Summary
- Government amendments would create vendor-related directions covering technology used by organisations providing essential services.
- Ministers could prohibit new installations, restrict existing technology, or require equipment and services to be removed, disabled, or modified.
- National-security exemptions could limit disclosure around consultations and decisions, giving the powers significant commercial consequences.
UK ministers could gain powers to stop essential-service operators buying technology from particular suppliers, restrict systems already in use, and order equipment or services to be removed or disabled under amendments to the Cyber Security and Resilience (Network and Information Systems) Bill. The proposals would make technology procurement across health, energy, water, transport, digital infrastructure, managed services, and datacentres a more explicit national-security issue.
A running list of House of Lords amendments published on 26 August introduces “vendor-related directions”, which could be issued where the Secretary of State considers that particular goods, services, or facilities create a national-security risk around an essential activity or service.
The proposed direction could cover much more than a future purchasing decision. Ministers could prohibit or restrict the use of a supplier’s technology, block installation or uptake, require products or facilities to be removed, disabled, or modified, and compel organisations to appoint specialist help to implement the instruction.
The bill already contains powers allowing government to direct regulated entities during serious national-security threats, but the vendor amendments create a more specific mechanism around supplier risk. Intervention could therefore occur before hostile actors had exploited a product, shifting part of the regime towards controlling which technologies are allowed inside essential services.
Procurement moves into national-security policy
Supply chain security has become a larger part of UK cyber policy because compromise of a widely used technology provider can expose several organisations at once. The broader bill already expands regulation beyond conventional operators of essential services by bringing some managed service providers, datacentres, and critical suppliers into its scope.
Under the amendments, ministers could act where technology used in the UK creates risk even if the vendor itself is established overseas. That reach reflects the international supply chains on which British public services and critical industries depend.
The precedent most readily associated with vendor restrictions is the removal of Huawei equipment from the UK’s 5G networks, although the proposed powers extend across a much wider set of sectors and do not identify any individual company or country.
The commercial consequences could be significant because an order would not simply alter the next procurement cycle. An organisation might have to replace deployed technology, change configuration, terminate a service, or migrate operational systems according to a government timetable.
Those changes can produce security and resilience risks of their own. Replacing networking equipment, a cloud platform, a managed service, or operational technology may require data migration, integration work, testing, training, and transitional duplication while the essential service continues operating.
Security decisions may remain partly confidential
The amendments include consultation requirements, but ministers could reduce them where consultation itself was judged to conflict with national security. Normally the organisation receiving the direction and the vendor concerned would be consulted, although the proposed powers leave room for restrictions where disclosure creates additional risk.
Confidentiality could continue after an order was issued. Recipients might be prevented from revealing the existence or contents of a direction without permission, while specialists brought in to help could require approval before being appointed.
Parliament would receive some visibility through notices when a vendor-related direction is issued, varied, or revoked and through annual reporting on the use of the powers. Ministers could nevertheless omit material where publication would damage commercial interests or conflict with national security.
That balance is likely to attract scrutiny because a technology company could lose access to important customers while the intelligence behind the decision remained partly secret. Operators may also seek clarity around switching costs, implementation deadlines, rights of challenge, and the standards used to determine whether an alternative supplier reduces the underlying risk.
The policy also raises a broader concentration problem. Replacing one supplier considered dangerous does not automatically create a diverse technology market, particularly where cloud, identity, networking, and enterprise software are already dominated by a small number of global providers.
The Lords committee stage will determine how much of the amendment package survives and whether stronger safeguards are added around transparency or redress. The direction of travel is nevertheless clear: technology purchasing by essential-service operators is moving from an ordinary commercial decision with security controls around it towards a choice that ministers may be able to intervene in directly.












