CNI and MSPs: What UK Providers Need to Know
UK MSPs serving regulated sectors are part of CNI supply chains. Here's what that means for compliance, the Cyber Security Bill, and how to prepare.
Quick summary
- CNI is about essential functions, not fancy labels.
- Many MSPs already support CNI or "near CNI" clients without calling it that.
- If those clients go down, you are in the CNI story and expectations rise.
- You will not always be directly regulated, but you will be asked for proof, not promises.
You do not need to manage a nuclear plant or an NHS trust to be part of the Critical National Infrastructure story.
If your clients help keep utilities, health, transport, finance or government running, even indirectly, your MSP is already close to CNI and carries more risk than most people realise.
This guide breaks down what CNI really is, how to spot both CNI and near CNI clients, and what that means for expectations on your MSP under the Cyber Security and Resilience Bill and CAF.
For the full Cyber Security and Resilience Bill breakdown, see our separate Assurix guide for MSPs.
This article focuses on where CNI and "near CNI" show up in your client base and what that means for how you run and evidence your MSP.
This is general guidance for MSPs, not legal advice.
1. What is Critical National Infrastructure in UK terms?
Critical National Infrastructure is government shorthand for "the parts of the system we cannot afford to lose". It is not a badge for important companies. It is a way of flagging where failure would cause serious harm.
In plain English, CNI covers assets, systems, networks, processes and people where failure could lead to things like:
- major disruption to essential services
- significant economic or social damage
- serious loss of life or casualties
- harm to national security, national defence or the basic functioning of the state
That includes things that keep life running, such as power, communications and water, and things that are dangerous if mishandled, such as civil nuclear and certain chemical sites.
Government groups this into 13 CNI sectors. At a high level:
- Chemicals: major hazardous chemical production and storage
- Civil nuclear: nuclear power generation and fuel cycle facilities
- Communications: fixed and mobile telecoms, internet backbone, exchanges
- Defence: critical defence industrial base and key systems
- Emergency services: police, fire, ambulance and control rooms
- Energy: electricity and gas generation and transmission, key fuel infrastructure
- Finance: core payments, clearing, settlement and market infrastructure
- Food: major food production, processing and distribution
- Government: central government and key local capabilities that keep the state running
- Health: NHS and other providers that deliver essential care at scale
- Space: space based services for communications, navigation and timing
- Transport: rail, aviation, maritime, strategic roads and traffic control systems
- Water: water and wastewater utilities
For an MSP, you can translate that into client types such as:
- NHS trusts, ambulance services and large health providers
- water and energy utilities and their OT integrators
- central and local government bodies and their shared services
- payment processors, clearing houses and pension or benefits platforms
- data centres and communications providers that other CNI sectors sit on
2. Not everything in a CNI sector is "critical"
Being in a CNI sector does not automatically make an organisation CNI.
Government focuses on essential functions and the systems that deliver them. In practice they ask:
- What essential functions does the country rely on in this sector?
- What systems deliver those functions?
- Which organisations operate those systems?
If the loss or compromise of that combination would have severe impacts at scale, it is likely to be treated as CNI. If not, it might still be important, but it is not "critical" in the technical sense.
A few simple contrasts:
- Health: national 999 and 111 call handling and dispatch systems are clearly critical. If they fail nationwide, people die. A single private physio clinic is not.
- Transport: a rail signalling control system for a main line is critical. A small regional taxi firm using an app is not.
- In between: a cloud platform or MSP that runs a key application for a water company, payments provider or NHS body is part of the chain that delivers an essential function. It may not be labelled CNI itself, but it sits inside the risk picture.
Labels Aren't the Whole Story
For MSPs, the lesson is that labels are not the whole story. You can be part of a critical service without anyone ever saying "you are CNI".
3. Near CNI: how supply chains pull your MSP into the CNI picture
Government increasingly thinks about CNI as chains, not islands. That is what the criticalities work and the CNI Knowledge Base are for. In simple terms they:
- map the essential functions the country relies on
- identify the systems that support those functions
- look at sector level and cross sector impacts if those systems fail
- trace the supporting systems, organisations and relationships underneath, including supply chains
In that view, an MSP, cloud platform or SaaS provider can be part of the CNI picture even if it is not the headline operator.
You can think of three rough positions:
- Direct CNI: you support a recognised CNI owner or operator, such as an NHS trust, water company, DNO, blue light service or core government function.
- Near CNI: you support a supplier or platform that an operator relies on to deliver an essential function. For example, the SaaS scheduling tool used by several ambulance trusts, or the MSP that runs core infrastructure for a water utility's OT integrator.
- Outside CNI: your clients may be important businesses, but if they fail it mainly affects them, not the wider public or other essential services.
Where Many UK MSPs Sit
"Near CNI" is where many UK MSPs sit in reality. You are not directly regulated as an operator of essential services, but if your service fails, a critical function may still be hit. That is what worries boards, insurers and policymakers.
4. How CNI and near CNI affect your MSP
If you are a serious MSP with good clients, there is a decent chance you already serve organisations that sit in or close to the 13 sectors. Typical examples:
- Health and emergency: NHS bodies, ambulance services, large health and care providers
- Utilities and infrastructure: water companies, energy providers, smart grid and OT integrators
- Government: local authorities, central government agencies, shared service providers
- Financial infrastructure: payment gateways, trading and clearing platforms, pension and benefits systems
- Platforms and data centres: data centres, cloud platforms and key SaaS services that those organisations rely on
You might currently call these "regulated clients", "serious clients" or "business critical" accounts. Government increasingly sees them as part of CNI systems. That is what drives the change in expectations.
The Cyber Security and Resilience Bill strengthens duties on operators of essential services and relevant digital providers and brings medium and large MSPs into scope as "Relevant Managed Service Providers". It also gives powers to treat smaller providers as critical suppliers where failure would seriously disrupt essential or digital services.
CAF is the benchmark for what "good" looks like in this world. It is already used by regulators and owners of essential functions. It is outcome based, so it cares about what you actually do, not just what is written in a policy.
If you want the detail on size thresholds, incident reporting and regulated classes, our companion Assurix guide to the Cyber Security and Resilience Bill goes into that in depth. This CNI article is the companion piece. It focuses on where your clients and services fit in the bigger picture and what you should do about it.
5. How to tell if you already have CNI or near CNI clients
You do not need access to any government database to get started. Use a few simple questions and clues.
First, the big one:
The Key Question
If this client's key systems went down for several days, would it seriously affect the wider public or other essential services, not just their own business?
If the honest answer is "yes", treat them as CNI or near CNI for your own risk thinking.
Then look for clues like:
- Essential utilities: water, electricity, gas, fuel supply, major district heating
- Health and emergency: NHS trusts, ambulance and 999 operations, large social care providers tied into statutory services
- Transport and logistics: rail operators, airports, port authorities, motorway control, national distribution hubs
- Government and local authorities: councils delivering statutory services, central government agencies, blue light control rooms
- Financial infrastructure: major payment gateways, clearing or settlement platforms, benefits and pension systems
- Platforms and data centres: data centres, cloud platforms and SaaS products that dozens or hundreds of other organisations rely on
Size Isn't Everything
Be careful not to dismiss a client because they are small on paper. A 25 person software firm that provides the rostering system for multiple ambulance trusts, or a 15 person MSP that runs infrastructure for a regional water company, can still be very close to an essential function.
A good starting exercise is to take your top 20 or 50 clients and map them loosely against the 13 sectors. Highlight the ones where the blast radius clearly extends beyond the client's own P&L. These are the accounts where you want to be able to show proof, not just promises.
6. If you have CNI or near CNI clients, will you need to be compliant?
This is the question most MSPs really care about. There are three layers to the answer.
1. Your client's direct duties
Many operators of essential services and some digital providers already have duties under NIS and will gain stronger ones under the Cyber Security and Resilience Bill. They will be expected to manage supply chain cyber risk properly.
That means they will ask you for more detail, more evidence and more robust contracts, even if you are not directly regulated.
2. Being designated or classified yourself
If you are medium or large and meet the managed services definition, you may be brought into scope as a Relevant Managed Service Provider. Smaller MSPs and specific suppliers can also be designated as "critical suppliers" where failure would seriously disrupt essential or digital services.
Our Cyber Security and Resilience Bill article explains the RMSP definition, size thresholds and incident reporting expectations.
3. The de facto expectations
Even if you never receive a regulatory letter, the expectations will land through:
- stronger security and resilience clauses in contracts and frameworks
- tougher due diligence from prospects and insurers
- questions framed around CAF style outcomes rather than basic checklists
So the practical answer is:
- If you are large enough or embedded enough: You should assume you will need to align to CAF style expectations and future guidance and may be directly regulated.
- If you are smaller but close to CNI: You should still behave as if you will be asked to prove your security and operational maturity to CNI level clients, boards and insurers.
The Bottom Line
In both cases this is less about chasing every acronym and more about being able to show, with evidence, that you run a "proper" MSP.
7. What to do in the next 90 days
You do not need a policy department. You do need a focused plan that fits around the day job. Over the next 90 days you could:
Flag CNI and near CNI clients in your PSA or CRM
Add a simple field or tag so your team knows where the stakes are higher.
Have a specific resilience conversation with those clients
Ask about their regulatory context, whether CAF is on their radar, and what their board or regulator expects from suppliers. Capture that in your account plans so sales and ops are on the same page.
Tighten incident response and communication for those accounts
Make sure you have clear playbooks, escalation paths and contact trees, and that they align with the client's own incident processes. If something big happens at 2am, who does what and when?
Stress test your high impact controls
Look hard at privileged access, segregation, monitoring, backup and recovery for these clients. Ask yourself: if we had a serious incident affecting this client, what would regulators, boards and insurers want to see?
8. Where Assurix fits: turning CNI exposure into visible assurance
If your MSP has CNI or near CNI clients, you will increasingly need to show that you operate to a higher standard - not just claim it.
Assurix provides a continuous, evidence-based trustmark that aligns with CAF outcomes and operational maturity. It connects to the tools you already use and tracks whether you are actually doing what you say you are doing, day to day.
For MSPs with CNI exposure, that means:
- A clear, independent view of your security and operational controls
- Evidence you can share with clients, boards and insurers
- A framework that grows with you as expectations tighten
9. A simple next step
If you want to understand how your client base maps to CNI and near CNI, and what that means for your obligations and opportunities, book a short discovery call with Assurix.
We can help you identify which clients carry higher expectations, what gaps you might want to close, and whether continuous assurance could help you turn regulatory pressure into a competitive advantage.