Does the Cyber Security and Resilience Bill Require Penetration Testing?

by Rebecca Sutton

No, the Cyber Security and Resilience Bill does not contain a clause ordering anyone to run a penetration test. That surprises people. Many have heard the bill described as a tougher UK cyber law and assumed testing must be written in somewhere. It isn’t, not directly. But if your organisation falls inside its scope, you will still need regular, independently verified testing. That is how you prove you meet the standard the bill actually sets: “appropriate and proportionate security measures.”

That gap, between what the law says word for word and what regulators will expect you to prove, is the whole story. Here is how it plays out.

What the bill says versus what it means

The Cyber Security and Resilience Bill reforms the Network and Information Systems (NIS) Regulations 2018. That is the UK’s existing cyber law for operators of essential services and some digital providers. The government’s own summary confirms the bill does not specify testing methods. Instead it asks for an “all-hazards, risk-based approach.” Organisations must show their security measures fit the risk they actually face.

The bill was introduced to the House of Commons on 12 November 2025. It passed its third Commons reading on 16 June 2026 and moved to the House of Lords for committee stage, where it stands as of this writing. No date has been confirmed for Royal Assent. A government consultation is planned during 2026, and the detailed operational rules will follow later through secondary legislation.

Who has to comply?

The existing NIS Regulations already cover operators of essential services in energy, transport, health and drinking water. They also cover some digital infrastructure and digital service providers, such as cloud platforms, online marketplaces and search engines. The bill widens that list to include:

  • Data centres, across medium, large and enterprise size bands
  • Managed service providers, medium and large
  • Large load controllers in the energy sector
  • Designated critical suppliers: businesses supplying an essential service operator that a regulator judges important enough to its resilience. These suppliers get duties matching an operator of essential services.

Government estimates put roughly a thousand organisations in direct scope. Still, the designated critical supplier route created by the Cyber Security and Resilience Bill is the mechanism to watch. It exists because regulators know essential services depend more and more on third-party IT, software and facilities providers. Many of those suppliers are not household names.

So where does testing actually come from?

Regulators judge “appropriate and proportionate security” using the National Cyber Security Centre’s Cyber Assessment Framework, or CAF. It sets out objectives, principles and indicators of good practice. There is a Basic Profile for common attacks and an Enhanced Profile for organisations facing more capable adversaries.

Testing sits inside Objective B, under Principle B4 on system security. The vulnerability management outcome is direct. To be “partially achieved,” an organisation regularly tests to understand its own vulnerabilities. To reach “achieved,” it also brings in third-party testing to check that understanding, rather than marking its own homework. So the bill never says “penetration test.” But the framework regulators use to judge compliance does, in effect, expect one.

That is a higher bar than businesses may be used to from other schemes. Cyber Essentials, for comparison, does not require a penetration test at all. Its CE+ tier relies on vulnerability scanning, not adversarial testing. Ticking that box is not the same as meeting what the CAF expects.

The operational technology exception

The CAF is careful here. For operational technology, it accepts that testing live systems can affect availability. Organisations can gain the same assurance by testing non-operational environments, or individual components in a lab, instead of the live estate.

What “good” testing looks like, according to NCSC

NCSC’s own penetration testing guidance corrects a common assumption. A good test is not a discovery exercise, it is verification. The guidance puts it bluntly: an organisation should already know what the testers are going to find before they find it. A test only proves you are not vulnerable to known issues on the day it runs. NCSC notes that a year or more often passes between tests at many organisations, long enough for new weaknesses to build up unnoticed. And the organisation commissioning the work owns the decisions about what gets fixed and when, not the testing firm.

That framing matters for anyone caught by the bill. A single test booked to satisfy an auditor misses the point. Ongoing vulnerability management, checked periodically by independent testing, is what both NCSC and the CAF are actually describing.

The parts of the bill that bite faster than testing

Two provisions in the Cyber Security and Resilience Bill will land before any testing expectation does. Incident reporting tightens sharply. A significant incident needs an initial notification within 24 hours, and a fuller report within 72 hours covering impact, root cause and remediation. The National Cyber Security Centre is informed alongside the regulator. Meanwhile, data centres and digital or managed service providers must also notify affected customers directly.

Penalties are rising too. The government has said maximum fines will increase to reflect the significance of the regime, aligning with legislation such as GDPR. The bill’s April 2025 policy statement set out daily fines of up to £100,000 for organisations that fail to act against known threats. So the structure is built to punish inaction, not just a breach itself.

Practical questions to ask your organisation this quarter

A compliance document being reviewed by hand, reflecting the readiness checks the Cyber Security and Resilience Bill expects businesses to prove
Question Why it matters
Do we supply an energy, health, water or transport operator, or a large digital provider? You could be named a designated critical supplier even without thinking of yourself as critical infrastructure.
Can we show regular internal vulnerability testing, not just an annual scan? That is the CAF’s “partially achieved” bar for B4 vulnerability management.
Have we had independent, third-party testing in the last year? That step is what separates “partially achieved” from “achieved.”
Who signs off a 24-hour incident notification, and do they know it? The reporting clock starts the moment you become aware, not once you have all the details.

A scoped penetration test, built around the CAF’s expectations rather than treated as a compliance formality, is a sound way to answer that third question properly. Aardwolf Security carries out exactly this kind of scoped penetration testing for UK organisations working out where they stand. The designated critical supplier route in the Cyber Security and Resilience Bill might reach you if you supply into a regulated sector. If you are unsure, it is worth talking it through before the secondary legislation arrives. And if you are choosing who runs the test, it helps to know what a rigorous penetration testing methodology looks like before you buy one. Our team is happy to help. You can get in touch to discuss your situation.

Frequently asked questions

Does the Cyber Security and Resilience Bill require an annual penetration test?

No fixed interval is written into the bill. The Cyber Assessment Framework is what regulators use to judge compliance. It expects regular internal testing plus periodic independent verification, not a specific yearly requirement.

Is the Cyber Security and Resilience Bill already in force?

No. As of August 2026 it is in House of Lords committee stage after clearing the Commons. There is no confirmed Royal Assent date, and most detailed rules are still to follow through secondary legislation.

Could a small IT supplier really be caught by this?

Yes, through the designated critical supplier provision. A regulator can bring it in if it judges the supplier important enough to an essential service operator’s resilience, regardless of the supplier’s own size.

What is the difference between the CAF Basic and Enhanced profiles?

The Basic Profile addresses common cyber attacks, while the Enhanced Profile is for organisations in sectors facing more sophisticated, capable adversaries and sets a higher bar accordingly.

What are the penalties for non-compliance?

The government has said maximum fines will rise to a scale comparable with GDPR. The bill’s policy statement proposed daily fines of up to £100,000 for failing to act against known threats.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like