Clause 45 - Monitoring by regulatory authorities

Cyber Security and Resilience (Network and Information Systems) Bill – in a Public Bill Committee at 3:15 pm on 10 February 2026.

Alert me about debates like this

Question proposed, That the clause stand part of the Bill.

Photo of Graham Stringer Graham Stringer Labour, Blackley and Middleton South

With this it will be convenient to discuss clauses 46 and 47 stand part.

Photo of Kanishka Narayan Kanishka Narayan Parliamentary Under Secretary of State (Department for Science, Innovation and Technology)

This group of clauses concerns how compliance with national security directions will be monitored. Clause 45 enables the Secretary of State to delegate the task of monitoring compliance with the direction issued under clause 43 to a NIS regulator. Regulators have valuable sectoral expertise and existing relationships with the entities they regulate. As such, it may be effective to delegate monitoring of compliance to the relevant regulator. The Secretary of State will retain the sole ability to make judgments about whether non-compliance has occurred, or if any penalty is appropriate. The regulator would be required to obtain information relating to compliance, to be shared with the Secretary of State. The Secretary of State would then determine how they would like to receive this information—for example, in reports or at regular intervals.

Clause 46 grants information-gathering powers to the Secretary of State and to regulators that are subject to a monitoring direction or request. In order to determine whether an incident or threat meets the bar for issuing a direction, or whether a regulated entity is complying with the direction, the Secretary of State will need information from that entity and potentially other parties. The clause establishes the power for the Secretary of State to request that information. As the monitoring of compliance with the direction may be delegated to NIS regulators, the clause also equips those regulators with the power to request information needed for their monitoring functions.

Clause 47 grants the Secretary of State the power to carry out or delegate inspections needed to assess compliance with a direction, or with a confirmation decision specifying actions to be taken in the event of non-compliance. The Secretary of State is responsible for judging whether a regulated entity is complying with a direction, and therefore needs access to relevant information that the regulated entity holds. In some cases, this may not be possible to verify without physical attendance. To ensure the effective use of time and resources, the Secretary of State will have the power to appoint a person to carry out an inspection on their behalf, or to direct the recipient of a direction to appoint an approved inspector. The clause also grants these powers to regulators, where the regulator has been directed or requested to monitor compliance on behalf of the Secretary of State. This will ensure that they can provide the Secretary of State with the most accurate information. I commend the clauses to the Committee.

Photo of Ben Spencer Ben Spencer Shadow Minister (Science, Innovation and Technology)

Clause 45 gives the Secretary of State powers to require regulatory authorities to monitor and report on regulated entities’ compliance with directions given under clause 43 for reasons of national security. Clause 46 provides the Secretary of State with extensive information-gathering powers through the use of information notices to facilitate the giving of directions and monitoring of compliance with directions under clause 45(4). Clause 47 empowers the Secretary of State to conduct inspections to assess whether a regulated entity is complying with directions issued under clause 45(4). The Secretary of State may appoint a third party to conduct the inspection, and require the regulated entity to meet the costs associated with this.

I reiterate the point that these powers are necessary; however, given the potential for significant cost and administrative burden for businesses, they should be subject to contemporaneous or near-contemporaneous oversight by parliamentary authorities, observing the necessary confidentiality protocols. I also make the point that these information-gathering powers apply extraterritorially and may lead to conflict with regulated entities’ data privacy obligations in other jurisdictions. What discussions has the Secretary of State conducted with industry and law enforcement counterparts in other countries about the approach to information sharing for this purpose, and the implications for companies operating services on a cross-border basis?

Photo of Kanishka Narayan Kanishka Narayan Parliamentary Under Secretary of State (Department for Science, Innovation and Technology) 3:30, 10 February 2026

I am grateful to the hon. Gentleman for his points about proportionality and scrutiny. I want to give him assurances about that, as I did in our earlier conversation.

On cross-border compliance, the hon. Gentleman rightly points out that relevant information can be requested, regardless of whether it is held the UK. I am very happy to write to him with further detail on our ongoing engagement with counterparts elsewhere. During this process, we have engaged more broadly to understand other regulatory regimes and ensure compliance with them.

Question put and agreed to.

Clause 45 accordingly ordered to stand part of the Bill.

Clauses 46 and 47 ordered to stand part of the Bill.

Clause

A parliamentary bill is divided into sections called clauses.

Printed in the margin next to each clause is a brief explanatory `side-note' giving details of what the effect of the clause will be.

During the committee stage of a bill, MPs examine these clauses in detail and may introduce new clauses of their own or table amendments to the existing clauses.

When a bill becomes an Act of Parliament, clauses become known as sections.

clause

A parliamentary bill is divided into sections called clauses.

Printed in the margin next to each clause is a brief explanatory `side-note' giving details of what the effect of the clause will be.

During the committee stage of a bill, MPs examine these clauses in detail and may introduce new clauses of their own or table amendments to the existing clauses.

When a bill becomes an Act of Parliament, clauses become known as sections.

Secretary of State

Secretary of State was originally the title given to the two officials who conducted the Royal Correspondence under Elizabeth I. Now it is the title held by some of the more important Government Ministers, for example the Secretary of State for Foreign Affairs.