The UK government has tabled late amendments to its Cyber Security and Resilience Bill that would give ministers sweeping powers to block high-risk technology suppliers from critical national infrastructure operators.[4][5][14] The changes, introduced in late August, follow mounting concern over supply chain intrusions and geopolitical cyber threats targeting essential services such as energy, healthcare, transport and telecommunications.[4][5][14] Under the proposals, designated ministers could compel organizations in these sectors to cease procurement from specified vendors, restrict how their products are used, or remove existing equipment where it is judged to pose an unacceptable national security risk.[5][14]
The amendments build on a wider overhaul of the UK’s cyber regime that will replace and expand the scope of the Network and Information Systems Regulations 2018.[7][8][10] The Cyber Security and Resilience Bill would impose mandatory security standards on operators of essential services and relevant digital service providers, bringing data centres and key digital infrastructure firmly under regulation.[7][8][11] Regulators would be empowered to designate certain “critical suppliers” whose goods or services are essential to those operators, subjecting them to statutory cyber requirements and closer oversight of their network and information systems.[1][3][6] Serious failures to meet these duties or report incidents could attract fines of up to £17 million or 4% of global turnover, alongside daily penalties for ongoing non-compliance.[7][10]
While the original bill focused on regulators, the new amendments shift some of the most sensitive decisions to ministers, who could issue binding directions to critical infrastructure organizations over the use of particular technologies.[4][5][14] Reporting from industry and policy outlets suggests these powers would allow orders to quietly curtail the use of high-risk suppliers, including instructions to modify, disable or remove equipment already installed in sensitive networks.[5][14] Observers note that this approach mirrors existing arrangements in the telecommunications sector, where UK operators have been required to reduce and then eliminate dependence on certain foreign vendors over time.[5][14]
The push for direct ministerial powers comes after a series of supply chain incidents that exposed systemic reliance on a small number of technology providers across critical sectors.[4][9][14] One recent attack, attributed by officials to Iran-linked actors, prompted calls for stronger tools to force the phased removal of suspect vendors from energy, healthcare and telecoms networks.[14] In parallel, the UK Treasury has already designated several major cloud providers as “Critical Third Parties” to the financial sector, giving regulators direct oversight of how those firms manage resilience and cyber risk.[13][15] Together, these moves signal a broader policy shift toward treating technology suppliers as integral components of national infrastructure rather than peripheral service providers.[1][13][15]
For defenders inside regulated organizations, the evolving framework means greater scrutiny of third-party dependencies and less flexibility to rely on single vendors for mission-critical services.[1][3][6] Operators designated under the bill will need to ensure that core systems can tolerate rapid changes in supplier usage if ministers or regulators order restrictions, requiring robust exit strategies, data portability and interoperability planning.[3][9] Suppliers that meet the thresholds for “critical” designation can expect more intrusive assessments, mandatory incident reporting within tight timelines, and potential enforcement action if weaknesses are left unaddressed.[3][7][10]
The legislation is still making its way through Parliament, and the late-stage amendments on high-risk suppliers are likely to face detailed scrutiny from industry and civil liberties groups before becoming law.[4][7] Nonetheless, organizations in critical sectors are being urged by advisors to map their technology supply chains, identify where a single vendor failure could disrupt essential services, and prepare for a future in which ministerial directions may force abrupt changes to long-standing supplier relationships. Risk teams and CISOs will need to work closely with procurement and legal functions to ensure contracts, architectures and incident playbooks can withstand both sophisticated supply chain attacks and the regulatory interventions now on the horizon.
References
- Cyber security and resilience policy statement – GOV.UK
- Designating critical suppliers
- UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
- UK government seeks powers to secretly block risky tech …
- What are the key areas of focus of government’s Cyber …
- UK cybersecurity bill brings tougher rules for critical infrastructure
- Summary of the Bill
- Cyber supply chain risk management under the …
- FAST Legal Update Member Bulletin – January 2026
- New cyber obligations for tech suppliers and data centres …
- UK Names 4 Cloud Giants Critical Third Parties [2026]
- UK seeks supply chain security overhaul following Iran-linked cyber attack – Tech Digest
- Written statements – Written questions, answers and statements – UK Parliament