Cyber bill advances with data centres in scope

Cyber bill advances with data centres in scope

The UK’s Cyber Security and Resilience Bill has completed Lords Grand Committee scrutiny with qualifying data centres set to enter the NIS regime.

Cyber bill advances with data centres in scope
Summary
  • The bill was reprinted as amended in Grand Committee on 7 September.
  • Qualifying data centres are set to become operators of essential services, with Ofcom as operational regulator.
  • Detailed thresholds, technical obligations, and reporting requirements will continue to be developed through the regulatory process.

The UK’s Cyber Security and Resilience (Network and Information Systems) Bill has completed House of Lords Grand Committee scrutiny, advancing legislation that will bring qualifying data centres into the country’s essential-services cyber and operational-resilience regime.

A version of the bill amended in Grand Committee was published on 7 September, moving the legislation towards its next stage in the Lords.

For data-centre operators, the central change is the government’s plan to bring qualifying facilities into the Network and Information Systems regime as operators of essential services.

Ofcom is intended to become the competent authority and operational regulator for the sector.

Government guidance says operators that fall in scope will have to inform Ofcom and provide required basic information within three months of being designated as an operator of essential services.

The regulator is also expected to receive powers to request information, conduct inspections, interview staff, and enter premises to examine infrastructure. Compliance assessments will be guided by a statutory code of practice.

Failure to comply can lead to enforcement action, including financial penalties and daily fines for continuing breaches. Ofcom may also direct interim security measures where required.

The change gives formal regulatory weight to a resilience issue that has already moved closer to government infrastructure policy. UK data centres were designated as critical national infrastructure in 2024, reflecting their role in supporting public services, businesses, communications, and wider economic activity.

Critical national infrastructure status, however, is not itself the same as a detailed operating regime. The NIS changes add a regulator, statutory obligations, information requirements, inspection powers, and enforcement.

The operational effect will reach beyond conventional information-security policy.

A serious data-centre outage can originate in cyber systems, operational technology, network infrastructure, power distribution, cooling, physical access, suppliers, or dependencies outside the site. Managing resilience therefore requires coordination between facility, network, security, and operational teams.

Operators may need to demonstrate not only that controls exist, but that risks are identified, systems are maintained, incidents are escalated, suppliers are governed, and recovery arrangements are tested.

That could increase the regulatory importance of maintenance records, access controls, monitoring, incident response, continuity testing, asset management, and evidence showing how redundant systems behave under failure conditions.

Some of the detailed obligations remain to be settled. Government guidance says technical requirements and sector-specific rules will continue to be developed with Ofcom and industry, while powers in the legislation allow duties to evolve as risks change.

That detail will determine which operators fall within scope, what incidents have to be reported, and what evidence Ofcom expects when assessing whether controls are appropriate and proportionate.

The bill’s Lords passage has also generated debate over exceptional emergency powers, including an amendment proposing a mechanism to shut data centres during an AI security emergency. That proposal did not displace the wider structure of the legislation.

The enduring change is broader: qualifying data centres are moving into an enforceable essential-services framework under a named regulator.

Completion of Grand Committee scrutiny removes another procedural step, but operators still do not have the complete rulebook. The next regulatory questions concern thresholds, implementation, incident criteria, codes of practice, and the level of evidence facilities will need to provide to demonstrate resilience in live operation.


Stay updated with the latest insights and trends in the data centre industry by subscribing to our newsletter.

← Back

Thank you for your response. ✨