On April 1, 2025, the UK government published the Cyber Security and Resilience Policy Statement (the “Policy Statement”), which details the UK government’s legislative proposals for the Cyber Security and Resilience Bill (the “Bill”), which was originally announced in July 2024. As explained in the Policy Statement, currently, the key legislation in the UK governing “cross sector” cybersecurity is the Network and Information Systems (NIS) Regulations 2018 (the “NIS Regulations”). The NIS Regulations were the pre-Brexit national implementation of the EU NIS Directive. The EU NIS Directive was recently repealed and replaced by the Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the EU (the “NIS2 Directive”). The Bill will propose amendments to the NIS Regulations, taking into consideration “insights” and “valuable lessons” from the EU on the implementation of NIS2. According to the Policy Statement, the Bill will “address the specific cybersecurity challenges faced by the UK while aligning, where appropriate, with the approach taken in the EU NIS 2 directive. This strategic approach ensures…[the UK] can be flexible and responsive to cyber threats in a proportionate way that balances the impact on business.”

As detailed further in the Policy Statement, the Bill will include measures such as:

The Policy Statement also sets out plans to extend the scope by strengthening supply chain duties for operators of essential services (an “OES”) and relevant digital service providers (an “RDSP”) through secondary legislation. Regulators will also be able to designate critical suppliers if the supplier’s goods or services are so critical that disruption could cause a significant disruptive effect on the essential or digital service it supports. According to the Policy Statement, critical suppliers are expected to account for a “very small number and percentage of those suppliers providing goods or services” to an OES or RDSP.

In addition, the Policy Statement detailed other measures under consideration by the UK government, which may be included in the Bill or advanced under other legislation, such as:

According to the press release on the Policy Statement, the Bill is to be introduced later this year.

Leave a Reply

Your email address will not be published. Required fields are marked *