The Cyber Security Bill for UK Businesses

The Cyber Resilience Bill raises supply chain and IT provider expectations for UK businesses. Here's what it means and what questions to ask your MSP.

This guide is written for UK business owners, directors, and senior managers who want to understand the Cyber Security and Resilience Bill without wading through parliamentary language. Whether you run a 20-person professional services firm or a 200-person manufacturer, this article explains what the Bill does, whether it affects you directly, and what practical steps to take now.

Quick summary

Status note (as of 10 February 2026)

The relevant legislation is the Cyber Security and Resilience (Network and Information Systems) Bill. It was introduced to Parliament on 12 November 2025 and is not yet law. It is currently in Committee stage in the House of Commons.

This guide focuses on what is confirmed in law today, what is proposed in the Bill, and what appears to be the policy direction of travel but is not (yet) law.

If you are looking for the MSP-specific breakdown of this Bill, see our MSP-focused guide.

1. Executive summary

What the Cyber Security and Resilience Bill is

The Cyber Security and Resilience (Network and Information Systems) Bill is a Government Bill that would amend the Network and Information Systems Regulations 2018 (NIS Regulations) and add new powers and duties aimed at improving the cyber security and resilience of services that are important to the UK's economy and day to day functioning.

Why it exists

The core problem the Bill is trying to solve is that the UK's cross sector cyber resilience rules for critical services are seen as needing updates to reflect changes in:

A practical driver is that, following the repeal of the European Communities Act 1972, Government argues it lacks the right delegated powers to keep updating the NIS Regulations quickly using secondary legislation, so it needs new primary legislation to modernise the framework and give it "futureproofing" powers.

Why SMEs should care even if they are not directly regulated

Most UK SMEs will not suddenly become directly regulated just because this Bill becomes law. The NIS framework is aimed at essential and certain digital services, not "every UK organisation".

However SMEs should care because:

A simple way to think about it

For SMEs, this Bill is less about "new compliance for everyone" and more about a shift toward:

2. What the Cyber Security and Resilience Bill actually is

Purpose of the Bill

The Bill's long title makes its intent clear: it makes provision, including provision amending the NIS Regulations, about the security and resilience of network and information systems used in connection with essential activities.

In substance, the Bill is best understood as a package of reforms to:

How it updates or replaces parts of the NIS Regulations

It does not "replace" NIS. It amends the existing NIS Regulations 2018.

Key structural changes proposed include:

Why Government attention has shifted to supply chain and managed services

The policy rationale is that essential services are now deeply dependent on suppliers and outsourced technology operations. Two particularly important dependencies are:

The Government's policy statement explicitly highlights supply chain vulnerability as a reason for reform and ties the Bill to modernisation and (where appropriate) alignment with EU NIS2 style approaches.

3. What has changed and what has not

This section separates:

Confirmed law today: the NIS framework already exists

The NIS Regulations 2018 are in force and create statutory cyber security duties for:

They work through sector regulators (competent authorities) and focus on the security and resilience of networks and information systems used to provide those essential or digital services.

Proposed in the Bill: what is being added or expanded

The Bill proposes, at a high level:

Direction of travel but not law

Even if the Bill passes, important practical detail is expected to come later via:

So the "direction" is clear, but some of what businesses will actually have to do will depend on later instruments and guidance.

Common misconceptions to correct

"This Bill regulates all SMEs."

Not accurate. The NIS regime is targeted at essential and certain digital services, and the Bill expands that scope, but it is still not a universal regime.

"We will have to buy a specific framework or certification."

The legal duty is generally framed as "appropriate and proportionate" risk management, not "buy X product" or "get badge Y".

"If we use an MSP, cyber risk is the MSP's problem."

Outsourcing changes how you deliver IT, not whether the business owns its operational risk. Under NIS style regimes, responsibility for resilience outcomes typically remains with the organisation delivering the regulated service, even when suppliers are involved. The Bill also adds a route to regulate certain suppliers directly (critical suppliers and MSPs), but that does not remove the customer's governance obligations.

4. Who is in scope

This is the section SMEs most often want answered quickly. The practical answer is: there are two kinds of scope, direct and indirect.

Directly regulated: organisations likely to be in scope

Under the Bill, organisations most likely to be directly regulated include:

Existing NIS regulated sectors and digital services

These remain in scope (OES in key sectors, plus certain digital services such as cloud computing services).

Data centre services as an essential service

The Bill defines "data centre service" and introduces threshold requirements based on "rated IT load":

Relevant managed service providers (RMSPs)

The Bill defines "managed service" as a contract for ongoing management of IT systems where the provider connects to or has access to the customer's network and information systems, including remotely. RMSPs are defined to exclude micro and small enterprises (as defined by a referenced standard), and to handle certain "public authority oversight" cases.

Large load controllers (energy sector)

Load control is brought into scope as an essential service with a 300 MW threshold for electrical load to and from relevant smart appliances.

Designated critical suppliers

The Bill introduces "critical suppliers" designated under new provisions, aimed at suppliers that are critical to regulated entities' ability to provide essential or digital services.

Indirectly impacted: organisations affected through supply chains

Even if your SME is not directly regulated, you are more likely to feel the Bill if you are:

The Government's futureproofing material is explicit that supply chain duties will be clarified and that regulators will gain tools to tackle supply chain vulnerabilities.

Practical SME examples

Example A: Not directly regulated, but commercially impacted

A 40 person manufacturer supplies components to an energy network operator. Your IT outage does not directly stop the grid, but if you cannot deliver for 2 weeks, your customer's continuity risk goes up. Expect procurement and assurance questionnaires to become more evidence driven.

Example B: Potentially directly regulated as a managed service provider

A 120 person IT services firm provides outsourced monitoring and administration for multiple businesses and connects into customer environments. Under the Bill's definition, that is within the concept of a managed service. Whether it is an RMSP depends on the detailed criteria and thresholds in the Bill and later implementation steps.

Example C: Potentially designated as a critical supplier

A small specialist provider supports a regulated transport operator's operational systems. Even if small, a supplier could be designated "critical" if it is essential to provision of the regulated service.

5. Managed service providers and supply chain risk

Why MSPs are a focus of the Bill

The Bill's approach reflects a basic reality: MSPs often have broad access across many customers, meaning compromise of one provider can cascade. The Bill defines "managed service" in terms of ongoing management plus network access to the customer environment.

DSIT's factsheet position is that medium and large MSPs meeting the RMSP definition would be brought into scope of the NIS Regulations.

For a deeper dive into how the Bill affects MSPs specifically, see our MSP-focused guide.

What this means for SMEs that outsource IT

If you outsource IT to an MSP, the Bill is likely to change what "good" looks like in three ways:

Better visibility into what is outsourced

Boards will increasingly be expected to know what systems and services are truly critical, who runs them, and what happens when they fail.

More explicit security and resilience obligations in contracts

Customers will increasingly need to show they have managed supplier risk. Expect pressure for clearer clauses on:

More structured incident collaboration

The Bill's tighter reporting expectations for regulated entities (and MSPs in scope) pushes everyone toward earlier notification, clearer facts, and better records.

What boards and directors will reasonably be expected to evidence

For most SMEs, the sensible expectation is not a technical dossier. It is evidence of ownership, oversight, and basic operational control, for example:

This aligns with the NIS concept of "appropriate and proportionate" risk management, and with a more consistent regulatory posture.

6. What "appropriate and proportionate security" means in practice

The phrase "appropriate and proportionate" is easy to misread as either "do everything" or "do almost nothing". In practice, regulators interpret it as a risk based duty: security and resilience should match the risk and the impact of failure.

Plain English interpretation for SMEs

A useful way to translate "appropriate and proportionate" for a board discussion is:

Focus on outcomes, not frameworks

The NCSC's Cyber Assessment Framework (CAF) exists to express cyber resilience as outcomes and principles, especially for organisations performing essential functions.

SME boards do not need to adopt CAF as a formal programme to behave consistently with its intent. The practical outcomes that tend to matter are:

You know what you are trying to protect

You reduce the most common causes of severe disruption

You can respond and recover predictably

Concrete business examples

7. Incident reporting and accountability

This is where SMEs often get confused because there are two overlapping worlds:

What types of incidents are likely to be reportable under NIS

Confirmed today (current ICO NIS guidance for digital service providers): RDSPs must notify the ICO of NIS incidents without undue delay and not later than 72 hours after becoming aware. OES notify their sector competent authority, not the ICO.

Proposed in the Bill: The Bill introduces a two stage reporting structure for regulated entities, with:

The Bill's drafting also shows broad "significance" concepts, including impacts on the security or continuity of the service, and other significant impacts.

Who holds responsibility when third parties are involved

A simple rule of thumb for boards is:

The Bill expands the set of "regulated persons" to include OES, RDSP, RMSP and critical suppliers, which indicates a policy intent to regulate certain suppliers directly where they are critical.

What evidence organisations should reasonably retain

Even for SMEs not directly regulated, evidence is what customers and insurers increasingly ask for. Sensible records include:

Separately, under UK GDPR, organisations should have robust breach detection and internal reporting procedures to support decisions about notifying the ICO and individuals, where required.

8. What UK SMEs should do now

The right approach is staged, practical, and focused on ownership and evidence.

Stage 1: Board level clarity (2 to 4 weeks of effort)

Deliverable: a one page "critical services and dependencies" map that a director can understand.

Stage 2: Supplier reality check (4 to 8 weeks)

For each critical supplier, confirm in writing:

Ensure your contract does not rely on vague statements like "industry standard security" without evidence expectations.

Deliverable: a short supplier schedule for your MSP and key providers.

Stage 3: Minimum viable resilience (ongoing)

Prioritise the controls that prevent the most common catastrophic outcomes:

Deliverable: tested restore evidence and a basic incident playbook.

Stage 4: Incident readiness (tabletop, then improve)

Run a tabletop exercise with leadership and your MSP:

The goal is not perfection. It is to expose gaps in escalation, decision making, and restoration.

Deliverable: an updated response plan and named roles.

9. What SMEs should not do

Do not chase badges as a substitute for resilience

Certifications and assessments can be useful in context, but a badge does not automatically mean you can prevent disruption or recover quickly. Avoid spending disproportionately on optics while underfunding restoration and response capability.

Do not assume suppliers handle everything

If you cannot explain what your MSP is responsible for during a major incident, you have a governance gap. Outsourcing IT is not outsourcing risk ownership.

Do not build compliance theatre

Policies that are not implemented, incident plans that are not rehearsed, and risk registers that are never used will not help in a real incident and will not satisfy serious customers.

10. Timeline and direction of travel

What is known about timing

Key dates from official sources:

What is still uncertain

Even if the Bill passes, many practical elements depend on secondary legislation and regulator guidance, including:

What is likely over the next 2 to 5 years

Without guessing exact dates, the official material supports a clear direction:

For SMEs, that translates into sustained commercial pressure for better cyber risk evidence, especially if you sell into regulated sectors or rely heavily on MSPs.

11. Key takeaways for boards and directors

Frequently asked questions

Does the Cyber Security and Resilience Bill apply to my SME?

Most UK SMEs will not be directly regulated under the Bill. The NIS framework targets operators of essential services, certain digital services, managed service providers above a size threshold, and designated critical suppliers. However, if you supply into regulated sectors or rely on an MSP that falls in scope, you will feel indirect effects through tighter contractual demands, evidence requirements, and incident reporting expectations from your customers and partners.

Is the Cyber Security and Resilience Bill law yet?

No. As of February 2026, the Bill has been introduced to Parliament (12 November 2025) and is in Committee stage in the House of Commons. It is not yet enacted. Many practical details will also depend on secondary legislation and regulator guidance published after Royal Assent.

What is a relevant managed service provider (RMSP) under the Bill?

The Bill defines a managed service as a contract for ongoing management of IT systems where the provider connects to or has access to the customer's network and information systems, including remotely. Micro and small enterprises are excluded from the RMSP definition. Medium and large MSPs meeting the criteria would be brought into scope of the NIS Regulations.

What are the penalties under the Cyber Security and Resilience Bill?

The Bill proposes maximum penalties of up to £17 million or 4 percent of worldwide turnover (whichever is higher) for more serious breaches, and up to £10 million or 2 percent for less serious breaches. The detail on how turnover is calculated will be set out in secondary legislation.

What should my business do now to prepare for the Bill?

Start with board-level clarity: identify your top 5 to 10 critical business services and map the IT systems and suppliers each depends on. Then do a supplier reality check with your MSP and key providers - confirm incident escalation routes, recovery responsibilities, and access controls in writing. You do not need to buy new frameworks or certifications. Focus on ownership, visibility, and evidence of resilience.

Does outsourcing IT to an MSP transfer my cyber risk?

No. Outsourcing IT changes how you deliver technology services, not whether the business owns its operational risk. Under NIS-style regimes, responsibility for resilience outcomes stays with the organisation delivering the regulated service, even when suppliers are involved. The Bill may also regulate certain MSPs directly, but that does not remove the customer's governance obligations.

How is the Cyber Security and Resilience Bill different from Cyber Essentials or ISO 27001?

Cyber Essentials and ISO 27001 are voluntary certifications. The Cyber Security and Resilience Bill is primary legislation that creates statutory duties for organisations in scope of the NIS framework. The legal duty is framed as "appropriate and proportionate" risk management - it does not mandate any specific certification or framework. Certifications can support compliance but are not substitutes for demonstrable resilience.

What incident reporting changes does the Bill introduce?

For regulated entities, the Bill introduces a two-stage reporting structure: an initial notification within 24 hours of becoming aware that a significant incident has occurred, followed by a fuller report within 72 hours. Even if your organisation is not directly regulated, your customers may push faster notification requirements down contractually to meet their own duties.

How some SMEs and MSPs make this easier (without compliance theatre)

If you rely heavily on a third-party IT provider, the practical challenge is rarely understanding what "good" looks like. It's proving it consistently, with current evidence, without scrambling every time a customer, insurer, or auditor asks.

Some organisations handle this with internal governance and regular assurance reviews. Others use independent, evidence-led assessment and continuous verification to keep proof current.

Assurix is one example of that approach. It independently verifies an MSP's cyber resilience (aligned to the NCSC Cyber Assessment Framework) and operational maturity using time-stamped evidence, with ongoing checks rather than point-in-time paperwork. If controls lapse and are not fixed, the trustmark is suspended. This is designed to reduce ambiguity, not to guarantee outcomes.

Book a 30 min intro call

Related reading