Cyber Security Bill: What UK MSPs Need to Know
The Cyber Security and Resilience Bill will change how UK MSPs operate. Here's what you need to know about compliance, CAF, and proving your security posture.
Wondering whether the new Cyber Security and Resilience Bill will really affect your MSP, or if it is just more red tape aimed at the big players?
This article breaks down what the Bill actually does, where it is in the process, how government will decide which MSPs are in scope, and what you can do this quarter to get ahead of it, in plain English for MSP owners and leadership teams, written from an MSP operator's perspective rather than a lawyer's.
Last updated: 26 June 2026, following the Bill's Report Stage and Third Reading in the House of Commons (10-16 June 2026) and passage to the House of Lords (17 June 2026).
This is general guidance for MSPs, not legal advice.
Bill status (as of 26 June 2026)
- Introduced: 12 November 2025
- Second Reading (Commons): 6 January 2026
- Committee Stage (Commons): 3-24 February 2026
- Report Stage and Third Reading (Commons): 10-16 June 2026
- Passed to House of Lords: 17 June 2026
- Current stage: House of Lords - Second Reading scheduled 14 July 2026
- Royal Assent expected: late 2026
- Full implementation expected: late 2027 (phased)
Source: bills.parliament.uk/bills/4035
1. What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience (Network and Information Systems) Bill is the UK government's refresh of the existing NIS Regulations 2018. Its purpose is to strengthen the cyber security and resilience of:
- operators of essential services
- relevant digital service providers
- some data centres and managed service providers
- critical suppliers in their supply chains
For MSPs, three things really matter.
A new regulated class: Relevant Managed Service Providers (RMSPs)
Medium and large MSPs may be in scope as "Relevant Managed Service Providers" (RMSPs). Under the government's definition, managed services means the ongoing management of a customer's IT systems under contract, delivered by connecting to or accessing their network and information systems.
Small and micro enterprises are generally excluded from the RMSP measure, but can still be designated as a critical supplier if their services are essential to a regulated entity.
Source: RMSP Factsheet
Direct duties for RMSPs
RMSPs are brought under a NIS-style regime. They are expected to:
- take appropriate and proportionate technical and organisational measures to manage cyber and resilience risk
- report certain significant cyber incidents within defined timeframes
- cooperate with investigations and, if necessary, face enforcement action
Powers to regulate critical suppliers
Regulators gain the power to designate specific suppliers as "critical" where failure or compromise of that supplier could seriously disrupt essential or digital services. That can include smaller MSPs, not just the largest players.
The Direction of Travel
When you provide managed services into critical sectors, you are treated as part of national infrastructure, not just "outsourced IT".
2. Where is the Bill now, and has it been passed?
- Introduced to House of Commons (12 Nov 2025)
- Completed First Reading (formal stage without debate)
- Second Reading passed (6 Jan 2026)
- Committee Stage completed (3-24 Feb 2026)
- Report Stage and Third Reading passed (10-16 Jun 2026)
- Passed to House of Lords (17 Jun 2026)
- Currently: House of Lords - Second Reading (14 Jul 2026)
- Future: Lords Committee, Report Stage, Third Reading
- Future: Royal Assent (expected late 2026)
- Future: Phased implementation (expected late 2027)
Not Law Yet - But Closer Than It Was
The Bill has cleared all Commons stages and is now in the House of Lords. The core provisions are settled - the Lords can refine but are unlikely to change the fundamental direction. Royal Assent is expected late 2026, with phased implementation running to late 2027.
2a. What RMSPs will be required to do
If you are classed as an RMSP, expect requirements in four practical areas:
Registration
- RMSPs must register with the Information Commission
- Once the RMSP provisions commence, there is a 3 month window to register
- Overseas RMSPs must appoint a UK representative
Security duties
- RMSPs must implement appropriate and proportionate measures to manage risk and minimise impact
- Technical detail is expected to be set out via secondary legislation
Incident reporting and customer notification
- 24 hours: initial notification (light touch)
- 72 hours: fuller report
- NCSC is informed at the same time as the regulator
- RMSPs must also notify customers likely to be affected
- Ransomware reporting is now compulsory. The Bill introduces mandatory ransomware reporting so authorities can build a fuller picture of the threat landscape and expand the categories of incident that regulated entities must disclose
Concentration risk duty
An amendment added at Report Stage introduces a new duty: RMSPs must not serve so many customers that an incident affecting their services would be likely to cause significant national disruption. In practice this means an RMSP cannot quietly become the IT backbone for an entire sector or subsector. If you are growing aggressively into NHS, utilities, or finance, this duty will be relevant to your growth planning.
Enforcement, fines, and fees
- Stronger enforcement model and higher maximum penalties
- Up to £10 million or 2% of worldwide turnover (whichever is higher) for standard breaches
- Up to £17 million or 10% of worldwide turnover (whichever is higher) for failure to comply with national security directions
- Up to £100,000 per day for continuing contraventions
- Regulators can recover the full costs of their NIS functions via charges and fees
Sources:
What does "secondary legislation and guidance" mean?
The Bill sets the main powers and structure. After it becomes law, ministers can use those powers to make "secondary legislation" (detailed regulations) and publish guidance. That is where the fine detail will live, for example:
- the precise definition of which incidents must be reported and in what format
- detailed security and resilience expectations for RMSPs
- how "critical suppliers" will be identified and designated in practice
3. How government classifies MSP size
To understand whether your MSP is likely to be an RMSP, you need to translate government's size language into something practical.
The government's MSP market study and NIS guidance use standard SME bands:
- Micro: fewer than 10 staff and annual turnover up to about €2 million
- Small: fewer than 50 staff and annual turnover up to about €10 million
- Medium: fewer than 250 staff and annual turnover up to about €50 million
- Large: at or above those thresholds
Under the Bill, RMSPs are specifically managed service providers that are not small or micro enterprises - in other words, broadly the medium and large MSPs that meet the managed-services definition.
Quick Self-Assessment
If you are around 50 or more staff and heading into eight-figure revenue: You should assume you are a candidate RMSP.
If you are smaller than that but deeply embedded in critical or regulated customers: You should assume you are still part of the regulated picture via the supply chain.
Being "small" by this definition doesn't mean "off the hook"; it just changes how the obligations reach you.
4. Why this matters for every MSP, not just the big ones
Only a minority of MSPs will be RMSPs at the start, but the Bill will change expectations across the entire channel. Three reasons.
Your clients will push obligations down
Operators of essential services and relevant digital services are already regulated under NIS. Government has been explicit that weaknesses in MSPs and data centres are a major concern. As those entities respond to the Bill, they will:
- ask more detailed questions about your security and resilience
- insert tougher clauses into contracts and frameworks
- expect you to provide independent proof, not just self-attestation
If you serve NHS bodies, utilities, transport, financial services, or large cloud and digital platforms, this will land on your desk sooner rather than later.
You can be designated as a critical supplier
Even if you are small on paper, regulators will be able to designate you as a critical supplier if your services are essential to a regulated entity's ability to operate. A 20 person MSP that effectively runs the IT and security stack for a hospital, water company or major SaaS provider is a prime example.
The wider direction of travel
Outside the Bill, NCSC's Cyber Assessment Framework (CAF) has become the benchmark for what good looks like for critical functions. CAF 4.0 tightens that further and is being referenced more in policy and guidance. The whole ecosystem is moving towards outcome based, evidence backed assurance, not just checklists.
Even if you never receive a formal notice from a regulator, your customers, prospects and insurers will increasingly benchmark you against these expectations and your clients expect you to keep up.
5. It is not just "be CAF compliant"
CAF sits at the heart of the UK's approach. It defines outcomes for:
- managing security risk
- protecting against cyber attack
- detecting cyber security events
- minimising the impact of incidents
The Bill builds on that, but it clearly goes beyond "map yourself to CAF once and tick a box".
Under the new regime:
- regulated entities, including RMSPs, must put in place appropriate and proportionate measures to manage risks to the systems they rely on to deliver their services
- they must notify regulators quickly when a significant incident happens (initially, in a matter of hours, not weeks), and follow up with fuller reporting
- regulators have stronger powers to gather information, require improvements and, in serious cases, impose penalties
The Practical Test for MSPs
Can you show, with evidence, that you are managing risk, protecting systems, detecting and responding to incidents, and learning from them - over time, not just on audit day?
A CAF spreadsheet, ISO 27001 certificate or Cyber Essentials badge is helpful, but only if it sits on top of a living system of controls and oversight.
6. Common MSP myths about the Bill
Myth: This is only for big MSPs
Reality: The direct RMSP rules are aimed at medium and large MSPs, but regulators can still designate smaller MSPs as critical suppliers, and regulated customers will expect higher standards from every MSP in their chain.
Myth: We'll deal with it when it's actually law
Reality: The Bill is already in Parliament with detailed policy analysis. Building governance, processes and evidence takes months or years, not days. Waiting means reacting when customers and regulators are already asking hard questions.
Myth: We have ISO 27001 or Cyber Essentials, so we're covered
Reality: Those frameworks remain valuable and recognised. But they are usually assessed at a point in time. Without ongoing monitoring and evidence, they easily become one and done badges. CAF and the Bill both push towards continuous resilience, not a logo you renew once a year and then forget about.
Myth: It is just another audit
Reality: The regime is built around ongoing duties, earlier incident reporting, stronger investigative powers and proportionate enforcement. Regulators will look for patterns in how you operate, not just whether you passed a single assessment.
7. What should MSPs actually do now?
You do not need a policy department. You do need a practical plan. Here are sensible first moves for any UK MSP.
Do a quick CAF flavoured health check
Use CAF's four high level objectives as headings and list your strengths and gaps under each. Focus on gaps that would really hurt if a key client suffered a serious incident and your name was in the mix.
Map your client base to criticality
Identify which clients are in essential services, highly regulated sectors, or key digital platforms. Those relationships will feel the new expectations and due diligence first.
Tighten incident response and communication
Create or sharpen an incident response plan that answers: who leads, who makes decisions, who communicates, how you classify incidents and decide what is "significant", and how quickly and clearly you tell clients what is happening. Design it so that, if you ever need to align to 24-hour / 72-hour reporting expectations, you are not starting from scratch.
Build a real evidence trail
Start collecting and keeping the kind of evidence any serious assessment will expect to see: security and service policies, records of access reviews and change approvals, monitoring logs, and notes from regular security reviews and post-incident reviews. You are not aiming for perfection, you are aiming to show you do what you say and improve over time.
Sanity check your contracts and DDQs
Look at the security and resilience promises you make in contracts and due diligence questionnaires. Make sure those claims are realistic and that you could evidence them under pressure. Better to tighten wording now than discover a gap in the middle of an incident.
8. Turning regulation into visible proof for clients and insurers
The Bill, CAF 4.0 and the broader policy direction are all pushing MSPs towards one idea: proof, not promises. That creates a risk, but also a chance to stand out from the noise.
Assurix exists to help MSPs turn that shift into an advantage rather than just more overhead.
Assurix: A live, evidence-based trustmark
Assurix is designed to align with CAF outcomes and the direction of the Cyber Security and Resilience Bill. It looks at both security controls and operational maturity, how you actually run patching, backup, monitoring, incident response and governance day to day. It stays up to date by drawing on live evidence from the tools and systems you already use.
For an MSP, having Assurix accreditation can deliver several concrete benefits.
Win more deals against less mature competitors
Good MSPs often sound the same as mediocre ones on paper. A live Assurix trustmark independently proves you do what others only claim, from patch compliance and backup success to communication and strategy. This helps you shorten sales cycles, win on proof not slideware, and protect your margins.
Run a more secure, predictable MSP
Assurix tracks your performance against CAF aligned and operational maturity criteria, encouraging better habits, clear ownership of controls, and fewer unmanaged exceptions. That creates a predictable rhythm of checks, fixes and reviews and reduces nasty surprises for leadership.
Unlock better insurance terms
Insurers and risk committees are tired of self certified questionnaires. A trusted, structured view of your security and operational maturity gives you a stronger hand when discussing cover, terms and pricing. Participating insurers are offering discounts of up to 25 percent for Assurix verified MSPs.
Build a more valuable business
Demonstrable operational maturity, proven security controls, and continuous evidence based assurance make your MSP easier to grow and eventually sell. Buyers and investors value transparent processes, predictable operations, and verified compliance that does not depend on heroics or tribal knowledge.
At Assurix our mission is to help MSPs turn the shift from "promises" to "proof" into a real advantage, not just another compliance burden.
9. What is known vs what is still to be confirmed
Known now
- RMSPs are being brought into scope of the NIS regime
- The regulator for RMSPs is the Information Commission
- Incident reporting shifts to 24 hour initial, 72 hour full reporting, and customer notification expectations
- Ransomware reporting is compulsory for regulated entities
- Maximum penalties: up to £10 million or 2% of worldwide turnover for standard breaches; up to £17 million or 10% for failure to comply with national security directions; up to £100,000 per day for continuing contraventions
- RMSPs have a concentration risk duty - they must not serve so many customers in a single sector that their failure would cause significant national disruption
- Royal Assent is expected late 2026, with phased implementation running to late 2027
Still to be confirmed via secondary legislation and consultation
- Detailed technical requirements and thresholds for what counts as a significant incident
- The full detail of reporting thresholds and templates
- Fee levels and charging schemes per regulator
10. A low-friction next step
You do not need to wait for every regulation and guidance note to be finalised before you act.
If you want to understand how this Bill intersects with your services and your client base, a straightforward next step is a short discovery call with Assurix.
On that call you can:
- clarify whether you are likely to be an RMSP, a potential critical supplier, or mainly impacted through your customers
- get an initial view of how you line up against CAF style expectations and operational maturity
- explore whether continuous, evidence based assurance via Assurix could help you stay ahead of client, insurer and regulatory expectations