Skip to main content
    NixInfinity-AI
    UK Legislation

    CSR Bill 24/72-Hour Incident Reporting Duty Explained

    Published 7 July 2026

    Who has the duty

    Directly: Operators of Essential Services, Relevant Digital Service Providers, Managed Service Providers and Data Centres in scope.

    Indirectly: any supplier whose contract cascades the obligation. If you are critical to a regulated customer, your contract will likely require you to notify them within tighter timelines so they can meet their own duty.

    The two-stage timeline

    • 0–24 hours – initial notification with what is known.
    • 24–72 hours – fuller report with impact, affected systems and mitigation.
    • 1 month – final report covering root cause and remediation.

    What counts as a "significant incident"

    • Unauthorised access to systems holding regulated data.
    • Ransomware or destructive malware that disrupts service.
    • Supply-chain compromise with material customer impact.
    • Confidentiality breach affecting customer or personal data.

    Where reports go

    The regulator is sector-specific (Ofcom, FCA, ICO, NCSC depending on the entity). For most SMEs the practical pathway is: notify the customer who is regulated, who in turn notifies the regulator. UK GDPR personal-data breach reporting to the ICO remains separate and is not replaced by this duty.

    Get ready in five steps

    1. Write an incident response plan with named roles and a callout tree.
    2. Pre-draft the 24-hour notification template now, when you are not under pressure.
    3. Rehearse a tabletop exercise quarterly.
    4. Hold Cyber Essentials so you have a baseline incident report can reference.
    5. Use the 24/7 helpline on the free £25,000 cyber insurance for first-hour triage if you are eligible.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions