Security.io Intelligence DeskThursday, 3 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Regulatory · Executive briefing

UK bill puts vendor removal and procurement restrictions on the table

The UK Parliament's 2 September amendment list includes government proposals for vendor-related directions, removal or prohibition requirements and a mandatory referral scheme for qualifying transactions tied to essential activities and services.

RegulatoryThird-Party RiskSecurity Leadership
Why it is in today’s brief

The government amendments were tabled on 24 August, but Parliament's 2 September second marshalled list made the proposed prohibition, removal and mandatory-referral mechanisms concrete for current Lords scrutiny. It warrants inclusion because covered enterprises need dependency and contractual-exit evidence before any direction. It ranks fifth because the powers remain proposed, while the other selected developments require immediate incident or exposure decisions.

Read first

Treat the amendments as a procurement and resilience planning signal, not a current prohibition. Map UK essential-service dependencies, contractual exit constraints and decision rights before the bill and implementing regulations settle the final scope.

Act now

Map vendors supporting UK essential activities and essential goods or services.

Accountable owner

CISO with general counsel, procurement, operational resilience and UK regulatory affairs

Decision horizon

Monitor through Lords consideration; complete an initial UK critical-vendor and contractual-exit map within 30 days.

AssessmentHigh confidence
Emerging riskCommittee changes, passage or rejection of amendments 102–105, definitions of covered persons and qualifying transactions, named supplier directions, secondary legislation and regulator implementation guidance.

What happened

SecurityWeek reported that the UK government tabled the vendor-related amendments on 24 August 2026. On 2 September 2026, UK Parliament published HL Bill 32-II, the second marshalled list for Grand Committee containing amendments 102–105. The proposals sit within the Cyber Security and Resilience (Network and Information Systems) Bill and address government intervention in technology and service dependencies connected to essential activities or essential goods and services.

Amendment 102 would allow the Secretary of State to issue vendor-related directions where specified organisations use vendor goods, services or facilities that create or could create a national-security risk, provided the direction is considered necessary and proportionate. Proposed directions may restrict or prohibit use, prohibit installation, require removal, disabling or modification, and require appointment of an approved skilled person.

Amendment 105 would permit a mandatory referral scheme for qualifying transactions, with criteria potentially based on transaction nature, value, criticality or vendor identity. The cited parliamentary document is a marshalled list of proposed amendments; it is not enacted law and identifies no prohibited vendor. Final obligations will depend on parliamentary passage, the final statutory text and subsequent regulations.

Why this matters now

The proposal moves supplier cyber risk beyond assurance questionnaires and contractual warranties. If enacted in its current form, the Secretary of State could direct specified organisations to restrict, prohibit, remove, disable or modify vendor goods, services or facilities where national-security conditions are met. That creates a technology-exit and continuity problem requiring joint security, legal, procurement and operational ownership.

A mandatory referral scheme could insert government review before qualifying supplier transactions proceed. Enterprises covered by the future regime may need earlier visibility of renewals, acquisitions, outsourcing and major technology changes. Procurement processes that involve security only after vendor selection would be poorly positioned to supply the required dependency, risk and transition evidence.

The amendments are not operative law. Security leaders should not claim a new legal duty or begin removing unnamed suppliers. The practical response is preparedness: identify concentrated dependencies, test exit assumptions, preserve evidence supporting supplier decisions and establish governance capable of responding quickly if the final Act and secondary legislation retain these powers.

The decision for security leaders

Build a decision-grade dependency register rather than a conventional vendor list. For each UK essential service, record the vendor, supplied function, technical integration, data access, substitution time, operational fallback and contractual exit constraints. This is the evidence needed to assess whether a future direction can be implemented safely.

Procurement and legal teams should review upcoming strategic renewals and technology transactions for potential referral exposure. Establish an internal gate so security and national-security considerations are assessed before commercial commitment, while avoiding premature claims that any supplier is prohibited under the current proposal.

Use resilience exercises to test removal or restriction scenarios for the most concentrated dependencies. The objective is not to predict which vendor could be designated; it is to determine whether the enterprise can maintain essential operations if a direction limits installation, use or continued reliance.

Evidence of closure

  • A dependency register links every UK essential activity to its critical technology and service suppliers.
  • A contract review records exit, migration, data-portability and transition-assistance gaps for each critical supplier.
  • Approved governance defines who assesses, refers, approves or pauses covered supplier transactions.
  • A regulatory tracker records amendment status, final scope, commencement and implementing guidance.

The Security.io assessment

The material change is the publication of specific proposed intervention mechanics, not the creation of a current supplier ban. The powers are broad enough to affect technology strategy, contracting and continuity planning, but their final scope remains contingent on the legislative process and secondary rules. Enterprises should prepare evidence and options without treating amendments as settled obligations.

The mandatory-referral concept could move cyber and national-security review earlier in the transaction lifecycle. That is a governance change: security leaders need visibility of procurement, renewal and outsourcing decisions before contracts become difficult to unwind. Organisations with concentrated foreign or domestic technology dependencies face the same operational question even if no vendor is ultimately designated.

Attribution posture: The parliamentary amendments assign no responsibility for a cyber incident and identify no vendor as a national-security risk. Any claim that a named supplier is covered, prohibited or culpable would exceed the cited evidence.

Questions for the morning meeting

  • Which vendors are indispensable to each UK essential service or essential-goods process?
  • Could the organisation remove or disable a designated supplier within a regulator-directed period?
  • Do contracts provide migration assistance, data portability and termination rights for national-security directions?
  • Who can approve a mandatory supplier referral before procurement or renewal proceeds?

Related intelligence

Shared decision context