Jocelyn S Paulley
Partner
Co-leader of Data Protection and Cyber Security sector (UK)
Article
The UK Government is proposing to bring data centres within a mandatory cyber security and resilience regime. The Cyber Security and Resilience (Network and Information Systems) Bill ("Bill"), introduced to Parliament in November 2025, would amend the NIS Regulations 2018 to designate certain data centres as essential services.
If enacted, many operators would face new legal duties, including implementing appropriate security and resilience measures, reporting serious incidents, and engaging proactively with regulators. The reforms are intended to address a regulatory gap: despite their critical role in the digital economy, data centres have not previously been subject to minimum statutory cyber or resilience standards. It will also mean that the UK's legislative protections match those in Europe as the Bill reflects the key elements of the EU's NIS2 Regulation.
Not all data centres will be regulated.
Those in scope are:
The Government has indicated that scope thresholds may be adjusted over time to reflect changes in industry scale or risk.
Data centre operators who are in scope will be subject to core security and incident management duties, broadly aligned with those already applying to other critical sectors such as energy and finance. The key obligations are:
The new regime will be overseen by joint competent authorities, with distinct but complementary roles for DSIT and Ofcom.
The Government has emphasised that the regime will be implemented collaboratively, with ongoing engagement between regulators and industry.
Security is already a key service provided by operators to protect their mechanical and electrical equipment (e.g. generators, transformers, cooling solutions) and customer's equipment. Some operators are already subject to contractual flow-downs from the UK's material outsourcing regime or the EU's Digital Operational Resilience Act (DORA) which also include incident notification, resilience, security and audit requirements.
The Bill's requirements focus on the operator's own networks and systems. Although the Bill is not yet law and could still change, operators who are in scope should begin preparing for the likely requirements:
The Bill is currently progressing through the House of Commons and should receive Royal Assent later in 2026. Its provisions would not take effect immediately: commencement is intended to follow via secondary legislation and DSIT will need to produce new Codes of Practice, allowing a lead-in period for operators to prepare for compliance.
The Cyber Security and Resilience Bill brings to life the designation of data centres as critical infrastructures , bringing them into a formal regulatory framework that reflects their critical role in the economy and public services. Once in force, operators above the relevant thresholds will be expected to demonstrate robust cyber security and resilience measures and be accountable to Ofcom for service continuity. While key details are still developing, the direction of travel is clear: greater accountability and higher security and resilience standards across the data centres sector.
If you would like to discuss the proposed Cyber Security and Resilience Bill and what it could mean for your organisation, please get in touch with Jocelyn Paulley.
NOT LEGAL ADVICE. Information made available on this website in any form is for information purposes only. It is not, and should not be taken as, legal advice. You should not rely on, or take or fail to take any action based upon this information. Never disregard professional legal advice or delay in seeking legal advice because of something you have read on this website. Gowling WLG professionals will be pleased to discuss resolutions to specific legal concerns you may have.
Gowling WLG is an international law firm comprising the members of Gowling WLG International Limited, an English Company Limited by Guarantee, and their respective affiliates. Each member and affiliate is an autonomous and independent entity. Gowling WLG International Limited promotes, facilitates and co-ordinates the activities of its members but does not itself provide services to clients. Our structure is explained in more detail on our Legal Information page.
© 2026 Gowling WLG All rights reserved.