- Enforced by
- Home Office
- Status
- Amended (in force with amendments)
- Penalty ceiling
- Imprisonment 3 of 6 obligations carry imprisonment (10 years). 3 carry different penalties — flagged in the list below.
Does it bind you?
Business-side roles with duties under this instrument.
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Any Person — also bound by 2340 other Acts
What it requires
Sections creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
- Gain unauthorised access to computer materialAny Person
- Unauthorised computer access with intent to facilitate a crimeAny Person
- Carry out unauthorised act that impairs computer operationAny Person
- Make, supply or obtain tools for computer misuseAny Person
- Carry out unauthorised computer act causing serious damageAny Person
- Conspiracy or attempt to commit computer misuse offencesAny Person
15 other provisions — procedural and definitional
Help complying
Guvnor’s practical routes through this instrument.
Respond to a cyber attack
Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data …
Cyber security fundamentals
A structured learning path for business owners new to cyber security. Understand the threat landscape, implement the five essential controls, prepare for …
Grow your tech business
Scale your tech business - funding, international expansion, investment, and preparing for exit
Run a tech business
Ongoing compliance, operations, and growth guidance for established UK tech and software businesses
PSTI IoT compliance check
Quick compliance check for IoT manufacturers, importers, and distributors. Confirm product scope, verify three mandatory security requirements, identify your supply chain role, …
Computer Misuse Act Compliance
How to comply with the Computer Misuse Act 1990 when conducting security testing, developing security tools, or running bug bounty programmes. Includes …
Tech Sector Compliance Overview
Comprehensive guide to regulatory compliance for technology businesses - UK GDPR, data protection, online safety, cybersecurity, and sector-specific requirements.
2 more guides that reference this instrument
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.