UK Legislation
CSR Bill 24/72-Hour Incident Reporting Duty Explained
Published 7 July 2026
Who has the duty
Directly: Operators of Essential Services, Relevant Digital Service Providers, Managed Service Providers and Data Centres in scope.
Indirectly: any supplier whose contract cascades the obligation. If you are critical to a regulated customer, your contract will likely require you to notify them within tighter timelines so they can meet their own duty.
The two-stage timeline
- 0–24 hours – initial notification with what is known.
- 24–72 hours – fuller report with impact, affected systems and mitigation.
- 1 month – final report covering root cause and remediation.
What counts as a "significant incident"
- Unauthorised access to systems holding regulated data.
- Ransomware or destructive malware that disrupts service.
- Supply-chain compromise with material customer impact.
- Confidentiality breach affecting customer or personal data.
Where reports go
The regulator is sector-specific (Ofcom, FCA, ICO, NCSC depending on the entity). For most SMEs the practical pathway is: notify the customer who is regulated, who in turn notifies the regulator. UK GDPR personal-data breach reporting to the ICO remains separate and is not replaced by this duty.
Get ready in five steps
- Write an incident response plan with named roles and a callout tree.
- Pre-draft the 24-hour notification template now, when you are not under pressure.
- Rehearse a tabletop exercise quarterly.
- Hold Cyber Essentials so you have a baseline incident report can reference.
- Use the 24/7 helpline on the free £25,000 cyber insurance for first-hour triage if you are eligible.
