On 13th May, the King delivered the legislative programme for the coming session of Parliament. I have to be honest, the King's Speech isn't normally something that I'd read, but what with the great speeches he delivered during his recent US state visit and all of the noise around the 2026 local elections, I thought I'd give it a go. In and amongst the CNI and public sector reform, what I found was far more cyber-relevant legislation than I had expected. This was simultaneously surprising and not: on one hand, cyber resilience has been considered in regulations for some time now, but on the other, the Computer Misuse Act has barely changed in 30 years despite years of campaigning, so seeing real movement on it surprised me.
Why does the speech contain so much cyber?
The political weather had changed well before the King arrived at Parliament. In January, DSIT published the Government Cyber Action Plan (GCAP) along with the second reading of the Cyber Security and Resilience Bill, £210m of central funding, and a new Government Cyber Unit. CyberUK 2026 in April set out the rationale more directly than government statements typically allow. Speakers described a unique moment: rising geopolitical tensions, extraordinary technological innovation, and a digital infrastructure that underpins both yet remains fragile and highly concentrated. Add the parallel ambitions to modernise public services and stimulate growth, and the policy logic for treating cyber as national security writes itself. Security Minister Dan Jarvis put it plainly: the cyber security of British business is a matter of national security. NCSC CEO Richard Horne added that the majority of nationally significant incidents now originate, directly or indirectly, from nation states.
So, what was actually in the Speech?
Cyber Security and Resilience Bill (CSRB): Expands NIS to cover managed service providers and digital supply chains, introduces 24-hour early-warning incident reporting, and grants the Technology Secretary direction powers over regulated organisations. The long-overdue NIS uplift; CAF outcomes are set to become the assurance lingua franca across sector regulators.
For practitioners who have lived with NIS for seven years, the Bill is the long-overdue uplift that takes the UK closer to NIS2 without copying it. The interesting practical question is how it will interlock with the Home Office's separate ransomware regime, which proposes a targeted payment ban for public sector and CNI, a payment-prevention regime for everyone else, and 72-hour mandatory reporting. The July 2025 government response to the ransomware consultation commits to "ensuring alignment and complementarity with the Cyber Security and Resilience Bill"; whether that produces a single reporting pipeline or two with different thresholds is the detail worth watching at committee stage.
Tackling State Threats Bill: Strengthens powers against foreign state entities and their proxies; closes gaps in state threats legislation. Expect vendor risk disclosure obligations, supply chain scrutiny, and likely measures targeting managed-service concentration risk.
Digital Access to Services Bill (Digital ID): Establishes a national Digital ID framework for how citizens interact with public services. Identity assurance at population scale brings substantial architectural questions across credential storage, fraud signal sharing, federation patterns, and attribute exchange.
Nuclear Regulation Bill: Implements the Nuclear Regulatory Review and supports a new generation of British nuclear generation. Likely to firm up expectations around IEC 62443 alignment and OT/IT convergence; the nuclear sector remains the leading indicator for where CNI cyber regulation lands.
National Security Bill: Includes long-awaited reform of the Computer Misuse Act 1990. The Bill introduces a Cyber Crime Risk Order to control the behaviour of convicted offenders, new search powers for evidence-concealment cases, and provisions that will, in the government's own words, "unlock the power of cyber security professionals to better enable them to secure computer systems". As Computer Weekly reported on the day of the speech, this is something the security research community has been campaigning for since 2020; the CyberUp Campaign called the announcement a genuine turning point.
Public Office (Accountability) Bill (Hillsborough Law): Introduces a statutory duty of candour for public servants in their dealings with inquiries and investigations. Accepted risks and warnings that were not acted on become disclosable evidence in any post-incident inquiry, raising the bar on how those decisions need to be documented and challenged at the time.
Another bill that I thought was of interest to cyber security professionals was the Regulating for Growth Bill. It aims to reduce "the burden of unnecessary regulation through innovation". Specifically, it sets out:
Cross-economy AI sandboxing powers: letting businesses test new products and technologies in real-world conditions where existing regulatory frameworks "currently slow innovation". The briefing notes specifically reference cross-cutting AI sandboxes "across multiple sectors".
A new duty on regulators to promote innovation: following Liz Kendall's January 2026 letter to 19 regulators asking them to publish plans for enabling AI-powered innovation. This shifts regulators from enforcement-first to innovation-first.
How and whether resilience will be factored into these innovations, and how this will interact with the other legislation above, I'm yet to get my head around. (If you have any thoughts, please do share!)
What does any of this mean in practice?
For me, three things follow.
The Cyber Assessment Framework is now the closest thing the UK has to a common cyber currency, and the CSRB will entrench it further. Sector regulators will increasingly use CAF outcomes as their assurance lingua franca, which makes CAF-aligned controls work substantially more valuable; bidirectional mapping between control frameworks, Secure by Design self-assessment, and operational evidence is now landing in a regulatory environment that has caught up with it. The patchwork problem RUSI flagged has not gone away. A vendor or service team today is navigating multiple Codes of Practice, Cyber Essentials, the CAF, the Critical Third Parties regime, NIS, the DUA Act, the OSA, the PSTI Act, and now the CSRB, plus the EU equivalents. Whether the forthcoming National Cyber Action Plan becomes the integrating framework that ties this together is the test for the document.
Supply chain assurance is about to become the binding constraint for most regulated organisations. The CSRB brings MSPs into scope; the ransomware regime is exploring extension into supply chains; the Tackling State Threats Bill will add vendor scrutiny on top. Anyone running a procurement function needs a regulatory radar that procurement alone cannot supply. If this unfolds anything like regulation in the US has, it will force cyber security to be considered throughout supply chains, hopefully right down to small and medium businesses, driving up the resilience of the entire country — though it will take time.
The cyber-specific personal accountability picture is tightening. Financial Services already operating under SMCR are used to this, but for many other sectors this is new. The GCAP made central government senior leaders personally accountable for cyber outcomes; the CSRB extends Technology Secretary direction powers over regulated organisations; the Hillsborough Law brings a statutory duty of candour for public servants engaging with inquiries and investigations. The risk-management consequence is sharper than it first appears. Under a duty of candour regime, an accepted risk or a warning that was not acted on becomes disclosable evidence in any post-incident inquiry, which raises the bar on how those decisions need to be documented, challenged, and re-tested at the time rather than after something has gone wrong. Boards in less-regulated sectors should not assume they will remain outside the perimeter for long.
Where does this leave us?
The political weather changed at CyberUK; the legislative weather is changing now. The question for 2026 is no longer whether to take cyber security seriously. That argument is settled. It is whether we can build operating models coherent enough to deliver against the whole stack of regulation, codes, frameworks, and sector regimes without drowning in compliance work. The CSRB and the forthcoming National Cyber Action Plan will be judged by whether they deliver the integrating framework RUSI argued for, or whether they add further tiles to an already complicated mosaic.
At CyberUK, Vincent Strubel, Director General of ANSSI, was asked what he had worked on that had the biggest impact over the last 10 years. He reflected:
"The most impact we've achieved was when we've gotten engagement from non-cyber people."
That is, in effect, what this Speech tries to legislate. The compliance burden is real, and it will land hardest on the teams least ready for it. But for many of us, the burden is also the price of admission to a conversation we have been trying to start for years. Boards, compliance, privacy, procurement, and risk functions are about to be required to take an interest in cyber security in a way that has, historically, been optional.
That is the actual win in the King's Speech. The harder work is making the most of it.
