Skip to main content
Loading…

Chamber and committees

Economy, Tourism and Energy Committee

Report on the supplementary Legislative Consent Memorandum on the Cyber Security and Resilience (Network and Information Systems) Bill (UK Parliament legislation)

Introduction

  1. Supplementary legislative consent memorandum LCM-S7-12 was lodged on 10 September 2026 by Neil Gray MSP, Cabinet Secretary for Justice ('the Cabinet Secretary'), and has been referred to the Economy, Tourism and Energy Committee for scrutiny.

  1. The supplementary legislative consent memorandum (sLCM) should be read in conjunction with the information on the Cyber Security and Resilience (Network and Information Systems) Bill page. That Bill page includes the initial memorandum lodged on the Bill, which was considered by the predecessor committee in Session 6.


Cyber Security and Resilience (Network and Information Systems) Bill

  1. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced by the UK Government in the House of Commons on 12 November 2025, with a carry-over motion being agreed to on 6 January 2026. The Bill was then reintroduced in the House of Commons on 14 May 2026.

  1. The Bill makes provision about the security and resilience of network and information systems which are used by or relied on for critical services in the UK. Its intention is to strengthen the UK’s defences against the growing threat of cyber attacks and the associated disruption to critical services which could occur as a result. The Bill:

    • amends the Network and Information Systems (NIS) Regulations 2018 and gives enhanced powers to competent authorities, including in relation to information sharing, incident reporting and enforcement;

    • gives the Secretary of State powers to:

      • further specify which activities should be regulated and by which authority;

      • make regulations relating to the security and resilience of network and information systems;

      • designate a statement of strategic priorities;

      • issue a code of practice for regulatory authorities, and

      • direct regulators and regulated bodies where threats relating to network and information systems pose a risk to national security.

  1. The Bill deals with issues of national security and telecommunications regulation and is therefore primarily within the legislative competence of the UK Parliament. However, it confers new powers and duties on “competent authorities” – bodies responsible for monitoring compliance with the cyber-security requirements.

  1. The Scottish Government is the competent authority for the health sector in Scotland, and the Drinking Water Quality Regulator is the competent authority for the drinking water sector. The Scottish Government’s key concern has been that the new powers and duties for competent authorities in the Bill alter its executive competence.


Original LCM

  1. The original LCM stated that the Scottish Government was supportive of the Bill’s overall aims, as they are designed to enhance the regulation, improve cyber security and resilience of key sectors. It considers that the Bill aligns with the visions and outcomes of the Scottish Government’s Strategic Framework for a Cyber Resilient Scotland in terms of improving critical sectors’ cyber security and resilience, including the devolved health and drinking water sectors.

  1. The Scottish Government and UK Government disagreed on which aspects of the Bill require consent. The UK Government considered that consent is required for clauses 12, 17, 19-22, 27-29, 31-35, 45-51 and 56. The Scottish Government agreed with the UK Government view but considered that consent is also required for clauses 15, 18, 23, 25, 26, 30, 38, 40, 41, 52 and Schedule 1 and 2. This is on the basis that these clauses have the potential to indirectly alter the functions of the Scottish Ministers due to their role as a designated competent authority under the NIS Regulations or through consequential amendments to primary legislation.

  1. Given the Scottish Government’s support for the overall aims of the Bill, the original LCM recommended consent to clauses 12, 15, 17-23, 33, 38, 40, 46-52, 56 and Schedules 1 and 2.

  1. However, the original LCM did not give a position on consent in relation to clauses 25-32, 34, 35, 41 and 45. This was because these provisions concerned the conferral of regulation making powers on the Secretary of State, which could be exercised in relation to devolved matters but did not require the consent of the Scottish Ministers. The original LCM stated that these provisions were subject to ongoing discussion with the UK Government.

  1. The Committee’s predecessor in Session 6 took evidence from the then Cabinet Secretary for Justice and Home Affairs, Angela Constance MSP, at its meeting on 4 March 2026. In that Committee’s report on the original LCM, the Committee reiterated its view that:

    • the Scottish Parliament should have the opportunity to effectively scrutinise the exercise of all legislative powers within devolved competence, and

    • accordingly, powers conferred on UK Ministers should be subject to a requirement for the Scottish Ministers’ consent when exercised within devolved competence.

  1. The Committee welcomed the constructive dialogue between the UK and Scottish Governments, and recommended that the Parliament give its consent to the clauses identified in the original LCM.


Supplementary LCM

  1. In the supplementary LCM which has been referred to the Economy, Tourism and Energy Committee, the Scottish Government reiterates its support for the overall aims of the Bill. The supplementary LCM sets out that the Scottish Government has worked closely with the UK Government to review those clauses (25-32, 34, 35, 41 and 45) where further discussion was required, to clarify the scope and intentions of those clauses, and reach agreement on the practical implementation of the Bill.

  1. The supplementary LCM states that, on balance, the Scottish Government considers that the ability of acting at speed to mitigate specific national security concerns, combined with the Scottish Ministers’ role as a competent authority under the NIS Regulations and the Scottish Government’s role in the practical implementation of the Bill, support recommending legislative consent for clauses 25-32, 34, 35, 41 and 45 in addition to the clauses covered by the original LCM.

  1. Further detail on the reasons given for recommending consent to clauses 25-32, 34, 35, 41 and 45 is set out below.

  1. Clauses 25-28 allow the Secretary of State to designate a statement of strategic priorities (SSP) and lay a report on how regulatory authorities, including devolved competent authorities, have complied with their duties. The supplementary LCM notes that, while there is no requirement to obtain the consent of the Scottish Ministers in relation to the SSP and necessary reporting, on a practical level the Scottish Government will be involved in its development and the Scottish Ministers, in their role as a competent authority, will be consulted. Therefore, the Scottish Government is now recommending that consent be granted for clauses 25-28.

  1. Clause 29 allows the Secretary of State to make further regulations relating to the security and resilience of network and information systems. Clauses 30, 31, 34 and 25 establish the parameters to shape the regulation-making power under clause 29. Again, the Scottish Government is now recommending consent to these clauses because, while there is no statutory requirement to obtain the consent of the Scottish Ministers, the Scottish Ministers will be consulted in their role as a competent authority if the powers are exercised in a way that confers functions on devolved regulatory authorities.

  1. Clause 32 permits the Secretary of State, when making regulations under clause 29(1), to make provisions for or in connection with the imposition of financial penalties by regulatory authorities. The Scottish Government is now recommending consent on the basis that, while there is no statutory requirement to obtain the consent of the Scottish Ministers, the Scottish Ministers, in their role as a competent authority, will be consulted before any financial liabilities are imposed on devolved bodies.

  1. Clause 41 introduces powers that allow the Secretary of State to make consequential amendments to primary legislation, including Acts of the Scottish Parliament, when making regulations under clause 24 or Chapter 3 of the Bill. The Scottish Government is recommending consent because the powers are narrowly focused to ensure that UK Government may only make consequential amendments when necessary to address specific, urgent and significant national security threats and risks.

  1. Clause 45 confers powers on the Secretary of State to direct regulatory authorities to do certain things. The Scottish Ministers are specifically excluded from this power but, instead, they would have the authority to comply with a request. However, the provision could be used in relation to the Drinking Watter Quality Regulator. The supplementary LCM states that the UK Government has provided assurances that, while there is no statutory requirement to obtain the consent of the Scottish Ministers, in practice the Secretary of State will seek to engage with the Scottish Ministers before issuing a direction to the Drinking Water Quality Regulator for Scotland. Therefore, the Scottish Government recommends that consent be granted for clause 45.

  1. The draft motion on legislative consent is as follows:

    That the Parliament, noting that the Cyber Security and Resilience (Network and Information Systems) Bill, introduced in the House of Commons on 12 November 2025 and reintroduced on 14 May 2026, so far as these matters fall within the competence of the Scottish Parliament, or alter the executive competence of the Scottish Ministers, agrees to give consent to such provision as is made by clauses 12, 15, 17-23, 25-35, 38, 40, 41, 45-52, 56, Schedule 1 and Schedule 2.


Committee scrutiny

  1. The Committee considered the supplementary LCM at its meeting on 22 September 2026, and agreed to write to the Cabinet Secretary seeking further information.

  1. The Committee sought a response from the Cabinet Secretary to the following questions set out in its letter of 22 September on the sLCM:

    • The Scottish Government previously withheld a recommendation on a number of clauses because they conferred powers on the Secretary of State that could be exercised in devolved areas without requiring the Scottish Ministers’ consent. What has changed to persuade the Scottish Government that consultation arrangements provide an adequate safeguard, and why is it satisfied that those arrangements will remain effective in the future – including through future changes of UK Government – despite not being placed on a statutory footing?

    • The supplementary LCM refers to assurances and practical arrangements agreed with the UK Government. Are those arrangements set out in writing and, if so, can they be shared with the Committee?

    • The supplementary LCM states that the Scottish Government is content to recommend consent to clause 41 because the power is “narrowly focused” and can be used only where necessary to address specific, urgent and significant national security threats and risks. Could you explain what is meant by “narrowly focused” in this context, what limits apply to the power, and provide examples of the circumstances in which it could be used to make consequential amendments to Acts of the Scottish Parliament?

    • Clause 45 could be used in relation to the Drinking Water Quality Regulator for Scotland, and the supplementary LCM states that the UK Government has provided assurances that the Scottish Ministers will be engaged before any direction is issued. Given the devolved nature of drinking water regulation, why is the Scottish Government satisfied that these non-statutory engagement arrangements provide sufficient protection for devolved decision-making, what opportunity would the Scottish Ministers have to influence or object to a proposed direction, and how does the Scottish Government consider this approach appropriately balances the need to respond quickly to national security threats with respect for devolved responsibilities?

  1. In his response letter to the Committee on 25 September the Cabinet Secretary responded to the questions raised by the Committee, summarised as follows:

    • Following discussions and correspondence between the Cabinet Secretary and the UK Government over the summer, UK Government has provided specific assurances that in practice the Secretary of State will seek to engage with Scottish Ministers before issuing any directions to the Drinking Water Quality Regulator for Scotland (DWQR).

    • Baroness Lloyd of Effra CBE, Minister for Space, Cyber and Regulatory Reform in the UK Government provided assurances to the Cabinet Secretary specifically relating to the powers to direct the DWQR through the correspondence on 13th August 2026, which is included in Annex A of the Cabinet Secretary's response letter.

    • The letter also confirms the UK Government’s position that the cyber security of the UK’s essential services is ultimately a shared concern for both the UK and Scottish governments and wherever possible they will seek to take a joined-up response to the threats facing those services.

    • In terms of the practical arrangements, beyond existing Cabinet Office Briefing Rooms (COBR) and the Scottish Government Resilience Room (SGoRR) arrangements for responding to national security incidents, the implementation of the Cyber Security and Resilience Bill will be the subject of a UK Government public consultation later this year. Scottish Government officials are working closely with UK Government to ensure that Scottish interests are appropriately represented and the practicalities of implementing the CRSB in an effective way are fully considered. The Scottish Government will seek to ensure that the practical arrangements for consulting Competent Authorities, including Scottish Ministers, on all aspects of the Bill are appropriate, effective and robust.

    • While clause 41 permits supplementary, incidental, transitional, or saving provisions in general, subsections (3) and (4) limit amendments to primary legislation (which includes an Act of the Scottish Parliament) to consequential provisions only. For example, it could be to amend references in primary legislation that are now out of date – e.g. if reference to the “NIS Regulations 2018” needs to be replaced by “Cyber Security and Resilience Bill” or another set of regulations. The provision cannot be used to amend policy.

    • The Scottish Government works very closely with DWQR, including in response to cyber resilience, NIS regulations and incidents. The UK Government position is that directions, which may require regulators or regulated entities to take an action, will always be proportionate to the threat it seeks to mitigate and will be subject to parliamentary scrutiny by UK Parliament. These provisions will only be used in the event of significant national security threats and are designed to ensure that powers are in place across all sectors and, where necessary, they can be used at pace. The assurances provided by UK Government confirm that in practice the Secretary of State will seek to engage with Scottish Ministers before issuing any such directions to the DWQR. This engagement will allow for discussions to take place on whether directions are needed and, if necessary, on the most appropriate routes to direct DWQR. Where necessary, these discussions will also include consideration of the potential benefits of using powers available to Scottish Ministers through existing Scottish legislation to achieve the same outcome.


Recommendation

  1. The Economy, Tourism and Energy Committee recommends to the Parliament that the supplementary legislative consent motion LCM-S7-12 in the name of Neil Gray MSP, Cabinet Secretary for Justice, be approved.