The Cyber Security and Resilience Bill had its second reading in the House of Lords this week. It is the UK's first law with "cyber security" in the title, and it names managed service providers directly.
Lord Holmes asked the government directly how MSP responsibilities inside client supply chains will be made explicit and enforceable. He called for obligations that are outcome-focused, measurable, and operationally realistic.
The direction of travel is clear: security evidence that is continuous and outcome-based, not point-in-time certificates. MSPs that can show live proof of their security controls will be better placed as the regulations tighten.