Reference

The UK rules, in brief

A short orientation to the rules that shape cybersecurity for UK essential services. This is a plain summary to get your bearings, not legal advice — check the current text and your own obligations before relying on any of it.

The NIS Regulations 2018

The Network and Information Systems Regulations 2018 are the current baseline. They place security and incident-reporting duties on two groups:

  • Operators of essential services (OES) — organisations in sectors such as energy, water, transport, health and digital infrastructure.
  • Relevant digital service providers (RDSPs) — certain online marketplaces, search engines and cloud providers.

If you fall in scope, you’re expected to manage the risks to the systems your service depends on, and to report significant incidents to your regulator.

The Cyber Security and Resilience Bill

The regime is being widened. The Cyber Security and Resilience Bill, introduced to Parliament in late 2025, is set to bring more organisations into scope (managed service providers among them), strengthen incident-reporting, and give regulators more teeth. The detail will firm up as it moves through Parliament, but the direction is clear: broader coverage and higher expectations.

The frameworks that tell you how

The law says you must manage cyber risk; the frameworks are how you actually do it and show it:

  • NCSC Cyber Assessment Framework (CAF). The UK’s outcome-based framework for essential-service cyber resilience — the most relevant “how” for organisations in scope.
  • Cyber Essentials. A recognisable baseline of fundamental controls; a sensible floor, not a ceiling.

Internationally recognised frameworks — CIS Controls, NIST CSF, ISO/IEC 27001 — line up with the same fundamentals and are a good way to structure and evidence the work.

The one honest caveat

A framework is how you evidence that your programme is complete; it isn’t itself what the law demands. No supplier can sell you compliance, and no single tool delivers it. The dull truth is that most of it comes down to knowing what you have, reducing what you expose, and keeping the basics current — the same fundamentals, whichever framework you map them to.