Eight regimes matter for UK organisations in 2026: the NIS Regulations 2018, UK GDPR and the Data Protection Act 2018, FCA and PRA operational resilience rules, DORA where you have EU exposure, Cyber Essentials, the NCSC Cyber Assessment Framework, the Telecommunications (Security) Act 2021, and the Cyber Security and Resilience Bill now before Parliament. Which apply depends on your sector, not your size.
This article sets out each one, what it obliges you to do, and the reporting window attached. Every claim is taken from a primary source and linked inline. Where a figure could not be confirmed at source, it is left out rather than estimated.
What UK cyber security regulations apply in 2026
| Regulation | Who it applies to | Key obligation | Reporting window | Enforcement body |
|---|---|---|---|---|
| NIS Regulations 2018 (as amended) | Operators of essential services in electricity, oil, gas, air, water, rail and road transport, healthcare, drinking water and digital infrastructure; relevant digital service providers | Appropriate and proportionate security measures; notify incidents with a significant impact on service continuity | No later than 72 hours after the operator is aware a NIS incident has occurred | Sector competent authority / NIS enforcement authority |
| UK GDPR and Data Protection Act 2018 | Any controller processing personal data | Appropriate technical and organisational measures; notify notifiable personal data breaches | Without undue delay and, where feasible, not later than 72 hours after becoming aware | Information Commissioner's Office |
| FCA operational resilience (PS21/3); PRA SS1/21 | FCA-regulated firms; dual-regulated firms for SS1/21 | Identify important business services, set impact tolerances, map and test, invest to stay within tolerance | Firm-set, against the tolerances you have declared | FCA; PRA for dual-regulated firms |
| DORA, Regulation (EU) 2022/2554 | Twenty types of EU financial entity and their ICT third-party service providers | ICT risk management, incident reporting, resilience testing and third-party oversight | Set by DORA and its technical standards | EU and national financial supervisors |
| Cyber Essentials | Voluntary, but often required contractually by buyers | Five technical controls, self-assessed or independently tested | Not applicable | NCSC scheme certification bodies |
| NCSC Cyber Assessment Framework v4.0 | CNI, NIS-regulated organisations, core government functions | Meet contributing outcomes across the framework's objectives and principles, to a Basic or Enhanced profile | Not applicable | Your sector regulator, using the CAF |
| Telecommunications (Security) Act 2021 | Providers of public electronic communications networks and services | Take security measures; respond to security compromises; inform others of compromises | Set under the Act's duties, not a single fixed clock | Ofcom |
| Cyber Security and Resilience (Network and Information Systems) Bill | Would amend the NIS Regulations 2018; final scope set on enactment | Not yet law: in Lords committee stage as of 4 September 2026 | Not yet in force | Not yet in force |
Most UK organisations sit under two or three of these at once, and the overlap is larger than the difference. Nearly every regime asks the same three questions: can you show your controls, can you detect an incident, and can you report it in time.
The Cyber Security and Resilience Bill: where it stands
The Bill is the biggest pending change. Its full title is the Cyber Security and Resilience (Network and Information Systems) Bill. It was introduced in the Commons on 12 November 2025, completed all Commons stages on 16 June 2026, was introduced in the House of Lords on 17 June 2026, had its Lords second reading on 14 July 2026, and began its Lords committee stage in Grand Committee on 1 September 2026. It has not received Royal Assent. Parliament's Bill page is the authority for the current stage; check it before you build a timeline on it.
The government's collection on gov.uk describes the Bill's purpose as to "reform and add to the existing Network and Information Systems (NIS) Regulations 2018, to increase UK defences against cyber attacks, better protecting the services the public rely on".
Say it plainly: this is not yet law. Nothing in the Bill obliges you to do anything until it receives Royal Assent, and then only as each provision is switched on by commencement regulations. The law you are held to today is the NIS Regulations 2018.
Direction is still safe to plan for. The Bill amends NIS rather than replacing it, so the duties it strengthens are the ones NIS already contains: proportionate risk management, incident notification, and supply chain accountability. Our NIS2 compliance guide covers how the EU's own NIS revision reshaped those duties.
The NIS Regulations 2018, as amended
The NIS Regulations 2018 are the current UK statutory regime for essential services. Schedule 2 sets the sectors: electricity, oil, gas, air transport, water transport, rail transport, road transport, healthcare, drinking water supply and distribution, and digital infrastructure including top-level domain name registries, DNS resolver and authoritative hosting services, and internet exchange points.
The notification duty is the one to design around. Regulation 11 requires an operator of essential services to notify its competent authority "without undue delay and in any event no later than 72 hours after the operator is aware that a NIS incident has occurred". Significance turns on the number of users affected, the duration, and the geographical area. The notification must cover the operator's name and services, when the incident occurred and for how long, its nature and impact, and any cross-border impact.
Penalties are banded. Regulation 18 sets maxima of £1,000,000 for a non-material contravention, £8,500,000 for a material one, and £17,000,000 where a material contravention has or could have created a significant risk to or impact on the service.
Two consequences follow. The clock starts at awareness, not containment, so slow detection eats the window before your incident process begins. And the notification demands scope: how long, how many, where. That comes from a joined-up case record, not an alert queue.
UK GDPR, the DPA 2018 and the 72-hour breach clock
Every organisation processing personal data is in scope here, regardless of sector. Article 33 of the UK GDPR requires that the controller "shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to" the Commissioner, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Notify later than 72 hours and you must give reasons for the delay. The notification must describe the nature of the breach, the individuals affected, the likely consequences, and the remedial measures taken or proposed, and you must keep records that let the Commissioner verify compliance.
The financial exposure sits in section 157. The standard maximum is £8,700,000 or 2% of an undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher. The higher maximum is £17,500,000 or 4% of that turnover, whichever is higher.
Note the shape of the duty. It is not "report a breach" but "describe the nature, the affected individuals, the likely consequences and your remediation, inside 72 hours". That is forensic work under time pressure.
Cyber security and FCA compliance in 2026
For FCA-regulated firms, cyber security sits inside the operational resilience regime, not beside it. The FCA's PS21/3 Building operational resilience set two dated milestones. By 31 March 2022, firms had to have identified their important business services, set impact tolerances for the maximum tolerable disruption, and carried out mapping and testing to a level of sophistication necessary to do so, identifying any vulnerabilities in their operational resilience. By 31 March 2025, firms had to have performed mapping and testing so that they are able to remain within impact tolerances for each important business service, and to have made the necessary investments to enable them to operate consistently within those tolerances.
That second deadline has passed. The FCA is now supervising against a standard firms were required to have already met. Cyber incidents are the obvious severe-but-plausible disruption scenario, so a firm that cannot evidence detection and recovery within its declared tolerance has an operational resilience gap, not just a security gap.
Dual-regulated firms also sit under the PRA's SS1/21 Operational resilience: Impact tolerances for important business services, published 11 March 2022 and effective from 31 March 2022. The systems and controls expectations behind all of this sit in the FCA Handbook's SYSC sourcebook, drafted as outcomes rather than a control checklist. That makes evidence the deliverable.
DORA, if you have EU exposure
DORA is EU law, not UK law, but it reaches UK firms through their EU entities, EU clients and their role as ICT providers to EU financial entities. It is Regulation (EU) 2022/2554, and it entered into application on 17 January 2025. It applies to 20 different types of financial entity, including banks, insurers and investment firms, and to the ICT third-party service providers serving that sector.
The reach into third parties is the part UK firms underestimate. Sell technology services to an EU financial entity and DORA's third-party provisions land on you through your customer's contracts, even though you are not directly supervised. Our DORA compliance guide covers the ICT risk management, incident reporting and testing pillars.
Cyber Essentials and the NCSC CAF
Neither is a statute, and that is why they matter: regulators and buyers use them as yardsticks.
Cyber Essentials is described by the NCSC as the minimum standard of cyber security recommended by the government for organisations of all sizes. It covers five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. Cyber Essentials Plus assesses the same five controls but adds independent technical testing rather than self-assessment, giving higher assurance at a higher cost. The NCSC page notes pricing tiered from £320 plus VAT, and that a growing number of organisations require suppliers to be certified to bid for work.
The Cyber Assessment Framework is the heavier instrument. Version 4.0 was published on 18 April 2024. The NCSC describes it as a tool to help organisations assess and improve their cyber security and resilience, comprising a set of objectives and underlying principles, outcomes and indicators of good practice. It offers a Basic Profile for baseline expectations across all sectors and an Enhanced Profile for organisations facing more sophisticated, well-resourced threat actors. Its users are organisations subject to the NIS Regulations, UK Critical National Infrastructure, organisations managing cyber-related risks to public safety, and public sector organisations supporting core government functions.
If you are NIS-regulated, treat the CAF as the exam paper. Regulators use it for oversight, so a CAF self-assessment with evidence attached tells you where you stand before someone else decides.
The Telecommunications (Security) Act 2021
Telecoms has its own regime. The Telecommunications (Security) Act 2021 places duties on providers of public electronic communications networks and services: section 1 requires measures to identify and reduce the risks of security compromises, section 2 requires an appropriate response when one occurs, and section 4 covers informing others. Ofcom enforces, with powers to assess compliance and require corrective action.
We do not quote a maximum penalty for this regime, because the figure is set in the enforcement provisions rather than on the face of the duties. Check those sections and Ofcom's published guidance directly if the number matters to your board paper.
What all of this asks of your security operation
Strip out the sector detail and the regimes converge on four capabilities.
Detect fast enough for the clock. Two separate 72-hour windows start at awareness. If mean time to detect is measured in weeks, the reporting duty is already unmeetable, and a regulator will read that as a control failure.
Scope an incident, not just alert on it. Both NIS regulation 11 and UK GDPR Article 33 demand duration, extent and impact. That requires correlated telemetry across endpoint, network, identity and cloud in one case record.
Show your working. SYSC outcomes, the CAF's indicators of good practice and the statutory records requirement are all evidence duties. A verdict you cannot reconstruct is not evidence.
Report to the board in the same language. Impact tolerances, essential services and notifiable breaches are business terms. Our guide to CISO board reporting covers translating detection metrics into them.
Volume makes this hard. In one Fortune 500 environment SenseOn protects, 33.4B events are analysed every month, and across more than 30 million investigated cases over a rolling twelve-month window confirmed true positives run at 0.68%. No compliance process built on a human reading a queue survives that ratio. SenseOn resolves 92.5% of incidents under human governance, reports a detect-and-respond time of <20 min, and carries a Decision Trace on every action. More on the machine first pass in AI in threat detection; sector mapping is on our solutions pages.
Finally, certification is not detection. Cyber Essentials and ISO 27001 evidence that controls exist. They do not evidence that you would notice an intrusion on a Tuesday night. Our ISO 27001 controls guide covers the control framework and our first 60 minutes of incident response covers the detection side.
Frequently asked questions
What UK cyber security regulations apply in 2026?
It depends on sector, not size. The NIS Regulations 2018 cover essential services and digital infrastructure. UK GDPR and the Data Protection Act 2018 cover anyone processing personal data. FCA and PRA operational resilience rules cover regulated firms. DORA reaches UK firms with EU exposure, and the Telecommunications (Security) Act 2021 covers telecoms providers.
Has the Cyber Security and Resilience Bill become law?
Not yet. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the Commons on 12 November 2025, completed all Commons stages on 16 June 2026, and began its Lords committee stage on 1 September 2026. It has not received Royal Assent. Its duties bite only after assent and the commencement regulations that follow.
How long do I have to report a cyber incident in the UK?
Two separate 72-hour clocks, both starting at awareness. Regulation 11 of the NIS Regulations 2018 requires notification no later than 72 hours after the operator is aware a NIS incident has occurred. Article 33 of the UK GDPR requires notification to the Commissioner without undue delay and, where feasible, within 72 hours.
What is the FCA deadline for operational resilience?
PS21/3 set two. By 31 March 2022 firms had to identify important business services, set impact tolerances and carry out mapping and testing. By 31 March 2025 firms had to have performed mapping and testing so they can remain within impact tolerances for each important business service, and made the necessary investments to operate consistently within them.
Does DORA apply to UK financial services firms?
DORA is EU law, Regulation (EU) 2022/2554, and it entered into application on 17 January 2025. It reaches UK firms through EU subsidiaries, EU clients, and through the role of ICT third-party service providers to EU financial entities. If you supply technology to an EU financial entity, DORA lands on you contractually.
Is Cyber Essentials enough for UK compliance?
No. The NCSC calls it the minimum standard recommended by government, covering five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. It evidences that controls exist. It does not evidence that you can detect, scope and report an incident within a 72-hour statutory window.