

Service Overview
Are you preparing for the UK's expanded cyber resilience framework?
The UK Cyber Security and Resilience Bill is currently progressing through Parliament. It is expected to broaden the existing UK cybersecurity framework — established under the Network and Information Systems Regulations 2018 — by extending coverage to additional categories of digital services and managed service providers, and updating incident-reporting and supervisory expectations. Royal Assent is anticipated in late 2026, with secondary legislation to follow that will set the operative scope, registration mechanics and penalty regime.
Until the Bill is enacted and the secondary legislation is published, the UK CSR representative obligation does not yet exist as a statutory duty. Lionheart is preparing service infrastructure now, so that clients can transition smoothly once the framework is operative — and is openly tracking the legislative progress in public.
Service Detail
What this service covers
Are you preparing for the UK's expanded cyber resilience framework?
The UK Cyber Security and Resilience Bill is currently progressing through Parliament. It is expected to broaden the existing UK cybersecurity framework — established under the Network and Information Systems Regulations 2018 — by extending coverage to additional categories of digital services and managed service providers, and updating incident-reporting and supervisory expectations. Royal Assent is anticipated in late 2026, with secondary legislation to follow that will set the operative scope, registration mechanics and penalty regime.
Until the Bill is enacted and the secondary legislation is published, the UK CSR representative obligation does not yet exist as a statutory duty. Lionheart is preparing service infrastructure now, so that clients can transition smoothly once the framework is operative — and is openly tracking the legislative progress in public.
Our position
A holding service, openly labelled
This is a holding page. Lionheart does not currently offer a UK CSR representative service because the underlying legal obligation is not yet in force. We have included this subtab in the Cyber Resilience navigation deliberately — so that organisations preparing for the new framework can find us early, register interest, and be notified the day the service goes live.
What we are doing in the meantime
Our UK team is monitoring the Bill's parliamentary progress, engaging with secondary-legislation consultations as they open, and pre-drafting the operational procedures (intake, escalation, registration support, incident-notification cadence) that will form the backbone of the service. The service appendix in our master representative services agreement (Appendix H2) is held open as a placeholder for the calibrated terms — including the indemnity and enforcement-exposure provisions — that will be finalised once the penalty framework under the secondary legislation is published. Existing Lionheart clients will be able to add UK CSR coverage as an addendum to their master agreement when the time comes.
How to track progress
You can monitor the Bill's progress directly through the official UK parliamentary record. The UK Parliament Bills page (bills.parliament.uk) publishes the current stage of every Bill before Parliament, the text of each version as it is amended, and the dates of forthcoming Commons and Lords sittings. The Department for Science, Innovation and Technology publishes policy statements and consultation responses as the Bill moves forward. We will publish a service-readiness update on this page when each of the following milestones is reached:
- Royal Assent received and the Cyber Security and Resilience Act 2026 is enacted.
- Draft secondary legislation laid before Parliament.
- Secondary legislation made and operative date set.
- Designated competent authority and notification mechanics confirmed.
- Lionheart's UK CSR representative service goes live, with pricing and the master-agreement appendix finalised.
What we expect to offer (subject to enactment)
The following outline reflects our current planning and is indicative only. Final scope, terms and pricing will be confirmed once the secondary legislation is published.
Formal designation
Acting as your UK Cyber Security and Resilience representative under the new framework, by written mandate, with clearly documented scope and procedures.
UK-based contact details
A dedicated representative email address, available for inclusion in registration filings and public-facing disclosures required under the framework.
Authority liaison
Acting as the formal contact point for the competent authority designated under the secondary legislation.
Registration support
Practical support with the registration mechanics established under the secondary legislation, including any template-letter or notification-format requirements set by the competent authority.
Incident-notification escalation
Defined escalation paths and service levels aligned with the new framework's incident-reporting cadence, once that cadence is set in secondary legislation.
Coordinated mandates
Single-relationship handling where UK CSR obligations overlap UK NIS, UK GDPR, EU NIS2, EU GDPR, DSA or AI Act — under one engagement and one escalation path.
Legal basis: UK Cyber Security and Resilience Bill (in preparation; Royal Assent anticipated late 2026). The operative obligation, designated competent authority, registration mechanics and penalty regime will be established by secondary legislation made under the Act.
Pending legislative framework:
Both pricing and the calibrated enforcement-exposure terms in our master representative services agreement are held in abeyance pending publication of the secondary legislation. We will confirm both within sixty days of that publication.
Where to follow the Bill in real time:
UK Parliament Bills tracker (bills.parliament.uk) for legislative status, votes and amendments; Department for Science, Innovation and Technology updates for policy and consultation announcements. We do not republish those sources here — the official record is the authoritative one — but we will signal each material milestone in this page's update log.
Coordinated continuity for existing clients
If your organisation currently holds a UK NIS Regulation 14A mandate with Lionheart, the transition into UK CSR (where applicable to your services) will be handled under your existing master representative services agreement. Where the new framework expands the scope of services covered, we will work with you in advance of the operative date to map the change and confirm what, if anything, needs to be added to your mandate.

Get started
Register your interest in the UK CSR Representative Service
info@lionheartsquared.com
Get started
We will contact you when the framework is enacted and the service goes live.
We will contact you when the framework is enacted and the service goes live. No obligation; no commitment until the operative scope is known.Get started
Not sure if you are in scope?
Use the guided self-check tool to map which representative obligations may apply.