Cyber Security and Resilience Bill: what it changes for guarding

If you guard a data centre in the UK, your client is probably not regulated for cyber security today. When the Cyber Security and Resilience Bill completes its passage, they will be. And the duties they inherit reach the loading bay, not just the server rack.

In short: The Bill is in the House of Lords and is not law yet. It overhauls the NIS Regulations 2018 rather than replacing them, pulls data centres and managed service providers into scope, and introduces 24-hour and 72-hour incident reporting plus a near-miss duty. Guarding contractors will feel it through their clients' supply chains.

Security officer scanning an NFC checkpoint outside a server room in a data centre at night

Where the Bill actually stands

Getting this right matters, because a good deal of commentary writes about the Bill as though it were already in force. It is not.

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025. It had its Commons second reading on 6 January 2026, went through committee in January and February, and completed Commons report stage and third reading on 10 June 2026. It was introduced to the House of Lords on 17 June 2026, with second reading there scheduled for 14 July 2026. Lords committee and report stages follow after that.

Royal Assent is widely expected late in 2026, with the new duties phased in over a period that runs towards 2028. Two consequences follow for anyone planning a bid or a compliance budget. First, nothing in the Bill binds your clients today. Second, the detail that will matter most, including thresholds and the codes built on the NCSC Cyber Assessment Framework, arrives through secondary legislation after Assent. Anyone quoting you firm figures from the Bill text alone is quoting a moving target.

One structural point is settled and worth holding onto: the Bill amends the existing NIS Regulations 2018 rather than sweeping them away. The regime your regulated clients already work to is the foundation, not a legacy system awaiting replacement.

The scope change that reaches guarding directly

The headline expansion brings data centres and managed service providers into scope. For a guarding contractor this is the single most consequential line in the Bill, and it has nothing to do with your own IT.

Data centres are guarded buildings. They have perimeters, loading bays, plant rooms, and a stream of engineers and delivery drivers who need escorting. That physical layer is almost always delivered by a contractor. When the operator becomes a regulated entity, the question they must answer about their own supply chain lands on the firm that controls the door.

The same logic applies to managed service providers, though less visibly. An MSP operating from a shared building still has to account for who can physically reach its equipment.

The practical effect is that a portfolio which contains no regulated clients today may contain several by 2028, without you winning a single new contract. Worth identifying now which of your sites sit in that category, because those are the clients who will arrive with new questions attached to an existing contract.

Reporting on the clock, and the near-miss duty

The Bill introduces incident reporting at 24 hours and 72 hours. That structure is familiar to anyone who has followed the EU regime, and the operational implication is the same: the clock starts when the incident becomes known, not when the internal review concludes.

The provision that deserves more attention than it gets is the near-miss reporting duty. Reporting an incident is one thing. Reporting something that could have become an incident but did not is a different discipline entirely, because it depends on someone having recorded an event that, by definition, caused no damage.

Consider what a near miss looks like in physical terms. Someone tailgates through a controlled door and is challenged. A contractor turns up without an escort and is turned away. A plant room is found unlocked and secured. None of these produce a loss. All of them are exactly the kind of thing a regulated client may need to surface. If your officers record them only when something goes wrong, the near-miss category is invisible by design.

This is not a call to log everything. It is a reason to make sure the recording of a challenged access attempt is as routine, and as time-stamped, as the recording of a completed patrol.

Facility security manager reviewing access control and incident data on a tablet in front of technical plant

Penalties, and why they change client behaviour

The penalty tiers reported for the Bill are substantial: a standard maximum of £10 million or 2 per cent of global turnover, a higher tier of £17 million or 4 per cent, and daily penalties running up to £100,000 for continuing non-compliance. Regulators including the ICO and Ofcom are set to enforce.

Treat those figures as scheduled rather than binding until Assent and the accompanying secondary legislation land. The number is less important than the behaviour it produces. An organisation facing turnover-linked penalties does not absorb supply chain risk quietly; it pushes the evidence requirement down its contracts. That is how a cyber statute reaches a guarding contract, and it is why the request usually arrives from a procurement or compliance team rather than from the facilities manager you deal with day to day.

None of this makes a security contractor a regulated entity. It makes you a supplier whose documentation forms part of someone else's compliance file.

Three things worth doing before Assent

None of these requires spending against a law that has not passed.

  1. Flag the sites that come into scope. Data centres first, then managed service providers and any client whose building houses someone else's infrastructure. These are the contracts where the conversation changes without the contract changing.
  2. Check whether your officers can record a non-event. Take a challenged access attempt from last month and see whether it exists as a record. If only incidents with consequences are logged, near-miss reporting has no source data.
  3. Agree escalation timing with regulated clients now. If their clock is 24 hours from awareness, your internal route to their security contact has to be measured in minutes, not left to the next shift handover.

Security control room at night with monitors showing patrol logs and incident reports

Where the evidence comes from

The second and third steps above are the ones that fail in practice, and rarely because officers are careless. They fail because the record is scattered: the access noted in a gatehouse book, the challenge mentioned on the radio, the handover delivered verbally. Reconstructing a specific night three weeks later takes hours and produces something nobody can authenticate.

A guard tour system solves this at source by capturing the work as it happens. In COREDINATE, every checkpoint scan lands in the digital daily occurrence book with a tamper-proof timestamp and the officer's identity, so "who was at that door and when" becomes a query rather than a reconstruction. A challenged access, a contractor turned away or an unsecured plant room can be captured on the spot with photo and location through incident recording, which is what makes a near-miss visible at all. And optional client access lets a regulated client pull the records for their own site directly, without an email chain.

For the current regime rather than the incoming one, our guide to NIS audits and CAF compliance covers what auditors accept and reject today.

Frequently asked questions

Is the Cyber Security and Resilience Bill law yet?

No. It was introduced on 12 November 2025, completed Commons report stage and third reading on 10 June 2026, and was introduced to the House of Lords on 17 June 2026 with second reading scheduled for 14 July 2026. Royal Assent is expected late in 2026, with duties phased in towards 2028.

Does it replace the NIS Regulations 2018?

No. It amends and overhauls the existing NIS Regulations rather than replacing them. The regime regulated organisations already work to remains the foundation, which is why current NIS and CAF preparation is not wasted effort.

Are security companies regulated under the Bill?

Not as such. The expansion brings data centres and managed service providers into scope. A guarding contractor is affected as a supplier to those organisations, whose own duties push evidence requirements down the supply chain.

What is near-miss reporting?

A duty to surface events that could have become incidents but did not. In physical terms that includes a challenged tailgating attempt, an unescorted contractor turned away, or a plant room found unsecured and made safe. Because no loss occurs, these are only reportable if someone recorded them at the time.

What penalties does the Bill carry?

Reported tiers are a standard maximum of £10 million or 2 per cent of global turnover, a higher tier of £17 million or 4 per cent, and daily penalties up to £100,000 for continuing non-compliance, with regulators including the ICO and Ofcom. These should be treated as scheduled rather than binding until Royal Assent and the supporting secondary legislation.


Could you show a data centre client every challenged access attempt at their site last month? Talk to our sales team or order the 14-day test kit with real devices.