The Cyber Security and Resilience (Network and Information Systems) Bill has now completed every stage in the House of Commons and moved to the House of Lords, where committee stage is scheduled for September and Royal Assent is expected before the end of the year. For a piece of legislation that’s been quietly working its way through Parliament since late 2025, this is the point where “eventually” starts turning into “soon,” and the detail that’s changed since it was first introduced matters more than the headline that it’s progressing.

The Bill updates the UK’s existing NIS Regulations, the framework that currently governs cybersecurity duties for essential services like energy, water, and transport. What’s shifted since the version most businesses read about earlier this year is scope: it now explicitly pulls in managed service providers, cloud platforms, data centres, and what the Bill calls “critical suppliers”, businesses that don’t run essential infrastructure themselves but supply or support the companies that do. That’s a much wider net than “critical national infrastructure operators,” and it’s the part smaller businesses are most likely to have missed.

Who’s newly in scope, and who isn’t yet

If you run or supply IT services, hosting, cloud infrastructure, or managed support to organisations in regulated sectors, energy, water, transport, health, digital infrastructure, this Bill is worth reading properly rather than filing under “not my industry.” The “critical supplier” category is designed to catch exactly the kind of specialist third-party vendor that a hospital trust, utility, or transport operator depends on but doesn’t directly control, which is precisely the supply-chain gap that’s caused several of the breaches covered in this space over the past few months. If you don’t supply into a regulated sector at all, you’re not in scope for now, though the enforcement powers and incident reporting standards this Bill sets are likely to become the de facto expectation across UK business over time regardless.

What’s worth doing before Royal Assent

Work out honestly whether you could be a “critical supplier.” This isn’t just about direct contracts with a regulated operator, it can include being far enough down someone else’s supply chain that your outage becomes their incident. If you’re not sure, this is worth a proper conversation rather than a guess.

Look at your incident reporting readiness now, not after Royal Assent. The Bill introduces enhanced, faster incident reporting requirements. Businesses that already have a clear, written process for who gets notified and how quickly will have a much easier transition than those working it out for the first time under a legal deadline.

Don’t wait for the final text to start the conversation with your suppliers. If you depend on an MSP, cloud provider, or IT partner who might fall into scope, ask them directly whether they’re tracking this. Their preparedness becomes your risk if they’re not.

Check what committee stage actually changes. Committee stage is where line-by-line amendments get debated and voted on, so some detail could still shift between now and Royal Assent. It’s worth a quick check-in once that stage wraps up in the autumn, rather than assuming the current scope is completely final.

If you want an outside view on where your business or supply chain actually sits against this kind of incoming regulation, KeepSafe tracks third-party and infrastructure exposure specifically, and CoolCoding can help assess whether your technical setup would meet the incident reporting standards the Bill is introducing.

The takeaway

Committee stage in September and Royal Assent by year-end means this Bill is no longer a distant “watch this space” story. The scope has grown to include suppliers as well as operators, so the honest first step for most businesses isn’t reading the full text, it’s working out whether “critical supplier” now describes you.