CNI and MSPs: What UK Providers Need to Know

UK MSPs serving regulated sectors are part of CNI supply chains. Here's what that means for compliance, the Cyber Security Bill, and how to prepare.

Quick summary

You do not need to manage a nuclear plant or an NHS trust to be part of the Critical National Infrastructure story.

If your clients help keep utilities, health, transport, finance or government running, even indirectly, your MSP is already close to CNI and carries more risk than most people realise.

This guide breaks down what CNI really is, how to spot both CNI and near CNI clients, and what that means for expectations on your MSP under the Cyber Security and Resilience Bill and CAF.

For the full Cyber Security and Resilience Bill breakdown, see our separate Assurix guide for MSPs.

This article focuses on where CNI and "near CNI" show up in your client base and what that means for how you run and evidence your MSP.

This is general guidance for MSPs, not legal advice.

1. What is Critical National Infrastructure in UK terms?

Critical National Infrastructure is government shorthand for "the parts of the system we cannot afford to lose". It is not a badge for important companies. It is a way of flagging where failure would cause serious harm.

In plain English, CNI covers assets, systems, networks, processes and people where failure could lead to things like:

That includes things that keep life running, such as power, communications and water, and things that are dangerous if mishandled, such as civil nuclear and certain chemical sites.

Government groups this into 13 CNI sectors. At a high level:

For an MSP, you can translate that into client types such as:

2. Not everything in a CNI sector is "critical"

Being in a CNI sector does not automatically make an organisation CNI.

Government focuses on essential functions and the systems that deliver them. In practice they ask:

If the loss or compromise of that combination would have severe impacts at scale, it is likely to be treated as CNI. If not, it might still be important, but it is not "critical" in the technical sense.

A few simple contrasts:

Labels Aren't the Whole Story

For MSPs, the lesson is that labels are not the whole story. You can be part of a critical service without anyone ever saying "you are CNI".

3. Near CNI: how supply chains pull your MSP into the CNI picture

Government increasingly thinks about CNI as chains, not islands. That is what the criticalities work and the CNI Knowledge Base are for. In simple terms they:

In that view, an MSP, cloud platform or SaaS provider can be part of the CNI picture even if it is not the headline operator.

You can think of three rough positions:

Where Many UK MSPs Sit

"Near CNI" is where many UK MSPs sit in reality. You are not directly regulated as an operator of essential services, but if your service fails, a critical function may still be hit. That is what worries boards, insurers and policymakers.

4. How CNI and near CNI affect your MSP

If you are a serious MSP with good clients, there is a decent chance you already serve organisations that sit in or close to the 13 sectors. Typical examples:

You might currently call these "regulated clients", "serious clients" or "business critical" accounts. Government increasingly sees them as part of CNI systems. That is what drives the change in expectations.

The Cyber Security and Resilience Bill strengthens duties on operators of essential services and relevant digital providers and brings medium and large MSPs into scope as "Relevant Managed Service Providers". It also gives powers to treat smaller providers as critical suppliers where failure would seriously disrupt essential or digital services.

CAF is the benchmark for what "good" looks like in this world. It is already used by regulators and owners of essential functions. It is outcome based, so it cares about what you actually do, not just what is written in a policy.

If you want the detail on size thresholds, incident reporting and regulated classes, our companion Assurix guide to the Cyber Security and Resilience Bill goes into that in depth. This CNI article is the companion piece. It focuses on where your clients and services fit in the bigger picture and what you should do about it.

5. How to tell if you already have CNI or near CNI clients

You do not need access to any government database to get started. Use a few simple questions and clues.

First, the big one:

The Key Question

If this client's key systems went down for several days, would it seriously affect the wider public or other essential services, not just their own business?

If the honest answer is "yes", treat them as CNI or near CNI for your own risk thinking.

Then look for clues like:

Size Isn't Everything

Be careful not to dismiss a client because they are small on paper. A 25 person software firm that provides the rostering system for multiple ambulance trusts, or a 15 person MSP that runs infrastructure for a regional water company, can still be very close to an essential function.

A good starting exercise is to take your top 20 or 50 clients and map them loosely against the 13 sectors. Highlight the ones where the blast radius clearly extends beyond the client's own P&L. These are the accounts where you want to be able to show proof, not just promises.

6. If you have CNI or near CNI clients, will you need to be compliant?

This is the question most MSPs really care about. There are three layers to the answer.

1. Your client's direct duties

Many operators of essential services and some digital providers already have duties under NIS and will gain stronger ones under the Cyber Security and Resilience Bill. They will be expected to manage supply chain cyber risk properly.

That means they will ask you for more detail, more evidence and more robust contracts, even if you are not directly regulated.

2. Being designated or classified yourself

If you are medium or large and meet the managed services definition, you may be brought into scope as a Relevant Managed Service Provider. Smaller MSPs and specific suppliers can also be designated as "critical suppliers" where failure would seriously disrupt essential or digital services.

Our Cyber Security and Resilience Bill article explains the RMSP definition, size thresholds and incident reporting expectations.

3. The de facto expectations

Even if you never receive a regulatory letter, the expectations will land through:

So the practical answer is:

The Bottom Line

In both cases this is less about chasing every acronym and more about being able to show, with evidence, that you run a "proper" MSP.

7. What to do in the next 90 days

You do not need a policy department. You do need a focused plan that fits around the day job. Over the next 90 days you could:

Flag CNI and near CNI clients in your PSA or CRM

Add a simple field or tag so your team knows where the stakes are higher.

Have a specific resilience conversation with those clients

Ask about their regulatory context, whether CAF is on their radar, and what their board or regulator expects from suppliers. Capture that in your account plans so sales and ops are on the same page.

Tighten incident response and communication for those accounts

Make sure you have clear playbooks, escalation paths and contact trees, and that they align with the client's own incident processes. If something big happens at 2am, who does what and when?

Stress test your high impact controls

Look hard at privileged access, segregation, monitoring, backup and recovery for these clients. Ask yourself: if we had a serious incident affecting this client, what would regulators, boards and insurers want to see?

8. Where Assurix fits: turning CNI exposure into visible assurance

If your MSP has CNI or near CNI clients, you will increasingly need to show that you operate to a higher standard - not just claim it.

Assurix provides a continuous, evidence-based trustmark that aligns with CAF outcomes and operational maturity. It connects to the tools you already use and tracks whether you are actually doing what you say you are doing, day to day.

For MSPs with CNI exposure, that means:

9. A simple next step

If you want to understand how your client base maps to CNI and near CNI, and what that means for your obligations and opportunities, book a short discovery call with Assurix.

We can help you identify which clients carry higher expectations, what gaps you might want to close, and whether continuous assurance could help you turn regulatory pressure into a competitive advantage.

Book a 30 min intro call

Related reading