M

Member

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

83: After Clause 28, insert the following new Clause— “Digital Sovereignty Strategy (relevant network and information systems)(1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems.(2) The Strategy must—(a) set out the Government’s assessment of the risks to relevant network and information systems arising from or related to—(i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference,(ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers,(iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities,(iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, and(v) foreign actors’ access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions;(b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK;(c) set out the Government’s approach to mitigating the risks identified under paragraph (b); (d) include an assessment of—(i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems,(ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems,(iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems,(iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems,(v) options for international collaboration in the production of open source components used in relevant network and information systems,(vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems,(vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and(viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems.(3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to—(a) infrastructure, including infrastructure concentration,(b) data-jurisdiction exposure,(c) value of information and cultural assets of the United Kingdom, and(d) dependency on foreign states.(4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult—(a) the Office for National Statistics,(b) the Competition and Markets Authority,(c) the National Cyber Security Centre,(d) the AI Security Institute, and(e) any other persons the Secretary of State deems relevant.(5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security.(6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen.(7) In this section—“Digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend;“open source” has the meaning given to it in the definition published by the Open Source Initiative;“relevant network and information system” means a network and information system belonging to—(a) an operator of an essential service, (b) a relevant digital service provider,(c) a relevant managed service provider, or(d) a critical supplier,within the meaning of the NIS Regulations.”Member’s explanatory statement This new clause would require the Secretary of State to prepare, maintain, and lay before Parliament a Digital Sovereignty and Resilience Strategy addressing risks to relevant network and information systems from foreign ownership, interference, and technological dependence. The Strategy would include a Digital Sovereignty Dashboard, which would provide evidence on UK procurement, innovation and resilience and keep an up-to-date understanding of emerging risk.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.