P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The Computer Misuse Act defence came back yesterday, with a new word in front of it

In Grand Committee the Minister said the Home Office proposes a defence to Section 1 for accredited cyber security researchers. The mechanism returned. The population narrowed, and no accreditation scheme exists.

By Parminder Kumar Sharma · · 9 min read

A long polished committee table in a wood-panelled parliamentary room after the sitting has risen and the room has emptied: a thick bundle of loose printed amendment papers stacked and unturned in the centre, a few separate sheets pulled clear beside it, a water glass, a pen and two pairs of reading glasses, with an empty green leather chair pushed back at an angle.

Yesterday afternoon, in Grand Committee on the Cyber Security and Resilience Bill, the Government answered Amendment 164. We wrote on Monday morning that the amendment created no statutory defence whatever its heading said, and that the thing worth listening for was whether the phrase the Government had quietly dropped in September would come back.

It came back. It came back with a word in front of it that appears in no previous statement.

Baroness Lloyd of Effra, replying for the Government:

“The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA.”

Read that twice. The mechanism is named again. A defence to Section 1 is a real, specific legal thing, and it is more than the written answer of 3 September offered, which named no mechanism at all. This is the first time since December 2025 that a Minister has put the defence back on the parliamentary record.

The qualifier is the new part.

One word, and where it came from

The same commitment, three times, in nine months

THE SAME COMMITMENT, THREE TIMES, IN NINE MONTHSWatch two things: whether a mechanism is named, and who it covers.WHAT WAS SAIDMECHANISMWHO IT COVERS3 December 2025 · Speech, published on gov.ukwould create a “statutory defence” … whichwould protect them from prosecutionnamed“these researchers”3 September 2026 · Written answer, UIN 22222will also unlock the power of cyber security professionalsnone“cyber securityprofessionals”7 September 2026 · Grand Committee, on the recordproposes to introduce a defence to Section 1named“accredited cybersecurity researchers”The mechanism came back. The population did not. “Accredited” is in neither earlier statement.Who runs the accreditation, what it costs, and who fails it are now the whole question, and none of it has been described.
A defence that protects accredited researchers is a real improvement on no defence at all. It is also a different proposition from the one described in December, because it converts a legal protection into a membership question, and the membership scheme does not yet exist.
All three statements read from primary sources: the gov.uk speech text of 3 December 2025, written answer UIN 22222 answered 3 September 2026, and Lords Hansard for Grand Committee day three on 7 September 2026, retrieved through the Hansard API on 8 September 2026.

In December the Security Minister said the change would create a statutory defence for “these researchers”, meaning the researchers he had spent the previous paragraph describing. In the written answer of 3 September the population was “cyber security professionals”. Yesterday it became “accredited cyber security researchers”.

A defence gated on accreditation is not a defence available to security researchers. It is a defence available to members of a scheme, and the scheme does not exist.

The questions the word opens, none of which have been answered

Nobody has said who would run the accreditation. Nobody has said what it would cost, whether it would run annually, whether it would be open to individuals or only to registered firms, what would disqualify an applicant, or what would happen to work carried out while an application was pending.

Nobody has said whether an accredited researcher’s protection reaches the people around them: a subcontractor on the same engagement, a student, an unpaid volunteer triaging reports for a coordinated disclosure programme, or somebody who finds a flaw by accident and does the right thing with it.

There is also a plain arithmetic problem. Most vulnerability research done in this country is done by people who could not currently name the body that would accredit them, because there is not one. Whatever the eventual scheme looks like, on the day it opens the number of accredited researchers in the United Kingdom is nought, and the defence protects nobody until that changes.

The contradiction in the same debate

The Minister’s reply contained a second claim: that “the noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February”, offered as evidence of “meaningful progress”.

Lord Clement-Jones replied a few minutes later, in the same sitting:

“I have had no contact from anybody in the Home Office about what they might insert in the Bill.”

And, on the record:

“It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.”

Both statements are in Hansard for the same debate. They can be reconciled, because a February briefing on Computer Misuse Act reform in general is not the same thing as contact about what the Home Office might insert into this Bill. But that reconciliation is doing a great deal of work, and neither speaker offered it. If you are trying to work out how firm the accreditation proposal is, the fact that the Government and its principal interlocutor do not agree on whether they have discussed it is a data point.

He also withdrew the amendment rather than press it, and said he expects to return to it: “She may well find that we come back to this on Report.”

Committee finished a day early

Grand Committee was listed for four sittings. It sat on 1, 3 and 7 September and concluded on the third. The sitting scheduled for 9 September did not happen. The Bill’s current stage on the parliamentary record is now Report stage, with no date set.

What Grand Committee did with 193 amendments

193 AMENDMENTS TABLED. FIVE AGREED. ALL FIVE THE GOVERNMENT’S OWN.Grand Committee, listed for four sittings, concluded in three on 7 September 2026.167NOT MOVED21WITHDRAWN21 withdrawn5 agreedWHAT “NOT MOVED” MEANSTabled, published, then never called. It was notdefeated. Nothing at all was decided about it.WHERE THE VENDOR PACKAGE LANDEDTabled by the Minister. Not moved by the Minister.Amendments 101, 102, 105, 151 and 152, back at Report.
A low agreement rate in Grand Committee is normal and is not by itself a criticism. It matters here because the two questions this Bill raised for security practitioners, researcher liability and vendor risk, were both resolved by not being decided.
Counts read from bills-api.parliament.uk, Bill 4035, stage 21083, on 8 September 2026. Every amendment carries a recorded disposal, and the sponsor of each is published alongside it.

Five amendments were agreed. All five, numbers 4, 5, 19, 36 and 44, stand in the Minister’s own name. Twenty-one were withdrawn after debate. The remaining 167 were not moved, which means they were tabled, published on the marshalled list, and then never called. Nothing was decided about any of them. They can return unchanged at Report.

A low agreement rate in Lords Grand Committee is entirely normal and is not by itself a criticism. Grand Committee cannot divide, so almost everything that is pressed is pressed to be answered rather than to be won. It matters here because both of the questions this Bill raised for people who actually do security work, researcher liability and vendor risk, were resolved by not being decided.

The Committee record, sitting by sitting

SittingDateWhat happened
Day one1 September 2026Committee stage began
Day two3 September 2026Committee stage continued
Day three7 September 2026Amendment 164 debated and withdrawn. Committee concluded.
Day fourListed for 9 September 2026Did not take place
Next stageNo date setReport stage, where the vendor package returns
Sitting dates and the current stage read from bills-api.parliament.uk, Bill 4035, on 8 September 2026. Committee was listed for four sittings and rose after three.

The Government did not move its own vendor package

This is the part that has gone unreported, and it is checkable in thirty seconds.

In late August the Government tabled a package of amendments creating powers to direct operators to remove or disable a named vendor’s equipment from critical infrastructure. It briefed the package to three trade outlets. It published no press release, no written statement and nothing on gov.uk. We wrote that up yesterday morning.

The five load-bearing amendments in that package are numbers 101, 102, 105, 151 and 152. Every one of them stands in the name of Baroness Lloyd of Effra. Every one of them is recorded as Not Moved.

The Government tabled its own vendor security package, briefed it to the press, and then did not put it to the Committee.

The Minister’s explanation, in the same debate:

“That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.”

So the powers are coming back at Report, on the Government’s own account, and “essential” is the Government’s word for them. The practical consequence is that a set of powers reaching removal of installed equipment, and capable of requiring something to be done outside the United Kingdom, will now receive its first substantive parliamentary consideration at a stage with less time and a narrower procedure than the one just skipped.

What to do about any of this

Take this with you

Practical positions, in order of how soon they matter

  • Nothing has changed in law. Section 1 of the Computer Misuse Act is exactly as it was yesterday, with no good faith carve-out. Scope and authorise your work on that basis and do not price in a defence that has no vehicle, no text and no date.
  • Keep your authorisation evidence. Every version of a proposed defence, including the accredited one, turns on authorisation, proportionality and reporting. Whatever eventually arrives, contemporaneous scope documents and disclosure records are what you will be asked for.
  • If you run or contribute to a disclosure programme, start thinking now about how an accreditation gate would treat your contributors. Volunteers, students and one-off reporters are the population a membership scheme handles worst, and consultation on the scheme has not opened.
  • If you supply critical national infrastructure, treat the vendor directions package as live rather than dropped. It was tabled by the Government, not moved, and the Minister has said on the record that it returns at Report.
  • Watch the Report stage date. It is not yet listed. Report is where the vendor package returns and where Lord Clement-Jones has said the Computer Misuse Act question returns as well.
  • Read the disposal, not the headline. “Not moved” is not “rejected”. One hundred and sixty-seven amendments to this Bill are in that state and every one of them can come back unchanged.

The position

Monday’s piece ended by saying the specific thing to listen for was whether the words “statutory defence” came back. They did, which is genuinely better than the alternative and should be said plainly.

But the sentence that came back is not the sentence that went away. In December the promise was a defence for researchers. Yesterday it was a defence for accredited researchers, and the accreditation scheme is not described anywhere in public: not in the speech, not in the written answer, not in Hansard, and not in the Bill. A protection that depends entirely on an institution nobody has built is not yet a protection. It is a design brief.

The Government now has two things it has told Parliament are priorities and has moved neither: a Computer Misuse Act defence that will arrive “as parliamentary time allows”, and a vendor security package it tabled, briefed and then left on the paper. Both now sit at Report stage, which has no date.

Sources

  1. PrimaryLords Grand Committee day three on the Cyber Security and Resilience Bill, 7 September 2026, containing the Minister’s reply on Amendment 164 naming a defence to Section 1 for accredited cyber security researchers, Lord Clement-Jones’s statement that he had had no contact from the Home Office, and the Minister’s undertaking to return to the vendor package at ReportUK Parliamentaccessed 2026-09-08
  2. PrimaryEvery amendment tabled at Lords Committee stage of the Cyber Security and Resilience Bill with its recorded disposal and sponsor: 193 in total, 5 agreed, 21 withdrawn and 167 not moved, including amendments 101, 102, 105, 151 and 152 in the Minister’s own nameUK Parliamentaccessed 2026-09-08
  3. PrimaryKeynote address to the FT Cyber Resilience Summit, 3 December 2025, the statement in which the Security Minister said a change would create a statutory defence for these researchers, with no accreditation qualifierHome Officeaccessed 2026-09-08
  4. PrimaryWritten question UIN 22222, answered 3 September 2026, the intermediate statement in which the mechanism was not named and the population was cyber security professionalsUK Parliamentaccessed 2026-09-08

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.