Resilience Reporting Obligations To Regulators
RESILIENCE REPORTING OBLIGATIONS TO REGULATORS
1. Meaning and Purpose
Resilience reporting obligations require electricity generators, network operators, system operators and other regulated entities to provide regulators with information about threats, vulnerabilities, disruptive incidents, recovery capability and measures taken to maintain continuity of electricity services. Reporting converts resilience from an internal corporate concern into a legally supervised regulatory responsibility.
The information may concern physical infrastructure failure, extreme weather, cybersecurity, supply shortages, network congestion, emergency preparedness, financial resilience or dependencies on communications and other critical infrastructure. Regulators use these reports to assess whether operators are identifying risks early enough and investing adequately in prevention, mitigation and recovery.
2. UK Electricity Framework
A particularly important modern example is Condition C7—Energy Resilience and Resilience Reporting of the National Energy System Operator's electricity-system-operator licence. NESO must inform Ofgem and the Secretary of State about identified risks or threats capable of compromising the safety, security or resilience of a significant part of the whole energy system. It must also advise on possible mitigation and regulatory changes. Ofgem or the Secretary of State may require post-event and post-emergency assessments.
This power is practical rather than theoretical. In 2026 Ofgem formally invoked Condition C7.5 to require NESO to conduct a post-event review concerning the operation and management of the electricity system during a June heat event, specifically linking the review to lessons for system resilience and safety.
Network companies are also subject to extensive Regulatory Instructions and Guidance (RIGs) requiring periodic submission of cost, output and performance information. Ofgem's 2025–26 electricity-transmission RIGs require licence-based regulatory reporting enabling it to assess delivery under the RIIO price-control framework.
3. Cyber-Resilience Reporting
Cyber resilience creates additional mandatory reporting. Under Regulations 10 and 11 of the Network and Information Systems Regulations 2018, an operator of essential services must implement appropriate and proportionate security measures and notify the competent authority of an incident significantly affecting continuity of its essential service.
Notification must ordinarily occur without undue delay and no later than 72 hours after awareness of a qualifying NIS incident. The report must address matters including its nature, duration, impact and any likely cross-border consequences.
For downstream gas and electricity, Ofgem acts as the relevant regulator for operators including transmission operators, distribution operators, system operators, large generators and interconnectors. Its January 2026 guidance includes self-assessment, improvement and annual-reporting requirements intended to provide structured information about security and resilience.
4. Case Laws
Wales & West Utilities Ltd v Competition and Markets Authority [2026] EWHC 99 (Admin)
Facts: Wales & West Utilities challenged aspects of the regulatory price-control framework applied by GEMA and the CMA. The background included Ofgem's introduction of Regulatory Financial Performance Reporting requirements designed to obtain more consistent information about network-company performance.
Legal Issue: The litigation concerned the lawful scope of regulatory decision-making and the statutory framework governing information and price-control obligations.
Judgment: The High Court examined the regulator's decisions within the statutory appeal and public-law framework.
Legal Principle/Ratio: Detailed reporting requirements imposed through regulatory licences and directions must derive from statutory powers and remain subject to legal scrutiny.
Significance: Although primarily concerned with financial regulation rather than physical resilience, the case demonstrates the wider principle underlying resilience reporting: regulators may require standardised information necessary for effective supervision, but their information-gathering architecture remains legally accountable.
Enel Produzione SpA v Autorità per l’energia elettrica e il gas, Case C-242/10
Facts: Italian rules imposed special obligations upon generating installations considered essential to secure reliable operation of the electricity system.
Legal Issue: Whether regulatory intervention aimed at system security was compatible with liberalised electricity-market law.
Judgment: The CJEU held that electricity-market regulation could impose obligations justified by security and general economic interests where applicable requirements of necessity, proportionality, transparency and non-discrimination were satisfied.
Legal Principle/Ratio: Liberalised markets do not prevent regulators from imposing obligations required to preserve electricity-system security.
Significance: The principle supports resilience-reporting regimes: regulators cannot supervise system security effectively unless essential operators disclose material risks and operational information.
5. Governance Standards
Effective resilience reporting should therefore include risk identification, incident notification, scenario analysis, recovery planning, mitigation actions, cybersecurity assessment, post-event review and verified regulatory data. Reporting should be timely and sufficiently detailed to permit regulatory intervention before vulnerabilities develop into systemic failures.
6. Conclusion
Resilience reporting is increasingly a core element of modern electricity regulation. UK licence conditions, RIIO reporting and the NIS Regulations require regulated entities to communicate material risks and incidents rather than merely manage them internally. The broader principles illustrated by Wales & West Utilities and Enel Produzione confirm that regulatory information requirements can support system security while remaining constrained by statutory authority, proportionality and public-law accountability.

comments