Skip to content
Industry

End-to-End Risk Management for the Cyber Security and Resilience Bill: A Guide for Critical National Infrastructure

A practical guide to proposed UK cyber resilience reforms for CNI: distinguish existing NIS duties from Bill proposals, verify scope and commencement, and plan evidence and incident workflows.

black transmission towers under green sky

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

15 min read

Share

Section 01

End-to-End Risk Management for the Cyber Security and Resilience Bill: A Guide for Critical National Infrastructure

The Cyber Security and Resilience Bill proposes changes to UK cyber regulation, including broader scope and incident-reporting reforms. It must be distinguished from existing NIS and sector duties: a Bill is not enacted or commenced law. CNI operators should verify their actual obligations, then prepare risk, incident and evidence processes against the relevant legal and regulator requirements. A platform can support those processes but does not confer compliance on onboarding.

The Cyber Security and Resilience (Network and Information Systems) Bill had its first reading in Parliament on 12 November 2025 and completed its second reading and committee stage through early 2026. Brought forward by the Department for Science, Innovation and Technology (DSIT), it is designed to deliver a step change in the resilience of the UK's essential and digital services against cyber criminals and hostile state actors.

For organisations that operate or supply critical national infrastructure, the Bill is not a minor regulatory update. It proposes changes to the legal baseline, accountability and penalties, subject to final legislation and commencement. This guide explains the proposed changes for CNI operators and their supply chains, how those requirements map to the NCSC Cyber Assessment Framework, and how the Fig Group platform provides the end-to-end risk management needed to comply - and to keep complying as expectations rise. It is a companion to our guide on the Energy Sector Cyber Security Strategy, which sets the same direction of travel for one of the most heavily targeted CNI sectors.

Section 02

What the Bill proposes

The official policy statement explains the policy intent. For the latest amended text and passage, check Parliament’s Bill record. Scope definitions, thresholds, designation powers, secondary legislation and commencement matter; do not infer a universal current duty from a policy summary or a passage legend.

Proposed changes concern managed service providers, data centres, critical suppliers, reporting and regulator powers. Not every CNI supplier is automatically directly regulated. The CAF is a useful assurance framework, but this guide does not establish an exact clause making every CAF outcome a universal statutory baseline. Apply the actual regulator’s requirements and applicable law.

Reporting and penalty proposals require the current Bill version, relevant offence, entity and trigger. Where proposed maximum penalties use a fixed sum or turnover percentage, apply the whichever-is-higher formulation and verify the turnover definition; do not assume one headline maximum covers every breach. Prepare for proposed reporting changes while continuing to comply with existing incident and data-protection duties.

Section 03

What this means for critical national infrastructure operators

As practical preparation for the proposed reforms, CNI operators can assess four areas against their existing duties and applicable regulator requirements:

1. Understand and govern risk across a complex estate of IT and operational technology, with full visibility of assets, data and dependencies.

2. Protect essential services to CAF maturity, and be able to evidence that maturity rather than assert it.

3. Detect, triage and report incidents against the applicable deadlines, distinguishing existing duties from proposed 24/72-hour reforms.

4. Minimise impact and recover, with tested continuity plans and supply chain assurance that holds up to scrutiny.

The challenge for most CNI operators is not understanding these obligations. It is the fragmentation behind them. Risk lives in one tool, asset registers in spreadsheets, vulnerability data in scanners, supplier assurance in inboxes, incident records in ticketing systems, and policies in document stores. Pulling that together into a coherent, regulator-ready picture - repeatedly, at CAF depth, across IT and OT - is where time and confidence are lost. End-to-end risk management is the answer, and it is exactly what Fig Group was built to provide.

Section 04

End-to-end risk management with the Fig Group platform

Fig Group brings the full lifecycle of cyber risk management into a single, governed platform, organised around five stages - Discover, Protect, Respond, Prove and Transfer. Each stage can support preparation for the proposed reforms, subject to the actual entity, service scope, control evidence and applicable duties.

Discover - know your estate and your dependencies

You cannot manage risk you cannot see. Fig Group's asset discovery builds a live, governed register across hardware, software, cloud and service dependencies, with accountable owners and evidence attached from day one - the foundation the CAF expects before any control conversation. Data discovery and classification identifies where critical and regulated data lives and which obligations apply to it. For CNI operators bridging IT and OT, this single view of the estate is the difference between defensible scope and educated guesswork.

Protect - reduce exposure to a measurable maturity

Use the CAF where required by the applicable regulator, checking the relevant profile and evidence requirements; the Bill does not establish a universal statutory CAF maturity baseline in this guide. Fig Group's vulnerability scanning consolidates scanner output and prioritises by exploitability and asset importance, so remediation effort goes where business risk is highest. Exposure modelling shows how individual weaknesses combine into business risk across critical services. Supply chain risk monitoring maps suppliers to the services and data they touch and tracks assurance evidence continuously - directly addressing the Bill's new supplier and MSP duties. People lifecycle governs access and accountability from joiner to leaver, closing one of the most common control gaps.

Respond - detect, manage and report on the clock

Proposed 24/72-hour reporting changes require readiness planning, but current duties depend on the actual law, regulator and incident trigger. Incident management can organise actions and evidence; record storage alone does not prove detection or a compliant notification. Confirm recipients, jurisdiction, authorised human approval and delivery evidence. Agentic remediation should retain accountable approval and ownership.

Prove - turn live work into regulator-ready evidence

This is where the heaviest CSRB workload sits, and where automation delivers most. Fig Group's compliance automation maps your controls to the frameworks behind the Bill - the NCSC CAF, the NIS Regulations and others - and collects evidence continuously, flagging stale or missing evidence before an assessor would. Policy management turns policies into operational control with approvals and attestations. Audit management builds audit packs from work that already happened, and training and policy acknowledgement evidences that people have been trained and policies acknowledged. Because evidence is reused across frameworks, demonstrating CAF maturity to a regulator does not mean rebuilding your compliance position from scratch each time.

Transfer - use your posture to manage residual risk

No control set eliminates risk entirely. Fig Group's business continuity makes recovery readiness measurable by connecting recovery plans, critical services and test evidence - central to the Bill's resilience focus. The insurer-grade evidence view organises live posture, compliance and risk data for customer-controlled sharing with an insurer, broker, or underwriter and for board-level risk reporting.

Section 05

Aligning directly with what the NCSC requires

The NCSC Cyber Assessment Framework is a useful assurance structure. The mapping below describes its four top-level objectives; confirm whether your regulator requires it, which profile applies and what evidence is needed.

Mapping work to the four CAF objectives can organise assurance evidence. Confirm applicable regulator requirements and test the underlying controls; a platform mapping does not establish CAF maturity or compliance with future legislation.

Section 06

Prepare incident workflows against the applicable clock

Record which entity and service is affected, the legal trigger, awareness/classification time, recipient, deadline and authorised approver. Test escalation outside office hours, retain decisions and verify delivery. Proposed initial and follow-up stages do not mean every current incident has the same deadline. Evidence systems support the workflow; confirm actual detection integrations and notification capability separately.

Section 07

The supply chain and MSP dimension

The proposed extension of scope means CNI operators should review supplier dependencies and actual flowed-down contract duties. MSPs, data centres and suppliers must check definitions, thresholds or designation rather than assume direct scope. Supply chain risk monitoring can support evidence review when configured; it does not replace statutory assessments or establish assurance automatically.

Section 08

Onboarding establishes a starting point

Confirm framework versions, service boundaries, data connectors, control owners and evidence provenance. Assess gaps and test controls before asserting maturity or compliance. Reuse evidence only where it meets the receiving framework’s requirements; new obligations may add work. Vulnerability information and an incident register do not alone establish CAF Objective C detection or automated regulator reporting.

Section 09

What CNI operators should do now

The Bill is progressing, and the direction is settled even where the final detail is not. The sensible moves are the ones that hold up regardless:

1. Adopt the CAF as your operating language now, rather than waiting for enforcement to begin.

2. Build a live, unified picture of your IT and OT estate and its dependencies.

3. Test detection, escalation and reporting against actual legal deadlines, including readiness for proposed 24/72-hour changes.

4. Maintain supplier assurance with evidence proportionate to risk, retaining any required questionnaires and contract assessments.

5. Move evidence off spreadsheets and onto a platform that maps controls to frameworks and collects evidence continuously, so rising requirements do not mean rising headcount.

Section 10

Frequently asked questions

What is the Cyber Security and Resilience Bill?

It is proposed UK legislation, brought forward by the Department for Science, Innovation and Technology, to reform and expand the NIS Regulations 2018 and strengthen the cyber resilience of essential and digital services. It had its first reading on 12 November 2025 and progressed through second reading and committee stage in early 2026. For relevant operators it proposes changes to baseline requirements, scope, incident reporting and penalties, subject to the final text and commencement.

Who comes into scope under the Bill?

The Bill proposes broader scope, including managed services, data centres and certain critical suppliers. Eligibility depends on actual definitions, thresholds or designation and commencement; supplying a CNI operator alone does not prove direct scope.

What are the new incident reporting requirements?

The proposed reporting reforms include initial and follow-up notifications, commonly described as 24/72-hour stages. Verify the current text, actual trigger, recipients and commencement before treating these as duties for your entity. Existing NIS and data-protection reporting continue to require separate checks.

What penalties does the Bill introduce?

Official Bill factsheets describe proposed maximum bands for the most serious breaches of £17 million or 4% of qualifying global annual turnover, whichever is higher, and standard breaches of £10 million or 2%, whichever is higher. Confirm the current text, breach category, applicable turnover definition and commencement before applying a band; these are proposed maximums, not an automatic penalty for every incident.

How does Fig Group help with NCSC CAF compliance?

Fig Group maps your controls to the NCSC Cyber Assessment Framework and the NIS Regulations and collects evidence continuously across assets, vulnerabilities, suppliers, incidents, policies and training. Its capabilities align with all four CAF objectives - managing security risk, protecting against attack, detecting events, and minimising impact - subject to configured integrations and verified control evidence. This does not establish a universal statutory CAF duty or guarantee maturity.

Does the Bill apply to managed service providers and data centres?

The Bill proposes bringing qualifying managed service providers, data centre operators and designated critical suppliers into scope. Direct duties depend on definitions, thresholds or designation, the final text and commencement. Serving CNI alone does not impose every customer duty on a provider.

Section 11

Summary

The Bill proposes broader cyber resilience regulation. Separate proposals from existing duties and verify scope, thresholds, final text and commencement before assigning legal obligations. Build risk ownership, tested response and defensible evidence; software can support this work but cannot establish compliance automatically.

Explore the Fig Group platform | Talk to our team about CNI compliance

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.