Bill · started in the Commons

Cyber Extortion and Ransomware (Reporting) Bill

A Bill to require a company that meets specified criteria to report any cyber extortion or ransomware attack on the company to the Government within a specified time after the attack; to make provision about the content of such reports, including a requirement to provide information about any payments made; and for connected purposes.

In progress Current stage: 2nd reading (Commons)

The story so farThe Cyber Extortion and Ransomware (Reporting) Bill was introduced in the House of Commons on 21 October 2025 by Bradley Thomas (Conservative). It is now at second reading in the House of Commons. Second reading is the first debate on the overall principle of the bill; if the bill clears it, detailed committee scrutiny follows.

Sponsor

Progress through Parliament

  1. 1st reading Commons 21 Oct 2025
  2. 2nd reading Commons Current

Source: the official bill page. Last updated 1 May 2026.