The UK Government is proposing to bring data centres within a mandatory cyber security and resilience regime. The Cyber Security and Resilience (Network and Information Systems) Bill ("Bill"), introduced to Parliament in November 2025, would amend the NIS Regulations 2018 to designate certain data centres as essential services.

If enacted, many operators would face new legal duties, including implementing appropriate security and resilience measures, reporting serious incidents, and engaging proactively with regulators. The reforms are intended to address a regulatory gap: despite their critical role in the digital economy, data centres have not previously been subject to minimum statutory cyber or resilience standards. It will also mean that the UK's legislative protections match those in Europe as the Bill reflects the key elements of the EU's NIS2 Regulation.

Who will be in scope?

Not all data centres will be regulated.

Those in scope are:

  • Where there is a "data centre service", meaning a dedicated physical facility (such as a data hall) providing IT housing together with supporting infrastructure, including power supply, cooling and environmental controls, security systems, and back‑up or resilience measures. So smaller server rooms or non‑purpose‑built facilities are not caught.
  • Colocation data centres (i.e. hosting multiple clients) with a rated IT load (i.e. the normal power supplied to IT equipment) of more than 1MW. Operators of these facilities may be designated as Operators of Essential Services (OES).
  • Enterprise data centres (i.e. operated solely for one organisation’s own use) with a rated IT load of 10MW or more. The higher capacity recognises that disruption to smaller enterprises are less likely to impact services on which significant numbers of consumers and businesses rely.
  • Facilities operated by both private sector companies and crown-operators, with some limited exemptions for certain national security or intelligence sites.

The Government has indicated that scope thresholds may be adjusted over time to reflect changes in industry scale or risk.

What are the new obligations for operators?

Data centre operators who are in scope will be subject to core security and incident management duties, broadly aligned with those already applying to other critical sectors such as energy and finance. The key obligations are:

  1. Appropriate and proportionate security measures: Operators must manage cyber risks affecting the networks and information systems that support their data centre services by implementing suitable technical and organisational measures. This includes both cyber security controls and operational resilience measures to maintain continuity of service (such as redundancy and recovery planning). While the Bill does not prescribe detailed standards, a statutory Code of Practice issued by the Department for Science, Innovation and Technology (DSIT) will give guidance on what is “appropriate and proportionate”.
  2. Incident reporting: Operators must notify Ofcom in writing of incidents that have, or could have had, a significant impact on service continuity or security. This duty is intended to cover not only major outages and breaches but also serious “near misses”. The early notification must be within 24 hours of becoming aware of the incident, with fuller details within 72 hours. The precise reporting thresholds will be set out in secondary legislation, likely taking into account factors such as the scale, duration and impact of an incident.
  3. Notification and information duties: Designated operators must notify Ofcom within three months of designation and provide prescribed business and contact information. They must keep this information up to date and comply with any information requests from the regulator. Failure may result in enforcement action.

Regulator roles: DSIT and Ofcom

The new regime will be overseen by joint competent authorities, with distinct but complementary roles for DSIT and Ofcom.

  • DSIT is the policy lead. It will designate which operators are treated as essential services, set the high‑level security and resilience framework, and issue the statutory Code of Practice that interprets the regime. This ensures the framework remains aligned with national security priorities and technological developments.
  • Ofcom will act as the operational regulator. It will receive notifications and incident reports, monitor compliance through information requests and inspections, and enforce the regime where necessary. Ofcom will have powers to require remedial action and impose financial penalties, including potentially significant fines for ongoing non-compliance.

The Government has emphasised that the regime will be implemented collaboratively, with ongoing engagement between regulators and industry.

What should data centre operators do now?

Security is already a key service provided by operators to protect their mechanical and electrical equipment (e.g. generators, transformers, cooling solutions) and customer's equipment. Some operators are already subject to contractual flow-downs from the UK's material outsourcing regime or the EU's Digital Operational Resilience Act (DORA) which also include incident notification, resilience, security and audit requirements.

The Bill's requirements focus on the operator's own networks and systems. Although the Bill is not yet law and could still change, operators who are in scope should begin preparing for the likely requirements:

  • Initiate a compliance gap analysis: Review existing cyber security and operational resilience measures, including risk management processes, incident response and business continuity planning, and the resilience and testing of critical systems (such as power, cooling and networks). Identify any gaps against the expected “appropriate and proportionate” standard, using existing NIS guidance or international benchmarks (such as ISO 27001) where helpful.
  • Develop an incident reporting protocol: Put in place internal procedures to identify, assess and escalate incidents that may be reportable. Ensure relevant staff understand escalation routes, and plan how customers will be informed in the event of serious disruption, reflecting the Government’s emphasis on transparency.
  • Prepare for the notification requirement: Assemble the information likely to be required for initial notification to Ofcom, including corporate details and a designated security contact, and identify who will manage regulatory communications.
  • Engage leadership and stakeholders: Brief senior management and the board on the upcoming regime, recognising that compliance will require governance oversight, investment and cross-functional co-ordination.

Implementation timeline and next steps

The Bill is currently progressing through the House of Commons and should receive Royal Assent later in 2026. Its provisions would not take effect immediately: commencement is intended to follow via secondary legislation and DSIT will need to produce new Codes of Practice, allowing a lead-in period for operators to prepare for compliance.

What this means for data centre operators

The Cyber Security and Resilience Bill brings to life the designation of data centres as critical infrastructures , bringing them into a formal regulatory framework that reflects their critical role in the economy and public services. Once in force, operators above the relevant thresholds will be expected to demonstrate robust cyber security and resilience measures and be accountable to Ofcom for service continuity. While key details are still developing, the direction of travel is clear: greater accountability and higher security and resilience standards across the data centres sector.

If you would like to discuss the proposed Cyber Security and Resilience Bill and what it could mean for your organisation, please get in touch with Jocelyn Paulley.