Skip to main content
Consultation outcome

Whole energy cyber resilience requirements: reshaping cyber regulation in downstream gas and electricity

Applies to England, Scotland and Wales

This consultation has concluded

Read the full outcome

Detail of outcome

After considering the feedback we received to the Reshaping Cyber Regulation in Downstream Gas and Electricity (DGE) consultation, we intend to take forward proposals to review the applicability of the Network and Information Systems (NIS) Regulations 2018 in the DGE sector, and to develop baseline cyber resilience requirements for all Ofgem licensees.

We will tailor our approach to reflect stakeholder feedback, including the need for requirements to be appropriate and aligned with existing frameworks where possible.

On reviewing NIS applicability, we intend to continue working with Ofgem, the National Energy System Operator, the National Cyber Security Centre (NCSC) and the Department for Digital, Culture, Media and Sport (DCMS) to assess whether the current definitions and thresholds remain appropriate for the evolving energy system.

On baseline cyber resilience requirements, Ofgem will lead further development of detailed proposals, working with DESNZ and NCSC. We intend for these requirements to establish a consistent baseline level of cyber resilience across Ofgem licensees, while avoiding duplication and/or misalignment with any existing cyber security obligations.

On the need for intermediate requirements (above baseline but below NIS), responses were mixed. We intend to focus first on implementing baseline requirements and reviewing NIS applicability. Once these changes are established, government will review their effectiveness and consider whether there is evidence to support the need for further intermediate requirements.

This response is a key milestone towards strengthening cyber resilience across the DGE sector and meeting the objectives set out in the cross-government energy cyber strategy.

Detail of feedback received

We received 49 responses to this consultation from a wide range of interested parties.

Respondents broadly supported the need to strengthen cyber oversight and assurance across the downstream gas and electricity sector, while emphasising the importance of an appropriate, risk-based approach that avoids unnecessary duplication and burden.


Original consultation

Summary

We're seeking views on proposals for a new approach to cyber resilience regulation for downstream gas and electricity operators.

This consultation ran from
to

Consultation description

In light of the changing energy landscape as the country moves towards Clean Power 2030 and the increased cyber security threat, Ofgem and the Department of Energy Security and Net Zero are seeking views on reshaping cyber regulation for the downstream gas and electricity sector in Great Britain.

The consultation considers whether there is a need to change how cyber resilience requirements apply across the downstream gas and electricity sector. We propose introducing baseline cyber requirements for all Ofgem licensees, to ensure cyber is on everyone’s agenda and introduce a consistent cyber starting point for the energy system. It also explores the possible expansion of the scope of the Network and Information System Regulations 2018, through a review of thresholds and essential services for designation in the downstream gas and electricity sectors.

We welcome feedback and evidence from a range of stakeholders; including from Ofgem licensees, developers and industry bodies to think tanks and academia, to inform the development of our proposals. Your input will be vital in shaping requirements that are appropriate and proportionate, future-proof, and are effective in defending against an evolving and complex, threat landscape.

Read our consultation privacy notice.

Documents

Updates to this page

Published 27 March 2026
Last updated 5 August 2026 Show all updates
  1. Published the government response for this consultation.

  2. First published.

Sign up for emails or print this page