Premier League CyberSecurity Rules

Premier League cyber security rules: what clubs need to do next

The Premier League has introduced mandatory cyber security requirements for every club. The rules set a phased route to stronger controls, annual reporting and, ultimately, independent assurance.

They are set out in the Premier League Handbook 2026/27. Clubs must implement and maintain the Premier League Information Security Baselines, provide an interim assessment by 10 January each season and submit final evidence by 30 April.

For clubs, this makes cyber security a formal part of operational governance. It applies to the systems and suppliers that support ticketing, stadium operations, retail, hospitality, player and scouting data, media and supporter services.

The rules of the game

The requirements are phased over three years.

DeadlineRequirements
30 April 2027Risk management and governance; staff training; account approval and offboarding; multi-factor authentication where feasible; asset registers; network and endpoint controls; immutable backups; incident response; supplier-risk policy; and security monitoring.
30 April 2028Security assessments for new systems; annual risk assessments; specialist training; access reviews; vulnerability remediation; backup-restoration testing; incident playbooks; and supplier security terms.
30 April 2029Executive-approved risk appetite; recovery objectives; annual incident exercises; risk-based supplier assurance; centralised, immutable logging; a recognised security framework; and regular third-party audit against it.

If a club is not fully compliant with the applicable requirements at its interim assessment, it has 28 days to provide a detailed plan. The League may ask for further evidence and may grant a dispensation in exceptional circumstances.

The rules can be enforced through the Premier League's existing disciplinary processes. The £100,000 figure in some reporting is the general maximum available to the Board under summary jurisdiction, not a fixed cyber security penalty.

The opening fixture: understanding the starting point

The first task is to understand what the club needs to protect and who depends on it.

That means identifying critical services, systems, data and suppliers. A useful starting question is: if this service were unavailable on a matchday, what would stop working, who would be affected and how quickly would it need to recover?

For many clubs, the most immediate priorities will be:

  • Confirming that asset registers cover the devices, cloud services and key systems in use.
  • Reviewing administrator and supplier access, including how quickly access is removed when people leave.
  • Enabling multi-factor authentication where it is available.
  • Checking that critical data has backups which cannot be altered by an attacker.
  • Testing whether those backups can restore services, rather than simply confirming that they exist.
  • Updating the incident-response plan so that it is usable by the people who would need to act.

The NCSC's ransomware-resistant backup guidance is particularly relevant. A backup is only valuable if it can be recovered when production systems and administrator accounts may be compromised.

A stronger defence

The Premier League has deliberately not mandated Cyber Essentials, Cyber Essentials Plus, the NCSC Cyber Assessment Framework or ISO 27001. From 2029, clubs must select and implement a recognised security framework, but the Handbook leaves the choice open.

That allows clubs to take an approach that reflects their size, technology and operational risks. It also means clubs should be clear about what each approach provides.

Cyber Essentials offers a defined technical baseline against common attacks. Cyber Essentials Plus adds an independent technical assessment of the controls in place. Neither replaces the wider Premier League requirements around suppliers, recovery, incident response and governance. They can, however, help a club establish and demonstrate the technical foundation on which those wider requirements depend.

CAF and ISO 27001 can support a broader resilience or management-system approach. The right route will depend on the club's existing maturity, regulatory obligations and the systems it operates.

The practical aim is not to collect standards. It is to operate controls that reduce risk, test whether they work and improve them over time.

AI changes the pace of play

The timetable arrives as frontier AI is changing the speed of cyber security.

The NCSC has warned that advanced AI tools can make it easier, faster and cheaper to identify and exploit weaknesses. It also points to the potential for the same technology to improve vulnerability discovery, monitoring and response. Retaining defensive advantage in the age of frontier AI cyber capabilities

The NCSC and its Five Eyes counterparts advise organisations to focus on the basics: reduce unnecessary exposure, patch promptly, strengthen access controls and prepare for incidents before they happen. The AI shift in cyber risk: why leaders must act now

For clubs, this reinforces the value of the Premier League's early requirements. Asset visibility, strong access control, timely updates and tested recovery are not separate projects. Together, they determine how much an attacker can access and how quickly the club can recover.

Getting match-fit

The rules set deadlines, but clubs do not need to wait for each phase to start the work.

A proportionate plan should bring together technology, operations, legal, procurement and senior leadership. It should identify the most important services and suppliers, set owners for each requirement and build evidence into everyday processes.

The most useful measures are often straightforward:

  • Track critical systems and their owners.
  • Review and remove unnecessary access.
  • Fix known vulnerabilities to an agreed timetable.
  • Test a service recovery, not only a backup.
  • Include cyber security requirements and incident-notification expectations in important supplier contracts.
  • Rehearse an incident involving a critical service or supplier.
  • Give the board a clear view of the risks, recovery priorities and outstanding decisions.

Beyond the final whistle

The Premier League's baseline creates a common direction of travel for clubs. It recognises that cyber resilience is part of running a modern football organisation and that it requires more than one-off technical work.

The clubs that benefit most will treat the requirements as a way to improve how they operate now, rather than as a documentation exercise ahead of each deadline. The result should be a clearer view of their risks, stronger foundations and greater confidence that the organisation can continue to operate when something goes wrong.