (a) publish those elements of the National Cyber Action Plan which relate to the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities, (b) lay a statement before Parliament confirming that those elements of the National Cyber Action Plan have been published, and (c) allow for a period of 28 days to elapse during which those elements of the National Cyber Action Plan are available for review by Parliament, before any provisions of this Act other than this section and Part 5 may come into force."

174

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 58, insert the following new Clause "Funding of regulatory authorities: statement (1) The provisions of this Act, other than this section and Part 5, may not come into force until the Secretary of State has laid before each House of Parliament a statement setting out the Government's plan for funding the exercise of functions of the regulatory authorities conferred or modified by this Act. (2) The statement must include- (a) the resources the Secretary of State considers the regulatory authorities will require to operate the designation and regulation of critical suppliers under section 12 of this Act, to enforce the provision of information and reporting of incidents under Chapter 2 of this Act, and to undertake directives by the Secretary of State under powers conferred by this Act, (b) the funding the Secretary of State intends to make available for each of the first three financial years following the day on which this Act is passed, and (c) the basis on which the adequacy of that funding will be kept under review. (3) In this Part, “regulatory authority” means (a) a person designated for the purposes of this Act by regulations made by the Secretary of State, (b) a person designated by Regulation 3(1) of the NIS Regulations (competent authorities for operators of essential services), or (c) the Information Commission."

175

Viscount Camrose (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 27 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

Clause 60, page 85, line 2, leave out subsections (1) and (2) and insert- (1) Section (Publication of relevant elements of the National Cyber Action Plan) and this Part come into force on the day on which this Act is passed. (2) The other provisions of this Act may not come into force in accordance with subsection (3) until the requirements set out in section (Publication of relevant elements of the National Cyber Action Plan) have been met."

26th August 2026
Amendment Paper
HL Bill 32 Running list of amendments – 26 August 2026

74

Baroness Morgan of Cotes (None)
Baroness Kidron (XB)
Baroness Ludford (LD)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

After Clause 21, insert the following new Clause—
“Liability of Senior Executives
(1) This regulation applies where a designated competent authority or the Information Commission has reasonable grounds to believe that—
(a) a person that is a body corporate, a partnership (including a Scottish partnership) or an unincorporated body has failed to comply with a duty referred to in regulation 17(1), (2), (2ZA) or (2ZB), and
(b) the failure was committed with the consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly.
(2) The competent authority or the Information Commission may serve a notice of intention to impose a penalty on the senior executive(s) if it considers that a penalty is warranted having regard to the facts and circumstances of the case.
(3) Before serving a senior executive(s) notice, the authority or the Information Commission must inform the senior executive(s), in such form and manner as it considers appropriate having regard to the facts and circumstances of the case, of—
(a) the alleged failure and the officer's alleged consent, connivance or neglect, and
(b) how and by when representations may be made in relation to the alleged failure and any related matters.
(4) A senior executive(s) notice must be in writing and must specify the following—
(a) the reasons for serving the notice;
(b) the alleged failure or failures and the senior executive(s) alleged consent, connivance, neglect or carelessness which are the subject of the notice;
(c) any remedial actions required;
(d) the amount of the penalty and the number of penalties which the authority or the Information Commission is minded to impose.
(5) The authority or the Information Commission may, after considering any representations made in accordance with paragraph (3)(b), serve a penalty notice on the officer with a final penalty decision if satisfied that a penalty is warranted having regard to the facts and circumstances of the case.
(6) A penalty imposed under this regulation must be of an amount which the authority or the Information Commission determines is appropriate and proportionate in the circumstances, having regard to the matters mentioned in regulation 18(6) [NIS] for each infringement individually.
(7) If the authority or the Information Commission is satisfied that no further action is required, having considered any representations submitted in accordance with paragraph (3)(b), it must inform the senior executive(s) in writing as soon as reasonably practicable.
(8) In this regulation “senior executive(s)”—
(a) in relation to a body corporate, means a CEO, director, manager, secretary or other similar senior executive of the body, or a person purporting to act in any such capacity;
(b) in relation to a partnership, means a partner or a person having control or management of the partnership business, or a person purporting to act in any such capacity;
(c) in relation to an unincorporated body other than a partnership, means a member of its governing body, or a person purporting to act in any such capacity.”


Explanatory Text

This amendment seeks to create provision in the Bill for executives or senior managers to be held responsible for failure to comply or report on the measures placed upon regulated bodies within the Bill.

81

Baroness Northover (LD)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 42, insert the following new Clause—
“Space sector to be specified as an essential activity
(1) The Secretary of State must, within six months of the passing of this Act, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities.
(2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector.
(3) In this section, “the space sector” means the sector identified as the space sector in the Government’s Industrial Strategy, and includes—
(a) the manufacture of satellites, launch vehicles and ground systems,
(b) the provision of launch and in-orbit services,
(c) the operation of satellites and satellite constellations, and
(d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”


Explanatory Text

This new clause would require the Secretary of State to specify the space sector, as identified in the Government’s Industrial Strategy, as an essential activity under Part 3, bringing space operators within the scope of the Bill’s regime.

7

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 7, page 6, line 31, after “engine” insert “, software or a digital platform,”


Explanatory Text

This amendment, and others in the name of Lord Birt, seek to include software and platform providers in the definition of a relevant digital service provider.

8

Baroness Kidron (XB)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 7, page 7, line 23, after “EC” insert “, unless the Information Commission or Artificial Intelligence Security Institute determines that the person’s provision of the relevant digital service poses a risk to public safety, national security, or the security of network and information systems relied on for the carrying on of essential activities that is disproportionate to the size of the person”


Explanatory Text

This amendment seeks to designate a Regulated Digital Service Provider under the size-threshold if it provides services which, if disrupted, would cause significant harm to essential activities, public safety, or national security, irrespective of size.

9

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 7, page 7, line 28, after “nature;” insert—
“and in the case of software or a digital platform, includes a person which—
(i) creates software for distribution,
(ii) distributes software on behalf of other businesses,
(iii) manages services for the distribution of software, or
(iv) supports software on behalf of others.”


Explanatory Text

This amendment, and others in the name of Lord Birt, seek to include software and platform providers in the definition of a relevant digital service provider.

11

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “engine;” insert—
“(ba) software or a digital platform;”.”


Explanatory Text

This amendment, and others in the name of Lord Birt, seek to include software and platform providers in the definition of a relevant digital service provider.

13

Baroness Kidron (XB)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 9, page 8, line 24, after “EC” insert “, unless the Information Commission determines that the person’s provision of the relevant service poses a risk to public safety, national security, or the security of network and information systems relied on for the carrying on of essential activities that is disproportionate to the size of the person”


Explanatory Text

This amendment seeks to designate a Relevant Managed Service Provider under the size-threshold if it provides services which, if disrupted, would cause significant harm to essential activities, public safety, or national security.

76

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 24, page 51, line 15, at end insert—
“(3A) In specifying an activity for the purposes of subsection (3), the Secretary of State must consider any recommendations they receive from the Office for Cyber Resilience.”


Explanatory Text

This amendment seeks to ensure that the Secretary of State considers Office for Cyber Resilience recommendations for essential activities.

77

Lord Birt (XB)
Lord Londesborough (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 24, page 51, line 17, leave out from “essential” to end of line 22 and insert “because it has—
(a) a material economic impact,
(b) a material societal impact, or
(c) an impact on national security or defence.”


Explanatory Text

This amendment seeks to allow an activity to be specified as essential if it has a material economic or societal impact, or affects national security or defence.

88

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
“Office for Cyber Resilience
(1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR).
(2) The OCR is to be—
(a) the single regulatory authority for the purposes of this Act,
(b) the single designated competent authority for the purposes of the NIS Regulations, and
(c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under Regulation 18 of those Regulations.
(3) The functions and powers of the OCR are to—
(a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited;
(b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning;
(c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies;
(d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with Regulation 18 (penalties);
(e) share knowledge of threats and work in partnership with the National Cyber Security Centre;
(f) recommend to the Secretary of State activities to be specified as an “essential activity”.
(4) In this section—
“relevant body” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.
(5) The Secretary of State must by regulations—
(a) provide for the transfer to the OCR of the functions of—
(i) each designated competent authority under the NIS Regulations, and
(ii) each regulatory authority designated under Chapter 1 of this Part,
(b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and
(c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

89

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
“Office for Cyber Resilience: software and platform providers
(1) The OCR must establish and maintain a register of software and platform providers permitted to supply network and information system services as a relevant digital service provider in the United Kingdom to operators of essential services.
(2) The OCR must require registered software and platform providers—
(a) to certify their products as safe when used as directed, and
(b) to inform the OCR and all affected customers within 24 hours of the discovery of a new vulnerability or breach affecting network or information services.
(3) The OCR must not include in its register any software or platform providers which also supply cyber resilience audit services.”


Explanatory Text

This amendment seeks to establish a register of software and platform providers permitted to supply services to operators of essential services in the UK and to certify their products as safe for use.

90

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
“Office for Cyber Resilience: cyber resilience professionals
(1) The OCR must work with the UK Cyber Security Council to—
(a) ensure that relevant bodies have sufficient and appropriately qualified cyber security professionals, and
(b) produce a timetable to increase the number of chartered cyber security professionals available to work on the security and resilience of network and information systems of relevant bodies.
(2) In this section—
“relevant bodies” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”


Explanatory Text

This amendment seeks to ensure that the OCR works with the UK Cyber Security Council to ensure that relevant bodies have sufficient and appropriately qualified cyber security professionals.

91

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
“Office for Cyber Resilience: cyber resilience audit
(1) Within two years of the day of the establishment of the OCR, and every 12 months thereafter, the OCR must designate which commercial companies and public sector bodies must, from that year on, conduct an annual independent audit of the cyber security and resilience of their network and information systems (“the cyber resilience audit”).
(2) The OCR may designate those companies or bodies individually or with reference to any relevant categorisation (including sector, scale, or materiality).
(3) Organisations designated under subsection (1) must be—
(a) relevant bodies with respect to the NIS Regulations, or
(b) regulated persons within the meaning of this Chapter.
(4) A “relevant body with respect to the NIS Regulations” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.
(5) The results of the annual cyber resilience audit must be shared only with the company’s or body’s board, except where any material vulnerabilities or breaches are identified, which must be shared in confidence with the OCR.”


Explanatory Text

This amendment seeks to require the Office for Cyber Resilience to designate commercial companies and public sector bodies regulated under the NIS Regulations or the Bill which must conduct an annual independent audit of the cyber security and resilience of their network and information systems.

101

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Before Clause 43, insert the following new Clause—
“Chapter 1
Functions under Part 4
Functions under this Part
For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster.”


Explanatory Text

This amendment would ensure that the functions conferred on the Secretary of State by provisions of Part 4 would also be exercisable by the Chancellor of the Duchy of Lancaster.

102

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Before Clause 43, insert the following new Clause—
“Chapter 2
Vendor-related directions etc
Vendor-related directions
(1) The Secretary of State may give a direction to a person (“P”) if—
(a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and
(b) conditions 1 and 2 are met.
(2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description—
(a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1),
(b) carries on a Part 4 essential activity in the United Kingdom, or
(c) provides essential goods or services.
(3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person.
(4) Condition 2 is that the Secretary of State considers that—
(a) the direction is necessary having regard to that risk, and
(b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction.
(5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3).
(6) A direction under this section may in particular impose any of the following kinds of requirement—
(a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P;
(b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services;
(c) a requirement relating to the provision of information, including information relating to compliance with the direction;
(d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities;
(e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities;
(f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services;
(g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction;
(h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom.
(7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so.
(8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified.
(9) For the purposes of subsection (8), the appropriate authority is—
(a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person;
(b) otherwise, the Secretary of State.
(10) Regulations under subsection (1)(a) may make different provision for different purposes.
(11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency).”


Explanatory Text

This amendment would enable directions to be given where the Secretary of State considers risks to national security could arise from the use of goods, services or facilities in connection with network and information systems linked to essential activities or the provision of essential goods or services.

103

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Before Clause 43, insert the following new Clause—
“Further provision about giving of vendor-related directions
(1) It does not matter for the purposes of section (Vendor-related directions) whether or not—
(a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services;
(b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom;
(c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom;
(d) the use or proposed use of goods, services or facilities is within the United Kingdom.
(2) A direction under section (Vendor-related directions) must specify—
(a) the person to which the direction is given;
(b) the vendor to which the direction relates;
(c) the goods, services or facilities to which the direction relates;
(d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so;
(e) the time at which the direction comes into force;
(f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with.
(3) A person to which a direction is given under section (Vendor-related directions) must comply with it.
(4) A person to which a direction is given under section (Vendor-related directions) (“P”)—
(a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g));
(b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement).
(5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters.
(6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult—
(a) that person,
(b) the vendor to which the direction relates, and
(c) such other persons as the Secretary of State considers it appropriate to consult,
so far as it is reasonably practicable to do so.
(7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security.
(8) The Secretary of State may require—
(a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State;
(b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State.
(9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security.”


Explanatory Text

This amendment would make provision about a direction given under my new Clause (Vendor-related directions), including provision about the content of the direction, the consultation requirements that apply, and non-disclosure requirements that may be imposed.

104

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Before Clause 43, insert the following new Clause—
“Power to make regulations about time frame for giving vendor-related directions
(1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise).
(2) The provision that may be made by regulations under subsection (1) includes, in particular, provision—
(a) about the period for making the decision;
(b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations.
(3) Regulations under subsection (1) may—
(a) make different provision for different purposes;
(b) make provision subject to exceptions;
(c) make consequential, supplementary, incidental, transitional or saving provision;
(d) confer functions involving the exercise of a discretion.
(4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament.”


Explanatory Text

This amendment would enable the Secretary of State to make regulations setting out the time frame for a decision whether or not to give a direction under my new Clause (Vendor-related directions).

105

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Before Clause 43, insert the following new Clause—
“Power to establish mandatory referral scheme
(1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme.
(2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State.
(3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security.
(4) “Qualifying transaction” has the meaning given by regulations under this section.
(5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to—
(a) the nature of a transaction,
(b) the value of a transaction,
(c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or
(d) the identity of the vendor in relation to a transaction.
(6) Regulations under this section may make provision about—
(a) when a person is required to make a referral;
(b) the procedure for making a referral;
(c) information to be provided in connection with a referral;
(d) monitoring of compliance with requirements imposed by the regulations;
(e) enforcement of compliance with requirements imposed by the regulations.
(7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52.
(8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so.
(9) Regulations under this section may—
(a) make different provision for different purposes;
(b) make different provision for different areas;
(c) make provision subject to exceptions;
(d) require a person to have regard to guidance;
(e) make consequential, supplementary, incidental, transitional or saving provision.
(10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament.
(11) References in this section to a transaction include references to a proposed transaction.”


Explanatory Text

This amendment would enable the Secretary of State to establish a scheme under which persons to which directions may be given under my new Clause (Vendor-related directions) are required to refer transactions meeting specified conditions to the Secretary of State for a decision whether to give such a direction.

18

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 15, page 21, line 33, at end insert—
“(c) if requested by the designated competent authority following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (2)(b), as the authority may specify, and
(d) a final report containing the information listed in paragraph (5A) in relation to the incident.”

20

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 15, at end insert—
“(f) whether there has been, is or is likely to be any impact as a result of the incident on network and information systems of users of the service;
(g) any impact that the incident has had, is having or is likely to have on the economy or the day-to-day functioning of society.”

21

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 28, at end insert—
“(5A) The information referred to in paragraph (2)(d) is—
(a) a detailed description of the incident, including its severity and impact;
(b) the type of threat or root cause which is likely to have caused the incident;
(c) the mitigation measures applied and, so far as known to the OES, ongoing;
(d) so far as known to the OES, any cross-border impact of the incident.”

22

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 30, after “notification” insert “without undue delay and in any event”

23

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 33, after “notification” insert “without undue delay and in any event”

25

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 34, at end insert—
“(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request.
(d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

26

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 22, line 34, at end insert—
“(6A) Where the OES incident is still occurring at the time a final report would otherwise fall to be given under paragraph (6)(d), the OES must instead give—
(a) a progress report, at the time provided for in paragraph (6)(d), containing the information listed in paragraph (5A) so far as then known; and
(b) a final report, containing the information listed in paragraph (5A), before the end of the period of one month beginning with the time at which the OES incident ceases.”

27

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 12, at end insert—
“(c) if requested by the designated competent authority following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (2)(b), as the authority may specify, and
(d) a final report containing the information listed in paragraph (4A) in relation to the incident.”

29

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 35, at end insert—
“(4A) The information referred to in paragraph (2)(d) is—
(a) a detailed description of the incident, including its severity and impact;
(b) the type of threat or root cause which is likely to have caused the incident;
(c) the mitigation measures applied and, so far as known to the OES, ongoing;
(d) so far as known to the OES, any cross-border impact of the incident.”

30

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 37, after “notification” insert “without undue delay and in any event”

31

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 40, after “notification” insert “without undue delay and in any event”

33

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 41, at end insert—
“(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request.
(d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

34

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 41, at end insert—
“(5A) Where the data centre incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the OES must instead give—
(a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and
(b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the data centre incident ceases.”

35

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 26, line 12, at end insert—
“(c) if requested by the Information Commission or Artificial Intelligence Security Institute following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (1)(b), as the Information Commission may specify, and
(d) a final report containing the information listed in paragraph (4A) in relation to the incident.”

37

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 10, at end insert—
“(4A) The information referred to in paragraph (1)(d) is—
(a) a detailed description of the incident, including its severity and impact;
(b) the type of threat or root cause which is likely to have caused the incident;
(c) the mitigation measures applied and, so far as known to the RDSP, ongoing;
(d) so far as known to the RDSP, any cross-border impact of the incident.”

38

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 12, after “notification” insert “without undue delay and in any event”

39

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 15, after “notification” insert “without undue delay and in any event”

41

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 16, at end insert—
“(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request.
(d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

42

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 27, line 16, at end insert—
“(5A) Where the RDSP incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the RDSP must instead give—
(a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and
(b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the RDSP incident ceases.”

43

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 29, line 24, at end insert—
“(c) if requested by the Information Commission following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (1)(b), as the Information Commission may specify, and
(d) a final report containing the information listed in paragraph (4A) in relation to the incident.”

45

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 24, at end insert—
“(4A) The information referred to in paragraph (1)(d) is—
(a) a detailed description of the incident, including its severity and impact;
(b) the type of threat or root cause which is likely to have caused the incident;
(c) the mitigation measures applied and, so far as known to the RMSP, ongoing;
(d) so far as known to the RMSP, any cross-border impact of the incident.”

46

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 26, after “notification” insert “without undue delay and in any event”

47

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 29, after “notification” insert “without undue delay and in any event”

49

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Lord Holmes of Richmond (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 30, at end insert—
“(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request.
(d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

50

Baroness Harding of Winscombe (Con)
Baroness Kidron (XB)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 30, line 30, at end insert—
“(5A) Where the RMSP incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the RMSP must instead give—
(a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and
(b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the RMSP incident ceases.”

51

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 16, page 32, line 34, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”

52

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 32, line 36, leave out “adversely”

54

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 1, leave out “adversely”

55

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 6, at end insert—
“(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned,
(bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

56

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 11, leave out “adversely”

57

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 11, at end insert—
“(c) advise on any measures or remedies that customers are able to take in response to the incident.”

58

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 15, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”

59

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 17, leave out “adversely”

61

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 21, leave out “adversely”

62

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 26, at end insert—
“(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned,
(bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

63

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 31, leave out “adversely”

64

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 31, at end insert—
“(c) advise on any measures or remedies that customers are able to take in response to the incident.”

65

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 35, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”

66

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 33, line 37, leave out “adversely”

68

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 34, line 3, leave out “adversely”

69

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 34, line 8, at end insert—
“(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned,
(bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

70

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 34, line 13, leave out “adversely”

71

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 16, page 34, line 13, at end insert—
“(c) advise on any measures or remedies that customers are able to take in response to the incident.”

72

Baroness Harding of Winscombe (Con)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

After Clause 16, insert the following new Clause—
“Notification of near misses, cyber threats and sub-threshold incidents
(1) The NIS Regulations are amended as follows.
(2) After regulation 14G insert—
“Notification of near misses, cyber threats and sub-threshold incidents
(1) A regulated person must notify the designated competent authority without undue delay and in any event no later than 72 hours of becoming aware, of—
(a) a cyber threat, or
(b) a near miss,
(c) a sub-threshold incident affecting the regulated person's network and information systems.
(2) A person other than a regulated person may notify the designated competent authority on a voluntary basis of a significant incident, a cyber threat or a near miss affecting that person's network and information systems, regardless of whether that person is subject to any requirement under these Regulations.
(3) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, a person who gives a notification under paragraph (1) or (2) is not, by reason only of that notification, subject to any additional duty, liability or requirement to which that person would not otherwise have been subject.
(4) In this regulation—
“cyber threat” means any potential circumstance, event or action that could, if it occurred, adversely affect the network and information systems of a person, or the users of a service provided by means of such systems;
“near miss” means an event that could have compromised the availability, authenticity, integrity or confidentiality of data, or of a service provided by means of network and information systems, but that was prevented from having that effect or did not in fact have that effect;
“regulated person” means an OES, an RDSP, an RMSP or a critical supplier;
“sub-threshold incident” means an incident affecting the regulated person's network and information systems which the regulated person is not otherwise required to notify under regulation 11(2), 11A(2), 12A(1) or 14E(1).””


Explanatory Text

This new clause seeks to ensure that regulated persons must report to their designated competent authority any near miss incident, cyber threat, or sub-threshold incident that could adversely affect the network and information systems of a person, or the users of a service provided by means of such systems.

73

Lord Alton of Liverpool (XB)
Lord Hunt of Kings Heath (Lab)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Baroness Ludford (LD)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 18, page 41, line 7, at end insert—
“Exemption from disclosure: right to a fair trial
(1) Nothing in paragraphs (1)(d) to (f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that—
(a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or
(b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial.
(2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of—
(a) subject matter experts, and
(b) competent civil society groups.
(3) Every 12 months the Secretary of State must publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) in the previous 12 months.
(4) The first report under paragraph (3) must be published and laid within 12 months of the day on which the Cyber Security and Resilience (Network and Information Systems) Act 2026 is passed.”

82

Lord Ravensdale (XB)
Tabled: 26 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 25, page 52, line 20, at end insert—
“(2A) In preparing a statement under this section, the Secretary of State must have regard to any timelines published by the National Cyber Security Centre for the migration of network and information systems to post-quantum cryptography.”


Explanatory Text

This amendment establishes that the Secretary of State must have regard to the timelines published by the National Cyber Security Centre for the migration of network and information systems to post-quantum cryptography in the preparation of the statement of strategic priorities, which may prompt focus on the NCSC’s PQC roadmap across the 12 competent authorities.

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause- AI Security Institute: standards, inspection and enforcement powers (1) The Secretary of State must ensure that the AI Security Institute (or any successor or replacement body designated by the Secretary of State) has power, under the circumstances described in subsection (2), to - (a) set, and keep under review, safety standards for certain frontier AI systems, (b) inspect certain frontier AI systems, and the practices of persons developing or deploying them, for the purpose of assessing conformity with those standards, and (c) require a provider or operator of certain frontier Al systems to take remedial action, including suspending or restricting the provision or deployment of the system, where it fails to conform to those standards,. (2) The powers described in subsection (1) are exercisable where a frontier Al system's capabilities pose a material risk to the security or resilience of network and information systems used in the carrying out of essential activities, as defined in section 24, including risk of – (a) harm to national security, or (b) catastrophic harm, arising from a failure or compromise of such systems. (3) In exercising its powers under this section the AI Security Institute must have regard to the desirability of proportionate, evidence-based and transparent regulation, and to any relevant standards or guidance issued by the National Cyber Security Centre or a competent authority designated under this Act. (4) The Secretary of State must by regulations make provision about the exercise of the powers described in subsection (1), including procedures for notice, representations, appeal and enforcement. (5) In this section “frontier AI system” means an artificial intelligence system meeting criteria specified by the Secretary of State by regulations, by reference to the computational resources used in training, the system's capabilities, or such other matters as the Secretary of State considers appropriate."

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 26 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 42, page 65, line 36, at end insert- “(aa) which is made under section (AI Security Institute: standards, inspection and enforcement powers), or”

25th August 2026
Amendment Paper
HL Bill 32 Running list of amendments – 25 August 2026

3

Baroness Kidron (XB)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 4, page 3, line 18, at end insert—
“(3A) A data centre also meets the threshold requirement in this subsection, regardless of its rated IT load, if the Office of Communications considers that an incident affecting the data centre would be likely to have a significant impact on the economy or the day-to-day functioning of society in the United Kingdom or any part of it, having regard in particular to the data centre’s customer base and level of interconnection with essential services.”


Explanatory Text

The amendment seeks to add a risk-based designation criterion alongside the existing megawatt thresholds for operators of essential services.

1

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 2, page 2, line 13, leave out “on the Secretary of State”


Explanatory Text

This amendment is consequential on my new new Clause (Functions under this Part).

2

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”


Explanatory Text

This amendment is consequential on my new Clause (Vendor-related directions), and on my amendments to Clause 43.

4

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Agreed To
View the speech made in the House

Clause 6, page 4, line 31, after “controller” insert “—
(a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and”


Explanatory Text

This amendment would ensure that the threshold requirement relating to the essential service of load control, inserted by Clause 6 of the Bill, applies only to organisations which carry out activities for system-balancing purposes.

12

Lord Tarassenko (XB)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an AI product or service within the UK.”


Explanatory Text

This amendment seeks to require RSDPs to follow guidance issued by the ICO and AISI when identifying and taking proportionate measures to manage the risks posed to the security of network and information systems which it relies on to provide services within the UK.

19

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Agreed To
View the speech made in the House

Clause 15, page 22, line 14, leave out “users of”


Explanatory Text

This amendment would require an operator of an essential service to consider whether any data relating to the essential service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.

36

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Agreed To
View the speech made in the House

Clause 15, page 26, line 31, leave out “users of”


Explanatory Text

This amendment would require a relevant digital service provider to consider whether any data relating to the relevant digital service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.

44

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Agreed To
View the speech made in the House

Clause 15, page 30, line 4, leave out “users of”


Explanatory Text

This amendment would require a relevant managed service provider to consider whether any data relating to the relevant managed service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.

78

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 24, page 51, line 30, at end insert—
“(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;”


Explanatory Text

This amendment is a technical amendment and would ensure all essential services in the NIS Regulations are captured.

83

Baroness Kidron (XB)
Baroness Ludford (LD)
Lord Holmes of Richmond (Con)
Lord Tarassenko (XB)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

After Clause 28, insert the following new Clause—
“Digital Sovereignty Strategy (relevant network and information systems)
(1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems.
(2) The Strategy must—
(a) set out the Government’s assessment of the risks to relevant network and information systems arising from or related to—
(i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference,
(ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers,
(iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities,
(iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission,
(v) foreign actors’ access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions;
(b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK;
(c) set out the Government’s approach to mitigating the risks identified under paragraph (b);
(d) include an assessment of—
(i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems,
(ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems,
(iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems,
(iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems,
(v) options for international collaboration in the production of open source components used in relevant network and information systems,
(vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems,
(vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and
(viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems.
(3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to—
(a) infrastructure, including infrastructure concentration,
(b) data-jurisdiction exposure,
(c) value of information and cultural assets of the United Kingdom, and
(d) dependency on foreign states.
(4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult—
(a) the Office for National Statistics,
(b) the Competition and Markets Authority,
(c) the National Cyber Security Centre,
(d) the AI Security Institute, and
(e) any other persons the Secretary of State deems relevant.
(5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security.
(6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen.
(7) In this section—
“Digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend;
“open source” has the meaning given to it in the definition published by the Open Source Initiative;
“relevant network and information system” means a network and information system belonging to—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require the Secretary of State to prepare, maintain, and lay before Parliament a Digital Sovereignty and Resilience Strategy addressing risks to relevant network and information systems from foreign ownership, interference, and technological dependence. The Strategy would include a Digital Sovereignty Dashboard, which would provide evidence on UK procurement, innovation and resilience and keep an up-to-date understanding of emerging risk.

106

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 8, leave out “regulated person” and insert “person within subsection (1A)”


Explanatory Text

This amendment and my amendment to Clause 43 at page 66, line 14 would enable directions under the Clause to be given to persons other than regulated persons, if the Secretary of State considers that they carry on essential activities or provide essential goods or services.

107

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 11, leave out “relevant network and information system” and insert “system that is a Part 4 NIS in relation to the person”


Explanatory Text

This is a drafting amendment.

108

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 14, at end insert—
“(1A) A person is within this subsection if the person—
(a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), or
(b) is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument.
(1B) A person may be specified in regulations under subsection (1A)(b) only if the person, or every person of that description—
(a) carries on a Part 4 essential activity in the United Kingdom, or
(b) provides essential goods or services.”


Explanatory Text

See the explanatory statement for my amendment to Clause 43 at page 66, line 8.

109

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 16, at end insert “with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (1)(a)”


Explanatory Text

This amendment would set out the purpose of a direction under Clause 43.

110

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 19, leave out “relevant network and information systems” and insert “a system that is a Part 4 NIS in relation to the person to which the direction is given”


Explanatory Text

This is a drafting amendment.

111

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 22, leave out “an” and insert “a Part 4”


Explanatory Text

This is a drafting amendment.

112

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 23, leave out “an activity-critical supply” and insert “essential goods or services”


Explanatory Text

This is a drafting amendment.

113

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 66, line 38, at end insert—
“(3A) Before making regulations under subsection (1A)(b), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so.
(3B) Where a person is specified in regulations under subsection (1A)(b), the Secretary of State must notify the person that they have been so specified.”


Explanatory Text

This amendment is consequential on my amendment to Clause 43 at page 66, line 14, and imposes consultation and notification duties in relation to the regulations.

115

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 67, line 2, leave out “an” and insert “a Part 4”


Explanatory Text

This is a drafting amendment.

116

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 67, line 3, leave out “an activity-critical supply” and insert “essential goods or services”


Explanatory Text

This is a drafting amendment.

117

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 43, page 67, line 42, at end insert—
“(13) Regulations under subsection (1A)(b) may make different provision for different purposes.
(14) A statutory instrument containing regulations under subsection (1A)(b) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency).”


Explanatory Text

This amendment is consequential on my amendment to Clause 43 at page 66, line 14, and would make further provision about the regulations.

118

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 4, leave out “regulated person” and insert “person to which a relevant direction has been given”


Explanatory Text

This amendment and my other amendments to Clause 44 would apply this clause to directions under my new Clause (Vendor-related directions), as well as to directions under Clause 43, and make associated drafting changes.

119

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 5, leave out “direction given to the person under section 43” and insert “relevant direction given to the person”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

120

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 10, leave out “duty of the regulated person” and insert “person’s duty”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

121

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 14, leave out “regulated”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

122

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 18, leave out “regulated person” and insert “person to which the relevant direction has been given”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

123

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 24, after “varies the” insert “relevant”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

124

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 26, after “the” insert “relevant”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

125

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 29, leave out “the regulated person” and insert “—
(i) the person to which the relevant direction has been given,”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

126

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 44, page 68, line 33, at end insert—
““relevant direction” means a direction under section (Vendor-related directions) or 43.”


Explanatory Text

See the explanatory statement to my amendment to Clause 44 at page 68, line 4.

127

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 44, insert the following new Clause—
“Regulations under section (Vendor-related directions)(1)(a)or 43(1A)(b): procedure in urgent cases
(1) A statutory instrument containing regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b) may be made without a draft of the instrument being laid before and approved by a resolution of each House of Parliament if it contains a declaration that the Secretary of State considers that, by reason of urgency, it is necessary to make the regulations without a draft being so laid and approved.
(2) After an instrument is made in accordance with subsection (1), it must be laid before each House of Parliament.
(3) Regulations contained in an instrument made in accordance with subsection (1) cease to have effect at the end of the period of 28 days beginning with the day on which the instrument is made unless, during that period, the instrument is approved by a resolution of each House of Parliament.
(4) In calculating the period of 28 days, no account is to be taken of any time during which—
(a) Parliament is dissolved or prorogued, or
(b) either House of Parliament is adjourned for more than four days.
(5) If regulations cease to have effect as a result of subsection (3), that does not—
(a) affect the validity of anything previously done under the regulations, or
(b) prevent the making of new regulations.”


Explanatory Text

This amendment would set out the Parliamentary procedure that would apply to regulations under my new Clause (Vendor-related directions) and under Clause 43 in cases of urgency.

128

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 45, page 68, line 38, after “section” insert “(Vendor-related directions) or”


Explanatory Text

This amendment and my other amendment to Clause 45 are consequential on my new Clause (Vendor-related directions), and would enable the Secretary of State to direct a regulatory authority to monitor compliance with a direction given under that new Clause.

129

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 45, page 69, line 8, after “section” insert “(Vendor-related directions) or”


Explanatory Text

See the explanatory statement to my other amendment to Clause 45.

130

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 71, line 24, after “section” insert “(Vendor-related directions) or”


Explanatory Text

This amendment is consequential on my new Clause (Vendor-related directions) and would enable an inspection to be carried out to verify compliance with a direction given under that new Clause.

131

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 71, line 27, at end insert—
““the affected person” means—
(a) where the inspection relates to a direction under section (Vendor-related directions) or 43, the person to which the direction was given;
(b) where the inspection relates to a confirmation decision under section 50, the person to which the decision is given.”


Explanatory Text

This amendment and various of my other amendments to Clause 47 are drafting changes that are consequential on my new Clause (Vendor-related directions) and on my amendments to Clause 43.

132

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 71, line 33, leave out “a regulated” and insert “the affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

133

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 1, leave out “a regulated” and insert “the affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

134

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 3, leave out “regulated” and insert “affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

135

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 20, leave out “regulated person to which the inspection relates” and insert “ affected person”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

136

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 23, leave out “a regulated” and insert “the affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

137

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 33, leave out “regulated” and insert “affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

138

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 72, line 36, leave out “regulated” and insert “affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

139

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 47, page 73, line 1, leave out “regulated” and insert “affected”


Explanatory Text

See the explanatory statement to my amendment to Clause 47 at page 71, line 27.

140

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 48, page 73, line 23, after “section” insert “(Vendor-related directions) or”


Explanatory Text

This amendment is consequential on my new Clause (Vendor-related directions), and would enable a notification of contravention to be given in relation to a requirement in a direction under that new Clause, or a related requirement.

141

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 48, page 73, line 24, after “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or”


Explanatory Text

This amendment is consequential on my new Clause (Further provision about giving of vendor-related directions), and would enable a notification of contravention to be given in relation to a requirement to obtain approval before appointing a skilled person in relation to a direction given under the new Clause (Vendor-related directions).

142

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 8, after first “section” insert “(Vendor-related directions) or”


Explanatory Text

This amendment and my first amendment to Clause 49 at page 75, line 25 are consequential on my new Clause (Vendor-related directions), and would apply the penalty provisions to a failure to comply with a requirement in a direction under that Clause, or a related requirement.

143

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 8, after second “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or”


Explanatory Text

This amendment and my second amendment to Clause 49 at page 75, line 25 are consequential on my new Clause (Further provision about giving of vendor-related directions), and would apply the penalty provisions to a failure to obtain approval before appointing a skilled person.

144

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 18, leave out “regulated”


Explanatory Text

This amendment and my amendment to Clause 49 at page 75, line 26 are consequential on my amendments to Clause 47 at page 71, line 33, at page 72, line 1, and at page 72, line 3.

145

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 25, after first “section” insert “(Vendor-related directions) or”


Explanatory Text

See the explanatory statement to my first amendment to Clause 49 at page 75, line 8.

146

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 25, after second “section” insert “(Further provision about giving of vendor-related directions)(4)(a) or”


Explanatory Text

See the explanatory statement to my second amendment to Clause 49 at page 75, line 8.

147

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 49, page 75, line 26, leave out “regulated”


Explanatory Text

See the explanatory statement to my amendment to Clause 49 at page 75, line 18.

148

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 52, page 78, line 24, after “section” insert “(Further provision about giving of vendor-related directions)(8),”


Explanatory Text

This amendment is consequential on my new Clause (Further provision about giving of vendor-related directions), and would enable Clause 52 (enforcement of non-disclosure requirements) to apply in relation to a non-disclosure requirement imposed under that new Clause.

149

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 54, page 80, line 26, after “section” insert “(Vendor-related directions),”


Explanatory Text

This amendment and my other amendment to Clause 54 are consequential on my new Clause (Vendor-related directions), and would apply the provisions on review, variation and revocations of directions to directions under that new Clause.

150

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 54, page 81, line 5, after “section” insert “(Vendor-related directions) or”


Explanatory Text

See the explanatory statement to my other amendment to Clause 54.

151

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 54, insert the following new Clause—
“Publication of notice of direction under section (Vendor-related directions) etc
(1) Subject to subsection (3), the Secretary of State must publish, in such manner as the Secretary of State considers appropriate, notice of the fact that—
(a) a direction under section (Vendor-related directions) has been given, or
(b) such a direction has been varied or revoked under section 54.
(2) The notice under subsection (1) must be published as soon as practicable and must—
(a) state when the direction, variation or revocation comes into force,
(b) state the person to which the direction, variation or revocation has been given,
(c) include a summary of the direction, variation or revocation, its effect and the reasons for it, and
(d) include any other information that the Secretary of State considers it appropriate to include.
(3) The Secretary of State may exclude from the notice under subsection (1) anything the publication of which the Secretary of State considers—
(a) might harm the commercial interests of any person to an unreasonable degree, or
(b) would be contrary to the interests of national security.”


Explanatory Text

This amendment would require the Secretary of State to publish notice of the giving, variation or revocation of a direction under my new Clause (Vendor-related directions).

152

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 54, insert the following new Clause—
“Annual report in relation to directions under section (Vendor-related directions)
(1) The Secretary of State must, in relation to each relevant period—
(a) prepare a report in accordance with this section, and
(b) lay a copy of it before each House of Parliament as soon as practicable after the end of that period.
(2) Each report must provide details of—
(a) the number of directions given under section (Vendor-related directions) during the relevant period,
(b) the kinds of services provided by persons to which directions under section (Vendor-related directions) were given during the relevant period (including, where relevant, the sectors in which the services are provided),
(c) the number of directions under section (Vendor-related directions) that have been varied during the relevant period, and
(d) the number of directions under section (Vendor-related directions) that have been revoked during the relevant period.
(3) “Relevant period” means—
(a) the period of 12 months beginning with the day on which section (Vendor-related directions)(1) comes into force for any purpose other than the purpose of making regulations;
(b) each subsequent period of 12 months.”


Explanatory Text

This amendment would require the Secretary of State to produce and lay before Parliament an annual report in relation to directions given under my new Clause (Vendor-related directions).

154

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 55, page 81, line 26, at end insert “in respect of a direction under section 43 or 53”


Explanatory Text

This amendment is consequential on various of my other amendments, and would ensure that a notice of variation relating to a direction under my new Clause (Vendor-related directions) does not have to be laid before Parliament.

155

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, leave out lines 19 and 20


Explanatory Text

This is a drafting amendment (the definition being left out would be replaced by the definition of “essential goods or services” which would be inserted by my amendment to Clause 58 at page 84, line 23).

156

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, leave out lines 21 to 23


Explanatory Text

This is a drafting amendment (the definition being left out would be replaced by the definition of “Part 4 essential activity” which would be inserted by my amendment to Clause 58 at page 84, line 26).

157

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 23, at end insert—
““essential goods or services” means goods or services without the provision of which the carrying on of a Part 4 essential activity would be at risk of disruption;”


Explanatory Text

This amendment would insert a definition used throughout my other amendments to Part 4.

158

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 26, at end insert—
““Part 4 essential activity” means an activity the carrying on of which the Secretary of State considers to be essential to—
(a) the economy of the United Kingdom or any part of the United Kingdom, or
(b) the day-to-day functioning of society in the United Kingdom or any part of the United Kingdom;”


Explanatory Text

This amendment would insert a definition used throughout my other amendments to Part 4.

159

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 26, at end insert—
““Part 4 NIS” , in relation to a person, means a network and information system that is—
(a) used or relied on by the person in connection with the carrying on of a Part 4 essential activity or the provision of essential goods or services, or
(b) associated with a system mentioned in paragraph (a) (and section 29(4) (meaning of “associated”) applies for the purposes of this paragraph as it applies for the purposes of section 29(3));”


Explanatory Text

This amendment would insert a definition used throughout my other amendments to Part 4.

160

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 28, after “30(2)” insert “and (5)”


Explanatory Text

This is a drafting amendment.

161

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, leave out lines 32 and 33


Explanatory Text

This is a drafting amendment (the definition being left out would be replaced by the definition of “Part 4 NIS” which would be inserted by my amendment to Clause 58 at page 84, line 26).

162

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 34, leave out from “compromise”” to end and insert “, in relation to a network and information system, means—
(a) anything that compromises the security, availability, functionality or reliability of the system,
(b) any unauthorised access to, interference with or exploitation of the system or anything which enables such access, interference or exploitation,
(c) anything that compromises the confidentiality, authenticity, integrity or availability of data stored on or processed, received or transmitted by the system, or
(d) anything that causes data stored on or processed by the system to be lost.”


Explanatory Text

This is a drafting amendment (it would replicate the definition in Part 3 rather than cross-referring to it).

163

Baroness Lloyd of Effra (Lab) - Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

Clause 58, page 84, line 35, at end insert—
“(2) For the purposes of this Part—
(a) a reference to the carrying on of an activity includes a reference to the provision of a service;
(b) a reference to a person specified or of a description specified for the purposes of section 30(2) includes a reference to a person treated by section 30(5) as having been so specified.”


Explanatory Text

This amendment would make provision about the interpretation of certain expressions in Part 4.

168

Baroness Ludford (LD)
Tabled: 25 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 58, insert the following new Clause—
“Review of the regulation of data-storing sectors
(1) The Secretary of State must carry out a review of whether the NIS Regulations should be extended to persons who store or process personal data on behalf of other organisations at scale, but who are not otherwise regulated under those Regulations.
(2) The review must, in particular, consider the case for extending regulation to—
(a) providers of software as a service,
(b) any other sector or description of provider which the Secretary of State considers, at the time of the review, to hold personal data on behalf of other organisations at a scale or in a manner that may warrant regulation under the NIS Regulations.
(3) In carrying out the review the Secretary of State must consider, in particular—
(a) the number of organisations relying on any single such provider, and the number of individuals whose personal data is held;
(b) the extent to which those organisations are able in practice to assess or influence the security of the network and information systems on which their data is held;
(c) whether the data protection legislation is sufficient to manage the risks identified, in particular as regards the security of network and information systems and the reporting of incidents;
(d) whether providers within subsection (2) could be brought within the meaning of "relevant managed service provider" or "relevant digital service provider", or designated under regulation 14H of the NIS Regulations, and what changes (if any) to those Regulations would be needed to achieve this;
(e) the effect of any such extension on organisations that are small or medium-sized enterprises, or that are charities or other voluntary organisations, whether as providers or as customers.
(4) In carrying out the review the Secretary of State must consult the Information Commission, the National Cyber Security Centre, and such other persons as the Secretary of State considers appropriate.
(5) The Secretary of State must lay a report on the review before Parliament within 12 months of the day on which this Act is passed.
(6) In this section—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“the NIS Regulations” has the meaning given by section 1.”


Explanatory Text

This probing amendment would require the Secretary of State to review, and report to Parliament within 12 months of Royal Assent, whether cyber security regulation under the NIS Regulations should be extended to further sectors that store or process personal data on behalf of other organisations at scale, including software-as-a-service providers

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(za) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Ravensdale (XB)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 12, page 12, line 26, at end insert- “Restrictions on designation: systemic risk 14IA. - (1) In determining whether to designate a supplier as a "critical supplier" under this section, the designated competent authority must assess whether a failure or disruption in the services provided by that supplier would pose a systemic risk to the digital ecosystem, essential services, or economy of the United Kingdom. (2) A supplier shall not be designated as a critical supplier solely on the basis that it provides services to a single OES, critical national infrastructure entity, or public authority. (3) In assessing whether a supplier poses a systemic risk, the Secretary of State or competent authority must have regard to- (a) the overall concentration of operators or essential services reliant upon the supplier and the degree of substitutability of the supplier's services; (b) the extent to which a cyber security incident affecting the supplier could cause cascading or multi-sectoral failure across critical infrastructure; and (c) whether the risks arising from the supply relationship can be appropriately managed through contractual, procurement, and vendor risk management measures exercised directly by the receiving entity. (4) The Secretary of State must, following consultation with relevant regulatory authorities and industry representatives, publish statutory guidance setting out consistent criteria for assessing systemic risk and designating critical suppliers across all regulated sectors."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 21, line 33, at end insert- "(c) if requested by the designated competent authority following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (2)(b), as the authority may specify, and (d) a final report containing the information listed in paragraph (5A) in relation to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 15, at end insert- "(f) whether there has been, is or is likely to be any impact as a result of the incident on network and information systems of users of the service; (g) any impact that the incident has had, is having or is likely to have on the economy or the day-to-day functioning of society.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 28, at end insert— "(5A) The information referred to in paragraph (2)(d) is – (a) a detailed description of the incident, including its severity and impact; (b) the type of threat or root cause which is likely to have caused the incident; (c) the mitigation measures applied and, so far as known to the OES, ongoing; (d) so far as known to the OES, any cross-border impact of the incident.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 30, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 33, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 34, at end insert- “(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request. (d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 22, line 34, at end insert- "(6A) Where the OES incident is still occurring at the time a final report would otherwise fall to be given under paragraph (6)(d), the OES must instead give- (a) a progress report, at the time provided for in paragraph (6)(d), containing the information listed in paragraph (5A) so far as then known; and (b) a final report, containing the information listed in paragraph (5A), before the end of the period of one month beginning with the time at which the OES incident ceases."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 12, at end insert- "(c) if requested by the designated competent authority following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (2)(b), as the authority may specify, and (d) a final report containing the information listed in paragraph (4A) in relation to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 35, at end insert- “(4A) The information referred to in paragraph (2)(d) is – (a) a detailed description of the incident, including its severity and impact; (b) the type of threat or root cause which is likely to have caused the incident; (c) the mitigation measures applied and, so far as known to the OES, ongoing; (d) so far as known to the OES, any cross-border impact of the incident.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 37, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 40, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 41, at end insert- “(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request. (d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 41, at end insert- "(5A) Where the data centre incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the OES must instead give- (a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and (b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the data centre incident ceases."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 26, line 12, at end insert- "(c) if requested by the Information Commission or Artificial Intelligence Security Institute following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (1)(b), as the Information Commission may specify, and (d) a final report containing the information listed in paragraph (4A) in relation to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 27, line 10, at end insert- “(4A) The information referred to in paragraph (1)(d) is – (a) a detailed description of the incident, including its severity and impact; (b) the type of threat or root cause which is likely to have caused the incident; (c) the mitigation measures applied and, so far as known to the RDSP, ongoing; (d) so far as known to the RDSP, any cross-border impact of the incident.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 27, line 12, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 27, line 15, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 27, line 16, at end insert- “(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request. (d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 27, line 16, at end insert- "(5A) Where the RDSP incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the RDSP must instead give- (a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and (b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the RDSP incident ceases."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 29, line 24, at end insert- "(c) if requested by the Information Commission following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (1)(b), as the Information Commission may specify, and (d) a final report containing the information listed in paragraph (4A) in relation to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 30, line 24, at end insert- "(4A) The information referred to in paragraph (1)(d) is – (a) a detailed description of the incident, including its severity and impact; (b) the type of threat or root cause which is likely to have caused the incident; (c) the mitigation measures applied and, so far as known to the RMSP, ongoing; (d) so far as known to the RMSP, any cross-border impact of the incident.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 30, line 26, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 30, line 29, after “notification” insert “without undue delay and in any event"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 30, line 30, at end insert- "(c) in the case of an intermediate report, before the end of such period as the designated competent authority may specify when requesting the report, being a period of not more than 14 days beginning with the date of the request. (d) In the case of a final report, no later than the end of the period of one month beginning with the time at which the full notification is given.”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 30, line 30, at end insert- "(5A) Where the RMSP incident is still occurring at the time a final report would otherwise fall to be given under paragraph (5)(d), the RMSP must instead give- (a) a progress report, at the time provided for in paragraph (5)(d), containing the information listed in paragraph (4A) so far as then known; and (b) a final report, containing the information listed in paragraph (4A), before the end of the period of one month beginning with the time at which the RMSP incident ceases."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 32, line 34, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 32, line 36, leave out “adversely"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 1, leave out “adversely"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 6, at end insert- "(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned, (bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 11, leave out “adversely”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 11, at end insert— “(c) advise on any measures or remedies that customers are able to take in response to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 15, leave out “as soon as reasonably practicable” and insert "without delay and in any event within 24 hours of becoming aware of the incident"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 17, leave out “adversely”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 21, leave out “adversely"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 26, at end insert- "(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned, (bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 31, leave out “adversely"

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 31, at end insert- "(c) advise on any measures or remedies that customers are able to take in response to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 35, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 33, line 37, leave out “adversely”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 34, line 3, leave out “adversely”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 34, line 8, at end insert – "(ba) if the incident has caused or is capable of causing severe operational disruption of the services or financial loss for the customer concerned, (bb) if the incident has affected or is capable of affecting related natural or legal persons to the customer by causing considerable material or non-material damage, and”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 34, line 13, leave out “adversely”

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 16, page 34, line 13, at end insert- "(c) advise on any measures or remedies that customers are able to take in response to the incident."

Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

After Clause 16, insert the following new Clause- "Notification of near misses, cyber threats and sub-threshold incidents (1) The NIS Regulations are amended as follows. (2) After regulation 14G insert – "Notification of near misses, cyber threats and sub-threshold incidents 14GA. – (1) A regulated person must notify the designated competent authority without undue delay and in any event no later than 72 hours of becoming aware, of- (a) a cyber threat, or (b) a near miss, (c) a sub-threshold incident affecting the regulated person's network and information systems. (2) A person other than a regulated person may notify the designated competent authority on a voluntary basis of a significant incident, a cyber threat or a near miss affecting that person's network and information systems, regardless of whether that person is subject to any requirement under these Regulations. (3) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, a person who gives a notification under paragraph (1) or (2) is not, by reason only of that notification, subject to any additional duty, liability or requirement to which that person would not otherwise have been subject. (4) In this regulation- "cyber threat" means any potential circumstance, event or action that could, if it occurred, adversely affect the network and information systems of a person, or the users of a service provided by means of such systems; “near miss” means an event that could have compromised the availability, authenticity, integrity or confidentiality of data, or of a service provided by means of network and information systems, but that was prevented from having that effect or did not in fact have that effect; "regulated person” means an OES, an RDSP, an RMSP or a critical supplier; “sub-threshold incident” means an incident affecting the regulated person's network and information systems which the regulated person is not otherwise required to notify under regulation 11(2), 11A(2), 12A(1) or 14E(1).'"""

Lord Alton of Liverpool (XB)
Lord Hunt of Kings Heath (Lab)
Lord Markham (Con) - Shadow Minister (Science, Innovation and Technology)
Baroness Ludford (LD)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 18, page 41, line 7, at end insert - "Exemption from disclosure: right to a fair trial 6AA. - (1) Nothing in paragraphs (1)(d) to (f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that- (a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or (b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial. (2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of - (a) subject matter experts, and (b) competent civil society groups. (3) Every 12 months the Secretary of State must publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) in the previous 12 months. (4) The first report under paragraph (3) must be published and laid within 12 months of the day on which the Cyber Security and Resilience (Network and Information Systems) Act 2026 is passed.”

Baroness Kidron (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Baroness Harding of Winscombe (Con)
Lord Holmes of Richmond (Con)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 23, insert the following new Clause – "Red lines on AI products and services (1) Al products and services which are classified as “relevant digital services” for the purposes of the NIS Regulations must demonstrate they are not capable of performing capabilities that cross “red lines” as defined in subsection (2). (2) The red lines referred to in subsection (1) are- (a) evading human oversight or shutdown or resisting any action that, at a given level of confidence, compromises the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, network and information systems, (b) autonomously self-replicating, self-improving, or acquiring compute or other resources to the extent that this presents a risk to the authenticity and integrity of the processed data held within the system, (c) autonomously conducting or substantially accelerating sophisticated attacks on critical infrastructure, including government, security, services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (d) providing support for the development of chemical, biological, radiological, or nuclear weapons by non-state actors or hostile states to facilitate attacks on critical infrastructure, including government, security services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (e) providing support for terrorist groups and hostile actors to facilitate attacks on critical infrastructure, including government, security services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (f) deceiving or manipulating populations at scale or compromising confidence in a network and information system's ability to resist any action that compromises the availability, authenticity, integrity or confidentiality of the services offered by those systems, (g) other capabilities which are found to compromise, at a given level of confidence, the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, those network and information systems. (3) In order to demonstrate successfully that the product or service is not capable of performing capabilities that cross the “red lines” as defined in subsection (2) the Al product or service classified as a “relevant digital service” for the purposes of the NIS Regulations must be assessed and approved by the Artificial Intelligence Security Institute before it is made available within the United Kingdom. (4) In this section, “relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Baroness Northover (LD)
Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was No Decision

After Clause 24, insert the following new Clause- "Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities - (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified.”

Lord Ravensdale (XB)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 25, page 52, line 20, at end insert- "(2A) In preparing a statement under this section, the Secretary of State must have regard to any timelines published by the National Cyber Security Centre for the migration of network and information systems to post-quantum cryptography."

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Baroness Kidron (XB)
Baroness Harding of Winscombe (Con)
Tabled: 25 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 29, insert the following new Clause- ""Last-resort” powers in respect of data centres and AI models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers") to direct the shutdown of – (a) data centres, or (b) AI systems deployed on a substantial scale, in the event of an AI security or operational emergency. (1A) For the purposes of this section- "data centre" has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); “AI system” means a machine-based system that, from the input it receives, can infer how to - (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; “deployment on a substantial scale” means AI systems made available to – (a) a substantial number of individuals within the United Kingdom, or (b) providers and operators of essential service; “AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that- (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an AI system operating from data centres or deployed on a substantial scale, whether through autonomous or non-autonomous means, and (c) this compromise poses a catastrophic risk; “catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to - (a) large-scale disruption to critical infrastructure or essential services, (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom, or (c) severe, large-scale harm to human life; "data centre operator" means a person who operates a data centre; "AI provider" means a person who deploys one or more AI systems on a substantial scale. (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the directions and the reasons for it, and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, and on AI providers, including relating to- (a) the possession or installation of technical infrastructure necessary for those operators or providers to be able to comply with last-resort powers, (b) the provision by those operators or providers of secure communication channels for use by the Secretary of State when utilising last-resort powers, (c) the implementation by those operators or providers of regular emergency exercises to ensure that a direction under this section can be received safely and implemented, and (d) post-mortem processes to be followed by those operators or providers before a data centre operator or an Al provider is allowed to resume operations after the use of last-resort powers, including - (i) incident reporting, and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if - (a) the person is a data centre operator and fails to comply with any requirement imposed on data centre operators by regulations made under subsection (4), or (b) the person is an AI provider and fails to comply with any requirement imposed on AI providers by regulations made under subsection (4). (6) A person guilty of an offence under subsection (5) is liable (a) on conviction on indictment, to imprisonment for a term not exceeding 2 years or a fine (or both); (b) on summary conviction, to imprisonment for a term not exceeding 6 months or a fine (or both). (7) Regulations relating to last-resort powers may (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to – (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (8) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must- (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable, and (b) inform the operator or provider of their right to apply to the High Court for relief. (9) The High Court may make any order it thinks fit on an application under subsection (7)(b), including – (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (10) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (11) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (12) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament. (13) The report must include (in particular) consideration of - (a) adversarial uses of AI systems by state and non-state actors, (b) the capabilities for cyber-attacks by autonomous AI systems, and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability (including systems described as “superintelligent AI”).”

25th August 2026
Delegated Powers Memorandum
Supplementary Delegated Powers Memorandum
24th August 2026
Amendment Paper
HL Bill 32 Running list of amendments – 24 August 2026
Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out “on the Secretary of State”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 2, page 2, line 13, leave out from “directions” to end of line 15 and insert “in particular circumstances involving a risk to national security interests.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 4, line 31, after “controller” insert “. (a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and"

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 6, page 5, line 5, at end insert - “(a) an activity is carried on for "system-balancing purposes" if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;"

Lord Tarassenko (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 8, page 8, line 7, leave out from “Commission” to end of line 8 and insert “and the Artificial Intelligence Security Institute when carrying out the duties imposed on it by paragraph (1) of the NIS Regulations when they rely on an Al product or service within the UK."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 24, page 51, line 30, at end insert- “(ia) a service which is deemed by regulation 8(2A) of those Regulations to be an essential service;"

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes – (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Baroness Kidron (XB)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 28, insert the following new Clause – "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to – (i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers, (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities, (iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, (v) foreign actors' access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions; (b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK; (c) set out the Government's approach to mitigating the risks identified under paragraph (b); (d) include an assessment of – (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems, (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems, (iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems, (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems, (v) options for international collaboration in the production of open source components used in relevant network and information systems, (vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems, (vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and (viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to - (a) infrastructure, including infrastructure concentration, (b) data-jurisdiction exposure, (c) value of information and cultural assets of the United Kingdom, and (d) dependency on foreign states. (4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult- (a) the Office for National Statistics, (b) the Competition and Markets Authority, (c) the National Cyber Security Centre, (d) the AI Security Institute, and (e) any other persons the Secretary of State deems relevant. (5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (7) In this section- "Digital sovereignty" means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; “open source" has the meaning given to it in the definition published by the Open Source Initiative; "relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (No. 2) (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section “relevant body" means (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations (a) provide for the transfer to the OCR of the functions of - (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.”

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "CHAPTER 1 FUNCTIONS UNDER PART 4 Functions under this Part For the purposes of this Part, any reference to the Secretary of State includes a reference to the Chancellor of the Duchy of Lancaster."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "CHAPTER 2 VENDOR-RELATED DIRECTIONS ETC Vendor-related directions (1) The Secretary of State may give a direction to a person (“P”) if — (a) P is specified or of a description specified for the purposes of this paragraph in regulations made by the Secretary of State by statutory instrument, and (b) conditions 1 and 2 are met. (2) A person may be specified in regulations under subsection (1)(a) only if the person, or every person of that description – (a) is specified or of a description specified for the purposes of section 30(2) in regulations under section 29(1), (b) carries on a Part 4 essential activity in the United Kingdom, or (c) provides essential goods or services. (3) Condition 1 is that the Secretary of State considers that a risk to national security arises or could arise as a result of the use or potential use by P, in connection with a system that is a Part 4 NIS in relation to P, of goods, services or facilities provided by another person. (4) Condition 2 is that the Secretary of State considers that - (a) the direction is necessary having regard to that risk, and (b) the requirements imposed by the direction are proportionate to what is sought to be achieved by the direction. (5) A direction under this section is a direction requiring P to do, or not to do, a particular thing specified in the direction with a view to eliminating, reducing or mitigating the risk to national security referred to in subsection (3). (6) A direction under this section may in particular impose any of the following kinds of requirement – (a) a requirement relating to the management of a system that is a Part 4 NIS in relation to P; (b) a requirement designed to reduce risks relating to, or to mitigate impacts on, the carrying on of a Part 4 essential activity or the provision of essential goods or services; (c) a requirement relating to the provision of information, including information relating to compliance with the direction; (d) a requirement in the form of a prohibition or restriction on the use of goods, services or facilities; (e) a requirement in the form of a prohibition on the installation of goods or the taking up of services or facilities; (f) a requirement relating to removing, disabling or modifying goods or facilities or modifying services; (g) a requirement for P to appoint a person with expertise in relation to the security of network and information systems (a “skilled person”) for the purpose of assisting P to comply with the direction; (h) a requirement for a thing to be done or not done in or in relation to the United Kingdom, relevant UK waters (as defined by section 41(2)) or a place other than the United Kingdom. (7) Before making regulations under subsection (1)(a), the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (8) Where a person is specified in regulations under subsection (1)(a), the appropriate authority must notify the person that they have been so specified. (9) For the purposes of subsection (8), the appropriate authority is – (a) where the person is specified in reliance on subsection (2)(a), a regulatory authority in relation to the person; (b) otherwise, the Secretary of State. (10) Regulations under subsection (1)(a) may make different provision for different purposes. (11) A statutory instrument containing regulations under subsection (1)(a) may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament (but see section (Regulations under section (Vendor-related directions)(1)(a) or 43(1A)(b): procedure in urgent cases) for further provision about the making of such an instrument in cases of urgency)."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- “Further provision about giving of vendor-related directions (1) It does not matter for the purposes of section (Vendor-related directions) whether or not- (a) the risk to national security referred to in section (Vendor-related directions)(3) relates to the carrying on of a Part 4 essential activity or the provision of essential goods or services; (b) the person referred to in section (Vendor-related directions)(3) by whom goods, services or facilities are provided (“the vendor”) is established in the United Kingdom; (c) the goods, services or facilities provided by the vendor are provided from within or outside the United Kingdom; (d) the use or proposed use of goods, services or facilities is within the United Kingdom. (2) A direction under section (Vendor-related directions) must specify – (a) the person to which the direction is given; (b) the vendor to which the direction relates; (c) the goods, services or facilities to which the direction relates; (d) the reasons for the direction, except if or to the extent that the Secretary of State considers that it would be contrary to the interests of national security to do so; (e) the time at which the direction comes into force; (f) in relation to each requirement imposed by the direction that requires a thing to be done, a reasonable period within which the requirement must be complied with. (3) A person to which a direction is given under section (Vendor-related directions) must comply with it. (4) A person to which a direction is given under section (Vendor-related directions) ("P") - (a) must obtain the written approval of the Secretary of State before appointing a skilled person for the purpose of assisting P to comply with the direction (whether or not in pursuance of a requirement imposed by virtue of section (Vendor-related directions)(6)(g)); (b) must notify the Secretary of State as soon as reasonably practicable after appointing a skilled person (whether or not in pursuance of such a requirement). (5) For the purposes of giving approval as required by subsection (4)(a), the Secretary of State may rely on a list of persons published by the Government Communications Headquarters. (6) Before giving a direction under section (Vendor-related directions) to a person, the Secretary of State must consult- (a) that person, (b) the vendor to which the direction relates, and (c) such other persons as the Secretary of State considers it appropriate to consult, so far as it is reasonably practicable to do so. (7) The duty under subsection (6) does not apply if or to the extent that the Secretary of State considers that compliance with the duty would be contrary to the interests of national security. (8) The Secretary of State may require- (a) a person to which a direction is given under section (Vendor-related directions) not to disclose, in whole or in part, the existence of the direction and the contents of the direction without the permission of the Secretary of State; (b) a person consulted under subsection (6) not to disclose, in whole or in part, the existence of the consultation and any information disclosed to the person in the consultation without the permission of the Secretary of State. (9) The Secretary of State may not impose a requirement under subsection (8) unless the Secretary of State considers that the requirement is necessary and proportionate in the interests of national security."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause- "Power to make regulations about time frame for giving vendor-related directions (1) The Secretary of State may by regulations made by statutory instrument make provision about the time frame for determining whether to give a direction under section (Vendor-related directions) (whether on a referral by a person specified or of a description specified in regulations under subsection (1)(a) of that section or otherwise). (2) The provision that may be made by regulations under subsection (1) includes, in particular, provision- (a) about the period for making the decision; (b) enabling the Secretary of State to extend or pause the period in circumstances specified or described in the regulations. (3) Regulations under subsection (1) may - (a) make different provision for different purposes; (b) make provision subject to exceptions; (c) make consequential, supplementary, incidental, transitional or saving provision; (d) confer functions involving the exercise of a discretion. (4) A statutory instrument containing regulations under subsection (1) is subject to annulment in pursuance of a resolution of either House of Parliament."

Baroness Lloyd of Effra (Lab) - Parliamentary Under-Secretary of State (Department for Digital, Culture, Media and Sport)
Tabled: 24 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Before Clause 43, insert the following new Clause – "Power to establish mandatory referral scheme (1) The Secretary of State may by regulations made by statutory instrument make provision for the establishment and operation of a mandatory referral scheme. (2) A “mandatory referral scheme” is a scheme which, for the purpose of enabling the Secretary of State to determine whether to give a direction under section (Vendor-related directions) in respect of a qualifying transaction, requires a person specified or of a description specified in regulations under section (Vendor-related directions)(1)(a) to refer the transaction to the Secretary of State. (3) The Secretary of State may make regulations under this section establishing a mandatory referral scheme only if the Secretary of State considers that the establishment of such a scheme is necessary or expedient in the interests of national security. (4) "Qualifying transaction" has the meaning given by regulations under this section. (5) Provision made by virtue of subsection (4) may define “qualifying transaction” by reference to criteria set out in the regulations, which may, for example, be framed by reference to – (a) the nature of a transaction, (b) the value of a transaction, (c) whether or not a transaction is critical to the carrying on of a Part 4 essential activity or the provision of essential goods or services, or (d) the identity of the vendor in relation to a transaction. (6) Regulations under this section may make provision about- (a) when a person is required to make a referral; (b) the procedure for making a referral; (c) information to be provided in connection with a referral; (d) monitoring of compliance with requirements imposed by the regulations; (e) enforcement of compliance with requirements imposed by the regulations. (7) The provision that may be made by virtue of subsection (6)(d) and (e) includes provision applying (with or without modifications) any provision made by sections 45 to 52. (8) Before making regulations under this section, the Secretary of State must consult such persons as the Secretary of State considers appropriate, so far as it is reasonably practicable to do so. (9) Regulations under this section may (a) make different provision for different purposes; (b) make different provision for different areas; (c) make provision subject to exceptions; (d) require a person to have regard to guidance; (e) make consequential, supplementary, incidental, transitional or saving provision. (10) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament. (11) References in this section to a transaction include references to a proposed transaction."

21st August 2026
Amendment Paper
HL Bill 32 Running list of amendments – 21 August 2026

93

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was Not Called
View the speech made in the House

After Clause 37, insert the following new Clause—
“Consultation before issue of codes of practice and regulations
(1) Before preparing, issuing, amending or revising a code of practice under Chapter 4 of this Part, the Secretary of State must carry out an open public consultation.
(2) Before making regulations under section 24 or Chapter 3 of this Part, or giving a direction under Part 4 that applies to a description of regulated persons generally, the Secretary of State must carry out an open public consultation.
(3) A consultation under this section must—
(a) be open to any person providing, or proposing to provide, services of a kind regulated under this Act or the NIS Regulations, and to any other interested person,
(b) be published in a manner that is readily accessible, including to small and medium-sized enterprises,
(c) last for a period of not less than eight weeks, except where the Secretary of State reasonably considers that a shorter period is justified by urgency and publishes the reasons for that decision, and
(d) invite representations on the likely costs, benefits and practical effects of the proposal.
(4) The Secretary of State must publish a response to the consultation, setting out how the representations received have been taken into account, before the code of practice, regulations or direction take effect.
(5) This section does not apply to a direction given under Part 4 in respect of a specific regulated person for national security purposes.”


Explanatory Text

This new clause would require an open, publicly accessible consultation before the Secretary of State issues or revises codes of practice, makes regulations, or gives directions of general application, and would require publication of a response before they take effect.

17

Baroness Neville-Jones (Con)
Tabled: 21 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 15, page 21, line 19, leave out “capable of having” and insert “likely to have”


Explanatory Text

This amendment would narrow the definition of 'incident' in regulation 1(2) of the NIS Regulations so that it covers events likely to have an adverse effect, rather than events capable of having one, aligning the definition with the likelihood tests applied to notification later in the Bill.

28

Baroness Neville-Jones (Con)
Tabled: 21 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

Clause 15, page 23, line 13, leave out “could have had”


Explanatory Text

This amendment would remove the reference to an incident which could have had an impact from the definition of 'data centre incident', so that the definition covers incidents which have had, are having or are likely to have a significant impact.

100

Baroness Northover (LD)
Tabled: 21 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 42, insert the following new Clause—
“National cyber security support service for small and medium-sized enterprises
(1) The Secretary of State must, by regulations, make provision for the establishment and operation of a national cyber security support and incident response service for relevant small and medium-sized enterprises (SMEs), for the purpose of improving the security and resilience of their network and information systems.
(2) The service established under this section must—
(a) be free at the point of use, and
(b) provide, in particular following a cyber incident affecting a relevant SME—
(i) advice and technical assistance,
(ii) incident response support, and
(iii) guidance on recovery and remediation.
(3) For the purposes of this section, a relevant SME is a small or medium-sized enterprise which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.
(4) In establishing and operating the service the Secretary of State must have regard to comparable national cyber security support services operated in other jurisdictions.”


Explanatory Text

This new clause would require the Secretary of State to establish a national, free-at-the-point-of-use cyber security support and incident response service for relevant SMEs, modelled on comparable overseas services such as the small-business support provided by the Australian Cyber Security Centre.

Baroness Kidron (XB)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

Clause 4, page 3, line 18, at end insert- "(3A) A data centre also meets the threshold requirement in this subsection, regardless of its rated IT load, if the Office of Communications considers that an incident affecting the data centre would be likely to have a significant impact on the economy or the day-to-day functioning of society in the United Kingdom or any part of it, having regard in particular to the data centre's customer base and level of interconnection with essential services."

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 7, page 6, line 31, after “engine” insert “, software or a digital platform,”

Baroness Kidron (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 7, page 7, line 23, after “EC” insert “, unless the Information Commission or Artificial Intelligence Security Institute determines that the person's provision of the relevant digital service poses a risk to public safety, national security, or the security of network and information systems relied on for the carrying on of essential activities that is disproportionate to the size of the person”

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 7, page 7, line 28, after “nature;” insert– "and in the case of software or a digital platform, includes a person which- (i) creates software for distribution, (ii) distributes software on behalf of other businesses, (iii) manages services for the distribution of software, or (iv) supports software on behalf of others."

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 8, page 7, line 36, at end insert – "(1A) In paragraph (1), after “engine;” insert- "(ba) software or a digital platform;”."

Baroness Kidron (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 9, page 8, line 24, after “EC” insert “, unless the Information Commission determines that the person's provision of the relevant service poses a risk to public safety, national security, or the security of network and information systems relied on for the carrying on of essential activities that is disproportionate to the size of the person”

Baroness Morgan of Cotes (None)
Baroness Kidron (XB)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was No Decision

After Clause 21, insert the following new Clause– "Liability of senior executives After regulation 18 of the NIS Regulations insert– "Liability of senior executives 18A.-(1) This regulation applies where a designated competent authority or the Information Commission has reasonable grounds to believe that – (a) a person that is a body corporate, a partnership (including a Scottish partnership) or an unincorporated body has failed to comply with a duty referred to in regulation 17(1), (2), (2ZA) or (2ZB), and (b) the failure was committed with the consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly. (2) The competent authority or the Information Commission may serve a notice of intention to impose a penalty on the senior executive(s) if it considers that a penalty is warranted having regard to the facts and circumstances of the case. (3) Before serving a senior executive(s) notice, the authority or the Information Commission must inform the senior executive(s), in such form and manner as it considers appropriate having regard to the facts and circumstances of the case, of- (a) the alleged failure and the office's alleged consent, connivance or neglect, and (b) how and by when representations may be made in relation to the alleged failure and any related matters. (4) A senior executive(s) notice must be in writing and must specify the following- (a) the reasons for serving the notice; (b) the alleged failure or failures and the senior executive(s) alleged consent, connivance, neglect or carelessness which are the subject of the notice; (c) any remedial actions required; (d) the amount of the penalty and the number of penalties which the authority or the Information Commission is minded to impose. (5) The authority or the Information Commission may, after considering any representations made in accordance with paragraph (3)(b), serve a penalty notice on the officer with a final penalty decision if satisfied that a penalty is warranted having regard to the facts and circumstances of the case. (6) A penalty imposed under this regulation must be of an amount which the authority or the Information Commission determines is appropriate and proportionate in the circumstances, having regard to the matters mentioned in regulation 18(6) for each infringement individually. (7) If the authority or the Information Commission is satisfied that no further action is required, having considered any representations submitted in accordance with paragraph (3)(b), it must inform the senior executive(s) in writing as soon as reasonably practicable. (8) In this regulation “senior executive(s)”— (a) in relation to a body corporate, means a CEO, director, manager, secretary or other similar senior executive of the body, or a person purporting to act in any such capacity; (b) in relation to a partnership, means a partner or a person having control or management of the partnership business, or a person purporting to act in any such capacity; (c) in relation to an unincorporated body other than a partnership, means a member of its governing body, or a person purporting to act in any such capacity."

Baroness Kidron (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 23, insert the following new Clause– "Red lines on AI products and services (1) Al products and services which are classified as “relevant digital services” for the purposes of the NIS Regulations must demonstrate they are not capable of performing capabilities that cross “red lines” as defined in subsection (2). (2) The red lines referred to in subsection (1) are— (a) evading human oversight or shutdown or resisting any action that, at a given level of confidence, compromises the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, network and information systems, (b) autonomously self-replicating, self-improving, or acquiring compute or other resources to the extent that this presents a risk to the authenticity and integrity of the processed data held within the system, (c) autonomously conducting or substantially accelerating sophisticated attacks on critical infrastructure, including government, security, services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (d) providing support for the development of chemical, biological, radiological, or nuclear weapons by non-state actors or hostile states to facilitate attacks on critical infrastructure, including government, security, services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (e) providing support for attacks conducted by terrorist groups and hostile actors to facilitate attacks on critical infrastructure, including government, security, services, policing, health services, education services, banking and finance, public utilities, food and water, and any other relevant network and information system, (f) deceiving or manipulating populations at scale or compromising confidence in a network and information system's ability to resist any action that compromises the availability, authenticity, integrity or confidentiality of the services offered by those systems, (g) other capabilities which are found to compromise, at a given level of confidence, the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, those network and information systems. (3) In order to demonstrate successfully that the product or service is not capable of performing capabilities that cross the “red lines” as defined in subsection (2) the Al product or service classified as a “relevant digital service” for the purposes of the NIS Regulations must be assessed and approved by the Artificial Intelligence Security Institute before it is made available within the United Kingdom. (4) In this section, “relevant network and information system” means a network and information system belonging to - (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 24, page 51, line 15, at end insert- "(3A) In specifying an activity for the purposes of subsection (3), the Secretary of State must consider any recommendations they receive from the Office for Cyber Resilience."

Lord Birt (XB)
Lord Londesborough (XB)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 24, page 51, line 17, leave out from “essential” to end of line 22 and insert “because it has – (a) a material economic impact, (b) a material societal impact, or (c) an impact on national security or defence.”

Baroness Northover (LD)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause– “Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify the following as essential activities - (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified.”

Baroness Northover (LD)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

After Clause 24, insert the following new Clause- “Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes— (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Baroness Kidron (XB)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was No Decision

After Clause 29, insert the following new Clause- ""Last-resort” powers in respect of data centres and AI models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of – (a) data centres, or (b) AI systems deployed on a substantial scale, in the event of an AI security or operational emergency. (1A) For the purposes of this section – "data centre" has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); "AI system” means a machine-based system that, from the input it receives, can infer how to - (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "deployment on a substantial scale” means AI systems made available to – (a) a substantial number of individuals within the United Kingdom, or (b) providers and operators of essential service; “AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an AI system operating from data centres or deployed on a substantial scale, whether through autonomous or non-autonomous means, and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to- (a) large-scale disruption to critical infrastructure or essential services, (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom, or (c) severe, large-scale harm to human life; “data centre operator” means a person who operates a data centre; "AI provider" means a person who deploys one or more AI systems on a substantial scale. (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the directions and the reasons for it, and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of AI systems, and on AI providers, including relating to - (a) the possession or installation of technical infrastructure necessary for those operators or providers to be able to comply with last-resort powers, (b) the provision by those operators or providers of secure communication channels for use by the Secretary of State when utilising last-resort powers, (c) the implementation by those operators or providers of regular emergency exercises to ensure that a direction under this section can be received safely and implemented, and (d) post-mortem processes to be followed by those operators or providers before a data centre operator or an Al provider is allowed to resume operations after the use of last-resort powers, including - (i) incident reporting, and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if - (a) the person is a data centre operator and fails to comply with any requirement imposed on data centre operators by regulations made under subsection (4), or (b) the person is an AI provider and fails to comply with any requirement imposed on AI providers by regulations made under subsection (4). (6) A person guilty of an offence under subsection (5) is liable – (a) on conviction on indictment, to imprisonment for a term not exceeding 2 years or a fine (or both); (b) on summary conviction, to imprisonment for a term not exceeding 6 months or a fine (or both). (7) Regulations relating to last-resort powers may (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to– (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (8) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must- (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable, and (b) inform the operator or provider of their right to apply to the High Court for relief. (9) The High Court may make any order it thinks fit on an application under subsection (7)(b), including – (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (10) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (11) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (12) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament. (13) The report must include (in particular) consideration of - (a) adversarial uses of AI systems by state and non-state actors, (b) the capabilities for cyber-attacks by autonomous AI systems, and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability (including systems described as “superintelligent AI")."

Lord Birt (XB)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience (1) Within 12 months of the day on which this Act is passed, the Secretary of State must establish the Office for Cyber Resilience (OCR). (2) The OCR is to be- (a) the single regulatory authority for the purposes of this Act, (b) the single designated competent authority for the purposes of the NIS Regulations, and (c) the NIS enforcement authority, including for the purposes of imposing penalties on relevant bodies under Regulation 18 of those Regulations. (3) The functions and powers of the OCR are to- (a) ensure that the security and resilience of the network and information systems of relevant bodies is effective and audited; (b) define and update security and resilience standards for network and information systems of relevant bodies, including for responding to incidents and for business continuity planning; (c) require relevant bodies to adjust to threats to network and information systems from new and emerging technologies; (d) impose fines on relevant bodies in serious breach of their obligations under the NIS Regulations in line with Regulation 18 (penalties); (e) share knowledge of threats and work in partnership with the National Cyber Security Centre; (f) recommend to the Secretary of State activities to be specified as an “essential activity". (4) In this section- "relevant body" means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The Secretary of State must by regulations – (a) provide for the transfer to the OCR of the functions of – (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment."

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience: software and platform providers (1) The OCR must establish and maintain a register of software and platform providers permitted to supply network and information system services as a relevant digital service provider in the United Kingdom to operators of essential services. (2) The OCR must require registered software and platform providers- (a) to certify their products as safe when used as directed, and (b) to inform the OCR and all affected customers within 24 hours of the discovery of a new vulnerability or breach affecting network or information services. (3) The OCR must not include in its register any software or platform providers which also supply cyber resilience audit services."

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause- "Office for Cyber Resilience: cyber resilience professionals (1) The OCR must work with the UK Cyber Security Council to – (a) ensure that relevant bodies have sufficient and appropriately qualified cyber security professionals, and (b) produce a timetable to increase the number of chartered cyber security professionals available to work on the security and resilience of network and information systems of relevant bodies. (2) In this section – "relevant bodies" means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Lord Birt (XB)
Lord Londesborough (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 21 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause – "Office for Cyber Resilience: cyber resilience audit (1) Within two years of the day of the establishment of the OCR, and every 12 months thereafter, the OCR must designate which commercial companies and public sector bodies must, from that year on, conduct an annual independent audit of the cyber security and resilience of their network and information systems (“the cyber resilience audit”). (2) The OCR may designate those companies or bodies individually or with reference to any relevant categorisation (including sector, scale, or materiality). (3) Organisations designated under subsection (1) must be – (a) relevant bodies with respect to the NIS Regulations, or (b) regulated persons within the meaning of this Chapter. (4) A “relevant body with respect to the NIS Regulations” means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (5) The results of the annual cyber resilience audit must be shared only with the company's or body's board, except where any material vulnerabilities or breaches are identified, which must be shared in confidence with the OCR."

Baroness Northover (LD)
Tabled: 21 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 42, insert the following new Clause- "Cyber security competence: functions of the UK Cyber Security Council (1) The UK Cyber Security Council is to exercise the functions in described subsection (2) and is accountable to the Secretary of State for the exercise of those functions. (2) The functions are – (a) to validate and accredit professional qualifications, standards and titles for cyber security professionals employed by regulated persons, (b) to monitor the supply of, and demand for, qualified cyber security professionals across the sectors regulated under this Act and the NIS Regulations, and (c) to audit whether, and to what extent, regulated persons employ or have access to appropriately certified cyber security professionals. (3) For the purposes of this section, “regulated person” has the same meaning as in Chapter 3 (see section 30). (4) A regulatory authority (as defined in section 24) must have regard to the information and standards provided by the Council under this section when exercising its functions. (5) The Secretary of State must by regulations made by statutory instrument make further provision about the exercise of the Council's functions under this section, including provision about its accountability for the exercise of the functions described in subsection (2). (6) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament."

14th August 2026
Amendment Paper
HL Bill 32 Running list of amendments – 14 August 2026

10

Baroness Ludford (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”


Explanatory Text

This amendment would explicitly include risks arising from fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.

14

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Moved
View the speech made in the House

Clause 9, page 9, line 13, at end insert—
“(3E) A person does not provide a managed service for the purposes of paragraph (3B) where the service provided consists only of—
(a) the provision of advice, consultancy, training or professional services that does not involve the person, or a person acting on the person’s behalf, connecting to or otherwise obtaining privileged access to the network and information systems of the customer,
(b) the development, licensing, sale or support of software, where that support does not involve ongoing privileged administrative access to the customer’s network and information systems, or
(c) the provision of a help desk or user-support service that does not include the active administration or management of the customer’s network and information systems.
(3F) In paragraph (3E), “privileged access” means access which enables the person to alter the configuration of, install software on, or exercise administrative control over, the customer’s network and information systems.”


Explanatory Text

This amendment would refine the definition of “managed service” so that non-critical advisory, software-support and help-desk activities that do not involve privileged administrative access to a customer’s systems are not drawn into the regulatory regime, ensuring the definition targets providers whose compromise would present a material risk.

79

Baroness Ludford (LD)
Tabled: 14 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Withdrawn After Debate
View the speech made in the House

After Clause 24, insert the following new Clause—
“Services to support political parties to be specified as essential activities
(1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify that an activity carried out for the primary purpose of the operation of a registered political party be an essential activity.
(2) In this section “registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.
(3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the specified activities.”


Explanatory Text

This new clause would require the Secretary of State to specify services with the primary aim to support the operation of political parties as essential activities under Part 3, bringing them within the scope of the Bill’s security and resilience regime.

87

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32-II Second marshalled list for Grand Committee
This amendment was Not Moved
View the speech made in the House

After Clause 35, insert the following new Clause—
“Office for Cyber Resilience
(1) There is to be a body corporate known as the Office for Cyber Resilience (“the OCR”).
(2) The OCR is to be—
(a) the single regulatory authority for the purposes of this Act, and
(b) the single designated competent authority for the purposes of the NIS Regulations.
(3) The Secretary of State must by regulations—
(a) provide for the transfer to the OCR of the functions of—
(i) each designated competent authority under the NIS Regulations, and
(ii) each regulatory authority designated under Chapter 1 of this Part,
(b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and
(c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment.
(4) Regulations under subsection (3) must in particular make provision about the OCR’s constitution, membership, staffing, funding, governance and accountability to Parliament.
(5) In exercising its functions the OCR must—
(a) act in a way that is proportionate, consistent, transparent and targeted only at cases in which action is needed,
(b) have regard to differences in the nature, scale and risk profile of the sectors and persons it regulates, and
(c) maintain arrangements for co-operation with the National Cyber Security Centre, the Information Commission and other relevant persons.
(6) The Secretary of State must, before the OCR assumes any function, lay before Parliament a report setting out—
(a) how the OCR will be resourced and staffed to discharge its functions across all regulated sectors, and
(b) the arrangements for maintaining sector-specific technical expertise within the OCR.”


Explanatory Text

This new clause seeks to replace the Bill’s current model of multiple sectoral regulators with a single, overarching regulator, the Office for Cyber Resilience. It requires the transfer of existing regulatory functions to the new regulator and a report to Parliament on its resourcing and technical expertise before the new regulator assumes any function.

94

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

After Clause 39, insert the following new Clause—
“Presumption of conformity with recognised standards
(1) A regulated person who demonstrates compliance with a designated standard in relation to a matter is to be presumed, in relation to that matter, to have complied with the corresponding duty under this Act or the NIS Regulations to which the designated standard relates.
(2) The Secretary of State must by regulations designate for the purposes of subsection (1) one or more internationally or nationally recognised cyber security standards or frameworks, which must include—
(a) the standard published as ISO/IEC 27001 (information security management systems), and
(b) the Cyber Essentials Plus certification scheme operated under the authority of the National Cyber Security Centre.
(3) When designating a standard the Secretary of State must specify the duty or duties under this Act or the NIS Regulations to which the presumption in subsection (1) applies.
(4) The presumption in subsection (1)—
(a) applies only to the extent that the scope of the designated standard covers the network and information systems to which the duty relates, and
(b) may be rebutted by a regulatory authority where it has reasonable grounds to believe that, despite compliance with the designated standard, the regulated person has not met the duty in question.
(5) The Secretary of State must review the designated standards at least once in every three-year period and update them to reflect current best practice.”


Explanatory Text

This new clause would create a statutory presumption of conformity so that organisations complying with recognised gold-standard frameworks such as ISO/IEC 27001 or Cyber Essentials Plus are presumed to meet the corresponding security duties, while allowing a regulator to rebut that presumption in an individual case.

95

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was Not Called
View the speech made in the House

Clause 40, page 63, line 27, leave out “5” and insert “3”


Explanatory Text

This amendment would reduce the maximum interval between the Secretary of State’s reports on the operation of the legislation from five years to three years.

96

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 42, page 65, line 36, at end insert—
“(aa) which is made under section (Office for Cyber Resilience), or”

97

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32–III Third marshalled list for Grand Committee
This amendment was No Decision

Clause 42, page 65, line 36, at end—
“(aa) which is made under section (Presumption of conformity with recognised standards), or”

164

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause—
“Computer Misuse Act 1990: statutory defence for cyber security activities
(1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.
(2) The review under subsection (1) must consider, in particular—
(a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith,
(b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and
(c) the approaches taken in other jurisdictions.
(3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out—
(a) the findings and conclusions of the review, and
(b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”


Explanatory Text

This new clause seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence under section 1 of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.

165

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause—
“Annual report on incident volumes
(1) The Secretary of State must, for each calendar year, prepare and lay before Parliament a report on the volume of incidents reported under the NIS Regulations and under regulations made under this Act during that year.
(2) A report under this section must include, so far as is consistent with national security—
(a) the number of incidents reported, broken down by regulated sector and subsector,
(b) the number of incidents reported by each description of regulated person,
(c) the number of incidents that were significant incidents, and
(d) a summary of the principal types and causes of the incidents reported.
(3) A report under this section must be laid before Parliament within four months of the end of the calendar year to which it relates.
(4) This section does not require the disclosure of information which would, in the opinion of the Secretary of State, be prejudicial to national security or which would identify a particular regulated person without its consent.”


Explanatory Text

This new clause would require the Secretary of State to report annually on the number and principal types of cyber incidents reported under the regime, complementing the three-yearly review of the legislation provided for by Lord Clement-Jones’ amendment to clause 40.

166

Baroness Ludford (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause—
“Digital Sovereignty Strategy
(1) The Secretary of State must, within 12 months of the day on which this Act is passed, publish a strategy (“the Digital Sovereignty Strategy”) setting out the Government’s approach to maintaining the security and resilience of relevant network and information systems by assessing, managing and mitigating risks—
(a) associated with foreign interference, and
(b) arising from reliance on foreign-supplied technologies.
(2) The Digital Sovereignty Strategy must—
(a) include risks associated with—
(i) hardware,
(ii) software,
(iii) supply chains, and
(iv) procurement processes;
(b) include a specific focus on the security and resilience of government digital procurement, detailing how the Government intends to reduce strategic dependencies on foreign-owned suppliers and on the hardware and software of hostile states so as to mitigate the risk of systemic disruption;
(c) include a commitment to prioritise, where appropriate, the use of secure technologies developed in the United Kingdom by United Kingdom organisations in relevant network and information systems;
(d) set out how the Government intends to address any risks identified under subsection (1), including by supporting the use of sovereign and domestic technologies or systems.
(3) The Secretary of State must review and, if necessary, revise the Digital Sovereignty Strategy at least once in every three-year period.
(4) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require the Government to publish, within 12 months, a Digital Sovereignty Strategy addressing risks from foreign interference and reliance on foreign technologies, with a specific focus on reforming government digital procurement to prioritise secure, sovereign and home-grown UK technology.

167

Baroness Ludford (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause—
“Board oversight and accountability: security and resilience of network and information systems
(1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of the arrangements relating to the security and resilience of the body’s network and information systems.
(2) In exercising that oversight, the management body must—
(a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems, and
(b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks.
(3) The management body may be held accountable for a failure by the body to comply with its duties relating to the security and resilience of its network and information systems.
(4) Members of the management body must undertake training designed to enable them to identify risks to, and assess appropriate risk-management practices for, the body’s network and information systems.
(5) For the purposes of this section, a relevant body is one which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require active board-level oversight of, and explicit accountability for, the security and resilience of a relevant body’s network and information systems, including a duty on board members to undertake relevant training, where the body is governed by a board or similar management body.

6

Baroness Kidron (XB)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 21 August 2026
This amendment was Withdrawn After Debate
View the speech made in the House

Clause 7, page 6, line 31, after “engine” insert “, an AI product or service”


Explanatory Text

This amendment probes whether the definition of “relevant digital service” being inserted into the NIS Regulations by this bill includes large language models and chatbots.

Baroness Neville-Jones (Con)
Tabled: 14 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 21, line 19, leave out “capable of having” and insert “likely to have”

Baroness Neville-Jones (Con)
Tabled: 14 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 15, page 23, line 13, leave out “could have had”

Baroness Morgan of Cotes (None)
Baroness Kidron (XB)
Baroness Ludford (LD)
Tabled: 14 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 21, insert the following new Clause – "Liability of Senior Executives (1) This regulation applies where a designated competent authority or the Information Commission has reasonable grounds to believe that – (a) a person that is a body corporate, a partnership (including a Scottish partnership) or an unincorporated body has failed to comply with a duty referred to in regulation 17(1), (2), (2ZA) or (2ZB), and (b) the failure was committed with the consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly. (2) The competent authority or the Information Commission may serve a notice of intention to impose a penalty on the senior executive(s) if it considers that a penalty is warranted having regard to the facts and circumstances of the case. (3) Before serving a senior executive(s) notice, the authority or the Information Commission must inform the senior executive(s), in such form and manner as it considers appropriate having regard to the facts and circumstances of the case, of- (a) the alleged failure and the officer's alleged consent, connivance or neglect, and (b) how and by when representations may be made in relation to the alleged failure and any related matters. (4) A senior executive(s) notice must be in writing and must specify the following- (a) the reasons for serving the notice; (b) the alleged failure or failures and the senior executive(s) alleged consent, connivance, neglect or carelessness which are the subject of the notice; (c) any remedial actions required; (d) the amount of the penalty and the number of penalties which the authority or the Information Commission is minded to impose. (5) The authority or the Information Commission may, after considering any representations made in accordance with paragraph (3)(b), serve a penalty notice on the officer with a final penalty decision if satisfied that a penalty is warranted having regard to the facts and circumstances of the case. (6) A penalty imposed under this regulation must be of an amount which the authority or the Information Commission determines is appropriate and proportionate in the circumstances, having regard to the matters mentioned in regulation 18(6) [NIS] for each infringement individually. (7) If the authority or the Information Commission is satisfied that no further action is required, having considered any representations submitted in accordance with paragraph (3)(b), it must inform the senior executive(s) in writing as soon as reasonably practicable. (8) In this regulation “senior executive(s)”— (a) in relation to a body corporate, means a CEO, director, manager, secretary or other similar senior executive of the body, or a person purporting to act in any such capacity; (b) in relation to a partnership, means a partner or a person having control or management of the partnership business, or a person purporting to act in any such capacity; (c) in relation to an unincorporated body other than a partnership, means a member of its governing body, or a person purporting to act in any such capacity."

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Baroness Kidron (XB)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 29, insert the following new Clause – ""Last-resort” powers in respect of data centres and AI models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of – (a) data centres, or (b) AI systems deployed on a substantial scale, in the event of an AI security or operational emergency. (1A) For the purposes of this section- “data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); “AI system” means a machine-based system that, from the input it receives, can infer how to - (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "deployment on a substantial scale” means AI systems made available to - (a) a substantial number of individuals within the United Kingdom, or (b) providers and operators of essential service; “AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that- (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an Al system operating from data centres or deployed on a substantial scale, whether through autonomous or non-autonomous means, and (c) this compromise poses a catastrophic risk; “catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to - (a) large-scale disruption to critical infrastructure or essential services, (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom, or (c) severe, large-scale harm to human life; "data centre operator" means a person who operates a data centre; "AI provider" means a person who deploys one or more AI systems on a substantial scale. (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the directions and the reasons for it, and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, and on AI providers, including relating to- (a) the possession or installation of technical infrastructure necessary for those operators or providers to be able to comply with last-resort powers, (b) the provision by those operators or providers of secure communication channels for use by the Secretary of State when utilising last-resort powers, (c) the implementation by those operators or providers of regular emergency exercises to ensure that a direction under this section can be received safely and implemented, and (d) post-mortem processes to be followed by those operators or providers before a data centre operator or an Al provider is allowed to resume operations after the use of last-resort powers, including - (i) incident reporting, and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if - (a) the person is a data centre operator and fails to comply with any requirement imposed on data centre operators by regulations made under subsection (4), or (b) the person is an AI provider and fails to comply with any requirement imposed on AI providers by regulations made under subsection (4). (6) A person guilty of an offence under subsection (5) is liable- (a) on conviction on indictment, to imprisonment for a term not exceeding 2 years or a fine (or both); (b) on summary conviction, to imprisonment for a term not exceeding 6 months or a fine (or both). (7) Regulations relating to last-resort powers may- (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to- (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (8) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must- (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable, and (b) inform the operator or provider of their right to apply to the High Court for relief. (9) The High Court may make any order it thinks fit on an application under subsection (7)(b), including – (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (10) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (11) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (12) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament. (13) The report must include (in particular) consideration of – (a) adversarial uses of AI systems by state and non-state actors, (b) the capabilities for cyber-attacks by autonomous AI systems, and (c) the development of AI systems that can autonomously compromise national security, escape human oversight, and upend international stability (including systems described as “superintelligent AI”).”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 14 Aug 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 37, insert the following new Clause- “Consultation before issue of codes of practice and regulations (1) Before preparing, issuing, amending or revising a code of practice under this Chapter, the Secretary of State must carry out an open public consultation. (2) Before making regulations under section 24 or Chapter 3 of this Part, or giving a direction under Part 4 that applies to a description of regulated persons generally, the Secretary of State must carry out an open public consultation. (3) A consultation under this section must- (a) be open to any person providing, or proposing to provide, services of a kind regulated under this Act or the NIS Regulations, and to any other interested person, (b) be published in a manner that is readily accessible, including to small and medium-sized enterprises, (c) last for a period of not less than eight weeks, except where the Secretary of State reasonably considers that a shorter period is justified by urgency and publishes the reasons for that decision, and (d) invite representations on the likely costs, benefits and practical effects of the proposal. (4) The Secretary of State must publish a response to the consultation, setting out how the representations received have been taken into account, before the code of practice, regulations or direction take effect. (5) This section does not apply to a direction given under Part 4 in respect of a specific regulated person for national security purposes.”

Baroness Northover (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 14 August 2026
This amendment was No Decision

After Clause 42, insert the following new Clause – "Critical manufacturing and retail to be specified as essential activities (1) The Secretary of State must, within six months of the passing of this Act, make regulations under section 24(3) to specify the following as essential activities – (a) the manufacture of critical transport equipment, including the manufacture of vehicles, (b) the industrial production and processing of food products, and (c) the retail sale of food and essential goods through large-scale distribution chains. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the activities so specified."

Baroness Northover (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 14 August 2026
This amendment was No Decision

After Clause 42, insert the following new Clause– "Space sector to be specified as an essential activity (1) The Secretary of State must, within six months of the passing of this Act, make regulations under section 24(3) to specify activities carried on in the space sector as essential activities. (2) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the space sector. (3) In this section, “the space sector” means the sector identified as the space sector in the Government's Industrial Strategy, and includes- (a) the manufacture of satellites, launch vehicles and ground systems, (b) the provision of launch and in-orbit services, (c) the operation of satellites and satellite constellations, and (d) the provision of satellite-based services, including position, navigation and timing services and satellite communications."

Baroness Northover (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 24 August 2026
This amendment was No Decision

After Clause 42, insert the following new Clause- "Cyber security competence: functions of the UK Cyber Security Council (1) The UK Cyber Security Council is to exercise the functions in subsection (2) and is accountable to the Secretary of State. (2) The functions are– (a) to validate and accredit professional qualifications, standards and titles for cyber security professionals employed by regulated persons, (b) to monitor the supply of, and demand for, qualified cyber security professionals across the sectors regulated under this Act and the NIS Regulations, and (c) to audit whether, and to what extent, regulated persons employ or have access to appropriately certified cyber security professionals. (3) A regulatory authority must have regard to the information and standards provided by the Council under this section when exercising its functions. (4) The Secretary of State must by regulations make further provision about the exercise of the Council's functions under this section, including provision about its governance, funding and accountability. (5) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament."

Baroness Northover (LD)
Tabled: 14 Aug 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 42, insert the following new Clause – “National cyber security support service for small and medium-sized enterprises (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a national cyber security support and incident response service for relevant small and medium-sized enterprises (SMEs), for the purpose of improving the security and resilience of their network and information systems. (2) The service established under this section must— (a) be free at the point of use, and (b) provide, in particular following a cyber incident affecting a relevant SME — (i) advice and technical assistance, (ii) incident response support, and (iii) guidance on recovery and remediation. (3) For the purposes of this section, a relevant SME is a small or medium-sized enterprise which is – (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (4) In establishing and operating the service the Secretary of State must have regard to comparable national cyber security support services operated in other jurisdictions."

23rd July 2026
Amendment Paper
HL Bill 32 Running list of amendments – 23 July 2026
Baroness Kidron (XB)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 23 Jul 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 7, page 6, line 31, after “engine” insert “, an AI product or service”

22nd July 2026
Amendment Paper
HL Bill 32 Running list of amendments – 22 July 2026
Baroness Ludford (LD)
Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 8, page 7, line 36, at end insert— “(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

Clause 9, page 9, line 13, at end insert— “(3E) A person does not provide a managed service for the purposes of paragraph (3B) where the service provided consists only of— (a) the provision of advice, consultancy, training or professional services that does not involve the person, or a person acting on the person’s behalf, connecting to or otherwise obtaining privileged access to the network and information systems of the customer, (b) the development, licensing, sale or support of software, where that support does not involve ongoing privileged administrative access to the customer’s network and information systems, or (c) the provision of a help desk or user-support service that does not include the active administration or management of the customer’s network and information systems. (3F) In paragraph (3E), “privileged access” means access which enables the person to alter the configuration of, install software on, or exercise administrative control over, the customer’s network and information systems.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32-I Marshalled list for Grand Committee
This amendment was No Decision

After Clause 24, insert the following new Clause— “Services to support political parties to be specified as essential activities (1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify that an activity carried out for the primary purpose of the operation of a registered political party be an essential activity. (2) In this section “registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000. (3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the specified activities.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

After Clause 35, insert the following new Clause— “Office for Cyber Resilience (1) There is to be a body corporate known as the Office for Cyber Resilience (“the OCR”). (2) The OCR is to be— (a) the single regulatory authority for the purposes of this Act, and (b) the single designated competent authority for the purposes of the NIS Regulations. (3) The Secretary of State must by regulations— (a) provide for the transfer to the OCR of the functions of— (i) each designated competent authority under the NIS Regulations, and (ii) each regulatory authority designated under Chapter 1 of this Part, (b) make provision for the OCR to exercise those functions in place of the authorities mentioned in paragraph (a), and (c) make such transitional, transitory, saving, consequential and supplementary provision as the Secretary of State considers appropriate in connection with the establishment of the OCR, including provision amending this Act, the NIS Regulations or any other enactment. (4) Regulations under subsection (3) must in particular make provision about the OCR’s constitution, membership, staffing, funding, governance and accountability to Parliament. (5) In exercising its functions the OCR must— (a) act in a way that is proportionate, consistent, transparent and targeted only at cases in which action is needed, (b) have regard to differences in the nature, scale and risk profile of the sectors and persons it regulates, and (c) maintain arrangements for co-operation with the National Cyber Security Centre, the Information Commission and other relevant persons. (6) The Secretary of State must, before the OCR assumes any function, lay before Parliament a report setting out— (a) how the OCR will be resourced and staffed to discharge its functions across all regulated sectors, and (b) the arrangements for maintaining sector-specific technical expertise within the OCR.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

After Clause 37, insert the following new Clause— “Consultation before issue of codes of practice and regulations (1) Before preparing, issuing, amending or revising a code of practice under Chapter 4 of this Part, the Secretary of State must carry out an open public consultation. (2) Before making regulations under section 24 or Chapter 3 of this Part, or giving a direction under Part 4 that applies to a description of regulated persons generally, the Secretary of State must carry out an open public consultation. (3) A consultation under this section must— (a) be open to any person providing, or proposing to provide, services of a kind regulated under this Act or the NIS Regulations, and to any other interested person, (b) be published in a manner that is readily accessible, including to small and medium-sized enterprises, (c) last for a period of not less than eight weeks, except where the Secretary of State reasonably considers that a shorter period is justified by urgency and publishes the reasons for that decision, and (d) invite representations on the likely costs, benefits and practical effects of the proposal. (4) The Secretary of State must publish a response to the consultation, setting out how the representations received have been taken into account, before the code of practice, regulations or direction take effect. (5) This section does not apply to a direction given under Part 4 in respect of a specific regulated person for national security purposes.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

After Clause 39, insert the following new Clause— “Presumption of conformity with recognised standards (1) A regulated person who demonstrates compliance with a designated standard in relation to a matter is to be presumed, in relation to that matter, to have complied with the corresponding duty under this Act or the NIS Regulations to which the designated standard relates. (2) The Secretary of State must by regulations designate for the purposes of subsection (1) one or more internationally or nationally recognised cyber security standards or frameworks, which must include— (a) the standard published as ISO/IEC 27001 (information security management systems), and (b) the Cyber Essentials Plus certification scheme operated under the authority of the National Cyber Security Centre. (3) When designating a standard the Secretary of State must specify the duty or duties under this Act or the NIS Regulations to which the presumption in subsection (1) applies. (4) The presumption in subsection (1)— (a) applies only to the extent that the scope of the designated standard covers the network and information systems to which the duty relates, and (b) may be rebutted by a regulatory authority where it has reasonable grounds to believe that, despite compliance with the designated standard, the regulated person has not met the duty in question. (5) The Secretary of State must review the designated standards at least once in every three-year period and update them to reflect current best practice.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Clause 40, page 63, line 27, leave out “5” and insert “3”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Clause 42, page 65, line 36, at end insert— “(aa) which is made under section (Office for Cyber Resilience), or”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 25 August 2026
This amendment was No Decision

Clause 42, page 65, line 36, at end— “(aa) which is made under section (Presumption of conformity with recognised standards), or”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Computer Misuse Act 1990: statutory defence for cyber security activities (1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities. (2) The review under subsection (1) must consider, in particular— (a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith, (b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and (c) the approaches taken in other jurisdictions. (3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out— (a) the findings and conclusions of the review, and (b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”

Lord Clement-Jones (LD) - Liberal Democrat Lords Spokesperson (Science, Innovation and Technology)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Annual report on incident volumes (1) The Secretary of State must, for each calendar year, prepare and lay before Parliament a report on the volume of incidents reported under the NIS Regulations and under regulations made under this Act during that year. (2) A report under this section must include, so far as is consistent with national security— (a) the number of incidents reported, broken down by regulated sector and subsector, (b) the number of incidents reported by each description of regulated person, (c) the number of incidents that were significant incidents, and (d) a summary of the principal types and causes of the incidents reported. (3) A report under this section must be laid before Parliament within four months of the end of the calendar year to which it relates. (4) This section does not require the disclosure of information which would, in the opinion of the Secretary of State, be prejudicial to national security or which would identify a particular regulated person without its consent.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Digital Sovereignty Strategy (1) The Secretary of State must, within 12 months of the day on which this Act is passed, publish a strategy (“the Digital Sovereignty Strategy”) setting out the Government’s approach to maintaining the security and resilience of relevant network and information systems by assessing, managing and mitigating risks— (a) associated with foreign interference, and (b) arising from reliance on foreign-supplied technologies. (2) The Digital Sovereignty Strategy must— (a) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on the security and resilience of government digital procurement, detailing how the Government intends to reduce strategic dependencies on foreign-owned suppliers and on the hardware and software of hostile states so as to mitigate the risk of systemic disruption; (c) include a commitment to prioritise, where appropriate, the use of secure technologies developed in the United Kingdom by United Kingdom organisations in relevant network and information systems; (d) set out how the Government intends to address any risks identified under subsection (1), including by supporting the use of sovereign and domestic technologies or systems. (3) The Secretary of State must review and, if necessary, revise the Digital Sovereignty Strategy at least once in every three-year period. (4) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

Baroness Ludford (LD)
Tabled: 22 Jul 2026
HL Bill 32 Running list of amendments – 26 August 2026
This amendment was No Decision

After Clause 58, insert the following new Clause— “Board oversight and accountability: security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of the arrangements relating to the security and resilience of the body’s network and information systems. (2) In exercising that oversight, the management body must— (a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems, and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for a failure by the body to comply with its duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks to, and assess appropriate risk-management practices for, the body’s network and information systems. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

14th July 2026
2nd reading: Minutes of Proceedings (Lords)
14th July 2026
2nd reading (Lords)
1st July 2026
Select Committee report
3rd Report from the Select Committee on the Constitution
23rd June 2026
Briefing papers
Cyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026–27
19th June 2026
Delegated Powers Memorandum
Delegated Powers Memorandum
17th June 2026
Bill
HL Bill 32 (as brought from the Commons)
17th June 2026
1st reading: Minutes of Proceedings (Lords)
17th June 2026
1st reading (Lords)
17th June 2026
Explanatory Notes
HL Bill 32 Explanatory Notes
17th June 2026
Keeling schedules
Keeling text (schedules) prepared by the Department for Science, Innovation and Technology to show changes to the Network and Information Systems Regulations 2018 proposed by the Bill as introduced to the House of Lords on 17 June 2026
16th June 2026
3rd reading (Commons)
16th June 2026
Report stage (Commons)
16th June 2026
Amendment Paper
Consideration of Bill Amendments as at 16 June 2025
16th June 2026
Bill proceedings: Commons
Report Stage Proceedings as at 16 June 2026
16th June 2026
Selection of amendments: Commons
Speaker’s provisional grouping and selection of Amendments
15th June 2026
Amendment Paper
Notices of Amendments as at 15 June 2026
12th June 2026
Amendment Paper
Notices of Amendments as at 12 June 2026
11th June 2026
Amendment Paper
Notices of Amendments as at 11 June 2026

NC21

Matt Western (Lab)
Iqbal Mohamed (Ind)
Tabled: 11 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Food supply chain to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— “Food supply Food supply chain The Secretary of State for Environment, Food and Rural Affairs (United Kingdom)” (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert— “The food supply chain subsector 12 — (1) This paragraph describes the threshold requirements which apply to essential services in the food supply chain subsector. (2) For the essential service of the food supply chain in the United Kingdom the threshold requirement is that the person is in the food supply chain and does not qualify as small or a micro-entity (or is excluded) within the meaning of Part 15 of the Companies Act 2006. (3) For the purposes of this paragraph— (a) a “food supply chain” is a supply chain for providing individuals with items of food or drink for personal consumption, where the items consist of or include, or have been produced to any extent using— (i) anything grown or otherwise produced in carrying on agriculture, or (ii) anything taken, grown or otherwise produced in carrying on fishing or aquaculture; (b) a person is “in” a food supply chain if that person is a producer or an intermediary in a food supply chain. (4) In paragraph (3)(b)— (a) “producer” means a person who is carrying on agriculture, fishing or aquaculture; (b) “intermediary” means a person in the food supply chain between a producer and the individuals referred to in paragraph (3)(a). (5) In this paragraph— “agriculture” includes any growing of plants, and any keeping of animals, for the production of food or drink; “aquaculture” means the breeding, rearing, growing or cultivation of— (a) any fish or other aquatic animal, (b) seaweed or any other aquatic plant, or (c) any other aquatic organism. “plants” includes fungi. (6) In regulation 8A of the NIS Regulations (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert— “(c) provides an essential service of a kind referred to in paragraph 12 of Schedule 2 (food supply chain sector) within the United Kingdom.””

28

Matt Western (Lab)
Iqbal Mohamed (Ind)
Tabled: 11 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

Clause 10, page 9, line 33, at end insert— “(2A) The measures taken by an RMSP under paragraph (1) must ensure that the number of customers to whom the RMSP provides services does not exceed the critical risk threshold. (2B) In paragraph (2A), the “critical risk threshold” is the number of customers within a sector or subsector where an incident affecting the provision of services to those customers by the RMSP would result in disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom. (2C) Paragraph (2D) applies where the number of customers to whom an RMSP provides services exceeds the critical risk threshold by virtue of contracts entered into before the coming into force of section 10 of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (2D) The RMSP must take steps to reduce the number of customers to below the critical risk threshold, including exercising any right to terminate a contract or vary the terms of a contract.”

10th June 2026
Amendment Paper
Notices of Amendments as at 10 June 2026

NC19

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Review of risks posed by foreign state ownership or control of providers of cellular Internet of Things modules (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by foreign state ownership or control of providers of cellular Internet of Things modules. (2) For the purposes of this section– “cellular Internet of Things modules” means devices that communicate over public mobile networks for the purposes of enabling autonomous machine to machine communication;”

NC20

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause— “Specification of retail commerce as an essential activity (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify as an essential activity retail commerce carried out by companies with an annual turnover in excess of £12 billion. (2) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector.”

7

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 38, line 33, leave out first “and” and insert “or”

8

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 38, line 35, leave out “and” and insert “or”

9

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 39, leave out lines 15 to 17

10

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 39, line 42, leave out from “paragraph (1)” to end of line 2 on page 40

11

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 12, leave out “(1)(c)” and insert “(1)(b)”

12

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 24, leave out from “regulation 6(1)” to “, or” in line 26

13

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 40, line 31, leave out from “regulation 6(1)” to end of line 33

14

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 41, line 4, at end insert— “(4A) A disclosure of information under any provision of regulation 6 or this regulation must be limited to information which is relevant and proportionate to the purpose for which the disclosure is being made.”

15

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 18, page 41, line 23, at end insert— “(1A) A disclosure of information under paragraph (1) must be limited to information which is relevant and proportionate to the purpose for which the disclosure is being made.”

16

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 20, page 44, line 15, at end insert— “(da) assesing the security or resilience of network and information systems relied on by a person regulated by the designated competent authority; (db) establishing whether any incident has occurred that the designated competent authority believes could have had, has had, is having or is likely to have, an adverse effect on the security or resilience of network and information systems relied on by a person regulated by the authority, and the nature and impact of any such incident; (dc) assessing the implementation of measures taken under regulation 10 to manage risks and to prevent and minimise the impact of incidents, including as a result of any inspection conducted under regulation 16; (dd) identifying a failure of a person to comply with any duty imposed by these Regulations;”

17

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 20, page 44, line 28, at end insert— “(da) assessing the security or resilience of network and information systems relied on by a person regulated by the Information Commission; (db) establishing whether any incident has occurred that the Information Commission believes could have had, has had, is having or is likely to have, an adverse effect on the security or resilience of network and information systems relied on by a person regulated by the Commission, and the nature and impact of any such incident; (dc) assessing the implementation of measures taken under regulation 12 or 14B to manage risks and to prevent and minimise the impact of incidents, including as a result of any inspection conducted under regulation 16; (dd) identifying a failure of a person to comply with any duty imposed by these Regulations;”

18

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 16, leave out “or notice” and insert “, notice, notification or decision”

19

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 20, at end insert— “(1A) Where a regulated person has— (a) appointed a representative to act on their behalf, and (b) notified a regulatory authority of the appointment, a direction, notice, notification or decision under this Part may be given to that representative instead of the regulated person, by any of the methods mentioned in subsection (1). (1B) Any direction, notice, notification or decision given to a representative by virtue of subsection (1A) is to be treated as having been given to the regulated person.”

20

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 22, leave out “or notice” and insert “, notice, notification or decision”

21

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 23, leave out “or notice” and insert “, notice, notification or decision”

22

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 25, leave out “or notice” and insert “, notice, notification or decision”

23

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 82, line 28, leave out “or notice” and insert “, notice, notification or decision”

24

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 5, leave out “or notice” and insert “, notice, notification or decision”

25

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 14, leave out “or notice” and insert “, notice, notification or decision”

26

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Clause 57, page 83, line 17, leave out “or notice” and insert “, notice, notification or decision”

27

Liz Kendall (Lab) - Secretary of State for Science, Innovation and Technology
Tabled: 10 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Agreed To

Schedule 1, page 90, line 3, after “sub-paragraph (e)” insert “(including the “or” at the end)”

4th June 2026
Amendment Paper
Notices of Amendments as at 4 June 2026

NC17

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Withdrawn

To move the following Clause—"Specification of retail commerce carried out by UK-owned companies as an essential activity (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify retail commerce carried out by UK-owned companies as an essential activity. (2) For the purposes of this section, “UK owned companies” means companies incorporated in the United Kingdom and not controlled by non UK persons or entities. (3) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector."

NC18

Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Graeme Downie (Lab)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

To move the following Clause—"Review of the number of bodies providing cloud computing services (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services. (2) For the purposes of this section, “cloud computing services” has the meaning given in paragraph 1 of the NIS Regulations."

6

Iqbal Mohamed (Ind)
Neil Duncan-Jordan (Lab)
Tabled: 4 Jun 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Called

Clause 18, page 40, line 12, at end insert—"(8A) Where the CSIRT receives notification of an incident under regulation 11, 11A, 12A or 14E which it considers to materially involve autonomous or adaptive systems based on machine learning, the CSIRT must share relevant technical information with the relevant body within 72 hours. (8B) For the purposes of this regulation, a “relevant body” means the Al Security Institute or any successor or replacement body designated by the Secretary of State."

22nd May 2026
Amendment Paper
Notices of Amendments as at 22 May 2026
20th May 2026
Amendment Paper
Notices of Amendments as at 20 May 2026

4

Graeme Downie (Lab)
Luke Akehurst (Lab)
Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Christine Jardine (LD)
Tabled: 20 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 29, page 54, line 9, at end insert “, including the risks arising from the use of embedded communications components manufactured outside the UK;

5

Graeme Downie (Lab)
Luke Akehurst (Lab)
Chi Onwurah (Lab) - Shadow Minister (Business, Energy and Industrial Strategy)
Christine Jardine (LD)
Tabled: 20 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 43, page 66, line 18, at end insert—"(i) a requirement relating to embedded communications components manufactured outside the UK."

19th May 2026
Amendment Paper
Notices of Amendments as at 19 May 2026
15th May 2026
Amendment Paper
Notices of Amendments as at 15 May 2026

NC2

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Withdrawn After Debate
View the speech made in the House

To move the following Clause—"Cyber security support service for SMEs (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems. (2) For the purposes of this section, a relevant SME is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A support service established under this section must provide- (a) advice and technical assistance to SMEs following a cyber incident; and (b) guidance on recovery and remediation."

NC3

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Review of high-risk bodies (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies. (2) A review under this section must assess- (a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise; (b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and (c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities. (3) In this section—"relevant body" means- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. "foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest; "network and information systems" has the meaning given by section 24(1)."

NC5

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Critical manufacturing and retail sectors (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities- (a) the manufacture of critical transport equipment; (b) the industrial production and processing of food products; and (c) the retail sale of food and essential goods via large-scale distribution chains. (2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors."

NC4

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Local authorities to be regulated as essential services (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—"Local Government Local Government The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The Local Government Sector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector. (2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register. (3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records. (4) In this paragraph "local authority means"— (a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly; (b) in Wales, a county council or a county borough council; (c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994; (d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.""

NC6

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Computer Misuse Act 1990: security and resilience of network and information systems (1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities. (2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines— (a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review; (b) the review's conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and (c) the Government's intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”

NC7

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Consultation on resourcing of regulatory authorities and regulated persons (1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing- (a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and (b) whether further government support is needed. (2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1)"

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Electoral infrastructure to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—"Elections Electoral infrastructure The Electoral Commission" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The electoral infrastructure subsector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector. (2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to- (a) maintain a register of electors containing more than 50,000 entries; (b) issue, receive, or process postal ballots for a parliamentary or local government election; or (c) count or aggregate votes cast in a parliamentary, mayoral or local government election. (3) In this paragraph—"parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom; "network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—"(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.""

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Political parties to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—"Government Political parties The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—"The political parties subsector 12— (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector. (2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons. (3) In this paragraph—"registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.""

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Board oversight of security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body's network and information systems. (2) In exercising oversight, the management body must- (a) approve the approach taken by the body to the management of risks to the security and resilience of the body's network and information systems; and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Requirement for regular testing of network and information systems (1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services. (2) Testing undertaken in accordance with this section must- (a) be proportionate, having regard to the size, nature and risk profile of the business; and (b) be conducted periodically, at intervals that are appropriate to the risks identified by the body. (3) A relevant body must document- (a) the outcomes of testing undertaken in accordance with this section; and (b) any remedial actions required or taken in response to the testing. (4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC12

Alex Sobel (Lab)
Brian Leishman (Lab)
John Whitby (Lab)
Samantha Niblett (Lab)
Neil Duncan-Jordan (Lab)
Dawn Butler (Lab)
Chris Bloore (Lab)
John McDonnell (Lab)
Ben Lake (PC)
George Freeman (Con)
Desmond Swayne (Con)
Iqbal Mohamed (Ind)
Melanie Ward (Lab)
Jess Asato (Lab)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—""Last-resort" powers in respect of data centres and Al models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of- (a) data centres, or (b) Al systems used or deployed by a data centre, in the event of an Al security or operational emergency. (2) For the purposes of this section—"data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); "Al system" means a machine-based system that, from the input it receives, can infer how to- (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "used or deployed” means made available to— (a) a substantial number of individuals within the United Kingdom; or (b) providers and operators of essential services; "Al security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an Al system used or deployed by a data centre, whether through autonomous or non-autonomous means; and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to- (a) large-scale disruption to critical infrastructure or essential services; (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or (c) severe, large-scale harm to human life; "data centre operator” means a person who operates a data centre; (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the direction and the reasons for it; and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, including relating to- (a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers; (b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers; (c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and (d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including- (i) incident reporting; and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4). (6) Regulations relating to last-resort powers may- (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to— (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must— (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and (b) inform the operator or provider of their right to apply to the High Court for relief. (8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including- (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of Al security or operational emergencies and lay a copy of the report before Parliament. (12) The causes and potential causes of Al security or operational emergencies considered in any report under subsection (11) must include- (a) adversarial uses of Al systems by state and non-state actors; (b) the capabilities for cyber-attacks by autonomous Al systems; and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent Al”.”

NC13

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Iqbal Mohamed (Ind)
Caroline Voaden (LD) - Liberal Democrat Spokesperson (Schools)
Steve Darling (LD) - Liberal Democrat Spokesperson (Work and Pensions)
Mike Martin (LD)
Vikki Slade (LD)
Lisa Smart (LD) - Liberal Democrat Spokesperson (Cabinet Office)
Danny Chambers (LD) - Liberal Democrat Spokesperson (Mental Health)
Ian Sollom (LD) - Liberal Democrat Spokesperson (Universities and Skills)
Adrian Ramsay (Green) - Green Spokesperson (Treasury)
Liz Jarvis (LD)
Adam Dance (LD)
Cameron Thomas (LD)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Sarah Olney (LD) - Liberal Democrat Spokesperson (Business)
Pippa Heylings (LD) - Liberal Democrat Spokesperson (Energy Security and Net Zero)
Steff Aquarone (LD)
Bobby Dean (LD) - Liberal Democrat Shadow Leader of the House of Commons
Clive Lewis (Lab)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

To move the following Clause—"Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies (1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy ("a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by- (a) assessing, managing and mitigating risks— (i) associated with foreign interference, (ii) arising from reliance on foreign-supplied technologies, and (b) preventing over-reliance on foreign providers by building domestic capacity. (2) For the purposes of this section, a “relevant network and information system" is a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A Digital Sovereignty Strategy published under this section must— (a) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption; (c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and (d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems."

NC14

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Alison Griffiths (Con)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

To move the following Clause—"Register of foreign powers for the purposes of Part 4 (1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom's critical network and information systems. (2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups. (3) Regulations under this section are subject to the affirmative resolution procedure. (4) In this section, “foreign power” means— (a) the sovereign or other head of a foreign state in their public capacity; (b) a foreign government, or part of a foreign government; (c) an agency or authority of a foreign government, or of part of a foreign government; (d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or (e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government- (i) hold those posts as a result of, or in the course of, their membership of the party, or (ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”

NC15

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Alison Griffiths (Con)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Review of the cyber security risk posed by foreign powers (1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers. (2) A review under this section must identify whether any risk arises from— (a) activities undertaken outside of the UK, or (b) foreign owned or controlled infrastructure or locations within the UK. (3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups. (4) Within three months of each review under subsection (1), the Secretary of State must- (a) lay before Parliament a report containing the findings and conclusions of the review; and (b) where information is not included in a report on the grounds of being prejudicial to the UK's national security, send such information to the Intelligence and Security Committee of Parliament.”

NC16

Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

To move the following Clause—"Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy ("the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to— (i) dependence on hardware, software, or digital services that may be subject to foreign interference; (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers; (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities; (b) technological developments, market concentration, or strategic dependencies that may affect the security and resilience of relevant network and information systems; (c) set out the Government's approach to mitigating the risks identified under subsection (2); and (d) include an assessment of- (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems; (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems; (iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems; (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems; (v) options for international collaboration in the production of open source components used in relevant network and information systems; (vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (5) In this section—"relevant network and information system” means a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the Network and Information Systems Regulations 2018; "digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access and control over the hardware, software, data, and digital services on which relevant network and information systems depend; "open source” has the meaning given to it in the definition published by the Open Source Initiative.”

1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Not Moved

Clause 8, page 7, line 36, at end insert—"(1A) In paragraph (1), after "risks” insert “, including risks arising from fraud,””

3

Iain Duncan Smith (Con)
Sarah Owen (Lab)
Alex Sobel (Lab)
Rachael Maskell (Lab)
Marie Rimmer (Lab)
Emily Darlington (Lab)
Nadia Whittome (Lab)
Mark Sewards (Lab)
Christine Jardine (LD)
Chris Law (SNP) - Shadow SNP Spokesperson (Business)
Layla Moran (LD)
Alistair Carmichael (LD)
Desmond Swayne (Con)
Charlie Dewhirst (Con)
Greg Smith (Con) - Shadow Parliamentary Under Secretary (Energy Security and Net Zero)
Julian Lewis (Con)
Bradley Thomas (Con)
Bob Blackman (Con)
Tom Tugendhat (Con)
Alicia Kearns (Con) - Opposition Whip (Commons)
Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Peter Bedford (Con)
Jack Rankin (Con)
Danny Kruger (RUK)
Tabled: 15 May 2026
Consideration of Bill Amendments as at 16 June 2025 - large print
This amendment was Negatived On Division
View the speech made in the House

Clause 18, page 41, line 15, at end insert—"Exemption from disclosure: right to a fair trial 6AB.-(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that- (a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or (b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial. (2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of— (a) subject matter experts, and (b) competent civil society groups. (3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months."

14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - xml
14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - pdf
14th May 2026
Bill
Bill 002 2026-27 (reintroduced at Report Stage) - html
14th May 2026
Bill reintroduced
14th May 2026
Impact Assessments
Impact Assessment from the Department for Science, Innovation and Technology
14th May 2026
Explanatory Notes
Bill 002 EN 2026-27 - pdf
30th April 2026
Amendment Paper
Notices of Amendments as at 30 April 2026
29th April 2026
Amendment Paper
Notices of Amendments as at 29 April 2026
28th April 2026
Amendment Paper
Notices of Amendments as at 28 April 2026
16th April 2026
Amendment Paper
Notices of Amendments as at 16 April 2026
14th April 2026
Amendment Paper
Notices of Amendments as at 14 April 2026
10th April 2026
Amendment Paper
Notices of Amendments as at 10 April 2026
27th March 2026
Amendment Paper
Notices of Amendments as at 27 March 2026

NC16

Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Tabled: 27 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Digital Sovereignty Strategy (relevant network and information systems) (1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy ("the Strategy”) in relation to relevant network and information systems. (2) The Strategy must- (a) set out the Government's assessment of the risks to relevant network and information systems arising from or related to— (i) dependence on hardware, software, or digital services that may be subject to foreign interference; (ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers; (iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities; (b) technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems; set out the Government's approach to mitigating the risks identified under subsection (2); and (c) include an assessment of- (i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems; (ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems; (iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems; (iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems; (v) options for international collaboration in the production of open source components used in relevant network and information systems; (vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems. (3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security. (4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen. (5) In this section— "relevant network and information system" means a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the Network and Information Systems Regulations 2018; "digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend; "open source” has the meaning given to it in definition published by the Open Source Initiative."

26th March 2026
Amendment Paper
Notices of Amendments as at 26 March 2026

NC14

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Register of foreign powers for the purposes of Part 4 (1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom's critical network and information systems. (2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups. (3) Regulations under this section are subject to the affirmative resolution procedure. (4) In this section, "foreign power” means— (a) the sovereign or other head of a foreign state in their public capacity; (b) a foreign government, or part of a foreign government; (c) an agency or authority of a foreign government, or of part of a foreign government; (d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or (e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government- (i) hold those posts as a result of, or in the course of, their membership of the party, or (ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party."

NC15

Ben Spencer (Con) - Shadow Minister (Science, Innovation and Technology)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Review of the cyber security risk posed by foreign powers (1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers. (2) A review under this section must identify whether any risk arises from- (a) activities undertaken outside of the UK, or (b) foreign owned or controlled infrastructure or locations within the UK. (3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups. (4) Within three months of each review under subsection (1), the Secretary of State must- (a) lay before Parliament a report containing the findings and conclusions of the review; and (b) where information is not included in a report on the grounds of being prejudicial to the UK's national security, send such information to the Intelligence and Security Committee of Parliament.”

3

Iain Duncan Smith (Con)
Sarah Owen (Lab)
Alex Sobel (Lab)
Rachael Maskell (Lab)
Marie Rimmer (Lab)
Emily Darlington (Lab)
Tabled: 26 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

Page 41, Clause 18, line 15, at end insert— "Exemption from disclosure: right to a fair trial 6AB.—(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that- (a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or (b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial. (2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of— (a) subject matter experts, and (b) competent civil society groups. (3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months."

25th March 2026
Amendment Paper
Notices of Amendments as at 25 March 2026

NC12

Alex Sobel (Lab)
Brian Leishman (Lab)
John Whitby (Lab)
Tabled: 25 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— ""Last-resort” powers in respect of data centres and Al models (1) Regulations under section 29(1) may confer on the Secretary of State powers ("last-resort powers”) to direct the shutdown of- (a) data centres, or (b) Al systems used or deployed by a data centre, in the event of an Al security or operational emergency. (2) For the purposes of this section— "data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act); "Al system” means a machine-based system that, from the input it receives, can infer how to- (a) generate predictions, digital content, recommendations, decisions or other similar outputs, or (b) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective; "used or deployed” means made available to- (a) a substantial number of individuals within the United Kingdom; or (b) providers and operators of essential services; "Al security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that— (a) there is a security or operational compromise to one or more relevant network and information systems, (b) this compromise is caused, or contributed to, by the use or operation of an Al system used or deployed by a data centre, whether through autonomous or non-autonomous means; and (c) this compromise poses a catastrophic risk; "catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to— (a) large-scale disruption to critical infrastructure or essential services; (b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or (c) severe, large-scale harm to human life; "data centre operator” means a person who operates a data centre; (3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must- (a) lay a report before Parliament setting out the direction and the reasons for it; and (b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable. (4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of Al systems, including relating to- (a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers; (b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers; (c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and (d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including- (i) incident reporting; and (ii) implementation of mitigation measures to prevent recurrence. (5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4). (6) Regulations relating to last-resort powers may- (a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed; (b) include, for the purposes of paragraph (a), powers to— (i) close premises; (ii) turn off systems or require that they be turned off; (iii) take any other action necessary to control the risk arising from an Al security or operational emergency. (7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must— (a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and (b) inform the operator or provider of their right to apply to the High Court for relief. (8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including- (a) confirming, varying or cancelling the requirements; (b) imposing additional requirements; (c) ordering compensation. (9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section. (10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates. (11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of Al security or operational emergencies and lay a copy of the report before Parliament. (12) The causes and potential causes of Al security or operational emergencies considered in any report under subsection (11) must include- (a) adversarial uses of Al systems by state and non-state actors; (b) the capabilities for cyber-attacks by autonomous Al systems; and (c) the development of Al systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent Al”.”

NC13

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Siân Berry (Green) - Green Spokesperson (Crime and Policing)
Iqbal Mohamed (Ind)
Caroline Voaden (LD) - Liberal Democrat Spokesperson (Schools)
Steve Darling (LD) - Liberal Democrat Spokesperson (Work and Pensions)
Mike Martin (LD)
Vikki Slade (LD)
Lisa Smart (LD) - Liberal Democrat Spokesperson (Cabinet Office)
Danny Chambers (LD) - Liberal Democrat Spokesperson (Mental Health)
Ian Sollom (LD) - Liberal Democrat Spokesperson (Universities and Skills)
Adrian Ramsay (Green) - Green Spokesperson (Treasury)
Liz Jarvis (LD)
Adam Dance (LD)
Cameron Thomas (LD)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Sarah Olney (LD) - Liberal Democrat Spokesperson (Business)
Pippa Heylings (LD) - Liberal Democrat Spokesperson (Energy Security and Net Zero)
Steff Aquarone (LD)
Bobby Dean (LD) - Liberal Democrat Shadow Leader of the House of Commons
Tabled: 25 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies (1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy ("a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by- (a) assessing, managing and mitigating risks- (i) associated with foreign interference, (ii) arising from reliance on foreign-supplied technologies, and (b) preventing over-reliance on foreign providers by building domestic capacity. (2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to- (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A Digital Sovereignty Strategy published under this section must- (a) include risks associated with- (i) hardware, (ii) software, (iii) supply chains, and (iv) procurement processes; (b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption; (c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and (d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems."

18th March 2026
Amendment Paper
Notices of Amendments as at 18 March 2026
10th March 2026
Amendment Paper
Notices of Amendments as at 10 March 2026
2nd March 2026
Amendment Paper
Notices of Amendments as at 2 March 2026

NC1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was Withdrawn

To move the following Clause— "Statement on risks posed to systems by foreign interference (1) The Secretary of State must, within 12 months of the passing of this Act, publish a statement of the Government's plans in relation to risks to the security and resilience of relevant network and information systems arising from foreign interference. (2) For the purposes of this section, a “relevant network and information system" is a network and information system belonging to— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) Any statement under this section must— (a) set out the Government's intentions to assess, manage and mitigate the risks posed, or which could potentially be posed, to the security and resilience of relevant network and information systems by foreign interference in such systems; (b) include risks associated with— (i) hardware, (ii) software, (iii) supply chains, (iv) procurement processes, and (v) the use of, or reliance on foreign technologies or systems; (c) include a specific focus on government digital procurement processes; (d) where risks are identified under (2)(b)(v), state whether the Government intends to address these risks by encouraging or supporting the use of domestic technologies or systems."

NC2

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Cyber security support service for SMEs (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems. (2) For the purposes of this section, a relevant SME is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. (3) A support service established under this section must provide— (a) advice and technical assistance to SMEs following a cyber incident; and (b) guidance on recovery and remediation."

NC3

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Review of high-risk bodies (1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies. (2) A review under this section must assess— (a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise; (b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and (c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities. (3) In this section— "relevant body" means— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations. "foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest; "network and information systems" has the meaning given by section 24(1)."

NC4

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Critical manufacturing and retail sectors (1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities— (a) the manufacture of critical transport equipment; (b) the industrial production and processing of food products; and (c) the retail sale of food and essential goods via large-scale distribution chains. (2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors."

NC5

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Helen Maguire (LD) - Liberal Democrat Spokesperson (Primary Care and Cancer)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Local authorities to be regulated as essential services (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert— "Local Government Local Government The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The Local Government Sector 12- (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector. (2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register. (3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records. (4) In this paragraph "local authority means" (a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly; (b) in Wales, a county council or a county borough council; (c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994; (d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.""

NC6

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Computer Misuse Act 1990: security and resilience of network and information systems (1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities. (2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines– (a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review; (b) the review's conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and (c) the Government's intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”

NC7

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Consultation on resourcing of regulatory authorities and regulated persons (1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing- (a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and (b) whether further government support is needed. (2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1)"

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Electoral infrastructure to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— "Elections Electoral infrastructure The Electoral Commission" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The electoral infrastructure subsector 12- (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector. (2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to- (a) maintain a register of electors containing more than 50,000 entries; (b) issue, receive, or process postal ballots for a parliamentary or local government election; or (c) count or aggregate votes cast in a parliamentary, mayoral or local government election. (3) In this paragraph- "parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom; "network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026. (4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert— "(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.""

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Political parties to be regulated as an essential service (1) The NIS Regulations are amended as follows. (2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert— "Government Political parties The Secretary of State for Housing, Communities and Local Government" (3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert- "The political parties subsector 12 - (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector. (2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons. (3) In this paragraph- "registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.""

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— "Board oversight of security and resilience of network and information systems (1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body's network and information systems. (2) In exercising oversight, the management body must— (a) approve the approach taken by the body to the management of risks to the security and resilience of the body's network and information systems; and (b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks. (3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems. (4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices. (5) For the purposes of this section, a relevant body is one which is— (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

To move the following Clause— “Requirement for regular testing of network and information systems (1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services. (2) Testing undertaken in accordance with this section must— (a) be proportionate, having regard to the size, nature and risk profile of the business; and (b) be conducted periodically, at intervals that are appropriate to the risks identified by the body. (3) A relevant body must document – (a) the outcomes of testing undertaken in accordance with this section; and (b) any remedial actions required or taken in response to the testing. (4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request. (5) For the purposes of this section, a relevant body is one which is – (a) an operator of an essential service, (b) a relevant digital service provider, (c) a relevant managed service provider, or (d) a critical supplier, within the meaning of the NIS Regulations.”

1

Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Tabled: 2 Mar 2026
Notices of Amendments as at 29 April 2026
This amendment was No Decision

Clause 8, page 7, line 36, at end insert- "(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,””

26th February 2026
Committee stage (Commons)
25th February 2026
Bill
Bill 385 2024-26 (as amended in committee)
25th February 2026
Bill
Bill 385 2024-26 (as amended in committee) - xml
25th February 2026
Amendment Paper
Notices of Amendments as at 25 February 2026

NC8

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Local authorities to be regulated as essential services
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—

“Local Government

Local Government

The Secretary of State for Housing, Communities and Local Government”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The Local Government Sector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector.
(2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register.
(3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records.
(4) In this paragraph “local authority means” —
(a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly;
(b) in Wales, a county council or a county borough council;
(c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994;
(d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.””


Explanatory Text

This new clause would bring local authorities within the scope of the NIS Regulations as operators of essential services in relation to their functions managing electoral rolls and social care records. This ensures that public sector bodies holding sensitive data such as electoral rolls and social care records are subject to the same statutory protections as other critical infrastructure.

NC9

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Critical manufacturing and retail sectors
(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities—
(a) the manufacture of critical transport equipment;
(b) the industrial production and processing of food products; and
(c) the retail sale of food and essential goods via large-scale distribution chains.
(2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors.”


Explanatory Text

This new clause would require the Secretary of State to designate the manufacturing of critical transport equipment and retail of food and essential goods (when part of a large-scale distribution chain) as essential activities, bringing them within the scope of Part 3 of the Bill.

NC10

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Consultation on resourcing of regulatory authorities and regulated persons
(1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing—
(a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and
(b) whether further government support is needed.
(2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1).”


Explanatory Text

This new clause would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations, and whether additional government support is required.

NC11

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Electoral infrastructure to be regulated as an essential service
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Elections

Electoral infrastructure

The Electoral Commission”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The electoral infrastructure subsector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector.
(2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to—
(a) maintain a register of electors containing more than 50,000 entries;
(b) issue, receive, or process postal ballots for a parliamentary or local government election; or
(c) count or aggregate votes cast in a parliamentary, mayoral or local government election.
(3) In this paragraph—
“parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom;
“network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026.
(4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—
“(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.”


Explanatory Text

This new clause would designate the administration of elections and maintenance of voter registers as an “essential service” within the meaning of the NIS Regulations.

NC12

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Freddie van Mierlo (LD)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Not Moved

To move the following Clause—
“Political parties to be regulated as an essential service
(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Government

Political parties

The Secretary of State for Housing, Communities and Local Government”


(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—
“The political parties subsector
11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector.
(2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons
(3) In this paragraph—
“registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.”””


Explanatory Text

This new clause would designate political parties as providing essential services for the purposes of cyber security.

NC13

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Statement on risks posed to systems by foreign interference
(1) The Secretary of State must, within 12 months of the passing of this Act, publish a statement of the Government’s plans in relation to risks to the security and resilience of network and information systems arising from foreign interference.
(2) Any statement under this section must—
(a) set out the Government’s intentions to assess, manage and mitigate the risks posed, or which could potentially be posed, to the security and resilience of network and information systems by foreign interference in such systems;
(b) include risks associated with—
(i) hardware,
(ii) software,
(iii) supply chains,
(iv) procurement processes, and
(v) the use of, or reliance on, foreign technologies or systems;
(c) include a specific focus on government digital procurement processes.
(d) where risks are identified under (2)(b)(v), state whether the Government intends to address these risks by encouraging or supporting the use of domestic technologies or systems.”


Explanatory Text

This new clause would require the Government to publish a statement of how it intends to address and mitigate any risks to network and information systems posed by foreign interference.

NC14

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Cyber security support service for SMEs
(1) The Secretary of State must, by regulations, make provision for the establishment and operation of a cyber security support service for relevant small and medium-sized enterprises (SMEs) for the purposes of improving the security and resilience of their network and information systems.
(2) For the purposes of this section, a relevant SME is one which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.
(3) A support service established under this section must provide—
(a) advice and technical assistance to SMEs following a cyber incident; and
(b) guidance on recovery and remediation.”


Explanatory Text

This new clause would require the Secretary of State to establish a cyber security support service for relevant SMEs.

NC15

Freddie van Mierlo (LD)
David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Review of high-risk bodies
(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies.
(2) A review under this section must assess—
(a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise;
(b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and
(c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities.
(3) In this section—
“relevant body” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.
“foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest;
“network and information systems” has the meaning given by section 24(1).”


Explanatory Text

This new clause would require the Government to review the security risks posed by critical suppliers and essential service providers linked to foreign states and evaluate whether current powers are sufficient to address these threats.

NC16

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Board oversight of security and resilience of network and information systems
(1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body’s network and information systems.
(2) In exercising oversight, the management body must—
(a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems; and
(b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks.
(3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems.
(4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices.
(5) For the purposes of this section, a relevant body is one which is –
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require active board oversight of, and accountability for, security and resilience measures, where a relevant body is governed by a board or similar body.

NC17

David Chadwick (LD) - Liberal Democrat Spokesperson (Wales)
Victoria Collins (LD) - Liberal Democrat Spokesperson (Science, Innovation & Technology)
Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Negatived On Division

To move the following Clause—
“Requirement for regular testing of network and information systems
(1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services.
(2) Testing undertaken in accordance with this section must –
(a) be proportionate, having regard to the size, nature and risk profile of the business; and
(b) be conducted periodically, at intervals that are appropriate to the risks identified by the body.
(3) A relevant body must document –
(a) the outcomes of testing undertaken in accordance with this section; and
(b) any remedial actions required or taken in response to the testing.
(4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request.
(5) For the purposes of this section, a relevant body is one which is –
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier
within the meaning of the NIS Regulations.”


Explanatory Text

This new clause would require bodies to carry out proportionate, periodic testing of the security and resilience of their network and information systems and provide the results to regulatory bodies upon request.

NC18

Freddie van Mierlo (LD)
Tabled: 25 Feb 2026
Notices of Amendments as at 25 February 2026
This amendment was Withdrawn

To move the following Clause—
“Computer Misuse Act 1990: security and resilience of network and information systems
(1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities.
(2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines–
(a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review;
(b) the review’s conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and
(c) the Government’s intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”


Explanatory Text

This new clause would require the Secretary of State to review, within 12 months, whether amending the Computer Misuse Act 1990 could improve the resilience of network and information systems, and to report the government’s intentions to Parliament.

24th February 2026
Committee stage: 7th sitting (Commons)
24th February 2026
Written evidence
Written evidence submitted by National Grid (CSRB40)
24th February 2026
Written evidence
Written evidence submitted by the Regulatory Policy Committee (RPC) (CSRB34)
24th February 2026
Bill proceedings: Commons
All proceedings up to 24 February 2026
24th February 2026
Written evidence
Written evidence submitted by Capita (CSRB33)
24th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 24 February 2026
24th February 2026
Amendment Paper
Public Bill Committee Amendments as at 24 February 2026
24th February 2026
Written evidence
Further written evidence submitted by iProov (CSRB35)
24th February 2026
Written evidence
Supplementary written evidence submitted by techUK (CSRB37)
24th February 2026
Written evidence
Written evidence submitted by Microsoft (CSRB39)
24th February 2026
Written evidence
Written evidence submitted by Cloudflare (CSRB38)
12th February 2026
Amendment Paper
Notices of Amendments as at 12 February 2026
11th February 2026
Amendment Paper
Notices of Amendments as at 11 February 2026
10th February 2026
Committee stage: 6th sitting (Commons)
10th February 2026
Committee stage: 5th sitting (Commons)
10th February 2026
Amendment Paper
Public Bill Committee Amendments as at 10 February 2026
10th February 2026
Written evidence
Supplementary written evidence submitted by the NCC Group (CSRB29)
10th February 2026
Written evidence
Written evidence submitted by VIRTUS Data Centres (CSRB31)
10th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 10 February 2026
10th February 2026
Written evidence
Written evidence submitted by the UK Cyber Security Council (CSRB32)
10th February 2026
Written evidence
Written evidence submitted by CrowdStrike (CSRB30)
9th February 2026
Amendment Paper
Notices of Amendments as at 9 February 2026
6th February 2026
Amendment Paper
Notices of Amendments as at 6 February 2026
5th February 2026
Committee stage: 4th sitting (Commons)
5th February 2026
Committee stage: 3rd sitting (Commons)
5th February 2026
Written evidence
Written evidence submitted by the British Insurance Brokers' Association (BIBA) (CSRB28)
5th February 2026
Amendment Paper
Public Bill Committee Amendments as at 5 February 2026
5th February 2026
Written evidence
Written evidence submitted by Dr Aine MacDermott, Liverpool John Moores University (CSRB24)
5th February 2026
Written evidence
Written evidence submitted by The ABI (CSRB23)
5th February 2026
Written evidence
Written evidence submitted by the Internet Services Providers' Association (ISPA) (CSRB22)
5th February 2026
Written evidence
Written evidence submitted by Shoosmiths LLP (CSRB27)
5th February 2026
Written evidence
Written evidence submitted by the Online Safety Act Network (CSRB26)
5th February 2026
Written evidence
Written evidence submitted by Rob Wright, Chief Commercial Officer, Hexiosec, Ambassador for Software Security for DSIT (CSRB25)
5th February 2026
Written evidence
Written evidence submitted by BCS, The Chartered Institute for IT (CSRB21)
4th February 2026
Amendment Paper
Notices of Amendments as at 4 February 2026
4th February 2026
Selection of amendments: Commons
Chair’s selection and grouping of amendments for debate in Committee 5 February 2026
3rd February 2026
Committee stage: 2nd sitting (Commons)
3rd February 2026
Committee stage:Commitee Debate: 1st sitting (Commons)
3rd February 2026
Written evidence
Written evidence submitted by the UK Cyber Security Council (UK CSC) (CSRB06)
3rd February 2026
Written evidence
Written evidence submitted by ISACA (CSRB05)
3rd February 2026
Written evidence
Written evidence submitted by Richard Holland (CSRB07)
3rd February 2026
Written evidence
Written evidence submitted by PauseAI UK (CSRB09)
3rd February 2026
Amendment Paper
Public Bill Committee Amendments as at 3 February 2026
3rd February 2026
Written evidence
Written evidence submitted by ISC2 (CSRB10)
3rd February 2026
Written evidence
Written evidence submitted by the CyberUp Campaign (CSRB18)
3rd February 2026
Written evidence
Written evidence submitted by iProov (CSRB17)
3rd February 2026
Written evidence
Written evidence submitted by UK Finance (CSRB14)
3rd February 2026
Written evidence
Written evidence submitted by Zurich UK (CSRB12)
3rd February 2026
Written evidence
Written evidence submitted by the Institution of Engineering and Technology (IET) (CSRB08)
3rd February 2026
Written evidence
Written evidence submitted by National Gas (CSRB20)
3rd February 2026
Written evidence
Written evidence submitted by Infoblox (CSRB19)
3rd February 2026
Written evidence
Written evidence submitted by Liberty and Privacy International (CSRB16)
3rd February 2026
Written evidence
Written evidence submitted by the Cybersecurity Business Network (CSRB15)
3rd February 2026
Written evidence
Written evidence submitted by Philip Virgo (CSRB13)
3rd February 2026
Written evidence
Written evidence submitted by Doctors Lam and Seifert (CSRB11)
3rd February 2026
Written evidence
Written evidence submitted by Open Rights Group (CSRB04)
3rd February 2026
Written evidence
Written evidence submitted by Fortaegis (CSRB03)
3rd February 2026
Written evidence
Written evidence submitted by Rik Ferguson (CSRB02)
3rd February 2026
Written evidence
Written evidence submitted by Rob Newby (on the Retail sector) (CSRB01B)
3rd February 2026
Written evidence
Written evidence submitted by Rob Newby (on the Energy sector) (CSRB01A)
30th January 2026
Amendment Paper
Notices of Amendments as at 30 January 2026
29th January 2026
Amendment Paper
Notices of Amendments as at 29 January 2026
28th January 2026
Amendment Paper
Notices of Amendments as at 28 January 2026
27th January 2026
Amendment Paper
Notices of Amendments as at 27 January 2026
22nd January 2026
Keeling schedules
The Network and Information Systems Regulations 2018 - 22 January 2026
7th January 2026
Press notices
Cyber Security and Resilience (Network and Information Systems) Bill
6th January 2026
2nd reading2nd Reading Commons Hansard Link (Commons)
6th January 2026
Carry-over motion
6th January 2026
Programme motion
6th January 2026
Ways and Means resolution
6th January 2026
Money resolution
17th December 2025
Briefing papers
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26
12th November 2025
Bill
Bill 329 2024-26 (as introduced)
12th November 2025
Bill
Bill 329 2024-26 (as introduced) - xml download
12th November 2025
1st reading (Commons)
12th November 2025
Delegated Powers Memorandum
Memorandum from the Department of Science, Innovation and Technology
12th November 2025
Explanatory Notes
Bill 329 EN 2024-26
12th November 2025
Impact Assessments
Impact Assessment from the Department for Science, Innovation and Technology