The UK bill proposes amendments to the existing UK Network and Information Systems (NIS) Regulations that would bring the UK cybersecurity regime closer to the EU framework established under the NIS2 Directive. In particular, it would:
- expand the scope of regulated entities to include data centres, relevant managed IT service providers, large electrical load controllers and critical suppliers to secure the entire supply chain; and
- introduce stricter incident reporting requirements by, for example, widening the reporting criteria to include attacks, even if no impact has occurred yet but a significant one is likely to materialise.
However, the bill remains distinct from the NIS2 in several aspects, including by relying more on secondary legislation to set out detailed security requirements.
In addition, the bill would enable the UK government to update the cybersecurity framework, for example, by bringing more sectors into scope or introducing new security and resilience requirements.
The UK bill was introduced to parliament on 12 November 2025.
For more information and to read the full report, please click on “Access the full content” - or on “Request full report”, in case you are not subscribed to our European Digital Economy service.
more news
22 January 26
Digital Networks Act (DNA) proposal: great ambitions, moderate means
An EU-level authorisation regime for satellite services, a new EU access product, a voluntary “conciliation process” on IP interconnection disputes and a focus on network resilience are among the main innovations proposed under the Digital Networks Act.
22 January 26
Revised Cybersecurity Act (CSA2) - European Commission proposes mandatory phase-out of high-risk vendors from 5G networks
This is Cullen International's initial report on the European Commission's proposal for a revised Cybersecurity Act (CSA2). A more in-depth analysis will follow shortly.
21 January 26
EU Timeline: regulatory milestones for the first half of 2026
This edition of Cullen International’s EU Timeline highlights key policy and regulatory developments foreseen at EU level until mid-2026.