What is the Cyber Security & Resilience Bill?

The Cyber Security & Resilience (Network and Information Systems) Bill is a proposed reform of the UK's Network and Information Systems (NIS) Regulations 2018. It is designed to strengthen the resilience of critical services against evolving cyber threats while supporting a more risk-based, outcome-focused approach to cyber security.

The Bill is expected to expand regulatory scope and place greater emphasis on:

  • Operational preparedness 
  • Cyber incident detection, response and recovery 
  • Supply chain cyber security 
  • Business continuity and resilience 
  • Timely regulatory engagement 

Rather than focusing solely on compliance, the proposed legislation encourages organisations to demonstrate operational resilience in practice.

 

Who could be affected?

The CSR Bill is expected to affect organisations operating within or supporting critical national infrastructure and essential digital services, including:

  • Energy and utilities 
  • Financial services 
  • Healthcare and life sciences 
  • Transport and logistics 
  • Telecommunications 
  • Public sector and defence 
  • Managed Service Providers (MSPs) 
  • Data centres and cloud-enabled services 

Organisations that are not directly regulated may also be affected through contractual obligations and supplier assurance requirements imposed by regulated organisations.

 

Why prepare now?

Although the legislation is still progressing through Parliament, many of the expected requirements align with guidance already published by the National Cyber Security Centre (NCSC).

Preparing now can help you:

  • Reduce operational disruption 
  • Strengthen cyber resilience across your organisation 
  • Improve incident response capabilities 
  • Strengthen supplier assurance 
  • Demonstrate resilience to clients, regulators and stakeholders 

Organisations that take action early will be better placed to respond as the legislation develops.

 

How CGI can help

Preparing for the CSR Bill requires more than understanding the legislation. It requires a practical assessment of your current cyber resilience and a clear plan to strengthen the areas that matter most.

Our cyber security specialists can help you:

  • Assess how the CSR Bill applies to your organisation 
  • Evaluate your cyber resilience maturity against the NCSC Cyber Assessment Framework (CAF) 
  • Improve incident response readiness through planning and exercising 
  • Strengthen Security Operations Centre (SOC) and resilience monitoring capabilities 
  • Enhance supplier cyber assurance and due diligence 

We work alongside organisations to strengthen operational resilience and prepare for evolving cyber security expectations.

Our brochure explains:

  • What the CSR Bill is 
  • Who is likely to be affected 
  • Why organisations should prepare now 
  • How the Bill compares with existing frameworks, including NIS Regulations and DORA 
  • Practical actions organisations can begin taking today 

Download the brochure

If you wish to talk to our cyber security specialists further on this matter or whether you are assessing your readiness, reviewing supplier obligations or planning your cyber resilience strategy, our experts can help. Fill out our simple form.