The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with power to prohibit the recipient from disclosing that the direction exists.
Baroness Lloyd of Effra, the DSIT minister responsible for cyber security, said the new powers meant the government could act before a threat materialised rather than after the damage was done, and that working with industry would put national security at the heart of how essential services choose their suppliers.
The amendments, published on 25 August ahead of Lords Grand Committee, adapt the designated vendor direction mechanism in the Telecommunications (Security) Act 2021, used to remove Huawei equipment from 5G networks, and extend it across the sectors regulated under the Network and Information Systems Regulations 2018.
The new clauses, inserted before clause 43 of the bill, would provide that:
- The Secretary of State may give a "vendor-related direction" to a person specified in regulations, being a regulated entity under the bill or any person who carries on an essential activity in the UK or provides essential goods or services, where a risk to national security arises or could arise from that person's use of goods, services or facilities supplied by another person.
- A direction may require the recipient to manage its systems in a particular way, prohibit or restrict the use of specified goods or services, prohibit installation or take-up of new goods or services, remove, disable or modify goods or facilities already in use, provide information, or appoint a "skilled person" to assist with compliance. The skilled person must be approved in writing by the Secretary of State, who may rely on a list published by GCHQ.
- It does not matter whether the vendor is established in the UK, whether the goods or services are provided from inside or outside the UK, or whether their use is within the UK.
- Before giving a direction the Secretary of State must consult the recipient, the vendor and any other appropriate person, but that duty is disapplied to the extent the Secretary of State considers compliance would be contrary to the interests of national security. The direction must state reasons, except where doing so would be contrary to national security.
- The Secretary of State may require the recipient not to disclose the existence or contents of the direction, and may require anyone consulted not to disclose that the consultation took place, where this is considered necessary and proportionate in the interests of national security. The bill's existing enforcement provisions for non-disclosure requirements would apply.
- The Secretary of State must publish notice that a direction has been given, varied or revoked, but may withhold details where publication would be contrary to national security or would prejudice the commercial interests of any person.
- A mandatory referral scheme may be established by regulations requiring specified persons to refer "qualifying transactions", defined by reference to nature, value, criticality or vendor identity, to the Secretary of State for a decision on whether to give a direction.
- Regulations specifying who may receive directions would be subject to the affirmative procedure, but may be made without prior approval in cases of urgency, lapsing after 28 days unless approved by both Houses.
The amendments also extend the bill's existing clause 43 direction power so that it can be given to persons who are not regulated entities but who the Secretary of State considers carry on essential activities or provide essential goods or services, and provide that functions under Part 4 may be exercised by the Chancellor of the Duchy of Lancaster as well as the Secretary of State.
A statutory prohibition on disclosure imposed under the new clause would engage the absolute exemption in section 44 of the Freedom of Information Act 2000 for information whose disclosure is prohibited by or under any enactment, in addition to the qualified national security exemption in section 24 and the commercial interests exemption in section 43.
Public authorities in scope, including NHS bodies, water and energy operators and local authorities designated under the bill, could therefore be publicly identified as recipients of a direction while being legally prevented from disclosing which supplier it concerned or what they were required to do. The Telecommunications (Security) Act 2021, by contrast, requires the Secretary of State to designate a vendor publicly by notice before a direction can be given, and to send the vendor a copy of any direction.
A government spokesperson said the powers were intended to be used proportionately and only on a case-by-case basis where there were genuine national security concerns, and were not designed to enable broad intervention in routine commercial decisions. The government has also said it will publish cyber-safe procurement guidance for essential service providers and allow them to refer themselves for a risk assessment where they are unsure about a vendor. The Secretary of State would report annually to Parliament on the number of directions given, the sectors affected and how many had been varied or revoked.
The amendments were debated alongside a cross-party amendment from Lord Clement-Jones seeking last-resort powers to shut down AI systems and data centres, which the government rejected on 1 September on the basis that its own direction powers already allow a data centre operator to be told to cease using a particular AI model. Committee stage continues in the Lords.

