What happened
SecurityWeek reported that the UK government tabled the vendor-related amendments on 24 August 2026. On 2 September 2026, UK Parliament published HL Bill 32-II, the second marshalled list for Grand Committee containing amendments 102–105. The proposals sit within the Cyber Security and Resilience (Network and Information Systems) Bill and address government intervention in technology and service dependencies connected to essential activities or essential goods and services.
Amendment 102 would allow the Secretary of State to issue vendor-related directions where specified organisations use vendor goods, services or facilities that create or could create a national-security risk, provided the direction is considered necessary and proportionate. Proposed directions may restrict or prohibit use, prohibit installation, require removal, disabling or modification, and require appointment of an approved skilled person.
Amendment 105 would permit a mandatory referral scheme for qualifying transactions, with criteria potentially based on transaction nature, value, criticality or vendor identity. The cited parliamentary document is a marshalled list of proposed amendments; it is not enacted law and identifies no prohibited vendor. Final obligations will depend on parliamentary passage, the final statutory text and subsequent regulations.
Why this matters now
The proposal moves supplier cyber risk beyond assurance questionnaires and contractual warranties. If enacted in its current form, the Secretary of State could direct specified organisations to restrict, prohibit, remove, disable or modify vendor goods, services or facilities where national-security conditions are met. That creates a technology-exit and continuity problem requiring joint security, legal, procurement and operational ownership.
A mandatory referral scheme could insert government review before qualifying supplier transactions proceed. Enterprises covered by the future regime may need earlier visibility of renewals, acquisitions, outsourcing and major technology changes. Procurement processes that involve security only after vendor selection would be poorly positioned to supply the required dependency, risk and transition evidence.
The amendments are not operative law. Security leaders should not claim a new legal duty or begin removing unnamed suppliers. The practical response is preparedness: identify concentrated dependencies, test exit assumptions, preserve evidence supporting supplier decisions and establish governance capable of responding quickly if the final Act and secondary legislation retain these powers.
The decision for security leaders
Build a decision-grade dependency register rather than a conventional vendor list. For each UK essential service, record the vendor, supplied function, technical integration, data access, substitution time, operational fallback and contractual exit constraints. This is the evidence needed to assess whether a future direction can be implemented safely.
Procurement and legal teams should review upcoming strategic renewals and technology transactions for potential referral exposure. Establish an internal gate so security and national-security considerations are assessed before commercial commitment, while avoiding premature claims that any supplier is prohibited under the current proposal.
Use resilience exercises to test removal or restriction scenarios for the most concentrated dependencies. The objective is not to predict which vendor could be designated; it is to determine whether the enterprise can maintain essential operations if a direction limits installation, use or continued reliance.
Evidence of closure
- A dependency register links every UK essential activity to its critical technology and service suppliers.
- A contract review records exit, migration, data-portability and transition-assistance gaps for each critical supplier.
- Approved governance defines who assesses, refers, approves or pauses covered supplier transactions.
- A regulatory tracker records amendment status, final scope, commencement and implementing guidance.
The Security.io assessment
The material change is the publication of specific proposed intervention mechanics, not the creation of a current supplier ban. The powers are broad enough to affect technology strategy, contracting and continuity planning, but their final scope remains contingent on the legislative process and secondary rules. Enterprises should prepare evidence and options without treating amendments as settled obligations.
The mandatory-referral concept could move cyber and national-security review earlier in the transaction lifecycle. That is a governance change: security leaders need visibility of procurement, renewal and outsourcing decisions before contracts become difficult to unwind. Organisations with concentrated foreign or domestic technology dependencies face the same operational question even if no vendor is ultimately designated.
Attribution posture: The parliamentary amendments assign no responsibility for a cyber incident and identify no vendor as a national-security risk. Any claim that a named supplier is covered, prohibited or culpable would exceed the cited evidence.
Questions for the morning meeting
- Which vendors are indispensable to each UK essential service or essential-goods process?
- Could the organisation remove or disable a designated supplier within a regulator-directed period?
- Do contracts provide migration assistance, data portability and termination rights for national-security directions?
- Who can approve a mandatory supplier referral before procurement or renewal proceeds?