UK Cyber Security and Resilience Bill
Bill — not yet law
United Kingdom
· 2025
The Cyber Security and Resilience Bill is the UK's intended successor to the NIS Regulations 2018 and its answer to the EU's NIS2 — extending regulatory reach to managed service providers and data centres, strengthening incident reporting, and giving regulators cost-recovery powers. It is a bill: nothing in it binds anyone yet, and it is catalogued so the gap between the UK and EU cyber regimes is visible rather than assumed away.
This is a bill, not law. It has been introduced but not enacted, it can be
amended beyond recognition or die on the order paper, and nothing in it binds anyone today.
It is catalogued because the obligations it proposes are the ones worth building toward.
Sectoral regime. It binds the industries below; companies outside them
generally fall outside it.
Countries
Where this binds. Each links to the providers apis.io has catalogued there.
Regions
Industries
Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.