Ask most UK business owners what the Cyber Security and Resilience Bill will cost them and the honest answer is a shrug. It sounds like something for banks, hospitals and the National Grid. It is not.
The Cyber Security and Resilience Bill reaches past the obvious critical infrastructure operators and lands squarely on the companies that run other people’s IT. Managed service providers, data centres and a new category of designated critical suppliers all come into regulation for the first time, which means the supplier answering your helpdesk tickets is about to acquire statutory duties, a regulator, and a reporting clock measured in hours.
That has consequences for you even if you are never regulated yourself. This guide sets out what the Cyber Security and Resilience Bill does, who it captures, what the deadlines and fines actually are, and the specific questions worth putting to your IT supplier this quarter. If you have already read our companion piece on the Cyber Resilience Pledge, treat this as the legislative half of the same story — voluntary commitments are about to acquire a statutory floor beneath them, and most managed IT services contracts have not caught up.
Table of contents
- Why the Cyber Security and Resilience Bill Matters Now
- What the Cyber Security and Resilience Bill Actually Changes
- Who Comes Into Scope for the First Time
- How the Bill Defines a Managed Service Provider
- What Changes When Your MSP Becomes Regulated
- The 24-Hour and 72-Hour Incident Reporting Clock
- Enforcement and Penalties Under the Cyber Security and Resilience Bill
- What MSP Customers Should Do About the Cyber Security and Resilience Bill
- Designated Critical Suppliers: The Quiet Expansion
- How to Prepare Before the Bill Becomes Law
- Five Misreadings That Will Cost You
- Cyber Security and Resilience Bill FAQ
- The Practical Takeaway
Why the Cyber Security and Resilience Bill Matters Now
This is no longer a consultation document or a line in a King’s Speech. It is a Bill in its final parliamentary stretch, and the preparation window is closing.
Where the Bill has reached in Parliament
The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to the House of Commons on 12 November 2025. Second reading followed on 6 January 2026, committee stage ran through February, and the Commons completed report stage and third reading in June 2026. The Bill was introduced to the House of Lords on 17 June 2026 and had its Lords second reading on 14 July 2026, with committee stage scheduled for September. Royal Assent is expected before the end of the year.
What the Bill replaces
The regime being reformed is the Network and Information Systems Regulations 2018 — the UK’s retained version of the EU NIS Directive. Those regulations covered operators of essential services in energy, transport, health, drinking water and digital infrastructure, plus a narrow set of digital service providers. They were written before ransomware became an industrialised business model and before outsourced IT became the default operating pattern for mid-market firms.
Why the timing is awkward for buyers
Royal Assent is not the moment obligations bite. Most of the substance of the Cyber Security and Resilience Bill arrives through secondary legislation, with government consultation running through 2026 and detailed requirements following after. That creates an uncomfortable gap: the direction of travel is certain, the fine detail is not, and suppliers will be repricing contracts against requirements that are still being drafted.
The supply chain is the whole point
The clearest signal in the Cyber Security and Resilience Bill is that government has stopped treating cyber risk as something that stops at an organisation’s own perimeter. Recent UK incidents have repeatedly travelled through a supplier rather than through the front door. Regulating the providers with privileged access to hundreds of customer networks at once is a deliberate attempt to fix the concentration risk that outsourcing created.
What the Cyber Security and Resilience Bill Actually Changes
The Cyber Security and Resilience Bill is best understood as three pillars sitting on top of the existing NIS framework rather than a wholesale replacement of it.
Pillar one: expanded scope
New categories of organisation are brought into regulation — medium and large managed service providers, data centres, large load controllers managing 300MW or more of electrical demand, and designated critical suppliers to essential services. Each category gets its own entry criteria and its own regulator.
Pillar two: regulators with teeth
Existing regulators gain stronger powers under the Cyber Security and Resilience Bill. Incident reporting moves to a two-stage clock, financial penalties rise to levels comparable with data protection law, regulators may recover their costs from the entities they oversee, and information-sharing arrangements with law enforcement and the intelligence agencies are put on a clearer footing.
Pillar three: keeping the regime current
The Cyber Security and Resilience Bill includes futureproofing powers that let the Secretary of State update the regime through secondary legislation as threats change, rather than waiting years for primary legislation. There are also powers of direction — the ability to instruct regulated entities or regulators to act where there is an imminent national security threat.
Twelve regulators, one statement of priorities
Oversight remains sectoral, with roughly twelve regulators covering England, Wales, Scotland and Northern Ireland. To stop them drifting apart, the Bill lets the Secretary of State publish a statement of strategic priorities that regulators must have regard to. The Information Commission takes digital and managed service providers; Ofcom takes data infrastructure.
Who Comes Into Scope for the First Time
Four groups are newly captured by the Cyber Security and Resilience Bill. Most readers of this guide will sit downstream of at least one of them.
Managed service providers
Medium and large providers of managed IT services are the headline addition. Government analysis anticipates between 900 and 1,100 providers in scope. This includes remote IT support and helpdesks, infrastructure and application management, security operations centres and managed SIEM services. If a company holds privileged access into your systems as part of an ongoing contract, it is a candidate.
Data centres
Data centres are treated as an essential service. The threshold is one megawatt of rated IT load for colocation and third-party facilities, rising to ten megawatts for enterprise facilities operated purely for the owner’s own IT. Ofcom acts as the competent authority. Facilities handling secret or top secret government data, and those run by the intelligence agencies, are carved out.
Designated critical suppliers
This is the category most likely to surprise people. Under the Cyber Security and Resilience Bill a regulator can designate a supplier that is not otherwise regulated, if that supplier’s failure could seriously disrupt an essential service. Designation is not about size — it is about how much depends on you.
Large load controllers
Organisations that remotely manage 300MW or more of aggregated electrical demand — smart charging networks, demand-side response aggregators, heat pump fleets — come into scope because a compromise of that control layer is a grid stability problem, not merely an IT security problem.
How the Bill Defines a Managed Service Provider
Definitions matter here more than usual, because the Cyber Security and Resilience Bill applies the same test to a fifty-person support firm and a global outsourcer.
The four-part test
A relevant managed service provider is one whose service meets four conditions together: it is provided to another organisation under contract; it involves the ongoing management, support, maintenance, monitoring or administration of that organisation’s IT systems; it relies on a connection or access into the customer’s network and information systems; and it is not already covered as a data centre or public electronic communications service.
The size threshold
Micro and small enterprises are out of scope. The Cyber Security and Resilience Bill catches medium and large providers, on the basis that systemic importance and privileged access make them a different kind of risk. A twelve-person support firm is not directly regulated — which is precisely why customers of small providers need to ask harder questions rather than fewer.
Services that clearly qualify
Remote monitoring and management, outsourced service desks, patch and endpoint management, managed detection and response, managed SIEM, cloud tenancy administration and application management all sit inside the definition on any reasonable reading. So does co-managed IT support, where a provider works alongside an internal team.
Where the boundary is genuinely unclear
Pure software vendors, project-only consultancies and one-off migration work sit outside the ongoing-management test. The grey area is the vendor whose product includes a support tunnel into customer estates. A line-of-business application supplier with permanent remote access starts to look a lot like a managed service, and may be designated as a critical supplier even where the managed service definition does not reach it.
What Changes When Your MSP Becomes Regulated
For a provider, the Cyber Security and Resilience Bill converts good practice into legal duty. For a customer, it converts a vague assurance into something auditable.
Registration with the Information Commission
Regulated providers must register with the Information Commission, formerly the Information Commissioner’s Office, which becomes their competent authority. Registration creates a list, and a list is what makes enforcement practical. There will, for the first time, be a public-facing way of establishing whether a provider has acknowledged its own regulatory status.
A duty to manage risk, not tick a box
The core security duty in the Cyber Security and Resilience Bill is to identify and take appropriate and proportionate technical and organisational measures to manage risks to the security of network and information systems, and to minimise the impact of incidents. It is outcome-based rather than a prescriptive control list, which means a provider cannot discharge it by pointing at a certificate alone.
Incident notification duties
Regulated providers must notify significant incidents to their regulator on the statutory clock described below. This is a duty owed to the regulator, not to you — a distinction worth remembering when you read the contract.
The customer notification clause most people miss
Managed service providers, digital service providers and data centre operators must take steps to identify whether any of their customers are likely to have been adversely affected by an incident, and notify those customers with details and the reasoning behind that assessment. This is the single most valuable provision in the Cyber Security and Resilience Bill for buyers. It converts “we had an incident, nothing to worry about” into a documented judgement your provider has to stand behind.
Regulator fees will reach your invoice
The Cyber Security and Resilience Bill lets regulators recover the full cost of their functions from the entities they regulate, through published charging schemes and after consulting the sector. Regulators cannot profit, and they can exclude entities where charging is not appropriate. But the direction is clear: compliance costs money, and providers do not absorb costs indefinitely. Expect the pass-through at your next renewal, however it is labelled.
The 24-Hour and 72-Hour Incident Reporting Clock
Nothing in the Cyber Security and Resilience Bill will reshape operational behaviour more than the reporting timetable.
Two stages, two deadlines
An initial notification is due within 24 hours of the regulated entity becoming aware of a significant incident. A full report follows within 72 hours. The National Cyber Security Centre is informed at the same time as the regulator, so a single submission serves both the regulatory and the technical response.
What the initial report has to contain
The first notification is not a placeholder. It is expected to describe the incident and the key factors bearing on it: the extent of disruption, how long it has lasted, and how many users are affected. Producing that inside a day requires knowing what you run and who depends on it before anything goes wrong.
Near misses and pre-positioning now count
The reportable set under the Cyber Security and Resilience Bill is wider than most incident response plans assume. It includes incidents likely to have a significant UK impact even where no impact has yet occurred — pre-positioning by an attacker inside a network, or ransomware caught before detonation. An intrusion you contained successfully may still be a reportable event.
Why the clock breaks most response plans
Twenty-four hours sounds generous until you map it against a real incident. Detection, triage, escalation to someone with authority, legal review, and a decision on customer impact rarely complete inside a day when the process has never been rehearsed. Most organisations discover the gap during the incident, which is the worst possible time to find it.
Thresholds are still being set
What counts as “significant” will be defined in secondary legislation, with supplementary thresholds tailored by sector. Until those land, the sensible working assumption is that anything you would have voluntarily reported to the NCSC is in scope, plus a category of near misses you would previously have handled quietly.
Enforcement and Penalties Under the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill replaces the existing three-band penalty structure with a simpler and considerably more expensive two-band model.
Two penalty bands
The higher band, for more serious breaches such as failures of the security duty or of incident notification, is up to £17 million or 4% of worldwide turnover, whichever is higher. The standard band, for less serious breaches such as failing to register, is up to £10 million or 2% of worldwide turnover, whichever is higher. The alignment with data protection maxima is deliberate.
Daily penalties for continuing breaches
Regulators also gain the ability to impose daily penalties — reported at up to £100,000 per day — where a contravention continues. The design intent is to make ignoring an enforcement notice more expensive than fixing the problem.
How enforcement actually proceeds
The process is staged rather than instant. A regulator with reasonable grounds to believe an entity is non-compliant issues a notice of intention; the entity makes representations; an enforcement notice may require corrective action; and a penalty notice follows if warranted. Regulators are expected to use the ladder rather than jump to the top of it.
Appeals go to the First-tier Tribunal
Both penalty decisions and critical supplier designations can be appealed to the First-tier Tribunal. A designated supplier can also ask to be removed from designation if the grounds no longer hold.
What enforcement means for a customer
Fines land on your supplier, not on you. The exposure that reaches you is operational: a provider absorbing an enforcement action is a provider distracted, repricing, or in some cases exiting the market. Concentration risk in your supplier base is worth reviewing on that basis alone.
What MSP Customers Should Do About the Cyber Security and Resilience Bill
If you buy IT rather than sell it, the Cyber Security and Resilience Bill affects you through your contracts and your suppliers rather than through direct regulation.
You are probably not directly regulated
Unless you operate an essential service, run a qualifying data centre, provide managed services at medium or large scale, or get designated as a critical supplier, the Cyber Security and Resilience Bill does not apply to you directly. That is not the same as being unaffected — your suppliers’ new duties will change what you are told, when, and at what price.
Your contracts will change, quietly
Watch for three amendments at renewal: a cost line reflecting regulatory overhead, revised incident notification wording that aligns your provider’s obligations to you with its statutory obligations to the regulator, and new customer-side security requirements that the provider needs in order to meet its own duty. The third one matters most, because it can transfer work to you.
Five questions worth asking your provider now
Ask whether the provider expects to be in scope and on what basis. Ask who its regulator will be. Ask how it will meet a 24-hour notification and whether that process has been tested. Ask how it will decide which customers were adversely affected, and how quickly it will tell you. Ask what it expects the cost impact to be at renewal. Vague answers to those five questions are themselves an answer.
Watch for providers that claim exemption
Small providers genuinely fall outside the direct scope of the Cyber Security and Resilience Bill, and some will present that as an advantage. It is worth probing. An unregulated provider is not a safer provider — it is an unsupervised one. If your business depends on that relationship, the assurance has to come from the contract and from evidence rather than from statute.
Your own obligations do not vanish
Data protection law, sector rules and contractual commitments to your own customers continue to apply regardless. Good IT security governance and disciplined vendor management were the right answer before the Cyber Security and Resilience Bill and remain so afterwards. The legislation raises the floor; it does not do the work.
Designated Critical Suppliers: The Quiet Expansion
The designation power deserves separate attention because it reaches organisations that read every scoping factsheet and reasonably concluded they were outside the regime.
The four designation conditions
A regulator may designate a supplier where all four conditions hold: it supplies goods or services directly to a regulated operator, digital service provider or managed service provider; it relies on network and information systems to do so; an incident affecting those systems could disrupt service delivery downstream; and that disruption would likely have a significant impact on the UK economy or on the day-to-day functioning of society.
Substitutability is part of the test
Regulators are expected to consider whether the service could realistically be obtained elsewhere, and whether another regulatory framework already addresses the risk. A niche supplier with no practical substitute is a stronger designation candidate than a large one operating in a crowded market.
What a designated supplier has to do
Designated critical suppliers take on statutory cybersecurity requirements and duties to manage and reduce risk, set through secondary legislation and aligned with — but not exceeding — the obligations the Cyber Security and Resilience Bill already places on regulated operators.
Consultation and appeal
Designation is not a letter arriving out of nowhere. The regulator must consult the supplier and consider its representations, and must coordinate with other authorities so that decisions stay consistent across sectors. Appeal lies to the First-tier Tribunal.
Why smaller vendors should care
Size is not the trigger; dependency is. A specialist software vendor supporting a hospital trust, or a logistics platform underpinning water distribution, can be small and still designated. Any vendor selling into critical national infrastructure should be reading the designation criteria rather than the size thresholds.
How to Prepare Before the Bill Becomes Law
None of the sensible preparation depends on the final text of the Cyber Security and Resilience Bill. Every step below is worth doing whether or not you turn out to be in scope.
Establish your scope position in writing
Work through the four-part managed service test, the data centre thresholds and the designation criteria, and record the conclusion with your reasoning. If you are in scope, you have a start date to plan against. If you are not, you have a defensible document rather than an assumption.
Fix the asset and dependency register first
You cannot report a significant incident inside 24 hours if you cannot say what systems you run, who depends on them and which customers sit behind each one. For providers, the customer notification duty in the Cyber Security and Resilience Bill makes a per-customer dependency map a hard requirement rather than good hygiene.
Rehearse a 24-hour notification
Run a tabletop exercise with the clock visible. Who declares an incident, who has authority to notify a regulator on a Saturday, who drafts the customer impact assessment, and who signs it off. The first attempt is always slower than expected, which is the point of doing it while nothing is on fire.
Align to a framework you can evidence
The Cyber Assessment Framework is the natural reference point for the security duty, with Cyber Essentials Plus and ISO 27001 as supporting evidence. None of them constitutes compliance on its own, but a mapped, evidenced framework is a far better starting position than a set of unlinked controls.
Review supplier contracts in both directions
Look at what your providers owe you on notification and what you owe your own customers. Where those clauses do not line up, you are carrying a gap. Renewal is the cheapest moment to fix it, and renewals are already in motion across the market.
Budget for the pass-through
Regulatory cost recovery, additional tooling and the staffing required to meet a 24-hour clock all cost money, and they will surface in provider pricing during 2026 and 2027. Treat that as a known line item rather than an unwelcome surprise, and compare providers on what the increase buys rather than on its size.
Five Misreadings That Will Cost You
Each of these has been said in a real procurement conversation, and each is wrong in a way that creates exposure.
“It is just GDPR for cyber”
The overlap is real but partial. Data protection law is triggered by risk to personal data; the Cyber Security and Resilience Bill is triggered by disruption to services. An availability incident with no personal data involved can be fully reportable here and irrelevant under data protection law.
“We are too small to be affected”
Direct regulation has a size threshold; consequences do not. A small business whose provider is regulated will see contract changes, price changes and notification changes regardless. And a small supplier to critical infrastructure can be designated on dependency alone.
“Our provider handles compliance for us”
A provider’s statutory duties are its own. Nothing in the Cyber Security and Resilience Bill transfers your obligations to your supplier, and no contract clause makes a regulator look elsewhere. Outsourcing the work has never outsourced the accountability.
“Nothing happens until Royal Assent”
Some provisions commence at Royal Assent, others two months later, and the operationally significant parts arrive through secondary legislation after consultation. Waiting for the last statutory instrument leaves no room to build an incident process, and the market will move on pricing well before then.
“Certification equals compliance”
Cyber Essentials, ISO 27001 and SOC 2 are useful evidence and none of them is a defence. The duty is to identify and manage risk appropriately and proportionately for your own circumstances — a judgement a certificate cannot make on your behalf.
Cyber Security and Resilience Bill FAQ
Short answers to the questions that come up most often in supplier and board conversations.
When will the Cyber Security and Resilience Bill become law?
Royal Assent is expected during 2026, with Lords committee stage from September. The obligations that matter operationally arrive later, through secondary legislation following consultation, so the realistic compliance horizon runs into 2027.
Does the Cyber Security and Resilience Bill apply to small businesses?
Not directly, in most cases. Micro and small enterprises are excluded from the managed service provider category, and ordinary businesses that simply buy IT are not regulated at all. The exception is designation as a critical supplier, which turns on dependency rather than headcount.
What happens if a provider does not register?
Failure to register sits in the standard penalty band — up to £10 million or 2% of worldwide turnover, whichever is higher. More practically, a provider that has not worked out its own status under the Cyber Security and Resilience Bill has told you something useful about its risk management.
Does the Bill reach providers based outside the UK?
Yes, where they supply UK customers. Such providers are expected to appoint a UK representative, and the regime is drafted so that location alone does not create an exemption.
Where can I read the source material?
The government has published a full set of factsheets covering scope, incident reporting, enforcement and cost recovery on GOV.UK, and the Bill’s progress and published documents are tracked on the UK Parliament Bills site.
The Practical Takeaway
The Cyber Security and Resilience Bill is not a compliance project for most businesses. It is a change in what your suppliers owe, what they must tell you, and what they will charge.
Three things to do this quarter
Establish and document your scope position. Ask your provider the five questions above and record the answers. Review the incident notification clauses in your contracts against the 24-hour and 72-hour statutory clock.
Where the advantage sits
Organisations that can already answer “what do we run, who depends on it, and who do we tell” will find the Cyber Security and Resilience Bill a documentation exercise. Organisations that cannot will find it an expensive one, and will find that out on the worst possible day. The gap between those two positions is a quarter of deliberate work, and it is available now.