Description

Information Commissioner's Office issued response on Cyber Security and Resilience Bill

On 23 December 2025, the Information Commissioner's Office (ICO) issued its response on the Cyber Security and Resilience Bill, which was laid before Parliament on 12 November 2025. The Bill will update the Network and Information Systems (NIS) Regulations 2018 by expanding the regulatory scope to include a broader range of essential and digital service providers, including online marketplaces, cloud computing services, and search engines, as well as managed service providers. In its response as the competent authority for digital service providers and data protection, the ICO stated its approval of the Bill's expansion of the ICO's power to serve information notices, expansion of communication channels between the ICO and UK public authorities, introduction of new powers to enforce registration requirements, and expansion of its regulatory cost-recovery powers. Regarding other parts of the Bill, the ICO requested further clarity on certain aspects of the Bill, such as the factors and thresholds for determining a "significant impact" for incident reporting, security requirements, and the criteria for assessing critical suppliers. Additionally, the ICO requested clarity on the application of the new penalty measures and the impact of enhancements to the ICO's information gathering powers.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-07-17
under deliberation

On 17 July 2024, the Cyber Security and Resilience Bill was announced in the King's Speech. The Bil…

2025-04-01
under deliberation

On 1 April 2025, the Department for Science, Innovation & Technology published a policy statement d…

2025-11-12
under deliberation

On 12 November 2025, the Cyber Security and Resilience Bill was introduced to Parliament. The Bill …

2025-12-23
under deliberation

On 23 December 2025, the Information Commissioner's Office (ICO) issued its response on the Cyber S…