Cyber Security Bill: What UK MSPs Need to Know

The Cyber Security and Resilience Bill will change how UK MSPs operate. Here's what you need to know about compliance, CAF, and proving your security posture.

Wondering whether the new Cyber Security and Resilience Bill will really affect your MSP, or if it is just more red tape aimed at the big players?

This article breaks down what the Bill actually does, where it is in the process, how government will decide which MSPs are in scope, and what you can do this quarter to get ahead of it, in plain English for MSP owners and leadership teams, written from an MSP operator's perspective rather than a lawyer's.

Last updated: 26 June 2026, following the Bill's Report Stage and Third Reading in the House of Commons (10-16 June 2026) and passage to the House of Lords (17 June 2026).

This is general guidance for MSPs, not legal advice.

Bill status (as of 26 June 2026)

Source: bills.parliament.uk/bills/4035

1. What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience (Network and Information Systems) Bill is the UK government's refresh of the existing NIS Regulations 2018. Its purpose is to strengthen the cyber security and resilience of:

For MSPs, three things really matter.

A new regulated class: Relevant Managed Service Providers (RMSPs)

Medium and large MSPs may be in scope as "Relevant Managed Service Providers" (RMSPs). Under the government's definition, managed services means the ongoing management of a customer's IT systems under contract, delivered by connecting to or accessing their network and information systems.

Small and micro enterprises are generally excluded from the RMSP measure, but can still be designated as a critical supplier if their services are essential to a regulated entity.

Source: RMSP Factsheet

Direct duties for RMSPs

RMSPs are brought under a NIS-style regime. They are expected to:

Powers to regulate critical suppliers

Regulators gain the power to designate specific suppliers as "critical" where failure or compromise of that supplier could seriously disrupt essential or digital services. That can include smaller MSPs, not just the largest players.

The Direction of Travel

When you provide managed services into critical sectors, you are treated as part of national infrastructure, not just "outsourced IT".

2. Where is the Bill now, and has it been passed?

Not Law Yet - But Closer Than It Was

The Bill has cleared all Commons stages and is now in the House of Lords. The core provisions are settled - the Lords can refine but are unlikely to change the fundamental direction. Royal Assent is expected late 2026, with phased implementation running to late 2027.

2a. What RMSPs will be required to do

If you are classed as an RMSP, expect requirements in four practical areas:

Registration

Security duties

Incident reporting and customer notification

Concentration risk duty

An amendment added at Report Stage introduces a new duty: RMSPs must not serve so many customers that an incident affecting their services would be likely to cause significant national disruption. In practice this means an RMSP cannot quietly become the IT backbone for an entire sector or subsector. If you are growing aggressively into NHS, utilities, or finance, this duty will be relevant to your growth planning.

Enforcement, fines, and fees

Sources:

What does "secondary legislation and guidance" mean?

The Bill sets the main powers and structure. After it becomes law, ministers can use those powers to make "secondary legislation" (detailed regulations) and publish guidance. That is where the fine detail will live, for example:

3. How government classifies MSP size

To understand whether your MSP is likely to be an RMSP, you need to translate government's size language into something practical.

The government's MSP market study and NIS guidance use standard SME bands:

Under the Bill, RMSPs are specifically managed service providers that are not small or micro enterprises - in other words, broadly the medium and large MSPs that meet the managed-services definition.

<10Micro: Staff count
<50Small: Staff count
<250Medium: Staff count
50+Likely RMSP

Quick Self-Assessment

If you are around 50 or more staff and heading into eight-figure revenue: You should assume you are a candidate RMSP.

If you are smaller than that but deeply embedded in critical or regulated customers: You should assume you are still part of the regulated picture via the supply chain.

Being "small" by this definition doesn't mean "off the hook"; it just changes how the obligations reach you.

4. Why this matters for every MSP, not just the big ones

Only a minority of MSPs will be RMSPs at the start, but the Bill will change expectations across the entire channel. Three reasons.

Your clients will push obligations down

Operators of essential services and relevant digital services are already regulated under NIS. Government has been explicit that weaknesses in MSPs and data centres are a major concern. As those entities respond to the Bill, they will:

If you serve NHS bodies, utilities, transport, financial services, or large cloud and digital platforms, this will land on your desk sooner rather than later.

You can be designated as a critical supplier

Even if you are small on paper, regulators will be able to designate you as a critical supplier if your services are essential to a regulated entity's ability to operate. A 20 person MSP that effectively runs the IT and security stack for a hospital, water company or major SaaS provider is a prime example.

The wider direction of travel

Outside the Bill, NCSC's Cyber Assessment Framework (CAF) has become the benchmark for what good looks like for critical functions. CAF 4.0 tightens that further and is being referenced more in policy and guidance. The whole ecosystem is moving towards outcome based, evidence backed assurance, not just checklists.

Even if you never receive a formal notice from a regulator, your customers, prospects and insurers will increasingly benchmark you against these expectations and your clients expect you to keep up.

5. It is not just "be CAF compliant"

CAF sits at the heart of the UK's approach. It defines outcomes for:

The Bill builds on that, but it clearly goes beyond "map yourself to CAF once and tick a box".

Under the new regime:

The Practical Test for MSPs

Can you show, with evidence, that you are managing risk, protecting systems, detecting and responding to incidents, and learning from them - over time, not just on audit day?

A CAF spreadsheet, ISO 27001 certificate or Cyber Essentials badge is helpful, but only if it sits on top of a living system of controls and oversight.

6. Common MSP myths about the Bill

Myth: This is only for big MSPs

Reality: The direct RMSP rules are aimed at medium and large MSPs, but regulators can still designate smaller MSPs as critical suppliers, and regulated customers will expect higher standards from every MSP in their chain.

Myth: We'll deal with it when it's actually law

Reality: The Bill is already in Parliament with detailed policy analysis. Building governance, processes and evidence takes months or years, not days. Waiting means reacting when customers and regulators are already asking hard questions.

Myth: We have ISO 27001 or Cyber Essentials, so we're covered

Reality: Those frameworks remain valuable and recognised. But they are usually assessed at a point in time. Without ongoing monitoring and evidence, they easily become one and done badges. CAF and the Bill both push towards continuous resilience, not a logo you renew once a year and then forget about.

Myth: It is just another audit

Reality: The regime is built around ongoing duties, earlier incident reporting, stronger investigative powers and proportionate enforcement. Regulators will look for patterns in how you operate, not just whether you passed a single assessment.

7. What should MSPs actually do now?

You do not need a policy department. You do need a practical plan. Here are sensible first moves for any UK MSP.

Do a quick CAF flavoured health check

Use CAF's four high level objectives as headings and list your strengths and gaps under each. Focus on gaps that would really hurt if a key client suffered a serious incident and your name was in the mix.

Map your client base to criticality

Identify which clients are in essential services, highly regulated sectors, or key digital platforms. Those relationships will feel the new expectations and due diligence first.

Tighten incident response and communication

Create or sharpen an incident response plan that answers: who leads, who makes decisions, who communicates, how you classify incidents and decide what is "significant", and how quickly and clearly you tell clients what is happening. Design it so that, if you ever need to align to 24-hour / 72-hour reporting expectations, you are not starting from scratch.

Build a real evidence trail

Start collecting and keeping the kind of evidence any serious assessment will expect to see: security and service policies, records of access reviews and change approvals, monitoring logs, and notes from regular security reviews and post-incident reviews. You are not aiming for perfection, you are aiming to show you do what you say and improve over time.

Sanity check your contracts and DDQs

Look at the security and resilience promises you make in contracts and due diligence questionnaires. Make sure those claims are realistic and that you could evidence them under pressure. Better to tighten wording now than discover a gap in the middle of an incident.

8. Turning regulation into visible proof for clients and insurers

The Bill, CAF 4.0 and the broader policy direction are all pushing MSPs towards one idea: proof, not promises. That creates a risk, but also a chance to stand out from the noise.

Assurix exists to help MSPs turn that shift into an advantage rather than just more overhead.

Assurix: A live, evidence-based trustmark

Assurix is designed to align with CAF outcomes and the direction of the Cyber Security and Resilience Bill. It looks at both security controls and operational maturity, how you actually run patching, backup, monitoring, incident response and governance day to day. It stays up to date by drawing on live evidence from the tools and systems you already use.

For an MSP, having Assurix accreditation can deliver several concrete benefits.

Win more deals against less mature competitors

Good MSPs often sound the same as mediocre ones on paper. A live Assurix trustmark independently proves you do what others only claim, from patch compliance and backup success to communication and strategy. This helps you shorten sales cycles, win on proof not slideware, and protect your margins.

Run a more secure, predictable MSP

Assurix tracks your performance against CAF aligned and operational maturity criteria, encouraging better habits, clear ownership of controls, and fewer unmanaged exceptions. That creates a predictable rhythm of checks, fixes and reviews and reduces nasty surprises for leadership.

Unlock better insurance terms

Insurers and risk committees are tired of self certified questionnaires. A trusted, structured view of your security and operational maturity gives you a stronger hand when discussing cover, terms and pricing. Participating insurers are offering discounts of up to 25 percent for Assurix verified MSPs.

Build a more valuable business

Demonstrable operational maturity, proven security controls, and continuous evidence based assurance make your MSP easier to grow and eventually sell. Buyers and investors value transparent processes, predictable operations, and verified compliance that does not depend on heroics or tribal knowledge.

At Assurix our mission is to help MSPs turn the shift from "promises" to "proof" into a real advantage, not just another compliance burden.

9. What is known vs what is still to be confirmed

Known now

Still to be confirmed via secondary legislation and consultation

10. A low-friction next step

You do not need to wait for every regulation and guidance note to be finalised before you act.

If you want to understand how this Bill intersects with your services and your client base, a straightforward next step is a short discovery call with Assurix.

On that call you can:

Book a 30 min intro call

Related reading