The UK Cyber Security and Resilience Bill: Could It Affect Your Business?

The proposed Cyber Security and Resilience Bill would strengthen UK cyber rules and bring more technology suppliers into scope. Here is what SMEs should review now.
This article explains proposed legislation currently progressing through Parliament. The final requirements and implementation timetable may change before the Bill becomes law.
Bill status at a glance
| Item | Position |
|---|---|
| Parliamentary stage | House of Lords — Second Reading completed on 14 July 2026; Committee stage sittings scheduled for 1, 3, 7 and 9 September 2026 (the Bill has completed its House of Commons stages) |
| Latest Bill version | HL Bill 32, as brought from the Commons on 17 June 2026 |
| Last official source check | 28 July 2026 (GOV.UK and UK Parliament) |
| Royal Assent | Not yet granted — the Bill is not law |
| Implementation | No commencement dates announced; implementation is expected to be phased and to depend on secondary legislation |
| Next known milestone | House of Lords Committee stage, with sittings scheduled for 1, 3, 7 and 9 September 2026, followed by Report and Third Reading, then consideration of any amendments |
Last checked: 28 July 2026 against the GOV.UK Cyber Security and Resilience Bill collection and the UK Parliament Bill page. This panel will be updated when the Bill’s position materially changes.
The UK is proposing a significant expansion of the rules protecting essential services and digital infrastructure from cyber attacks. The Cyber Security and Resilience Bill — formally the Cyber Security and Resilience (Network and Information Systems) Bill — would update the existing Network and Information Systems Regulations 2018.
Its proposals include bringing certain managed service providers, data centres, large electricity-load controllers and critical suppliers within the regulatory framework. It would also expand incident-reporting duties and strengthen the powers available to regulators.
Most ordinary SMEs will not automatically become directly regulated. However, many rely heavily on MSPs, cloud services, data centres and other suppliers that could be affected. That means the Bill matters not only to organisations named in the legislation, but also to their customers and supply chains.
The core message for business owners
Your organisation may not be directly regulated by the Bill, but the technology providers, data centres and critical suppliers supporting your business could be.
What happened?
The Cyber Security and Resilience Bill proposes reforms and additions to the Network and Information Systems Regulations 2018 — usually shortened to the NIS Regulations. The existing NIS Regulations apply to selected essential and digital services, including areas such as energy, transport, healthcare, drinking water, digital infrastructure and selected digital services such as cloud computing, online marketplaces and search engines. They do not cover the whole economy.
The proposed Bill seeks to:
- Widen the organisations covered
- Improve cyber-incident reporting
- Strengthen regulatory oversight
- Improve information sharing
- Give regulators clearer enforcement and cost-recovery powers
- Allow the government to respond more quickly to evolving threats
- Improve the security of important technology supply chains
As at 28 July 2026, the Bill has completed its stages in the House of Commons and its Second Reading in the House of Lords (14 July 2026). Committee stage in the Lords is scheduled to begin on 1 September 2026, with further sittings listed for 3, 7 and 9 September 2026. The current version is HL Bill 32, as brought from the Commons on 17 June 2026.
The Bill must complete the parliamentary process and receive Royal Assent before becoming law. Many operational details are also expected to depend on future consultations and secondary legislation.
Who may be directly affected?
The principal proposed additions, in plain English, are set out below. In each case the proposed criteria, thresholds and final definitions must be checked against the latest version of the Bill and any subsequent regulations.
Managed service providers
Certain managed service providers may be brought into scope because they can have extensive access to customers’ systems, networks, administrative accounts, data, cloud services, security tools and backup platforms. This does not mean that every IT support company or MSP will be regulated — the Bill proposes criteria and definitions that will determine which providers qualify, and those details may still change.
Data centres
Qualifying data centres and enterprise data centres may become regulated because they underpin cloud services, business applications, communications, financial systems, public services and stored business data.
Large load controllers
Organisations controlling significant electrical demand, including certain smart-energy and EV-charging arrangements, may be brought within scope because disruption could affect the electricity system.
Critical suppliers
Regulators may be able to designate certain suppliers as critical where disruption to that supplier could seriously affect an essential or digital service.
The key point
The Bill focuses on organisations whose failure could cause wider disruption — not every company that uses technology.
Why managed service providers matter
MSPs can administer technology for multiple customers through remote-management platforms, privileged accounts, Microsoft 365 administration, backup systems, endpoint security platforms, network equipment, cloud infrastructure and support tools. A security failure at one provider can potentially affect numerous customers at once.
The Bill reflects a wider change in regulatory thinking: cyber security is no longer viewed only as the responsibility of the organisation using the system. The resilience of key technology suppliers also matters.
That said, regulation does not automatically guarantee that an MSP is secure. Regulation may raise expectations, but customers must still carry out appropriate supplier checks.
How incident reporting may change
The Bill proposes broader and faster reporting of certain cyber incidents. Subject to the final legislation and supporting regulations, regulated organisations may need to provide an initial notification within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours. Relevant MSPs, digital-service providers and data centres may also need to inform affected customers where appropriate.
- Not every minor IT incident will necessarily be reportable.
- Thresholds and definitions matter.
- Detailed requirements may be set through later regulations.
- These are proposed regulatory duties, not a general obligation currently applying to every SME.
Why does this matter to customers? A business may need timely information from its IT provider to protect its own systems, reset credentials, isolate affected devices, communicate with customers, meet contractual obligations, assess data-protection reporting and continue critical operations.
An incident notification is only useful when the customer already knows who must receive it and what actions should follow.
Does the Bill apply to ordinary SMEs?
Direct effect
Most ordinary small businesses will not automatically become directly regulated simply because they use computers, Microsoft 365 or an outsourced IT provider.
Possible direct effect
A business should seek specialist advice where it:
- Provides managed technology services
- Operates qualifying data-centre services
- Provides services to essential operators
- Could be designated as a critical supplier
- Already falls within the NIS regime
- Operates in a regulated or critical sector
Indirect effect
Many SMEs may be indirectly affected because their MSP, cloud provider, data-centre provider, software supplier, sector customer, insurer, procurement partner, regulator or larger supply-chain customer may introduce stronger contractual and assurance requirements.
Possible indirect consequences include requests for:
- Cyber Essentials or Cyber Essentials Plus
- Security questionnaires
- Incident-response plans
- Evidence of backups
- Multi-factor authentication
- Vulnerability management
- Staff training
- Business-continuity arrangements
- Supplier registers
- Prompt incident notification
- Contractual audit rights
The supply-chain reality
You may not be regulated directly, but you may still be asked to prove that your business is not the weak link in somebody else’s supply chain.
What could this mean for MSP customers?
If the Bill proceeds broadly as proposed, customers of MSPs and other technology suppliers may see:
- More detailed security assessments
- Clearer division of responsibilities
- Improved incident-notification clauses
- Stronger access controls
- More formal onboarding and offboarding
- Better audit logging
- Increased emphasis on supported systems
- Tighter requirements around backups and recovery
- Greater scrutiny of remote-management tools
- More structured business-continuity planning
- Changes to contracts or pricing
Some additional cost may result where providers must improve internal controls, maintain evidence, report to regulators, undergo assessments, invest in resilience and strengthen staffing and monitoring. That does not mean every MSP will automatically increase prices — and improved resilience may reduce the likelihood and impact of serious incidents, which carries real value of its own.
Cyber security versus cyber resilience
The Bill’s title includes both words deliberately, and the distinction matters for every business.
| Cyber security | Cyber resilience | |
|---|---|---|
| What it means | Measures intended to prevent or detect attacks | The ability to continue operating, recover and communicate when prevention fails |
| Examples | MFA, endpoint protection, patching, email security, secure configuration, access controls | Tested backups, disaster recovery, incident-response plans, alternative communication methods, business-continuity arrangements, supplier escalation procedures, recovery priorities |
The difference in one sentence
Security asks, “How do we stop this happening?” Resilience also asks, “What will we do when something still goes wrong?”
Practical business implications
Supplier visibility
- Which providers can access your systems
- Which services are business-critical
- Where data is hosted
- Who owns each supplier relationship
- How to contact the supplier during an incident
Contracts
- Who is responsible for each security control
- How quickly incidents must be reported
- What information the supplier must provide
- Who owns and can export the data
- How services will be recovered
- What happens when the relationship ends
Incident response
- Who can make decisions
- Who contacts the IT provider
- Who contacts insurers
- Who assesses ICO reporting
- Who communicates with staff and customers
- How operations continue if email or phones are unavailable
Backups and recovery
The existence of a backup is not enough. Businesses should know what is backed up, how often, whether backups are encrypted, whether they are separated from the main environment, how long recovery takes and when restoration was last tested.
Is Your Business Ready for Greater Supply-Chain Scrutiny?
- We know which technology suppliers have administrative access.
- We maintain a list of business-critical systems and suppliers.
- We understand which services depend on cloud or data-centre providers.
- Our IT responsibilities are clearly divided between us and our provider.
- Our contract includes a cyber-incident notification requirement.
- We know how to contact our provider urgently outside normal channels.
- Multi-factor authentication protects important accounts.
- Privileged and administrator access is controlled and reviewed.
- Unsupported software and equipment are identified.
- Security updates are monitored.
- Backups include critical cloud and on-premises data.
- Backups are protected from the main production environment.
- Recovery has been tested.
- We have an incident-response plan.
- We have a business-continuity plan.
- We can communicate if email or normal phone systems are unavailable.
- Employee joiner, mover and leaver processes are documented.
- Supplier access is removed when no longer required.
- We have considered Cyber Essentials or Cyber Essentials Plus.
- Senior management reviews cyber risk regularly.
This checklist does not determine whether an organisation falls legally within scope. It helps businesses prepare for the higher security and resilience expectations likely to flow through UK supply chains.
Questions to Ask Your IT Provider
- 1Could your organisation fall within the scope of the Cyber Security and Resilience Bill?
- 2Which of your services have administrative access to our systems?
- 3Which third-party platforms do you use to support us?
- 4How are privileged accounts protected?
- 5Is multi-factor authentication enforced across your support platforms?
- 6How quickly would you tell us about an incident that could affect our business?
- 7Is that notification period included in our contract?
- 8What information would you provide during an incident?
- 9How is access to our systems logged and reviewed?
- 10How do you secure remote-management tools?
- 11What happens if your own systems become unavailable?
- 12Do you have tested business-continuity and disaster-recovery arrangements?
- 13How are our backups protected from compromise?
- 14When was our recovery process last tested?
- 15Which responsibilities belong to you and which remain with us?
- 16Can we obtain our configurations, credentials and data if we change provider?
- 17Do you hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or other relevant assurance?
- 18How do you assess the security of your own suppliers?
- 19Who should we contact during an urgent cyber incident?
- 20What changes do you expect the Bill to require from your organisation?
Certifications and assurance schemes are useful evidence, but they do not remove the need for your own due diligence.
The IT Club View
The Cyber Security and Resilience Bill is primarily aimed at the services and suppliers whose disruption could cause wider harm. However, its influence is likely to reach much further than the organisations named directly in the legislation.
Large customers, regulators, insurers and providers are increasingly asking smaller businesses to demonstrate basic cyber hygiene and operational resilience. That is not necessarily unreasonable. An organisation cannot outsource responsibility simply by outsourcing its IT. At the same time, small businesses should be able to expect greater transparency and resilience from providers that hold powerful access to their systems.
The most useful question is not simply, “Does this law apply to us?” It is, “Would our business and our technology providers be ready for the standards it is trying to create?” The Bill’s final scope and details may change as it completes its passage — but the direction of travel is clear, and preparation loses none of its value if the details shift.
The Operational Heartbeat
Cyber resilience cannot be established through a one-off audit. A recurring review should include administrator accounts, supplier access, missing security updates, endpoint protection status, backup success, restore testing, unsupported systems, user and leaver accounts, incident contacts, continuity arrangements, critical supplier changes and insurance requirements.
Cyber resilience needs an operational heartbeat: controls should be checked, failures should be acted upon and recovery should be tested before an emergency.
Administrator Technical Note
Practical areas for MSPs, internal IT teams and potentially regulated suppliers to assess while the Bill progresses. These reflect established NIS-style expectations rather than final legal duties.
Governance
- Applicability and scope assessment
- Designated responsible owner
- Regulatory contact
- Asset and service inventory
- Critical-service mapping
- Risk register
- Board reporting
- Policy review
- Evidence retention
Access control
- Privileged-access management
- Separate administrator accounts
- Phishing-resistant MFA where appropriate
- Least privilege
- Conditional access
- Joiner, mover and leaver controls
- Access reviews
- Emergency-access accounts
- Service-account management
Technical security
- Secure configuration
- Vulnerability management
- Patch governance
- Endpoint detection and response
- Network segmentation
- Email security
- Remote-management platform security
- Centralised logging
- Security monitoring
- Data encryption
- Supported software and firmware
Resilience
- Business-impact analysis
- Recovery-time objectives
- Recovery-point objectives
- Immutable or isolated backups
- Restoration testing
- Supplier dependency mapping
- Alternative communications
- Disaster-recovery exercises
- Crisis-management roles
Incident management
- Incident classification
- Escalation criteria
- 24-hour initial notification preparation
- 72-hour fuller-report preparation
- Regulator and NCSC contact processes
- Customer-notification processes
- Evidence preservation
- Communications templates
- Post-incident review
Supply chain
- Subcontractor register
- Critical supplier assessment
- Contractual security clauses
- Incident-notification obligations
- Audit rights
- Data-location visibility
- Exit planning
- Concentration risk
- Fourth-party dependencies
A staged preparation model
- 1Identify — determine whether the organisation or any services could fall within scope.
- 2Map — document critical services, systems, customers, suppliers and dependencies.
- 3Assess — compare current controls with likely NIS and regulator expectations.
- 4Remediate — address priority weaknesses in access, monitoring, patching, backups and recovery.
- 5Prepare — develop reporting, customer-notification and regulatory communication procedures.
- 6Test — run cyber-incident and disaster-recovery exercises.
- 7Evidence — maintain records showing that controls operate in practice.
- 8Review — track parliamentary amendments, consultations and secondary legislation.
Do not design a compliance programme solely around the current Bill wording. Final duties, thresholds, regulator guidance and commencement dates may change.
This article provides general technology and cyber-security information, not legal advice. Organisations that may fall directly within scope should obtain appropriate legal, regulatory and technical advice.
Plain-English Takeaway
The Cyber Security and Resilience Bill proposes stronger rules for essential services and important technology suppliers, including certain managed service providers and data centres. Most SMEs will not automatically be regulated directly, but many may face higher security expectations through their suppliers, customers and contracts. Businesses should review provider access, incident reporting, backups, recovery and continuity now rather than waiting for the final legislation.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
Passkeys: How to Protect Your Microsoft and Google Accounts
Passkeys let a trusted device approve sign-in with a fingerprint, face or PIN instead of a typed password. Here is how to set one up safely on a Microsoft or Google account — and what to check first.
Read articleCyber Insurance: What Does It Really Protect?
Cyber insurance can support a business following a cyber incident, but policies, exclusions and security requirements vary. Here is what to check before buying or renewing.
Read articleMicrosoft Is Making Passkeys the Default: Is Your Business Ready?
Microsoft is making passkeys the default Entra authentication experience. Learn what this means for MFA, SMS authentication and business security.
Read article