According to the Department for Energy Security and Net Zero (DESNZ) and Ofgem, the baseline standards will be founded on the existing ‘Cyber Essentials Plus’ scheme that the government operates, which sets cyber standards that organisations can adopt and obtain independent certification for. A consultation on the precise substance of the requirements is planned for next year. The DESNZ and Ofgem have pledged to minimise regulatory burdens and duplication with existing and forthcoming cyber requirements some licensees in the DGE market are already subject to.
A cohort of DGE operators are subject to UK cyber regulation under the Network and Information Security (NIS) Regulations 2018. The NIS regime applies to ‘operators of essential services’, which must keep their networks and information secure and notify security incidents when they occur. However, amidst “energy system and technology transformation”, the DESNZ and Ofgem want to ensure “the most critical organisations” in the DGE market are within the scope of NIS and have commissioned the National Energy System Operator (NESO) to advise them on whether the existing scope and thresholds for NIS regulation need to be adjusted to achieve this.
The government intends to exercise powers contained in draft legislation currently making its way through the UK parliament to update the NIS regime, should such a move be recommended by NESO. Subject to the Cyber Security and Resilience Bill (CSRB) receiving Royal Assent, a consultation on those proposals will be opened in 2027, it said.
The policy decisions were contained in a response (39-page / 413KB PDF) published by the DESNZ and Ofgem to a consultation they ran earlier this year on reshaping cyber regulation in the DGE market. The government previously set out a strategic goal of raising cyber resilience across the whole DGE system by the end of 2030.
Cyber risk expert Stuart Davey of Pinsent Masons said: “It is notable that 90% of respondents to the consultation either agreed or cautiously agreed that there is a need for a review of NIS.”
“For those in the sector currently caught by NIS, proposals that follow to amend NIS thresholds and essential services will need to be kept under review, alongside the CSRB and other associated consultations – the government mentioned, for example, that further cyber resilience requirements could follow for a subset of Ofgem licensees from the European Partnership Bill it has committed to bring before parliament. That bill is earmarked for enabling implementation of agreements the UK reaches with the EU. A deal for the UK to rejoin the EU's internal electricity market is being considered by negotiators and could require some regulatory alignment – including around cyber,” he added.
“For the wider DGE sector, these proposals may represent the first time that they are subject to specific cybersecurity obligations, with compliance being potentially linked to licensing processes,” Davey said.