The Computer Misuse Act amendment before peers this afternoon creates no statutory defence, whatever its heading says
Amendment 164 obliges a review of whether a defence is needed, and a report saying whether ministers intend to legislate. That is a different and smaller thing, and it explains why it was tabled.
By Parminder Kumar Sharma · · 8 min read

Grand Committee on the Cyber Security and Resilience Bill sits again this afternoon at 15:45, and Amendment 164 is on the list. Its heading reads:
"Computer Misuse Act 1990: statutory defence for cyber security activities"
It is sponsored by Lord Clement-Jones for the Liberal Democrats, with Lord Arbuthnot of Edrom and Lord Holmes of Richmond from the Conservative benches and Baroness Finlay of Llandaff from the Crossbenches. Cross-party, and the long-running ask of the security research community.
I pulled the operative text from the Bills API this morning, because the marshalled list PDF blocks automated fetching and the heading is not the clause.
The amendment does not create a statutory defence.
What it actually does
What the heading says, and where the clause stops
The clause, verbatim, requires that the Secretary of State "must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 ... is necessary or desirable".
The review "must consider, in particular" three things: the position of "cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith"; the "conditions and safeguards (including as to authorisation, proportionality and reporting)" any defence should contain; and "the approaches taken in other jurisdictions".
Then a report to Parliament setting out the findings, and "whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so".
Three duties, all of them procedural. The sponsors' own explanatory statement says so plainly: it "seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence ... is needed".
So nobody is being misleading. The drafting is honest and the explanatory note is accurate. It is the heading that will travel, and the heading says something the clause does not do.
The reason a review duty is being asked for at all
Here is the part that makes this afternoon interesting, and it is visible only if you put two government statements side by side.
On 3 December 2025, the Security Minister Dan Jarvis told the FT Cyber Resilience Summit, and gov.uk published it:
"Which is why we are looking at a legal change to the Computer Misuse Act. This would create a 'statutory defence' for these researchers to spot and share vulnerabilities, which would protect them from prosecution, as long as they meet certain safeguards."
That is about as clear as ministerial language gets. Named mechanism, named effect.
On 3 September 2026, nine months later, the same minister answered written question UIN 22222, tabled by James Naish, on whether the department plans to review the effectiveness of the Act. The full relevant passage:
"The Government is conducting an ongoing review of the Computer Misuse Act 1990 and is actively taking forward reforms to the cyber landscape. Proposals to update the CMA will be introduced as soon as parliamentary time allows. The changes will allow law enforcement agencies to more effectively tackle threats posed by cyber criminals. The reforms will create a Cyber Crime Risk Order to place robust controls on the behaviours of cyber criminals, alongside new powers to search individuals believed to be concealing evidence on behalf of suspects. It will also unlock the power of cyber security professionals to better enable them to secure computer systems."
The phrase "statutory defence" is not in it.
The two named, concrete reforms are both enforcement powers: a Cyber Crime Risk Order, and new search powers. The researcher provision has become "unlock the power of cyber security professionals to better enable them to secure computer systems", which commits to no mechanism at all.
The same commitment, in the government's own words, four days ago and nine months ago
| Date | What was said | What it commits to |
|---|---|---|
| 3 December 2025 | “This would create a ‘statutory defence’ for these researchers … which would protect them from prosecution, as long as they meet certain safeguards” | A named legal mechanism with a named effect |
| 3 September 2026 | “It will also unlock the power of cyber security professionals to better enable them to secure computer systems” | No mechanism named. No effect named |
| 3 September 2026, same answer | “The reforms will create a Cyber Crime Risk Order … alongside new powers to search individuals” | Two specific new enforcement powers, both named |
Read that table in the other direction and it explains the amendment. If the government were still committed to a defence in the terms it used in December, a review duty would be redundant. Asking for one is a way of finding out whether the December sentence is still operative.
What this means if you do security research in Britain
Nothing changes today, and nothing changes if the amendment passes. That is the honest answer and it is worth saying before the practical notes.
Take this with you
Where this actually leaves you
- The legal position under section 1 of the Computer Misuse Act is unchanged, and will remain unchanged whatever happens this afternoon. Unauthorised access remains an offence with no good-faith carve-out.
- If you are relying on the December 2025 commitment when scoping work, note that the government’s most recent formal statement, four days ago and in writing, does not repeat it. Plan against the law as it is.
- Watch for the word used in the Minister’s reply this afternoon. If a defence is named, that is a restatement worth having on the record. If the answer is the September formulation, that is the answer.
- The reform vehicle is a future National Security Bill, and the timing is “as soon as parliamentary time allows”, which is not a date. An amendment forcing a report within twelve months of Royal Assent is an attempt to attach one.
- If you run a disclosure programme, keep documenting authorisation. Every version of a proposed defence, including the one in this amendment’s review criteria, turns on authorisation, proportionality and reporting. Whatever eventually arrives, that evidence is what you will need.
- Grand Committee day four is Wednesday 9 September at 16:15, so if this is not reached today it is reached then.
The position
There is a version of this story where a cross-party group of peers finally legislated protection for security researchers this afternoon. That version will be written. It is wrong on the face of the document.
What is actually happening is smaller and, in its way, more revealing. Four peers have concluded that the way to make progress on a nine-month-old ministerial commitment is to compel a review of whether the commitment should be honoured, with a report to Parliament and a stated timetable. You do not ask for that when a promise is being kept.
The Minister's answer this afternoon is the thing to listen to, and the specific thing to listen for is whether the words "statutory defence" come back.
Sources
- PrimaryAmendment 164 to the Cyber Security and Resilience Bill, read verbatim from the Bills API: the operative text, the four sponsors, and the status recording that the House has not considered itUK Parliamentaccessed 2026-09-07
- PrimaryWritten question UIN 22222, tabled 28 August 2026 by James Naish, answered 3 September 2026 by Dan Jarvis: the government's most recent formal statement on Computer Misuse Act reformUK Parliamentaccessed 2026-09-07
- PrimaryKeynote address to the FT Cyber Resilience Summit, 3 December 2025, in which the Security Minister said a change would create a statutory defence protecting researchers from prosecutionHome Officeaccessed 2026-09-07


