New legislation will raise the bar for cybersecurity across the UK, and the penalties are significant
▶ WATCH THE VIDEO
This blog post accompanies our video discussion on the UK Cyber Security and Resilience Bill, where Intercede’s experts break down what the bill means for organisations, the key requirements to prepare for, and how to position your authentication strategy ahead of the legislation. Watch the full video for the detailed conversation.
A New Era for UK Cybersecurity Regulation
The UK government is introducing the Cyber Security and Resilience Bill, and it is set to be one of the most significant pieces of cybersecurity legislation the country has seen. Introduced to Parliament on 12 November 2025 and progressing through its committee stage in early 2026, the bill aims to strengthen the UK’s cyber defences and protect essential public services. In our accompanying video, Intercede’s experts discuss what this means in practice and how organisations should be responding.
What the Bill Covers
The bill builds on the existing Network and Information Systems (NIS) Regulations, expanding their scope and strengthening enforcement. Key provisions include enhanced technical and methodological security requirements aligned with the NCSC’s Cyber Assessment Framework, expanded reporting obligations for significant cyber incidents, broader scope covering more organisations and supply chains, and notably, the introduction of requirements around passwordless authentication and stronger identity controls. As we discuss in the video, the passwordless requirement is particularly significant for organisations still relying primarily on password-based access.
The Penalties
The potential penalties for non-compliance are substantial. The standard maximum is £10 million or 2% of global turnover. For more serious breaches, the higher maximum reaches £17 million or 4% of worldwide turnover. These penalties are designed to ensure that cybersecurity is treated as a board-level priority, not an afterthought.
Timeline and Implementation
The bill completed its second reading on 6 January 2026 and has progressed through committee stage. The government intends to consult on implementation proposals throughout 2026, with Royal Assent expected later in the year. However, phased implementation means the full requirements may not come into force until 2028, giving organisations time to prepare, but as our experts stress in the video, not time to waste.
How to Start Preparing
Organisations should begin by assessing their current cybersecurity posture against the NCSC Cyber Assessment Framework. Key areas to focus on include reviewing and strengthening authentication mechanisms (the bill specifically references passwordless authentication), implementing robust incident detection and reporting processes, auditing supply chain security, and ensuring board-level governance of cybersecurity risk.
How Intercede Can Help
Intercede’s MyID product suite directly addresses several of the bill’s likely requirements. MyID MFA provides phishing-resistant, passwordless authentication using FIDO passkeys and hardware tokens. MyID PSM ensures passwords are checked against known breaches. And MyID CMS delivers certificate-based authentication for the highest-assurance environments. Together, they provide a comprehensive authentication platform that can help organisations meet both current and forthcoming regulatory requirements.
The Time to Act Is Now
Do not wait for the final regulations to be published. Organisations that start strengthening their authentication and cybersecurity posture now will be far better positioned when the bill comes into force, and far better protected against the threats that motivated the legislation in the first place.
▶ WATCH THE FULL DISCUSSION
For the expert discussion on the Cyber Security and Resilience Bill, including the specific authentication requirements, compliance timelines, and practical steps to prepare, watch our video: “The UK Cyber Security and Resilience Bill Is Coming, Here’s How to Prepare.”