Cyber Security and Resilience Bill: What It Is, What It Requires, and Why IT Providers Need to Be Ready
Our director, Jack Calloway, spent last month at the CBN CyberSummit in London, sat among policymakers, CISOs, and MSP leaders from across the UK’s critical sectors. One topic came up in nearly every session on the agenda: the Cyber Security and Resilience Bill, and what it’s about to mean for the businesses that keep the UK’s economy running, including the IT providers behind them.
This isn’t a niche piece of legislation for large infrastructure operators to worry about. For the first time, it reaches directly into the IT supply chain, and that includes managed service providers like us, and by extension, every SME that depends on one. Here’s a full breakdown of what the Bill is, what it requires, and why we believe IT providers should already be getting ready.
What Is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to Parliament on 12th November 2025. It’s the most significant update to UK cyber security law in almost a decade, and it works by amending the existing Network and Information Systems (NIS) Regulations 2018.
The 2018 NIS Regulations were designed to protect the UK’s essential services, energy, transport, water, and healthcare, from cyber threats. They were a reasonable starting point at the time, but the threat landscape has changed dramatically since then. State-sponsored actors, ransomware gangs, and increasingly sophisticated criminal groups have shown that attacking a supplier to a critical service can be just as damaging as attacking the service itself.
The 2025 attack on Jaguar Land Rover is the clearest recent example. The financial damage is estimated at between £1.6 billion and £2.1 billion, a cost shared between JLR directly and its wider supply chain. Incidents like this, alongside government research estimating that cyber attacks cost the UK economy close to £15 billion a year, are exactly why this Bill exists.
The government’s goal is straightforward: close the gaps that let attackers exploit weaker links in the supply chain, and make sure the organisations responsible for essential services, and the suppliers behind them, are held to a consistent, enforceable security standard.
Who Does the Bill Apply To?
This is where the Bill expands well beyond its 2018 predecessor. It broadens the scope of regulated organisations to include:
- Operators of Essential Services — energy, transport, drinking water, and healthcare providers, as before
- Managed Service Providers (MSPs) — brought into scope for the first time as “Relevant Managed Service Providers” (RMSPs), under Section 9 of the Bill
- Data centres — designated as essential services, with thresholds of 1 megawatt of Rated IT Load for colocation facilities and 10 megawatts for enterprise operations
- Large load controllers — providers managing electrical demand through technologies like smart appliances and battery storage, where load exceeds 300 megawatts
- Critical suppliers — regulators are being given new powers to designate any supplier as “critical” if their disruption could cause significant harm to an essential service, regardless of the supplier’s own size
That last point matters enormously for SMEs. A small, specialist supplier to the NHS or a water company, for example, could be designated a critical supplier and be held to the same security standards as a major operator, even if it has fewer than ten employees.
Estimates suggest between 900 and 1,100 MSPs across the UK will come under direct regulatory oversight once the Bill is fully in force.
What Does the Bill Actually Require?
Once an organisation is in scope, whether as an operator of essential services, an RMSP, or a designated critical supplier, the Bill introduces several concrete obligations:
1. Faster, more structured incident reporting
Regulated organisations must notify their regulator and the National Cyber Security Centre (NCSC) within 24 hours of becoming aware of a significant cyber incident. A full report must follow within 72 hours. This replaces the slower, less consistent reporting timelines that existed under the 2018 regulations.
The Bill also introduces “near miss” reporting — incidents that could have caused significant disruption but didn’t, giving regulators and the NCSC far better visibility into emerging threats before they cause real damage.
2. Proactive supply chain risk management
Regulated organisations, and this includes MSPs, must actively manage cyber risk across their own suppliers. In practice, this means understanding who your critical suppliers are, assessing their security posture, and putting “appropriate and proportionate measures” in place, which could include contractual security requirements, regular security checks, and tested business continuity plans.
3. Technical standards aligned to the NCSC Cyber Assessment Framework (CAF)
Rather than a vague requirement to “be secure,” organisations are expected to demonstrate risk management practices aligned with the NCSC’s established CAF framework, covering areas like access control, monitoring, and incident response.
4. Restrictions on RMSP customer concentration
A notable amendment under discussion would place a duty on RMSPs to avoid managing the technology systems for so many customers that an incident affecting the RMSP could cause disruption at a national scale. In effect, this is designed to prevent a single MSP outage from taking down an entire sector.
5. Stronger regulator powers
Regulators (including the ICO and Ofcom, depending on sector) are being given significantly enhanced powers, including the ability to inspect, audit, gather information, and enforce compliance, with the ability to recover the full cost of their enforcement activity from the organisations involved.
What Happens If You Don’t Comply?
The Bill introduces a two-tier fine structure that is considerably tougher than anything under the 2018 regime:
- Serious breaches can result in fines of up to £17 million or 4% of global annual turnover, whichever is higher
- Ongoing non-compliance can attract daily penalties of up to £100,000 until the issue is resolved
- Regulators can also recover the full cost of their enforcement action from the organisation in breach
For most SMEs, these fines won’t apply directly, since the Bill’s core financial penalties target regulated organisations rather than every business in a supply chain. But that doesn’t mean SMEs are unaffected. Losing a contract because your business, or your IT provider, can’t satisfy a client’s supply chain security requirements carries a very real financial cost of its own, even without a fine attached to it.
Where Is the Bill Right Now?
As of mid-2026, the Bill has cleared all its House of Commons stages and moved to the House of Lords (now HL Bill 32), where it’s progressing towards Royal Assent, expected later in 2026. Implementation will then be phased through 2026, 2027, and potentially into 2028 for some of the more complex secondary legislation, though the 24-hour incident reporting requirement is expected to be among the first measures to take effect.
The direction of travel, though, is already clear, and waiting for Royal Assent before acting isn’t a strategy we’d recommend to any business, least of all an IT provider.
Why This Matters Specifically for IT Providers
For managed service providers, this Bill isn’t a footnote. It’s a direct extension of regulatory duty into our sector for the first time, and we think that’s overdue.
Here’s why we believe every IT provider, not just Disking IT, should be treating this seriously right now, rather than waiting for the legislation to force their hand:
Clients are already asking the question. Even before Royal Assent, we’re seeing more clients, and prospective clients, ask directly how we handle incident response, certification, and supply chain risk. Regulated organisations are already tightening their own supplier requirements in anticipation of the Bill, and that pressure flows straight down to the IT providers supporting them.
Reactive compliance is expensive compliance. Building incident response processes, supplier risk assessments, and reporting workflows properly takes time. Providers who wait until the Bill is fully in force will be doing this under regulatory pressure and tight deadlines. Providers who start now get to do it properly.
Trust is the actual product. An MSP’s core offering isn’t really the hardware, the helpdesk, or the licensing, it’s the trust that a client’s systems and data are being looked after by people who take security seriously. A provider that can point to independently verified certification and a mature incident response process has a genuinely stronger claim to that trust than one relying on assurances alone.
Supply chain attacks are the growth area for criminals. Supply chain compromise has become one of the fastest-growing attack vectors precisely because it’s often the easiest way in. An IT provider with weak security isn’t just a risk to itself, it’s a risk to every client connected to it.
How Disking IT Is Already Preparing
We didn’t wait for the Bill to reach Royal Assent to start acting on this. A few things we’d point to directly:
- Cyber Essentials Plus certification, independently verified rather than self-assessed, held well ahead of this legislation putting supply chain security on every boardroom agenda
- 100% independent ownership, with no private equity backing, meaning our security investment decisions are driven by what our clients need, not by a portfolio-wide cost target or an exit timeline
- 39 years in business since 1987, which has meant building genuine continuity and resilience into how we operate, rather than reacting to whatever the latest headline demands
- Transparent, published pricing across our three service tiers, so when a client needs to demonstrate supply chain assurance to their own regulator or customer, there’s no ambiguity about what they’re getting from us
We’re also actively reviewing our internal incident reporting processes against the Bill’s proposed 24-hour notification window, ahead of it becoming a legal requirement, not after.
What SMEs Should Do Now
You don’t need to wait for Royal Assent to start preparing, and if you rely on an external IT provider, this affects you more directly than you might think:
- Ask your IT provider how they’re preparing for the Bill, and whether they expect to be classed as a Relevant Managed Service Provider
- Check whether your provider holds independently verified certification such as Cyber Essentials or Cyber Essentials Plus
- Map any contracts where a larger client, particularly one in healthcare, energy, water, or transport, might soon require evidence of supply chain security
- Make sure the fundamentals are already in place: multi-factor authentication, tested backups, and a documented incident response plan
- If you supply goods or services into a regulated sector, start thinking now about how you’d respond to a security assurance request from that client
Disking IT supports SMEs across Surrey, Hampshire, and West Sussex with managed IT, Cyber Essentials Plus certification, and proactive compliance readiness ahead of the Cyber Security and Resilience Bill. If you’d like to talk through how this legislation affects your business, get in touch with our team today.
👉 More on our certification: Cyber Essentials Certification – Disking IT
👉 Want a free audit? Free Cyber Security Audit | Disking IT
👉 Read next: What Happens After a Cyber Attack? – Disking IT



