This website uses cookies

Read our Privacy policy and Terms of use for more information.

UK Cyber Bill Reaches Lords Committee Tomorrow — Two 24-Hour Clocks Converge

The UK Cyber Security and Resilience Bill enters House of Lords Committee Stage on Tuesday 1 September — its first line-by-line scrutiny — days before the EU Cyber Resilience Act's incident-reporting obligations go live on 11 September. Cybersecurity, data-security and cloud-security teams face a dense fortnight of deadlines.

Why It Matters

Committee Stage is the first real chance to amend the Bill's expanded scope. Having cleared all Commons stages and passed Lords Second Reading on 14 July, the Bill pulls previously unregulated intermediaries — managed service providers, data centres and digital supply-chain participants — into the UK's NIS statutory regime. It adds a two-stage incident-reporting clock (a 24-hour initial notification followed by a 72-hour full report) and enforcement penalties of up to £17 million or 4% of worldwide turnover. Report Stage and Third Reading still follow; Royal Assent is expected late 2026.

The timing matters because a second 24-hour clock starts almost immediately after. From 11 September, the EU Cyber Resilience Act requires manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents on a 24h/72h/14-day cadence. For any organisation selling into both markets, two overlapping fast-reporting regimes now need a single, rehearsed runbook rather than two afterthoughts.

On the Calendar This Week

  • Today, 31 Aug — FedRAMP 20x Class B & C certification pipelines open; the Federal Secure Cloud Advisory Committee (FSCAC) meets.

  • Tue 1 Sep — UK Cyber Security and Resilience Bill begins Lords Committee Stage.

  • Wed 2 Sep — FedRAMP Rev5 Community Updates Meeting.

  • Mon 8 Sep — Comment windows close for FedRAMP RFC-0032 and NIST SP 800-209r1 (storage-infrastructure security).

  • Fri 11 Sep — EU Cyber Resilience Act vulnerability/incident reporting begins; ENISA's Single Reporting Platform goes live.

→ More on the calendar: cybereyeq.github.io/podcast/calendar

Action Items

  1. Reconcile your two reporting clocks — map your incident-response runbook against the UK CSR Bill's prospective 24-hour front end and the EU CRA's 24h/72h/14-day obligation (live 11 Sept), confirming who files, to which authority, in each regime.

  2. Confirm your FedRAMP path — with 20x Class B and C pipelines open today, decide between the 20x automated model and a legacy Rev5 certification; new Rev5 applications close 11 June 2027.

  3. Calendar the fortnight's closing windows — RFC-0032 and NIST SP 800-209r1 comments (8 Sept), CRA go-live (11 Sept), and the CMMC Reform Task Force report to the DoW CIO (~13 Sept).

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk