This article was originally published in May 2026.
September 2026 update:
Cyber security is no longer solely an IT concern. It is increasingly recognised as a board-level responsibility, a supply chain requirement and a core component of organisational resilience.
The UK's Cyber Security and Resilience (Network and Information Systems) Bill continues its progression through Parliament and represents one of the most significant updates to cyber security regulation since the introduction of the Network and Information Systems (NIS) Regulations 2018. The Government's intention is clear: strengthen the security and resilience of the digital systems that underpin essential services and critical infrastructure across the UK.
Whilst organisations await the final legislation, the direction of travel is already apparent. Businesses, public sector bodies and suppliers alike should be taking practical steps now to improve cyber resilience, strengthen incident response capabilities and ensure their workforce possesses the skills needed to operate securely in an increasingly complex threat landscape.
What is the Cyber Security and Resilience Bill?
The proposed legislation reforms and expands the existing Network and Information Systems Regulations, which were introduced in 2018 to improve the cyber security of organisations delivering essential services and certain digital services.
The Bill is designed to strengthen the UK's ability to withstand cyber attacks from criminal groups, hostile states and other threat actors by introducing updated security requirements, broader incident reporting obligations and enhanced powers for regulators and government.
The legislation is also intended to bring additional sectors and service providers into scope, reflecting the reality that modern organisations increasingly depend upon interconnected digital ecosystems and third-party suppliers.
Why this matters beyond regulated organisations
One common misconception is that only operators of critical national infrastructure will be affected.
In practice, the impact is likely to extend much further.
Organisations that supply products, services, cloud solutions or specialist expertise to regulated entities may find themselves facing increased scrutiny from customers, procurement teams and compliance departments. We are already seeing greater emphasis on:
supplier assurance
cyber security governance
business continuity planning
incident response preparedness
cyber security training
evidence of recognised security standards and good practice
For many organisations, customer requirements may become a more immediate driver than regulation itself.
As public and private sector organisations seek to strengthen their cyber resilience, suppliers will increasingly be expected to demonstrate robust security practices and appropriately skilled staff.
Supply Chain Security is becoming a business requirement
Recent years have shown that cyber incidents often originate through trusted third parties rather than direct attacks against the intended target.
This is one of the reasons the Government's proposed reforms place increasing emphasis on resilience across entire digital ecosystems rather than focusing solely on individual organisations.
As a result, organisations should consider reviewing:
third-party risk management processes
supplier onboarding and monitoring procedures
incident escalation workflows
backup and recovery capabilities
cyber security awareness programmes
technical skills development plans
Based on government research, these measures can help organisations strengthen resilience regardless of whether they ultimately fall directly within the scope of the legislation.
Practical steps organisations can take now
Whilst legislation continues its passage through Parliament, there is no need to wait before preparing.
Organisations should consider:
Review Incident Response Plans
Ensure roles, responsibilities and reporting processes are clearly documented and regularly tested.
Test Business Continuity and Recovery Procedures
Backups are important, but organisations should also validate that systems and data can be restored within acceptable timescales.
Reassess critical suppliers
Identify key external dependencies and understand the cyber security posture of important suppliers and service providers.
Strengthen security governance
Ensure senior leadership teams understand cyber risks and resilience obligations.
Develop Cyber Security skills
Technology alone cannot deliver resilience. Staff need the knowledge and confidence to identify threats, respond appropriately and implement secure solutions.
Review Cloud Security practices
As organisations continue to adopt cloud-based platforms and services, secure configuration, governance and ongoing monitoring remain essential components of a resilient cyber strategy.
Supporting Public Sector cyber resilience
Framework Training is pleased to have been approved as a supplier on G-Cloud 15 Lot 3: Cloud Support Services, enabling eligible public sector organisations to procure specialist technical training and support services through a recognised Crown Commercial Service framework.
The framework supports public sector organisations seeking expertise in areas including:
cyber security
cloud technologies
Microsoft Azure
Microsoft 365 security
security operations
incident response
AI governance and security
secure cloud adoption
As cyber resilience requirements continue to evolve, skills development remains one of the most effective and sustainable ways for organisations to improve their security posture.
Looking ahead
Although the final shape of the legislation may continue to evolve as it progresses through Parliament, the strategic message is already clear: organisations need to think beyond prevention and focus on resilience.
Cyber incidents cannot always be avoided. What increasingly matters is an organisation's ability to withstand disruption, respond effectively and recover quickly.
The organisations that invest now in governance, resilience, supplier assurance and workforce skills will be best positioned to meet future obligations and maintain the trust of customers, partners and regulators alike.
June 2026 legislation update: The UK Cyber Security and Resilience Bill is returning to the House of Commons for its critical report stage and third reading on Wednesday, June 10, 2026. As the Bill nears the final stages of the legislative process, the window for engineering teams to transition from "reactive security" to "engineered compliance" is closing fast. Below, we look at the core requirements teams must prepare for before the bill passes into law.
Original article - May 2026
For years, elements like Software Bills of Materials (SBOMs), automated vulnerability scanning, and secure-by-design principles were considered "gold standards" for elite engineering teams - but often neglected when the focus was on continuous deployment of new features.
With the introduction of the UK Cyber Security and Resilience Bill (and its EU counterpart, the Cyber Resilience Act), these are no longer optional extras. The defined spectrum of Relevant Managed Service Providers (RMSPs) is widening, too.
If you build, sell, or operate digital services in the UK, you should expect increasing scrutiny of your software supply chain and third-party dependencies. Organisations are increasingly expected to understand, monitor and mitigate cyber risks across their wider digital ecosystem.

"Compliance used to be a documentation exercise ...in 2026, it’s an engineering exercise. If you can’t sign your images and scan your manifests automatically, you aren't ready for this bill."
- Tom Walker, Technical Director, Framework Training
What engineering teams should prepare for
The legislation focuses on moving away from "reactive" security and toward demonstrable resilience. Key pillars include:
Secure-by-Design by default
Security can't be a "bolt-on" at the end of a sprint; it must be the foundation of the architecture.Supply Chain Transparency
You must be able to produce an SBOM (Software Bill of Materials) - essentially a list of ingredients for your software-on demand.Vulnerability Management
Fixed timelines for patching and reporting are no longer suggestions; they are mandates.Evidence-based Assurance
Regulators will expect to see logs, audit trails, and cryptographic proof of secure workflows.
Turning legislation into implementation
At Framework Training, we believe the best way to prepare for new legislation isn't to hire more lawyers, but to build better engineering habits. We’ve aligned our 2026 curriculum to address these exact regulatory hurdles.
1. Mastering the Container Supply Chain
Containers are the heartbeat of modern infrastructure, but they are also a primary source of supply chain risk. Our new Docker Security Workshop is designed specifically to address the legislative focus on transparency and provenance.
In this session, we move beyond basic builds to look at image signing, manifest management, and generating CycloneDX/SPDX-compliant SBOMs.
2. Shifting Security Left with DevSecOps
Compliance shouldn't slow down your deployment. The "DevSecOps" mindset integrates automated security gates directly into your CI/CD pipelines, providing the "evidence-based assurance" that regulators demand without sacrificing velocity.
3. Language-Specific Secure Coding
A "one-size-fits-all" security talk isn't enough. The UK Bill emphasises "Secure-by-Design" code, which looks very different in a memory-safe language like Java or Python than it does in a systems-level environment. We provide deep-dive workshops tailored to your specific stack - here are a few examples:
The bottom line
The UK Cyber Security and Resilience Bill is a fundamental step change in national security. For engineering teams, it represents an opportunity to formalise better ways of working. By investing in these skills now, you aren't just checking a compliance box - you’re building a more reliable, more professional, and more resilient business.