Back to Cybersecurity

UK Cybersecurity Laws and Regulations: A Guide for SMBs and SaaS Companies

London skyline at dusk, representing UK cybersecurity laws for businesses Photo: Unsplash

Short answer: The main UK cybersecurity laws for businesses are UK GDPR and the Data Protection Act 2018, which require appropriate security and 72-hour breach reporting to the ICO. Depending on what you do, the NIS Regulations 2018, PSTI Act 2022, PECR, the Computer Misuse Act 1990 and sector rules from the FCA or NHS also apply. Cyber Essentials is often expected.

Related guides:

Key takeaways

  • UK GDPR applies to almost every business that handles personal data about people in the UK. Its security principle and 72-hour breach reporting rule are the baseline for everyone.
  • The NIS Regulations 2018 cover operators of essential services and relevant digital service providers such as cloud computing services. The Cyber Security and Resilience Bill, introduced in November 2025, is designed to widen that scope. As of September 2026 it has not yet become law.
  • Product and communications rules matter if you make connected devices (PSTI Act 2022) or send marketing emails and use cookies (PECR).
  • Sector rules add a layer on top: FCA operational resilience for financial services and the NHS Data Security and Protection Toolkit for anyone handling NHS patient data.
  • Cyber Essentials and ISO 27001 are not laws, but they give you a structured way to show you meet the security expectations these laws share.

Which UK cybersecurity laws apply to your business?

Most UK businesses are covered by UK GDPR, and additional laws apply based on your sector, services and products. The UK has no single "cybersecurity act", so answer five questions to scope your obligations:

  1. Do you process personal data about people in the UK? If yes, UK GDPR and the Data Protection Act 2018 apply.
  2. Do you run essential services or provide cloud, online marketplace or search engine services? The NIS Regulations 2018 may apply.
  3. Do you make, import or distribute consumer connectable products? The PSTI Act 2022 product security regime applies.
  4. Do you send electronic marketing or use cookies and similar tracking? PECR applies.
  5. Are you regulated by the FCA, or do you handle NHS patient data? Sector-specific rules apply on top of everything else.

A typical UK SaaS company lands on UK GDPR plus PECR. HealthTech suppliers to the NHS add the DSPT, and fintechs add FCA rules and possibly DORA (see how DORA impacts UK entities).

What do UK GDPR and the Data Protection Act 2018 require for security?

UK GDPR requires appropriate technical and organisational security measures and reporting of qualifying breaches to the ICO within 72 hours. The Data Protection Act 2018 sits alongside it with UK-specific details and the ICO's enforcement powers.

  • Security principle. Security must be appropriate to the risk. The law names measures such as encryption, pseudonymisation, resilience, the ability to restore data after an incident, and regular testing. In practice, expect access control, MFA, patching, logging, backups, supplier checks and training.
  • Breach reporting. Report a breach likely to risk people's rights to the ICO without undue delay and, where feasible, within 72 hours of becoming aware. If the risk is high, tell affected people too. Record every breach internally, reported or not.
  • Penalties. The maximum fine is £17.5 million or 4% of annual worldwide turnover, whichever is higher.

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 amends UK GDPR, the Data Protection Act 2018 and PECR rather than replacing them, with changes brought into force in stages. It touches areas such as legitimate interests, automated decision-making, cookies and complaints handling, while the core security and breach duties remain. Use it as a prompt to review privacy notices, cookies and complaints processes. Our UK GDPR guide, linked above, covers the wider requirements.

Do the NIS Regulations and the Cyber Security and Resilience Bill apply to you?

The NIS Regulations 2018 apply to operators of essential services (OES) and relevant digital service providers (RDSPs), and most SMBs fall outside them unless they provide cloud, online marketplace or search engine services at scale.

  • Operators of essential services work in sectors such as energy, transport, drinking water, health and digital infrastructure, and meet thresholds set for each sector. They are supervised by sector competent authorities.
  • Relevant digital service providers are online marketplaces, online search engines and cloud computing services. Small and micro businesses are generally excluded. The ICO is the competent authority for RDSPs.

In-scope organisations must take appropriate and proportionate measures to manage security risks and must notify their competent authority of incidents that have a significant impact on service continuity, without undue delay and within 72 hours of becoming aware.

The Cyber Security and Resilience Bill

The government introduced a Cyber Security and Resilience Bill in Parliament in 2025 to update NIS. Its proposals include bringing managed service providers into scope, strengthening incident reporting and giving regulators more powers. As of September 2026, the Bill has passed the House of Commons and is before the House of Lords. It has not received Royal Assent, and most duties will start later through secondary legislation. The text can still change, so check the Bill's page on the Parliament website before planning around specific duties. Managed service providers should watch it closely.

What other UK cyber laws should SMBs know about?

Three more laws affect many SMBs: the Computer Misuse Act 1990, the PSTI Act 2022 and PECR.

Computer Misuse Act 1990

This criminal law makes unauthorised access to systems and data, and acts that impair systems, offences. For businesses, it shapes security testing: always get written authorisation and a clear scope before any penetration test or scan.

Product Security and Telecommunications Infrastructure (PSTI) Act 2022

The PSTI Act's security regime for consumer connectable products, such as cameras, wearables and smart home devices, has applied since April 2024. Manufacturers must not use universal default passwords, must publish a way to report vulnerabilities, and must state the minimum security update period. Importers and distributors have duties too. The Office for Product Safety and Standards enforces it, so it applies if you sell a connected wellness device to UK consumers.

Privacy and Electronic Communications Regulations (PECR)

PECR covers electronic marketing, cookies and similar tracking, and the security of public electronic communications services. For most SaaS companies, that means consent for non-essential cookies and a valid basis for marketing emails. The ICO enforces it.

What extra rules apply to financial services and HealthTech?

Financial services firms must meet FCA operational resilience rules, and organisations handling NHS patient data must complete the NHS Data Security and Protection Toolkit.

FCA operational resilience

In-scope FCA-regulated firms must identify important business services, set impact tolerances, map the people, technology and suppliers behind each service, and test that they can stay within tolerance in severe but plausible scenarios. SaaS vendors to UK banks and insurers should expect detailed resilience due diligence.

NHS Data Security and Protection Toolkit

The DSPT is an annual online self-assessment for organisations with access to NHS patient data and systems, measured against the National Data Guardian's 10 data security standards. Since 2024, larger NHS bodies such as trusts and integrated care boards use a version aligned with the NCSC Cyber Assessment Framework (CAF) instead. It covers training, access management, incident reporting, suppliers and continuity. For HealthTech suppliers, a current submission is usually a condition of NHS work, often alongside Cyber Essentials or Cyber Essentials Plus.

UK cybersecurity laws at a glance

Use this table as a starting map, then confirm the detail for your own situation.

Law or scheme Who it applies to Key obligations Regulator or owner
UK GDPR and Data Protection Act 2018 Organisations processing personal data about people in the UK Appropriate security, breach reporting to the ICO within 72 hours where required, records of breaches ICO
Data (Use and Access) Act 2025 Same scope as UK GDPR and PECR Amends existing data protection law in stages; review privacy, cookie and complaints processes ICO
NIS Regulations 2018 Operators of essential services and relevant digital service providers Risk management measures, incident notification within 72 hours Sector competent authorities; ICO for RDSPs
Cyber Security and Resilience Bill Proposed wider NIS scope, including managed service providers Stronger security and reporting duties, subject to final text and commencement Before the House of Lords (September 2026)
Computer Misuse Act 1990 Everyone Criminal offences for unauthorised access and impairment of systems Police and CPS
PSTI Act 2022 Manufacturers, importers and distributors of consumer connectable products No universal default passwords, vulnerability reporting route, stated update period Office for Product Safety and Standards
PECR Organisations using cookies, electronic marketing or providing public communications services Consent for cookies and marketing, security of communications services ICO
FCA operational resilience In-scope FCA-regulated firms Important business services, impact tolerances, mapping and scenario testing FCA (and PRA for dual-regulated firms)
NHS DSPT Organisations with access to NHS patient data and systems Annual self-assessment against data security standards NHS England
Cyber Essentials Voluntary; required for certain central government contracts Five technical controls, self-assessed or independently tested (Plus) NCSC-backed scheme

Where should an SMB start with UK cyber compliance?

Map your data and legal scope first, then put baseline controls and a tested incident response process in place.

  1. Map your personal data: what you hold, where it lives, who can access it and which suppliers process it.
  2. Confirm your scope using the five questions above.
  3. Run a risk assessment and record how you will treat each risk.
  4. Put baseline controls in place: firewalls, secure configuration, access control, malware protection and patching.
  5. Enforce MFA on email, cloud consoles and admin tools, and review access regularly.
  6. Write and test an incident response plan with the 72-hour ICO deadline and any NIS or sector timelines.
  7. Manage suppliers with data processing agreements and a subprocessor list.
  8. Train your team on phishing, data handling and incident reporting.
  9. Fix cookie and marketing consent.
  10. Get certified where buyers ask.

How Cyber Essentials and ISO 27001 help

Neither is a legal requirement for most businesses, but both help show your security is appropriate.

  • Cyber Essentials is a government-backed scheme covering five technical controls. It is required for certain central government contracts and widely requested by the public sector and the NHS. Start with the checklist linked above and compare Cyber Essentials and Cyber Essentials Plus.
  • ISO 27001 is an international standard for an information security management system (ISMS) covering governance, risk, suppliers and incident response, which lines up well with UK GDPR, NIS and DSPT expectations. See our guide to ISO 27001 certification.

Many SMBs get Cyber Essentials first, then build towards ISO 27001 as they sell to larger customers.

How SecureSlate helps

SecureSlate helps SMBs and HealthTech teams turn a patchwork of UK obligations into one manageable program. You work from a single control library mapped across ISO 27001, GDPR and other frameworks, so a control like access reviews or incident response is written once and reused. Automated evidence collection from your cloud and SaaS stack keeps proof current between audits, and built-in policies, a risk register and vendor risk management cover the areas UK regulators and buyers ask about most.

When a customer, auditor or NHS buyer asks for evidence, you can produce audit-ready exports instead of rebuilding folders by hand.

Start your free SecureSlate trial

FAQ

Is there a single UK cybersecurity law?

No. UK cybersecurity obligations are spread across several laws, including UK GDPR, the Data Protection Act 2018, the NIS Regulations 2018, the PSTI Act 2022, PECR and the Computer Misuse Act 1990. Sector regulators such as the FCA and NHS England add their own requirements on top.

Is Cyber Essentials mandatory in the UK?

Cyber Essentials is not a legal requirement for businesses in general. It is required for certain central government contracts, and many public sector and NHS buyers ask for it as a condition of doing business. For many SMBs it is effectively a commercial requirement.

How quickly must a UK business report a data breach?

Under UK GDPR, you must report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. If the risk is high, you must also inform the affected people without undue delay.

What is the Cyber Security and Resilience Bill?

It is government legislation, introduced in Parliament in November 2025, to update the NIS Regulations 2018. It proposes bringing more organisations such as managed service providers into scope and strengthening incident reporting. As of September 2026, the Bill has passed the House of Commons and is before the House of Lords. It has not received Royal Assent, and most duties will start later through secondary legislation.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Sep 30, 2026 · Cybersecurity

AWS Foundational Technical Review: FTR Checklist and Prep Guide for SaaS Teams

Sep 30, 2026 · Cybersecurity

BSI C5 compliance checklist: how SaaS and cloud providers prepare for a C5 attestation

Sep 30, 2026 · Cybersecurity

Cyber Essentials vs Essential Eight: UK and Australian Cyber Baselines Compared

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?