Cyber Security And Resilience Bill: Penetration Testing Requirements & Compliance Guide

The Cyber Security and Resilience Bill just cleared a real milestone. It sits in the House of Lords as HL Bill 32, with Grand Committee scrutiny running across four sittings in September 2026. Peers have tabled dozens of amendments, including proposals on AI governance, vendor powers, and potential personal liability for company directors. Meanwhile, the reporting rules underneath it are tightening hard. NIS 2018 relied on a vague trigger: whether an incident caused an adverse effect. That’s gone now. Organisations face a strict 24-hour initial notification and a 72-hour full report once an incident meets the Bill’s reportable-incident test.

Here’s why that gap matters in practice. Consider two real examples. The 2024 Synnovis ransomware attack on an NHS pathology provider cost an estimated £32.7 million and delayed over 11,000 appointments. The 2025 Marks & Spencer breach caused reported losses up to £300 million. Under NIS 2018’s subjective ‘adverse effect’ threshold, it was far from clear that incidents of this scale had to be reported at the time. This Bill exists specifically to close this issue.

This guide covers what actually changes, where penetration testing genuinely fits, and what newly in-scope organisations should be doing right now, not after Royal Assent.

What the Bill Actually Changes vs. NIS 2018

The Bill substantially expands who counts as regulated, replacing NIS 2018’s narrower sector-based scope with categories built around actual digital dependency. In practice, that shift is the biggest change for organisations that never considered themselves critical infrastructure.

Core coverage: The NIS Regulations 2018 covered Operators of Essential Services (OES) in energy, transport, health, and water, along with Relevant Digital Service Providers. The Cyber Security and Resilience Bill carries these categories forward and expands the scope.

Managed service providers: The NIS Regulations 2018 did not specifically regulate managed service providers. The Bill brings them into scope as Regulated Managed Service Providers (RMSPs) under Section 9.

Data centres: Data centres were not specifically covered under the NIS Regulations 2018. The Bill brings them into scope under Section 4, subject to 1MW and 10MW capacity thresholds.

Load controllers: Load controllers were not covered under the NIS Regulations 2018. The Bill introduces requirements for load controllers operating at 300MW or higher under Section 6.

Supply chain: The NIS Regulations 2018 did not directly address critical suppliers. The Bill allows critical suppliers to be designated under Section 12 based on the organisations they supply.

Incident reporting: The NIS Regulations 2018 used an “adverse effect” threshold to determine reportable incidents. The Bill introduces clearer reporting timelines, requiring initial notification within 24 hours and a full report within 72 hours once an incident is assessed as reportable.

Section 12’s critical supplier route deserves particular attention. An organisation can fall into scope purely because of who it supplies, even if its own sector has nothing to do with critical infrastructure. A software vendor serving a handful of energy companies could find itself regulated for that reason alone.

Source: https://qualysec.com/cyber- ...
London, Technical, Cyber Security And Resilience Bill: Penetration Testing Requirements & Compliance Guide
Atrás Próximo