JD Spicer Zeb Solicitors Banner Image

Useful Information

Services
People
News and Events
Other
Blogs

Computer Misuse Act 1990: Offences, Sentences and Defences

View profile for Umar Zeb
  • Posted
  • Author
  • Senior Partner - Head of Private Client Crime

The Computer Misuse Act 1990 is the main statute used to prosecute hacking and unauthorised computer access in England and Wales.

It creates five offences, from unauthorised access at the lower end up to acts causing serious damage, which carries a maximum of life imprisonment. This guide sets out what the prosecution must prove for each, what the sentences are, and what defences apply if you are under investigation.

The five offences at a glance. Under the Computer Misuse Act 1990, the offences and their maximum sentences on conviction on indictment are: Section 1 unauthorised access to computer material, 2 years; Section 2 unauthorised access with intent to commit or facilitate a further offence, 5 years; Section 3 unauthorised acts intending or reckless as to impairing the operation of a computer, 10 years; Section 3ZA unauthorised acts causing or risking serious damage, 14 years, rising to life where the damage involves loss of life, illness or injury, or damage to national security; section 3A making, supplying or obtaining articles for use in a section 1, 3 or 3ZA offence, 2 years.

What the Computer Misuse Act 1990 covers

The Act criminalises unauthorised access to computer systems and unauthorised interference with programs or data. It has been amended several times, most significantly by the Serious Crime Act 2015, which inserted the section 3ZA offence carrying a life maximum.

The Act deliberately does not define "computer". Technology moves faster than statute, so the meaning is left to the courts. In DPP v McKeown; DPP v Jones [1997] 2 Cr. App. R. 155, HL, at 163, Lord Hoffmann described a computer as "a device for storing, processing and retrieving information".

That covers phones, tablets and laptops as readily as servers. Many of the cases we see are not sophisticated hacking at all: they involve one person accessing a current or former partner's device or accounts.

The five offences and their maximum sentences

Section

Offence

Maximum on indictment

1

Unauthorised access to computer material

2 years

2

Unauthorised access with intent to commit or facilitate a further offence5 years

3

Unauthorised acts with intent to impair, or reckless as to impairing, the operation of a computer10 years

3ZA

Unauthorised acts causing, or creating risk of, serious damage14 years, or life in the circumstances below

3A

Making, supplying or obtaining articles for use in a section 1, 3 or 3ZA offence2 years

Section 1 is the foundation offence, and the prosecution must prove three things: that you caused a computer to perform a function intending to secure access to a program or data; that the access was unauthorised; and that you knew at the time that the access was unauthorised.

The section 3ZA life maximum is narrower than often reported. It applies where the serious damage is damage to human welfare involving loss of life, illness or injury, or damage to national security. Serious damage to the economy or environment falls under the 14-year maximum.

There is no offence-specific Sentencing Council guideline for these offences, so courts sentence by reference to the general guideline and comparable authorities. That makes the facts of your case, and how they are presented, unusually important.

The full text of the Act is on legislation.gov.uk, and the CPS legal guidance sets out how charging decisions are made.

What "unauthorised" actually means

Most of these cases turn on authorisation rather than on whether an act happened. Access is unauthorised where you are not entitled to control access to the program or data and do not have consent from someone who is. Two situations recur:

  • Exceeding permitted access. An employee with valid credentials who opens records they have no business reason to see may still be acting without authorisation.
  • Shared devices and passwords. Where a couple have long shared a tablet or a password, whether consent survived the end of the relationship is a question of fact, not a formality.

What happens during a computer misuse investigation

Expect the police to seize and examine any device said to have been used, usually extending beyond the handset to cloud accounts and backups. The case is then built from system and access logs showing what was accessed, when and from where.

Investigations of this kind are slow. You may be released on pre-charge bail or under investigation for months while devices sit in a forensic queue, and there are limits on how long that can continue. Being released without charge is not the end of the case. We have written separately about what the police do with evidence taken from digital devices.

You may also be served with a notice requiring you to disclose a password or encryption key. Failing to comply is a separate criminal offence in its own right, independent of the computer misuse allegation, so take advice immediately rather than deciding alone.

Defences to a Computer Misuse Act charge

What is available depends on what is actually in dispute.

  • You did not know the access was unauthorised. This goes to an element of the offence rather than being a defence in the strict sense, and it is the strongest line where credentials were shared, permissions were unclear, or a workplace policy was never communicated.
  • The access was authorised. Consent from a person entitled to give it defeats the charge.
  • It was not you. Attribution is often the real battleground: a device or IP address establishes a location, not an operator, and shared households, workplaces and networks complicate that.
  • No intent or recklessness as to impairment, where Section 3 or 3ZA is alleged.
  • General defences, including duress and, rarely, insanity or automatism.

Charging decisions matter too. These offences are frequently a precursor to something else, and the CPS may prosecute instead under the Fraud Act 2006, the Data Protection Act 2018 or the Investigatory Powers Act 2016. Which Act is chosen changes the elements, the sentence and sometimes the court.

Reform: a statutory defence for security researchers

The government has committed to reforming the Act, and proposals for a limited statutory defence covering legitimate cyber security research have been before Parliament during 2026. The intention is to protect professionals who find and report vulnerabilities from prosecution under Section 1. The scope is contested, with critics arguing it is drawn too narrowly to cover independent researchers and bug bounty work.

This is not settled law. If you are a security professional facing an allegation, the current position governs your case, not the proposed one.

If you have been accused

Instructing a solicitor does not imply guilt or damage your position. It ensures the account you give in interview is given once, with advice on what the prosecution must prove and what the seized material actually shows.

Under investigation for a computer misuse offence? Speak to us before your interview. The first conversation costs nothing, we will tell you whether you qualify for free representation at the police station, and we answer the phone 24 hours a day.

Common questions

What are the offences under the Computer Misuse Act?

There are five: unauthorised access to computer material (Section 1), unauthorised access with intent to commit a further offence (Section 2), unauthorised acts impairing the operation of a computer (Section 3), unauthorised acts causing or risking serious damage (Section 3ZA), and making, supplying or obtaining articles for use in those offences (Section 3A).

What is the maximum sentence under the Computer Misuse Act?

Life imprisonment, but only under Section 3ZA and only where the serious damage involves loss of life, illness or injury, or damage to national security. The other offences carry a maximum of 2, 5, 10 and 14 years.

Is accessing someone else's phone or social media an offence?

It can be. The Act is not limited to servers or networks, and accessing a partner's or former partner's phone or accounts without their consent can amount to a Section 1 offence.

Does the Computer Misuse Act define a computer?

No. The Act contains no definition, deliberately, and the courts apply the ordinary contemporary meaning. The most commonly cited formulation is Lord Hoffmann's in DPP v McKeown: "a device for storing, processing and retrieving information".

Can I be charged if I did not know the access was unauthorised?

Knowledge that the access was unauthorised is an element of the Section 1 offence. If the prosecution cannot prove you knew, the offence is not made out, which is why shared passwords, unclear permissions and uncommunicated workplace policies matter so much.

Contact our criminal law solicitors today

For urgent specialist advice, immediate representation or to speak to us confidentially about a Computer Misuse Act offence or any other criminal matter, please do not hesitate to contact our dedicated team of criminal defence lawyers.

Contact us today:

Or email: solicitors@jdspicer.co.uk

Alternatively, you can fill out our quick online enquiry form and we will get back to you as soon as possible.

By Umar Zeb, Senior Partner and Head of Private Client Crime, a criminal specialist with over 30 years' experience. This guide states the law of England and Wales. It is general information, not advice on your case.

 

Or email: solicitors@jdspicer.co.uk

Alternatively, you can fill out our quick online enquiry form and we will get back to you as soon as possible.