Purpose
To support internal assessment of the Cyber Security and Resilience (Network and Information Systems) Bill ahead of Lords Committee stage.
Current position
The Bill is before the House of Lords Committee and is scheduled for sittings on 1, 3, 7 and 9 September 2026. It was introduced in the Commons in November 2025, completed Commons Committee, Report and Third Reading stages in June 2026, and received Lords Second Reading on 14 July 2026. The latest primary-source update is dated 24 August 2026.
The Bill’s long title states that it would make provision, including amendments to the Network and Information Systems Regulations 2018, concerning the security and resilience of network and information systems used or relied on in connection with essential activities.
What this means for Northstar
Northstar’s infrastructure and consumer services operations, together with dependencies on suppliers and networked systems, make the Bill potentially relevant. The principal issues to test are whether any Northstar activities or services fall within the Bill’s scope and whether changes would affect existing cyber-security, incident-reporting, governance, assurance or supplier-management arrangements.
No conclusion should yet be drawn on precise coverage, compliance cost, operational impact or implementation burden. The source does not include the Bill’s clause text, committee amendments, detailed duties or implementation timetable, and no internal evidence has yet been supplied.
Immediate internal work
- Legal should map Northstar’s activities and regulated services against the Bill’s potential scope and identify existing NIS Regulations obligations.
- Cyber Security should summarise current governance, risk management, incident-reporting, assurance and resilience arrangements relevant to potentially in-scope systems.
- Operations should identify essential services, operational dependencies and critical suppliers that could be affected.
- Procurement or Supply Chain should identify material cyber-security requirements and dependencies in critical supplier contracts.
- Finance should provide an initial view of any material implementation or assurance costs once the scope assessment is clearer.
Parliamentary monitoring priorities
For each Lords Committee sitting, capture:
- amendments affecting the definition or scope of essential activities and regulated services;
- new or amended cyber-security, resilience, governance and assurance duties;
- incident-reporting thresholds, deadlines and information requirements;
- obligations relating to suppliers, managed services or third-party dependencies;
- enforcement powers, penalties and regulator responsibilities;
- transitional arrangements, commencement provisions and implementation periods;
- Government explanations of expected costs, proportionality and organisational readiness.
Decision required
Once Legal, Cyber Security and Operations complete the applicability scan, the Head of Public Affairs should decide whether the potential impact justifies developing a parliamentary engagement position. No external engagement or correspondence is proposed at this stage.