Purpose
To assess the significance of the 7 September 2026 Lords Committee-stage debate on the Network and Information Systems Bill and identify the internal work required for Northstar.
What changed
The Government has backed cyber security standards but rejected placing the UK Cyber Security Council on a statutory footing. The work item also identifies a possible route for new training and professional-standard requirements through secondary legislation, alongside a planned consultation on cyber training, skills and professional standards.
Why this matters to Northstar
Northstar operates UK-wide infrastructure and consumer services, has a large frontline workforce and depends on timely planning and consenting decisions. If the Bill or subsequent measures create requirements for cyber training, competence or professional standards, the potential impact could extend beyond the central cyber team to operational roles, suppliers and services supporting essential activities.
The immediate issue is not whether a direct burden has been confirmed. It is whether any Northstar activities, systems, suppliers or roles fall within the relevant scope, and whether existing training and assurance arrangements would meet future requirements.
What is known
- The Bill is in Lords Committee stage, with further sittings scheduled from 1 September 2026.
- The relevant debate took place on 7 September 2026.
- The Government supports cyber standards but does not support putting the UK Cyber Security Council on a statutory footing.
- Further requirements may be developed through secondary legislation.
- A consultation on cyber training, skills and professional standards is expected.
What remains uncertain
- The substantive wording and likely timing of any secondary legislation.
- The scope of any future consultation and whether it will cover mandatory qualifications, competence frameworks, training records or regulated roles.
- Which Northstar services, systems, suppliers and workforce groups would be affected.
- Whether current NIS compliance arrangements and training pathways would meet any future requirements.
- Whether Northstar has an approved position on professional standards or the role of the UK Cyber Security Council.
Recommended internal work
- Legal and Cyber Security should map potentially in-scope activities, systems, suppliers, roles and current NIS obligations.
- Operations should identify operational teams and frontline roles with cyber responsibilities or access to relevant systems.
- HR should provide current cyber training pathways, role profiles and assurance processes.
- Public Affairs should monitor the Bill, Committee proceedings, the Government consultation and any draft secondary legislation.
- Following the exposure assessment, the Head of Public Affairs and Legal should decide whether an organisational position is required and whether consultation engagement would be useful.
Provisional assessment
Relevance remains high enough for active work because Northstar’s infrastructure and consumer-service footprint could intersect with essential-activity requirements, while the skills and standards framework is still developing. The immediate priority is evidence gathering rather than external engagement. No external message has been drafted or sent.