Jocelyn S Paulley
Partner
Co-leader of Data Protection and Cyber Security sector (UK)
Article
The UK Government is proposing to bring data centres within a mandatory cyber security and resilience regime. The Cyber Security and Resilience (Network and Information Systems) Bill ("Bill"), introduced to Parliament in November 2025, would amend the NIS Regulations 2018 to designate certain data centres as essential services.
If enacted, many operators would face new legal duties, including implementing appropriate security and resilience measures, reporting serious incidents, and engaging proactively with regulators. The reforms are intended to address a regulatory gap: despite their critical role in the digital economy, data centres have not previously been subject to minimum statutory cyber or resilience standards. It will also mean that the UK's legislative protections match those in Europe as the Bill reflects the key elements of the EU's NIS2 Regulation.
Not all data centres will be regulated.
Those in scope are:
The Government has indicated that scope thresholds may be adjusted over time to reflect changes in industry scale or risk.
Data centre operators who are in scope will be subject to core security and incident management duties, broadly aligned with those already applying to other critical sectors such as energy and finance. The key obligations are:
The new regime will be overseen by joint competent authorities, with distinct but complementary roles for DSIT and Ofcom.
The Government has emphasised that the regime will be implemented collaboratively, with ongoing engagement between regulators and industry.
Security is already a key service provided by operators to protect their mechanical and electrical equipment (e.g. generators, transformers, cooling solutions) and customer's equipment. Some operators are already subject to contractual flow-downs from the UK's material outsourcing regime or the EU's Digital Operational Resilience Act (DORA) which also include incident notification, resilience, security and audit requirements.
The Bill's requirements focus on the operator's own networks and systems. Although the Bill is not yet law and could still change, operators who are in scope should begin preparing for the likely requirements:
The Bill is currently progressing through the House of Commons and should receive Royal Assent later in 2026. Its provisions would not take effect immediately: commencement is intended to follow via secondary legislation and DSIT will need to produce new Codes of Practice, allowing a lead-in period for operators to prepare for compliance.
The Cyber Security and Resilience Bill brings to life the designation of data centres as critical infrastructures , bringing them into a formal regulatory framework that reflects their critical role in the economy and public services. Once in force, operators above the relevant thresholds will be expected to demonstrate robust cyber security and resilience measures and be accountable to Ofcom for service continuity. While key details are still developing, the direction of travel is clear: greater accountability and higher security and resilience standards across the data centres sector.
If you would like to discuss the proposed Cyber Security and Resilience Bill and what it could mean for your organisation, please get in touch with Jocelyn Paulley.
CECI NE CONSTITUE PAS UN AVIS JURIDIQUE. L'information qui est présentée dans le site Web sous quelque forme que ce soit est fournie à titre informatif uniquement. Elle ne constitue pas un avis juridique et ne devrait pas être interprétée comme tel. Aucun utilisateur ne devrait prendre ou négliger de prendre des décisions en se fiant uniquement à ces renseignements, ni ignorer les conseils juridiques d'un professionnel ou tarder à consulter un professionnel sur la base de ce qu'il a lu dans ce site Web. Les professionnels de Gowling WLG seront heureux de discuter avec l'utilisateur des différentes options possibles concernant certaines questions juridiques précises.
Gowling WLG est un cabinet juridique international constitué des membres de Gowling WLG International Limited, une société à responsabilité limitée par garanties enregistrée en Angleterre, ainsi que leurs affiliés respectifs. Les membres et affiliés constituent des entités autonomes et indépendantes. Gowling WLG International Limited promeut, facilite et coordonne les activités de ses membres, mais ne fournit pas elle-même de services aux clients. Pour en savoir davantage sur notre structure, consultez notre page Avis juridique.
© 2026 Gowling WLG Tous droits réservés