The Energy Sector Cyber Security Strategy: What It Means and How to Prepare
The UK energy strategy sets a 2026–2030 roadmap. Separate current NIS duties, future Plus-based proposals and supplier expectations before planning controls and evidence.

Section 01
The Energy Sector Cyber Security Strategy: What It Means and How to Prepare
The Energy Sector Cyber Security Strategy was published on 28 May 2026 by DESNZ with Ofgem, the NCSC and NESO. Its five objectives and 2026–2030 roadmap describe policy commitments, not a new universal certification mandate. Operators should separate existing NIS and sector duties from planned reforms, then establish the controls and evidence their actual services require.
On 28 May 2026 the government published the Energy Sector Cyber Security Strategy. It is a joint piece of work between four bodies - DESNZ as policy and risk owner, Ofgem as regulator for downstream gas and electricity, the NCSC as technical authority, and the National Energy System Operator (NESO) for whole-system coordination. Together they set out how the UK intends to defend its energy networks against a threat landscape that now includes state-sponsored actors, while the sector is simultaneously rebuilding itself around Clean Power 2030.
That combination - rapid digitalisation, decentralised generation, ageing operational technology, and a hostile threat environment - is why the strategy exists. This guide explains what it asks for, the timeline you are working to, and how to meet it without turning compliance into a permanent full-time project.
Section 02
Why the strategy exists
Three pressures are converging at once, and the strategy is the government's response to all three:
- Escalating threat to critical national infrastructure. Energy is a primary target for nation-state actors. A successful attack on generation, transmission or distribution has cascading consequences for every other sector.
- The Clean Power 2030 transition. Net zero requires a wave of new, highly digital, decentralised infrastructure - smart grids, renewables, storage, and the IT/OT convergence that comes with them. New attack surface is being created faster than legacy security models can cover it.
- Regulatory evolution. The 2018 NIS Regulations are the current foundation, but they were not written for this environment. The proposed Cyber Security and Resilience Bill (CSRB) is set to expand both the scope and the depth of what regulators can require.
The result is a clear direction of travel: more organisations in scope, higher maturity expectations, and a shift from "tick the box once a year" to demonstrating resilience continuously.
Section 03
The five pillars
The strategy is built around five strategic objectives. These are the headings every energy operator and supplier should be planning against:
1. "Enhancing our understanding of threat, vulnerability, and risk" - comprehensive mapping of the energy system, its dependencies, critical failure points and component-level vulnerabilities, including supply chain risk assessment.
2. "Prevention through enhanced and accelerated resilience" - extending cyber oversight to more energy players proportionate to risk, setting maturity targets for the highest-impact operators, and embedding security-by-design into new infrastructure.
3. "Strengthening preparedness, response and recovery" - better threat detection, cross-cutting incident response and recovery plans, and regular testing and exercising.
4. "Effective monitoring, regulation and enforcement" - getting NIS operators to full compliance, strengthening regulator capacity, and developing deeper assurance frameworks built on established schemes.
5. "Fostering partnership, culture and skills" - moving from a compliance-driven to a risk-driven culture, growing the security-cleared workforce, and driving cyber governance to board level.
Read together, the pillars describe an operating model, not a checklist. You are expected to know your assets and dependencies, prevent issues by design, respond and recover when something happens, prove all of it to a regulator, and govern it from the top.
Section 04
Strategy milestones: government commitments, not universal supplier deadlines
The strategy attaches dates to its commitments. These are the milestones that will shape what regulators ask for:
- End 2026 - understand cyber risk across the most critical parts of the system; run a cross-industry and government exercise simulating a sophisticated attack; strengthen regulatory capacity through assured providers; publish preliminary supply chain security principles.
- End 2027 - reassess NIS regulatory thresholds and revise them via secondary legislation; accelerate maturity for critical systems among downstream gas and electricity operators; engage industry on security-by-design; develop new assurance frameworks.
- End 2028 - full delivery of advanced threat detection capability; deliver a CEO-level tabletop exercise.
- End 2030 - designate critical suppliers with maturity targets; ensure baseline cyber resilience across the whole downstream gas and electricity system.
The honest read of this timeline is that the requirements ratchet upward every year. An approach that just about passes a one-off assessment in 2026 will not survive the deeper assurance frameworks and supplier designations arriving by 2030. What you need is a way of working that compounds - where the evidence you produce this year carries forward and the bar can rise without the workload exploding.
Section 05
The frameworks behind the strategy
The strategy does not invent a brand-new standard. It leans on established schemes and tightens how they are used:
- NIS Regulations (2018) - the primary regulatory lever, applying to Operators of Essential Services. Thresholds are due to be reassessed and likely widened.
- The Cyber Security and Resilience Bill (CSRB) - proposed legislation to expand regulatory powers, including over suppliers.
- Cyber Essentials Plus - the August 2026 downstream gas and electricity response intends a Plus-based foundation, with additional sector controls under consideration; this is not yet a universal implemented mandate.
- The NCSC's assurance approach - deeper assurance frameworks built on established schemes, with the NCSC Cyber Assessment Framework (CAF) the recognised basis for assessing essential-service operators.
- Cyber Resilience Audit (CRA) and Cyber Adversary Simulation (CyAS) - industry assurance and advanced capability testing schemes referenced for assured providers and testing.
- The Cyber Governance Code of Practice - supporting board-level risk ownership.
Current Cyber Essentials can support technical baseline assurance, but does not by itself meet all NIS duties or future sector proposals. The government response of 5 August 2026 intends Cyber Essentials Plus as a foundation and considers additional controls, with further consultation on detailed design and initial implementation in 2027. Distinguish the wider UK strategy from downstream gas/electricity regulation in Great Britain, and check the applicable jurisdiction and current licence/NIS duties.
Section 06
What this actually means for operators and suppliers
For practical preparation, the strategy highlights four areas to assess against current NIS, licence and contractual duties:
1. Know your estate and your dependencies - including operational technology and the suppliers your essential services rely on.
2. Run controls to a measurable maturity - and be able to show the maturity, not just claim it.
3. Be ready to detect, respond and recover - with tested plans and defensible records.
4. Prove all of the above to a regulator - repeatedly, to a standard that rises each year.
And it is not just the large operators. The supply chain commitments mean that if you sell into the energy sector - software, hardware, OT services, managed services - you should expect your customers to push these expectations down to you through procurement and contracts. The strategy targets designation of critical suppliers and maturity targets by 2030, subject to the applicable legal process and implementation. Getting your house in order now is a commercial advantage, not just a regulatory chore.
For most organisations the hard part is not understanding the requirement. It is the sheer, ongoing weight of evidencing it across assets, vulnerabilities, suppliers, incidents, policies, training and audits - without a dedicated team buried in spreadsheets.
Section 07
How Fig Group can support implementation
Agree the actual service scope, integrations, mappings and evidence with Fig Group. Automation can support collection and review when configured appropriately; it cannot confer compliance, technical control maturity or regulator acceptance on onboarding.
The Fig Group platform was designed for exactly this kind of layered, evidence-heavy, continuously-assessed environment. Its five capability groups - Discover, Protect, Respond, Prove and Transfer - line up almost one-to-one with the strategy's five pillars. Here is how each pillar maps to the platform.
Pillar 1 - Understanding threat, vulnerability and risk
The strategy wants comprehensive mapping of assets, dependencies and component-level vulnerabilities. Fig Group's asset discovery builds a live, governed register across hardware, software, cloud and service dependencies, with owners and evidence attached. Data discovery and classification finds where sensitive and regulated data lives. Vulnerability scanning consolidates scanner output and prioritises by exploitability and asset importance, and exposure modelling shows how small weaknesses combine into business risk - exactly the dependency-and-failure-point picture the strategy asks operators to build.
Pillar 2 - Prevention through accelerated resilience
Maturity targets and resilience are the heart of pillar 2. Fig Group's supply chain risk monitoring maps suppliers to the services and data they touch and tracks assurance evidence continuously, rather than relying on an annual questionnaire - directly relevant to the strategy's supplier-designation agenda. Business continuity connects recovery plans, critical services and test evidence so resilience is measurable, and people lifecycle governs access and accountability from joiner to leaver.
Pillar 3 - Preparedness, response and recovery
The strategy prioritises incident response, recovery and exercising; actual legal requirements follow the relevant NIS and sector rules. Fig Group's incident management runs incidents from one structured record - actions, owners, decisions, notifications and reporting - so timelines stay defensible and reporting (including for incidents below NIS thresholds) is straightforward. Agentic remediation turns findings into assigned, evidenced fixes while keeping human approval and ownership intact.
Pillar 4 - Monitoring, regulation and enforcement
This is where most of the workload lives, and where automation pays off most. Fig Group's compliance automation maps your controls to the frameworks behind the strategy - NIS, Cyber Essentials, the CAF assurance approach and more - and collects evidence continuously, flagging stale or missing evidence before an assessor would. Policy management turns policies into operational control with approvals and attestations, and audit management builds audit packs from work that already happened, so you are not constructing a parallel process every time a regulator asks. Because evidence is reused across frameworks, raising the bar each year does not mean rebuilding from scratch.
Pillar 5 - Partnership, culture and skills
Risk-driven culture and board-level governance are evidenced too. Fig Group's training and policy acknowledgement tracks role-based training and acknowledgements with completion evidence and overdue actions, and its insurer-grade evidence view organises live posture and risk data for customer-controlled external review and board-level risk conversations.
Section 08
Establish a defensible evidence baseline
Agree the applicable framework version, system and service scope, control owners and integration coverage. Review the quality and history of imported evidence, resolve gaps and test whether controls operate. Onboarding alone does not establish compliance or audit readiness. Evidence reuse can reduce duplication where it is relevant, but new duties and higher maturity may still require additional work.
Section 09
What to do now
You do not need to wait for every piece of secondary legislation to land. The smart moves are the ones that hold up no matter how the detail settles:
1. Get the baseline in place. Check current NIS and licence duties and the intended Plus-based reforms; Cyber Essentials can be a useful starting point but is not the entire future sector baseline.
2. Build a live asset and dependency picture, including OT and the suppliers your essential services depend on.
3. Move evidence off spreadsheets. Adopt a platform that maps controls to frameworks and collects evidence continuously, so rising requirements do not mean rising headcount.
4. Push expectations down your supply chain early - and, if you are a supplier, get ahead of the designation and maturity targets coming by 2030.
Section 10
Frequently asked questions
Who published the Energy Sector Cyber Security Strategy?
It was published on 28 May 2026 by the Department for Energy Security & Net Zero (DESNZ), working with Ofgem, the National Cyber Security Centre (NCSC) and the National Energy System Operator (NESO). The four bodies share responsibility: DESNZ owns policy and risk, Ofgem regulates downstream gas and electricity, the NCSC is the technical authority, and NESO coordinates the whole system.
Does the strategy only apply to large energy operators?
No. The strategy addresses operators and the wider supply chain proportionately to risk. Supplier expectations can flow through contracts, while formal designation and future maturity requirements depend on the relevant legal process. Supplying the sector does not automatically create every operator duty.
What frameworks does the strategy rely on?
It builds on NIS, NCSC assurance approaches including CAF and sector assurance schemes. The August downstream gas/electricity response intends a Plus-based foundation with additional controls under consideration and further design/initial-implementation consultation in 2027. Check current GB duties separately from broader UK strategy commitments.
How does Fig Group help energy organisations comply?
Discuss the relevant mappings, integrations, owners and evidence coverage with Fig Group. Asset, supplier, incident and audit workflows can support the work when implemented appropriately; they do not establish every required control or guarantee regulator acceptance.
Is Cyber Essentials enough to meet the strategy?
No. Cyber Essentials alone does not establish the deeper governance, operational technology, continuity and supply-chain assurance relevant to energy services. The August response intends a Plus-based foundation with additional controls under consideration and a further 2027 consultation; check current duties separately from this future design.
Section 11
Summary
The strategy gives operators and suppliers a roadmap through 2030. Preserve the five objectives and dated commitments, while checking current legal duties, jurisdiction and future consultations separately. Build and maintain relevant evidence; a platform can support this work but cannot guarantee compliance from day one.
See the Fig Group platform | Talk to our team about energy sector compliance
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
End-to-End Risk Management for the Cyber Security and Resilience Bill: A Guide for Critical National Infrastructure
A practical guide to proposed UK cyber resilience reforms for CNI: distinguish existing NIS duties from Bill proposals, verify scope and commencement, and plan evidence and incident workflows.
Read articleFrameworks
Does Your G-Cloud Contract Require Cyber Essentials?
A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.
Read articleIndustry
Cyber Essentials for Solicitors and Law Firms: What the SRA Expects in 2026
The Legal Aid Agency now mandates Cyber Essentials for criminal legal aid contracts. The SRA expects appropriate cyber controls for all firms. Here is what solicitors and law firms need to know.
Read article

