The Cyber Security Bill for UK Businesses
The Cyber Resilience Bill raises supply chain and IT provider expectations for UK businesses. Here's what it means and what questions to ask your MSP.
This guide is written for UK business owners, directors, and senior managers who want to understand the Cyber Security and Resilience Bill without wading through parliamentary language. Whether you run a 20-person professional services firm or a 200-person manufacturer, this article explains what the Bill does, whether it affects you directly, and what practical steps to take now.
Quick summary
- The Cyber Security and Resilience Bill reforms and expands the existing NIS Regulations. It is not yet law but is progressing through Parliament.
- Most UK SMEs will not be directly regulated, but supply chain pressure, MSP obligations, and incident reporting expectations will tighten.
- Outsourcing IT does not outsource accountability. Boards should evidence visibility into critical suppliers, escalation paths, and recoverability.
- The smartest response is not panic compliance. It is improving ownership, visibility, and evidence.
Status note (as of 10 February 2026)
The relevant legislation is the Cyber Security and Resilience (Network and Information Systems) Bill. It was introduced to Parliament on 12 November 2025 and is not yet law. It is currently in Committee stage in the House of Commons.
This guide focuses on what is confirmed in law today, what is proposed in the Bill, and what appears to be the policy direction of travel but is not (yet) law.
If you are looking for the MSP-specific breakdown of this Bill, see our MSP-focused guide.
1. Executive summary
What the Cyber Security and Resilience Bill is
The Cyber Security and Resilience (Network and Information Systems) Bill is a Government Bill that would amend the Network and Information Systems Regulations 2018 (NIS Regulations) and add new powers and duties aimed at improving the cyber security and resilience of services that are important to the UK's economy and day to day functioning.
Why it exists
The core problem the Bill is trying to solve is that the UK's cross sector cyber resilience rules for critical services are seen as needing updates to reflect changes in:
- Which services are now "essential" (for example, data centres and managed services)
- How incidents spread through supply chains
- How regulators enforce and obtain information consistently across sectors
A practical driver is that, following the repeal of the European Communities Act 1972, Government argues it lacks the right delegated powers to keep updating the NIS Regulations quickly using secondary legislation, so it needs new primary legislation to modernise the framework and give it "futureproofing" powers.
Why SMEs should care even if they are not directly regulated
Most UK SMEs will not suddenly become directly regulated just because this Bill becomes law. The NIS framework is aimed at essential and certain digital services, not "every UK organisation".
However SMEs should care because:
- Supply chain pressure will increase. Regulated organisations will have stronger incentives to demand evidence from suppliers (including SMEs) that cyber risks are understood and managed, because failures in suppliers can disrupt essential services.
- Managed service providers (MSPs) are a regulatory focus. If you outsource IT, your provider may fall into scope, changing contract expectations, incident handling, and evidence requirements.
- Incident reporting expectations are tightening for regulated entities. Even where you are not required to report under NIS, your customers may require faster notification and better quality incident information so they can meet their own duties.
- Directors will be expected to show oversight. Not in the sense of "becoming cyber experts", but in the sense of knowing your critical dependencies, your outsourcing risks, and your ability to respond and recover.
A simple way to think about it
For SMEs, this Bill is less about "new compliance for everyone" and more about a shift toward:
- better enforced cyber resilience expectations for critical services, and
- more explicit management of supply chain and managed service risk.
2. What the Cyber Security and Resilience Bill actually is
Purpose of the Bill
The Bill's long title makes its intent clear: it makes provision, including provision amending the NIS Regulations, about the security and resilience of network and information systems used in connection with essential activities.
In substance, the Bill is best understood as a package of reforms to:
- Expand who is covered by the NIS regime (new types of regulated entities)
- Strengthen how the regime operates (reporting, information sharing, regulator capability and funding, enforcement)
- Add new Government powers linked to national security and to updating the framework over time
How it updates or replaces parts of the NIS Regulations
It does not "replace" NIS. It amends the existing NIS Regulations 2018.
Key structural changes proposed include:
- Adding new regulated categories (for example, relevant managed service providers and critical suppliers) into the NIS framework
- Bringing new services into scope as essential services, notably data centre services and large load control (energy smart appliance load controllers)
- Introducing "futureproofing" delegated powers so the Government can update scope and requirements through secondary legislation, subject to safeguards and parliamentary procedures
Why Government attention has shifted to supply chain and managed services
The policy rationale is that essential services are now deeply dependent on suppliers and outsourced technology operations. Two particularly important dependencies are:
- Managed services (outsourced IT administration, monitoring, and support with privileged access into customer systems)
- Concentrated digital infrastructure (data centres and cloud related dependencies)
The Government's policy statement explicitly highlights supply chain vulnerability as a reason for reform and ties the Bill to modernisation and (where appropriate) alignment with EU NIS2 style approaches.
3. What has changed and what has not
This section separates:
- Confirmed law today
- Proposed changes in the Bill
- Direction of travel but not law
Confirmed law today: the NIS framework already exists
The NIS Regulations 2018 are in force and create statutory cyber security duties for:
- Operators of Essential Services (OES) in defined sectors (energy, transport, health, drinking water, digital infrastructure)
- Certain digital services (online marketplaces, online search engines, cloud computing services), overseen by the ICO for those digital service providers
They work through sector regulators (competent authorities) and focus on the security and resilience of networks and information systems used to provide those essential or digital services.
Proposed in the Bill: what is being added or expanded
The Bill proposes, at a high level:
- Expanded scope: data centres, large load controllers, managed service providers, and critical suppliers
- Incident reporting reform: a two stage process with an initial notification within 24 hours for regulated entities, followed by fuller reporting
- Stronger enforcement and higher penalties: new maximum penalty approach tied to worldwide turnover for more serious breaches (up to £17m or 4 percent, whichever higher) and a second tier for less serious breaches (up to £10m or 2 percent). Detail such as turnover definition would be set in secondary legislation.
- Cost recovery: enabling regulators to recover costs more effectively (a capability Government argues is currently constrained)
- Information sharing gateways: clarifying and expanding who regulators can share information with (and safeguards), including Government departments and other authorities
- Strategic direction and national security powers: a statement of strategic priorities for regulators and powers for the Secretary of State to direct regulators or regulated entities in response to threats posing national security risk
- Futureproofing powers: allowing updates to scope and requirements via secondary legislation under defined conditions, with consultation and parliamentary procedure safeguards
Direction of travel but not law
Even if the Bill passes, important practical detail is expected to come later via:
- Secondary legislation (statutory instruments) for commencement and technical detail in multiple areas (for example, turnover calculation for penalties, and bringing certain powers into force).
- Regulator guidance to interpret "appropriate and proportionate" measures for new in scope sectors, especially where the Bill expands coverage.
So the "direction" is clear, but some of what businesses will actually have to do will depend on later instruments and guidance.
Common misconceptions to correct
"This Bill regulates all SMEs."
Not accurate. The NIS regime is targeted at essential and certain digital services, and the Bill expands that scope, but it is still not a universal regime.
"We will have to buy a specific framework or certification."
The legal duty is generally framed as "appropriate and proportionate" risk management, not "buy X product" or "get badge Y".
"If we use an MSP, cyber risk is the MSP's problem."
Outsourcing changes how you deliver IT, not whether the business owns its operational risk. Under NIS style regimes, responsibility for resilience outcomes typically remains with the organisation delivering the regulated service, even when suppliers are involved. The Bill also adds a route to regulate certain suppliers directly (critical suppliers and MSPs), but that does not remove the customer's governance obligations.
4. Who is in scope
This is the section SMEs most often want answered quickly. The practical answer is: there are two kinds of scope, direct and indirect.
Directly regulated: organisations likely to be in scope
Under the Bill, organisations most likely to be directly regulated include:
Existing NIS regulated sectors and digital services
These remain in scope (OES in key sectors, plus certain digital services such as cloud computing services).
Data centre services as an essential service
The Bill defines "data centre service" and introduces threshold requirements based on "rated IT load":
- If not provided on an enterprise basis: in scope at 1 megawatt or greater
- If provided on an enterprise basis: in scope at 10 megawatts or greater
Relevant managed service providers (RMSPs)
The Bill defines "managed service" as a contract for ongoing management of IT systems where the provider connects to or has access to the customer's network and information systems, including remotely. RMSPs are defined to exclude micro and small enterprises (as defined by a referenced standard), and to handle certain "public authority oversight" cases.
Large load controllers (energy sector)
Load control is brought into scope as an essential service with a 300 MW threshold for electrical load to and from relevant smart appliances.
Designated critical suppliers
The Bill introduces "critical suppliers" designated under new provisions, aimed at suppliers that are critical to regulated entities' ability to provide essential or digital services.
Indirectly impacted: organisations affected through supply chains
Even if your SME is not directly regulated, you are more likely to feel the Bill if you are:
- A supplier to a regulated operator (for example, a water company, health provider, transport operator, energy participant, large digital service provider)
- A supplier to a large MSP that supports regulated customers
- A niche supplier that is operationally critical (for example, you provide remote administration, monitoring, OT support, identity services, or a business critical platform used to run the essential service)
The Government's futureproofing material is explicit that supply chain duties will be clarified and that regulators will gain tools to tackle supply chain vulnerabilities.
Practical SME examples
Example A: Not directly regulated, but commercially impacted
A 40 person manufacturer supplies components to an energy network operator. Your IT outage does not directly stop the grid, but if you cannot deliver for 2 weeks, your customer's continuity risk goes up. Expect procurement and assurance questionnaires to become more evidence driven.
Example B: Potentially directly regulated as a managed service provider
A 120 person IT services firm provides outsourced monitoring and administration for multiple businesses and connects into customer environments. Under the Bill's definition, that is within the concept of a managed service. Whether it is an RMSP depends on the detailed criteria and thresholds in the Bill and later implementation steps.
Example C: Potentially designated as a critical supplier
A small specialist provider supports a regulated transport operator's operational systems. Even if small, a supplier could be designated "critical" if it is essential to provision of the regulated service.
5. Managed service providers and supply chain risk
Why MSPs are a focus of the Bill
The Bill's approach reflects a basic reality: MSPs often have broad access across many customers, meaning compromise of one provider can cascade. The Bill defines "managed service" in terms of ongoing management plus network access to the customer environment.
DSIT's factsheet position is that medium and large MSPs meeting the RMSP definition would be brought into scope of the NIS Regulations.
For a deeper dive into how the Bill affects MSPs specifically, see our MSP-focused guide.
What this means for SMEs that outsource IT
If you outsource IT to an MSP, the Bill is likely to change what "good" looks like in three ways:
Better visibility into what is outsourced
Boards will increasingly be expected to know what systems and services are truly critical, who runs them, and what happens when they fail.
More explicit security and resilience obligations in contracts
Customers will increasingly need to show they have managed supplier risk. Expect pressure for clearer clauses on:
- incident notification timelines
- access control and privileged access management expectations
- backup and recovery responsibilities
- subcontractor control
- evidence provision (not just promises)
More structured incident collaboration
The Bill's tighter reporting expectations for regulated entities (and MSPs in scope) pushes everyone toward earlier notification, clearer facts, and better records.
What boards and directors will reasonably be expected to evidence
For most SMEs, the sensible expectation is not a technical dossier. It is evidence of ownership, oversight, and basic operational control, for example:
- You can list critical systems and who operates them
- You can show you have assessed key supplier dependencies and concentration risk
- You can demonstrate you have agreed incident handling and escalation routes with suppliers
- You can show recovery objectives and tested backups for critical operations
- You can show decision making is documented (what risk was accepted, what was mitigated, why)
This aligns with the NIS concept of "appropriate and proportionate" risk management, and with a more consistent regulatory posture.
6. What "appropriate and proportionate security" means in practice
The phrase "appropriate and proportionate" is easy to misread as either "do everything" or "do almost nothing". In practice, regulators interpret it as a risk based duty: security and resilience should match the risk and the impact of failure.
Plain English interpretation for SMEs
A useful way to translate "appropriate and proportionate" for a board discussion is:
- Appropriate: would a reasonable organisation with your level of dependency and exposure consider these measures necessary to prevent or reduce disruption?
- Proportionate: are the measures balanced against the likely impact and likelihood, rather than unlimited spending?
Focus on outcomes, not frameworks
The NCSC's Cyber Assessment Framework (CAF) exists to express cyber resilience as outcomes and principles, especially for organisations performing essential functions.
SME boards do not need to adopt CAF as a formal programme to behave consistently with its intent. The practical outcomes that tend to matter are:
You know what you are trying to protect
- Critical business services (what you must keep running)
- Critical data and systems
- Key supplier dependencies
You reduce the most common causes of severe disruption
- Prevent avoidable compromise (especially identity and access control failures)
- Limit blast radius when compromise happens
- Ensure you can recover
You can respond and recover predictably
- Incident response roles are pre assigned
- Backups are not just taken, but restorable
- External dependencies are understood
Concrete business examples
- If your revenue depends on a single hosted platform, "proportionate" includes tested recovery, not just antivirus.
- If your finance team can be phished into paying false invoices, "appropriate" includes payment controls and verification steps, not just IT controls.
- If your MSP has admin access to everything, "proportionate" includes contractual and operational constraints on that access, monitoring, and clear break glass procedures.
7. Incident reporting and accountability
This is where SMEs often get confused because there are two overlapping worlds:
- NIS incident reporting (service continuity and security for regulated services)
- Personal data breach reporting (UK GDPR and Data Protection Act world)
What types of incidents are likely to be reportable under NIS
Confirmed today (current ICO NIS guidance for digital service providers): RDSPs must notify the ICO of NIS incidents without undue delay and not later than 72 hours after becoming aware. OES notify their sector competent authority, not the ICO.
Proposed in the Bill: The Bill introduces a two stage reporting structure for regulated entities, with:
- an initial notification within 24 hours of becoming aware that an incident has occurred or is occurring, and
- a fuller notification within 72 hours.
The Bill's drafting also shows broad "significance" concepts, including impacts on the security or continuity of the service, and other significant impacts.
Who holds responsibility when third parties are involved
A simple rule of thumb for boards is:
- If you are the organisation providing the service, you do not outsource accountability.
- If your supplier is itself regulated (for example, an RMSP), it may have its own parallel duties, but that does not remove your need to manage your side of the risk.
The Bill expands the set of "regulated persons" to include OES, RDSP, RMSP and critical suppliers, which indicates a policy intent to regulate certain suppliers directly where they are critical.
What evidence organisations should reasonably retain
Even for SMEs not directly regulated, evidence is what customers and insurers increasingly ask for. Sensible records include:
- Incident timeline: detection time, containment steps, recovery steps
- Decision log: who decided what, and why
- Impact assessment: what business services were affected and for how long
- Communications log: internal escalation, customer notifications, supplier escalation
- Proof of recovery: backup restore results, service restoration confirmation
Separately, under UK GDPR, organisations should have robust breach detection and internal reporting procedures to support decisions about notifying the ICO and individuals, where required.
8. What UK SMEs should do now
The right approach is staged, practical, and focused on ownership and evidence.
Stage 1: Board level clarity (2 to 4 weeks of effort)
- Define your top 5 to 10 critical business services (what must keep running)
- Map the IT and suppliers that each critical service depends on (including MSPs and cloud providers)
- Identify your single points of failure (one person, one supplier, one system)
Deliverable: a one page "critical services and dependencies" map that a director can understand.
Stage 2: Supplier reality check (4 to 8 weeks)
For each critical supplier, confirm in writing:
- incident notification and escalation route (including out of hours)
- recovery commitments and responsibilities (who restores what)
- administrative access model (who has privileged access and how it is controlled)
- subcontractor use (and whether it changes your risk)
Ensure your contract does not rely on vague statements like "industry standard security" without evidence expectations.
Deliverable: a short supplier schedule for your MSP and key providers.
Stage 3: Minimum viable resilience (ongoing)
Prioritise the controls that prevent the most common catastrophic outcomes:
- account compromise leading to fraud or ransomware
- inability to restore systems
- unmanaged privileged access
- silent supplier failure and slow escalation
Deliverable: tested restore evidence and a basic incident playbook.
Stage 4: Incident readiness (tabletop, then improve)
Run a tabletop exercise with leadership and your MSP:
- ransomware scenario
- business email compromise scenario
- key supplier outage scenario
The goal is not perfection. It is to expose gaps in escalation, decision making, and restoration.
Deliverable: an updated response plan and named roles.
9. What SMEs should not do
Do not chase badges as a substitute for resilience
Certifications and assessments can be useful in context, but a badge does not automatically mean you can prevent disruption or recover quickly. Avoid spending disproportionately on optics while underfunding restoration and response capability.
Do not assume suppliers handle everything
If you cannot explain what your MSP is responsible for during a major incident, you have a governance gap. Outsourcing IT is not outsourcing risk ownership.
Do not build compliance theatre
Policies that are not implemented, incident plans that are not rehearsed, and risk registers that are never used will not help in a real incident and will not satisfy serious customers.
10. Timeline and direction of travel
What is known about timing
Key dates from official sources:
- July 2024: Government announced intent to introduce a Cyber Security and Resilience Bill in the King's Speech (as described in the policy statement).
- 1 April 2025: DSIT published the Cyber Security and Resilience Bill policy statement describing confirmed and proposed measures.
- 12 November 2025: The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to Parliament.
- 10 February 2026: The Bill is still in progress (Commons Committee stage at last update) and is not yet enacted.
What is still uncertain
Even if the Bill passes, many practical elements depend on secondary legislation and regulator guidance, including:
- the commencement of several measures (many are stated to be brought into force via secondary legislation after Royal Assent)
- the precise definition and calculation of "turnover" for penalty purposes
- the detailed content of any clarified supply chain duties under futureproofing powers
What is likely over the next 2 to 5 years
Without guessing exact dates, the official material supports a clear direction:
- more agile updates to NIS scope and requirements through delegated powers
- increasing emphasis on supply chain risk management, including the ability to designate critical suppliers
- more consistent enforcement across sectors, with stronger penalties and cost recovery intended to support regulator effectiveness
- tightening and standardising incident reporting expectations (at least for regulated entities)
For SMEs, that translates into sustained commercial pressure for better cyber risk evidence, especially if you sell into regulated sectors or rely heavily on MSPs.
11. Key takeaways for boards and directors
- This Bill is not law yet. It is currently progressing through Parliament and may change before Royal Assent.
- The UK already has NIS cyber security law. The Bill reforms and expands the NIS Regulations 2018, rather than replacing them.
- Scope is expanding to include data centres, managed service providers, large load controllers, and designated critical suppliers.
- Enforcement is designed to get sharper and more consequential. Proposed maximum penalties include up to £17m or 4 percent of worldwide turnover for more serious breaches.
- Incident reporting expectations for regulated entities tighten to a 24 hour initial notification model. Even if you are not regulated, your customers may push this requirement down contractually.
- Outsourcing IT does not outsource accountability. Boards should expect to evidence visibility into critical suppliers, escalation paths, and recoverability.
- The smartest SME response is not panic compliance. It is improving ownership, visibility, and evidence: know your critical services, know your dependencies, test recovery, and formalise incident collaboration with suppliers.
Frequently asked questions
Does the Cyber Security and Resilience Bill apply to my SME?
Most UK SMEs will not be directly regulated under the Bill. The NIS framework targets operators of essential services, certain digital services, managed service providers above a size threshold, and designated critical suppliers. However, if you supply into regulated sectors or rely on an MSP that falls in scope, you will feel indirect effects through tighter contractual demands, evidence requirements, and incident reporting expectations from your customers and partners.
Is the Cyber Security and Resilience Bill law yet?
No. As of February 2026, the Bill has been introduced to Parliament (12 November 2025) and is in Committee stage in the House of Commons. It is not yet enacted. Many practical details will also depend on secondary legislation and regulator guidance published after Royal Assent.
What is a relevant managed service provider (RMSP) under the Bill?
The Bill defines a managed service as a contract for ongoing management of IT systems where the provider connects to or has access to the customer's network and information systems, including remotely. Micro and small enterprises are excluded from the RMSP definition. Medium and large MSPs meeting the criteria would be brought into scope of the NIS Regulations.
What are the penalties under the Cyber Security and Resilience Bill?
The Bill proposes maximum penalties of up to £17 million or 4 percent of worldwide turnover (whichever is higher) for more serious breaches, and up to £10 million or 2 percent for less serious breaches. The detail on how turnover is calculated will be set out in secondary legislation.
What should my business do now to prepare for the Bill?
Start with board-level clarity: identify your top 5 to 10 critical business services and map the IT systems and suppliers each depends on. Then do a supplier reality check with your MSP and key providers - confirm incident escalation routes, recovery responsibilities, and access controls in writing. You do not need to buy new frameworks or certifications. Focus on ownership, visibility, and evidence of resilience.
Does outsourcing IT to an MSP transfer my cyber risk?
No. Outsourcing IT changes how you deliver technology services, not whether the business owns its operational risk. Under NIS-style regimes, responsibility for resilience outcomes stays with the organisation delivering the regulated service, even when suppliers are involved. The Bill may also regulate certain MSPs directly, but that does not remove the customer's governance obligations.
How is the Cyber Security and Resilience Bill different from Cyber Essentials or ISO 27001?
Cyber Essentials and ISO 27001 are voluntary certifications. The Cyber Security and Resilience Bill is primary legislation that creates statutory duties for organisations in scope of the NIS framework. The legal duty is framed as "appropriate and proportionate" risk management - it does not mandate any specific certification or framework. Certifications can support compliance but are not substitutes for demonstrable resilience.
What incident reporting changes does the Bill introduce?
For regulated entities, the Bill introduces a two-stage reporting structure: an initial notification within 24 hours of becoming aware that a significant incident has occurred, followed by a fuller report within 72 hours. Even if your organisation is not directly regulated, your customers may push faster notification requirements down contractually to meet their own duties.
How some SMEs and MSPs make this easier (without compliance theatre)
If you rely heavily on a third-party IT provider, the practical challenge is rarely understanding what "good" looks like. It's proving it consistently, with current evidence, without scrambling every time a customer, insurer, or auditor asks.
Some organisations handle this with internal governance and regular assurance reviews. Others use independent, evidence-led assessment and continuous verification to keep proof current.
Assurix is one example of that approach. It independently verifies an MSP's cyber resilience (aligned to the NCSC Cyber Assessment Framework) and operational maturity using time-stamped evidence, with ongoing checks rather than point-in-time paperwork. If controls lapse and are not fixed, the trustmark is suspended. This is designed to reduce ambiguity, not to guarantee outcomes.