The Cyber Security and Resilience Bill will not test your people
The Cyber Security and Resilience Bill raises the cost of weak cyber capability. Why CVs and certifications will not evidence it, and what would instead.
On 1 September the Cyber Security and Resilience (Network and Information Systems) Bill went into Grand Committee in the Lords, with sittings continuing through 3, 7 and 9 September. Most attention has gone to scope: which data centres are caught, how far the managed services definition reaches, whether smaller suppliers get pulled in.
Buried in a long and deliberately disparate group of amendments was a sentence that should interest anyone who hires into a security team. Lord Clement-Jones, speaking to the amendments on cyber skills, said this:
“Regulation without competence is what might be described as pure compliance theatre.”
He is right. And the Bill, as drafted, does very little about it.
I wrote in August that the UK cyber skills shortage has become an assurance problem, and that the thing to watch was not the Bill’s text but its mechanism: secondary legislation, regulator guidance and the CAF. Committee has now named that mechanism out loud. This post is what changed.
What the Bill actually changes
In plain English, the Bill amends the Network and Information Systems Regulations 2018, the UK’s existing NIS regulations. It is not a replacement but an expansion and a tightening, and three changes matter commercially.
Scope widens. Managed service providers become a regulated class in their own right. Clause 9 defines “managed services”, and the definition is contested: Lord Clement-Jones argued it is drawn so broadly that it “in effect acts as a legal dragnet”, and tabled an amendment to exclude any provider without “ongoing privileged administrative access to configure, alter or control a customer’s live network”. Data centres come in too.
Critical suppliers can be designated. A competent authority will be able to designate a supplier to an operator of essential services and apply requirements directly to it. Small and micro providers are otherwise excluded, but can still be caught this way. The Minister has said there will be “a high bar for designation”. What that bar is has not been published.
The substantive duties move into secondary legislation. This is the part most commentary skips. The real requirements arrive as security and resilience requirements (SRRs), consulted on and then made by regulations. Baroness Lloyd of Effra told the Committee these will cover “governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising”, and that the Government intends to consult later this year.
The Bill sets the frame. The regulations set the bar. If you want to influence where that bar lands, the consultation is the moment, not Royal Assent.
Why this is operational, not just compliance
Compliance teams will read this Bill and see a reporting exercise. That is a mistake.
The regime is outcomes-based. The Minister said she is confident in “the Bill’s outcomes-based approach”, and that regulated entities “would be expected to maintain evidence demonstrating compliance”. Outcomes-based regulation does not ask whether you bought a tool. It asks whether the thing worked.
That changes who carries the risk. Under a checklist regime the failure mode is a missing document. Under an outcomes regime it is an incident a regulator works backwards from, and working backwards arrives at decisions. Who triaged the alert. Who judged it benign. Who owned the control that did not fire. Those are people, and that is where the assurance gap sits.
The skills assurance gap
The NCSC Cyber Assessment Framework, which the Minister confirmed the SRRs “will be consistent with”, already requires capable people. CAF Principle A1.b, on roles and responsibilities, sets the achieved bar as:
“Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.”
Principle B6 covers the wider workforce: staff should have “appropriate awareness, knowledge and skills to carry out their organisational roles effectively”.
So ask the obvious question. How does an organisation establish that someone is appropriately capable and knowledgeable?
The CAF does not say. B6’s indicators are about training delivery: that people “follow appropriate cyber security training paths”, that training is “tracked and refreshed at suitable intervals”. Those measure whether training happened, not whether capability exists.
To its credit, the CAF knows this. One of the “not achieved” indicators under B6.b is:
“The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.”
The framework explicitly warns against counting completions. Completions are nonetheless what most organisations count, because they are what is easy to evidence.
CVs, certifications and interviews are proxies
None of this is an argument against qualifications. A CISSP or a CREST registration tells you something real: someone committed the time, passed an assessment, and can be held to a professional standard. The UK Cyber Security Council exists to make that landscape coherent, and the Government told the Committee it is working with the Council to encourage “cyber training and professional standards”.
But a certification is a proxy. It evidences that a person could do something once, under exam conditions, possibly years ago. It does not evidence that they can do this job, in your stack, at your tier.
The CV is weaker still. It is self-authored, and now routinely written with help from a language model. That is not a scandal; candidates are responding rationally to a process that rewards keywords. But the document has lost most of its discriminating power, and the interview inherits the problem, because a well-prepared candidate can describe an investigation they never ran.
Citing ISC2’s 2025-26 workforce study, Lord Clement-Jones told the Committee that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance. The sector is about to be asked to demonstrate capability it is not confident it has, using methods never designed to measure it.
What practical competence assurance could look like
To be clear about what I am not proposing. Not a statutory licence to practise, and not a mandated national test. Both would be slow, expensive, and would ossify around whatever the threat landscape looked like the day they were drafted.
What I mean is narrower and duller:
- Role-specific and evidence-generating. For a SOC analyst, working real telemetry and reaching a defensible conclusion. For a detection engineer, writing and tuning a rule. Not a quiz about frameworks.
- Proportionate to consequence. Only the roles where a wrong call has material impact: people who triage, tune detections, hold privileged access, or lead response.
- Recorded. The value is not the score. It is having something on file, at the point of appointment, showing why this person was judged capable.
- Repeated. Capability decays. A one-off gate at hire beats nothing and loses to periodic revalidation.
None of that requires legislation. It requires that “appropriately capable” stops being an assertion and starts being a record.
Why MSSPs, MSPs and critical suppliers should care most
If you run a managed service, you are moving from being someone else’s third-party risk line item to being a regulated entity in your own right. That alone justifies attention to the Clause 9 definition and the designation power.
The second-order effect is the underrated one. Once your clients are themselves under a tightened regime, their assurance questions get sharper about you. The Bill’s own logic explains why: as Lord Clement-Jones put it, MSPs “act as trusted bridges into multiple enterprise networks”, so one compromised supplier can trigger a cross-sector failure. He cited the Collins Aerospace attack that halted airport check-in across Europe.
Now apply that to staffing. In a managed service, analysts are shared across clients. A weak analyst is not a contained problem the way a weak in-house hire is. They degrade detection quality for every client on that shift, which is commercial exposure as much as security exposure. It lands on SLAs, on renewals, and eventually in front of your client’s regulator.
My expectation, and this is inference rather than anything the Bill says, is that competence evidence will appear in client due diligence questionnaires long before it appears in MSSP regulation. Buyers move faster than statute.
What the Bill does not require
Being precise, because this is where commentary tends to overreach:
- It does not require practical skills testing of anyone. Nothing in the Bill mandates hands-on assessment of individuals.
- It does not create a competence duty for security leaders. Amendment 15, tabled by Lord Arbuthnot, would move that way. Lord Clement-Jones described it as placing “a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence”. It is an amendment, not government policy, and the Government resisted it, along with Amendments 174C and 174D on competency standards and workforce strategies.
- It does not define qualifications for “skilled persons”. Lord Holmes’s Amendment 114 would have required the Secretary of State to do so. The Minister declined, saying the Government should not “tie the Government’s hands to specific skills requirements”.
- The detail does not exist yet. The SRRs are secondary legislation and have not been consulted on. Anyone telling you today precisely what this Bill will require of your workforce is guessing.
What the Government did say is the most important sentence in the debate for this topic. Baroness Lloyd of Effra:
“We propose that the SRRs will address organisational capability and personnel skills and training, driven from board level.”
Capability, skills and training are in scope for the regulations. The mechanism for demonstrating them is not. That gap is what the consultation is for.
The recommendation
For whoever drafts the SRRs: encourage proportionate practical competence assurance for material cyber roles. Encourage, not mandate. Put it in guidance as an accepted way to evidence the CAF’s “appropriately capable and knowledgeable” bar, rather than writing a test into law. That stays flexible, and it closes the gap between requiring capability and never once checking it.
For organisations in scope: do not wait for the regulations. You will be asked to evidence that the people running your controls can run them. Training records will not answer that, and you already know it. Start generating the evidence at the point you hire, on the roles where being wrong is expensive.
For transparency, this is the problem my company works on. CyberHire assesses candidates in the tools of the job and returns evidence per skill, which is one way to produce that record. It is not the only way: an internal practical exercise, run consistently and documented properly, does the same job. The method matters far less than whether the evidence exists.
Conclusion
The Cyber Security and Resilience Bill is a sensible piece of UK cyber regulation. It widens the perimeter to the suppliers that actually carry systemic risk, and it pushes cyber resilience from box-ticking towards outcomes.
But an outcomes regime rests on people, and we still assess those people using documents they wrote themselves and exams they sat years ago. The Bill will not fix that, and probably should not try. The organisations that close the gap voluntarily will be the ones able to answer the hardest question a regulator asks after an incident. Not “what was your policy”, but “why did you believe this person could do the job?”
Sources
- Cyber Security and Resilience (Network and Information Systems) Bill, Lords Grand Committee, 1 September 2026.
- Bill 4035 stage history, UK Parliament.
- NCSC Cyber Assessment Framework v4.0: Principle A1 Governance and Principle B6 Staff awareness and training.
- ISC2 workforce study 2025-26, as cited by Lord Clement-Jones in Committee.
Stop reading CVs. Start reading evidence.
See what the evidence looks like.
The hiring intelligence report is the deliverable: ranked candidates, skill-level performance, integrity findings, and where to press each one at interview.