The Computer Misuse Act defence came back yesterday, with a new word in front of it
In Grand Committee the Minister said the Home Office proposes a defence to Section 1 for accredited cyber security researchers. The mechanism returned. The population narrowed, and no accreditation scheme exists.
By Parminder Kumar Sharma · · 9 min read

Yesterday afternoon, in Grand Committee on the Cyber Security and Resilience Bill, the Government answered Amendment 164. We wrote on Monday morning that the amendment created no statutory defence whatever its heading said, and that the thing worth listening for was whether the phrase the Government had quietly dropped in September would come back.
It came back. It came back with a word in front of it that appears in no previous statement.
Baroness Lloyd of Effra, replying for the Government:
“The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA.”
Read that twice. The mechanism is named again. A defence to Section 1 is a real, specific legal thing, and it is more than the written answer of 3 September offered, which named no mechanism at all. This is the first time since December 2025 that a Minister has put the defence back on the parliamentary record.
The qualifier is the new part.
One word, and where it came from
The same commitment, three times, in nine months
In December the Security Minister said the change would create a statutory defence for “these researchers”, meaning the researchers he had spent the previous paragraph describing. In the written answer of 3 September the population was “cyber security professionals”. Yesterday it became “accredited cyber security researchers”.
A defence gated on accreditation is not a defence available to security researchers. It is a defence available to members of a scheme, and the scheme does not exist.
The questions the word opens, none of which have been answered
Nobody has said who would run the accreditation. Nobody has said what it would cost, whether it would run annually, whether it would be open to individuals or only to registered firms, what would disqualify an applicant, or what would happen to work carried out while an application was pending.
Nobody has said whether an accredited researcher’s protection reaches the people around them: a subcontractor on the same engagement, a student, an unpaid volunteer triaging reports for a coordinated disclosure programme, or somebody who finds a flaw by accident and does the right thing with it.
There is also a plain arithmetic problem. Most vulnerability research done in this country is done by people who could not currently name the body that would accredit them, because there is not one. Whatever the eventual scheme looks like, on the day it opens the number of accredited researchers in the United Kingdom is nought, and the defence protects nobody until that changes.
The contradiction in the same debate
The Minister’s reply contained a second claim: that “the noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February”, offered as evidence of “meaningful progress”.
Lord Clement-Jones replied a few minutes later, in the same sitting:
“I have had no contact from anybody in the Home Office about what they might insert in the Bill.”
And, on the record:
“It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.”
Both statements are in Hansard for the same debate. They can be reconciled, because a February briefing on Computer Misuse Act reform in general is not the same thing as contact about what the Home Office might insert into this Bill. But that reconciliation is doing a great deal of work, and neither speaker offered it. If you are trying to work out how firm the accreditation proposal is, the fact that the Government and its principal interlocutor do not agree on whether they have discussed it is a data point.
He also withdrew the amendment rather than press it, and said he expects to return to it: “She may well find that we come back to this on Report.”
Committee finished a day early
Grand Committee was listed for four sittings. It sat on 1, 3 and 7 September and concluded on the third. The sitting scheduled for 9 September did not happen. The Bill’s current stage on the parliamentary record is now Report stage, with no date set.
What Grand Committee did with 193 amendments
Five amendments were agreed. All five, numbers 4, 5, 19, 36 and 44, stand in the Minister’s own name. Twenty-one were withdrawn after debate. The remaining 167 were not moved, which means they were tabled, published on the marshalled list, and then never called. Nothing was decided about any of them. They can return unchanged at Report.
A low agreement rate in Lords Grand Committee is entirely normal and is not by itself a criticism. Grand Committee cannot divide, so almost everything that is pressed is pressed to be answered rather than to be won. It matters here because both of the questions this Bill raised for people who actually do security work, researcher liability and vendor risk, were resolved by not being decided.
The Committee record, sitting by sitting
| Sitting | Date | What happened |
|---|---|---|
| Day one | 1 September 2026 | Committee stage began |
| Day two | 3 September 2026 | Committee stage continued |
| Day three | 7 September 2026 | Amendment 164 debated and withdrawn. Committee concluded. |
| Day four | Listed for 9 September 2026 | Did not take place |
| Next stage | No date set | Report stage, where the vendor package returns |
The Government did not move its own vendor package
This is the part that has gone unreported, and it is checkable in thirty seconds.
In late August the Government tabled a package of amendments creating powers to direct operators to remove or disable a named vendor’s equipment from critical infrastructure. It briefed the package to three trade outlets. It published no press release, no written statement and nothing on gov.uk. We wrote that up yesterday morning.
The five load-bearing amendments in that package are numbers 101, 102, 105, 151 and 152. Every one of them stands in the name of Baroness Lloyd of Effra. Every one of them is recorded as Not Moved.
The Government tabled its own vendor security package, briefed it to the press, and then did not put it to the Committee.
The Minister’s explanation, in the same debate:
“That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.”
So the powers are coming back at Report, on the Government’s own account, and “essential” is the Government’s word for them. The practical consequence is that a set of powers reaching removal of installed equipment, and capable of requiring something to be done outside the United Kingdom, will now receive its first substantive parliamentary consideration at a stage with less time and a narrower procedure than the one just skipped.
What to do about any of this
Take this with you
Practical positions, in order of how soon they matter
- Nothing has changed in law. Section 1 of the Computer Misuse Act is exactly as it was yesterday, with no good faith carve-out. Scope and authorise your work on that basis and do not price in a defence that has no vehicle, no text and no date.
- Keep your authorisation evidence. Every version of a proposed defence, including the accredited one, turns on authorisation, proportionality and reporting. Whatever eventually arrives, contemporaneous scope documents and disclosure records are what you will be asked for.
- If you run or contribute to a disclosure programme, start thinking now about how an accreditation gate would treat your contributors. Volunteers, students and one-off reporters are the population a membership scheme handles worst, and consultation on the scheme has not opened.
- If you supply critical national infrastructure, treat the vendor directions package as live rather than dropped. It was tabled by the Government, not moved, and the Minister has said on the record that it returns at Report.
- Watch the Report stage date. It is not yet listed. Report is where the vendor package returns and where Lord Clement-Jones has said the Computer Misuse Act question returns as well.
- Read the disposal, not the headline. “Not moved” is not “rejected”. One hundred and sixty-seven amendments to this Bill are in that state and every one of them can come back unchanged.
The position
Monday’s piece ended by saying the specific thing to listen for was whether the words “statutory defence” came back. They did, which is genuinely better than the alternative and should be said plainly.
But the sentence that came back is not the sentence that went away. In December the promise was a defence for researchers. Yesterday it was a defence for accredited researchers, and the accreditation scheme is not described anywhere in public: not in the speech, not in the written answer, not in Hansard, and not in the Bill. A protection that depends entirely on an institution nobody has built is not yet a protection. It is a design brief.
The Government now has two things it has told Parliament are priorities and has moved neither: a Computer Misuse Act defence that will arrive “as parliamentary time allows”, and a vendor security package it tabled, briefed and then left on the paper. Both now sit at Report stage, which has no date.
Sources
- PrimaryLords Grand Committee day three on the Cyber Security and Resilience Bill, 7 September 2026, containing the Minister’s reply on Amendment 164 naming a defence to Section 1 for accredited cyber security researchers, Lord Clement-Jones’s statement that he had had no contact from the Home Office, and the Minister’s undertaking to return to the vendor package at ReportUK Parliamentaccessed 2026-09-08
- PrimaryEvery amendment tabled at Lords Committee stage of the Cyber Security and Resilience Bill with its recorded disposal and sponsor: 193 in total, 5 agreed, 21 withdrawn and 167 not moved, including amendments 101, 102, 105, 151 and 152 in the Minister’s own nameUK Parliamentaccessed 2026-09-08
- PrimaryKeynote address to the FT Cyber Resilience Summit, 3 December 2025, the statement in which the Security Minister said a change would create a statutory defence for these researchers, with no accreditation qualifierHome Officeaccessed 2026-09-08
- PrimaryWritten question UIN 22222, answered 3 September 2026, the intermediate statement in which the mechanism was not named and the population was cyber security professionalsUK Parliamentaccessed 2026-09-08


