UK data centres have spent the last two years being quietly promoted up the regulatory ladder. In 2024 they were formally designated as Critical National Infrastructure, putting them on the same footing as energy, water and emergency services. The Cyber Security and Resilience (Network and Information Systems) Bill, currently moving through Parliament with Royal Assent expected later in 2026, now goes a step further: it makes data centre services an “essential service” in their own right, inside a new data infrastructure subsector.

For operators of colocation, hyperscale and large enterprise facilities, this is the most consequential change in a decade. It pulls data centres into the same regulatory framework that has governed banks, telecoms and energy companies for years – with statutory duties around resilience, incident reporting and, importantly for our work, physical security. Our team has fielded a sharp uptick in enquiries from operators trying to understand what “appropriate and proportionate” will look like in practice.

What has actually changed

Two regulatory shifts are converging. The 2024 CNI designation was symbolic but consequential: it signalled that the disruption of a major UK data centre is now treated as a national security event. The Cyber Security and Resilience Bill turns that signal into statute. It amends the existing NIS Regulations to bring data centre operators into scope, and names Ofcom as the operational regulator.

Once commenced, in-scope operators will be required to notify the regulator, satisfy structured information requirements, implement appropriate technical and organisational security measures, and report significant incidents. Full provisions will follow secondary legislation and statutory Codes of Practice issued by the Department for Science, Innovation and Technology. Industry analysis suggests phased implementation may not be fully in force until 2028, but operators are expected to begin preparing now.

Who falls inside the threshold

The Bill draws the line by rated IT load rather than floor area or revenue, which is the right call – it tracks the actual scale of the facility’s footprint on the digital economy.

  • Non-enterprise data centres – that is, colocation and third-party facilities – come into scope at a rated IT load of 1 megawatt or above.
  • Enterprise data centres, operated solely to support the IT needs of their owner, come into scope at 10 megawatts or above.

The thresholds are deliberately broad. A 1 MW colocation footprint is not a hyperscale campus – it is well within the range of mid-market UK operators in London, Slough, Manchester and the regional digital hubs. Most commercial colos we work with will be in scope.

Physical security is explicitly in the frame

The Bill is often framed as cyber legislation, but its drafters were careful to include physical and operational resilience inside the security obligations. The statutory language addresses protection from disruption caused by physical threats and hazards – power outages, equipment failure, human error, environmental damage, and unauthorised physical access leading to damage of network and information systems.

In practical terms, operators should expect their security baseline to be assessed across four overlapping areas:

  • Perimeter and access control – layered perimeters, anti-ram measures where appropriate, vehicle screening for delivery routes, biometric or two-factor access at controlled zones, and a documented visitor escort regime.
  • Manned guarding presence – 24/7 SIA-licensed officers, control-room staffing, mobile patrols, incident response procedures, and integration with police and emergency services.
  • Surveillance and detection – CCTV with retention aligned to incident response timelines, intrusion detection at zone boundaries, and increasingly counter-UAS capability for facilities flagged as higher-risk.
  • Construction-phase security – new-build and expansion projects sit in a vulnerable window. Construction site security for a data centre build is a specialist requirement, not a generic guarding contract.

What this means for operators and corporate occupiers

The shift is not just regulatory housekeeping. Three implications matter most.

First, the documentation burden rises sharply. Operators will need defensible records of their security posture, change management, supplier assurance and incident response – the kind of evidence the FCA and energy regulators have demanded of their sectors for years. Physical security audits and written procedures move from “nice to have” to “show me on inspection”.

Second, supplier vetting tightens. The Bill carries a managed services and supply-chain risk angle, which means guarding contractors, cleaning firms and engineering subcontractors will face closer scrutiny. SIA-regulated, fully insured, properly vetted suppliers will be a baseline requirement, not a premium feature.

Third, the bar rises for corporate occupiers too. Banks, government departments, healthcare providers and large enterprises hosting workloads in colocation facilities will increasingly ask hard questions about the physical security of the buildings their data sits in. Operators who can answer those questions with evidence will win contracts. Those who cannot will lose them. Our corporate security practice is already seeing this conversation come up in renewals.

Need a security review?

If you operate a UK data centre in the 1 MW-and-above range, or if you are an enterprise occupier whose contracts depend on the resilience of those facilities, now is the right time to benchmark your physical security against where the regulation is going. Our team carries out independent reviews covering perimeter, access control, manned guarding, surveillance and construction-phase security.

Call us on 020 3700 0967, email info@secureonsitesecurity.co.uk, or use our contact form. For sector-specific information, see our pages on corporate security and construction site security.

Loading...
Share This