124 City Rd, London EC1V 2NX Caxton Point, Stevenage SG1 2XT
Book a consultation Call 020 4634 2518
Cyber Security 27 July 2026 9 min read

The Cyber Security and Resilience Bill: what it means for your business

The biggest change to UK cyber regulation since 2018 is moving through Parliament, and for the first time it reaches managed IT providers and data centres. Here is what is actually changing, who it covers, and the sensible things to do now.

5.0 Google reviews Microsoft Cloud Solution Provider Cyber Essentials Certified 9-minute average response

If you run a business in the UK, the rules on cyber security are about to get firmer. The Cyber Security and Resilience Bill has cleared the House of Commons and is now being scrutinised in the House of Lords, and it represents the most significant overhaul of UK cyber regulation since the current rules came in back in 2018.

Most of the coverage so far has focused on critical national infrastructure. That undersells it. The Bill deliberately widens the net to include the technology supply chain that ordinary businesses depend on every day, and that includes managed IT providers, data centres and suppliers judged critical to essential services. Even if your own organisation never becomes directly regulated, the way your suppliers work, and what they owe you when something goes wrong, is set to change.

What the Bill actually does

The Bill updates and strengthens the Network and Information Systems (NIS) Regulations 2018. Those original rules were written for a narrower world, largely energy, transport, health, water and digital infrastructure, and they have not kept pace with how businesses now buy and run technology. The government has grouped the reform into three broad aims:

  • Expanded scope. Bringing new categories of organisation into the regime, most notably managed service providers and data centres.
  • Stronger regulators. Giving the twelve sector regulators better enforcement powers and a more consistent approach, including cost recovery so oversight is properly funded.
  • Faster adaptation. Allowing government to update requirements as threats evolve, rather than waiting years for new primary legislation.

Underlying all of it is a simple observation: attackers increasingly get in through suppliers rather than through the front door. Regulating only the biggest organisations leaves the route in wide open.

Where the Bill stands right now

The timeline matters, because it tells you how much runway you have:

  • 12 November 2025. The Bill is introduced to Parliament.
  • 6 January 2026. Second reading in the Commons.
  • 25 June 2026. The Bill completes all of its Commons stages and moves to the House of Lords.
  • Later in 2026. Royal Assent is expected, subject to the Lords stages.

Crucially, Royal Assent is not the moment everything switches on. A lot of the detail, including the duties that will apply to managed service providers, incident reporting and cost recovery, comes through secondary legislation after government consultation. In practice that means the obligations phase in over a period rather than landing overnight. The direction of travel, though, is already clear enough to plan around.

Who comes into scope

The existing sectors stay in: energy, transport, health, drinking water, digital infrastructure and certain digital services. The Bill then adds several new categories:

  • Managed service providers, medium and large. Regulated by the Information Commissioner's Office. This captures providers who manage customers' IT systems and have privileged access into those systems, which is precisely why they are seen as a risk worth regulating.
  • Data centres, medium and large. Treated as an essential service and regulated by Ofcom.
  • Designated critical suppliers. Regulators gain the power to designate a specific supplier as critical to an essential or digital service, which brings that supplier into the regime regardless of its sector.
  • Large load controllers. Organisations managing electrical load for smart appliances, overseen by the energy regulators.

The "medium and large" qualifier is worth reading carefully. Most small organisations will not be directly regulated. That is not the same as being unaffected.

Why it still matters if you are not directly regulated

This is the part that catches people out. There are three routes by which the Bill reaches businesses that are not themselves in scope.

First, the critical supplier designation. If you provide something a regulated organisation genuinely depends on, a regulator can bring you into the regime, and you will be expected to meet the same standards of security and reporting.

Second, the contract route, which is likely to be the most common. Regulated organisations have to manage their supply chain risk, and the practical way they do that is by pushing requirements down through contracts and procurement questionnaires. Expect more due diligence questions, more evidence requests and more security clauses, whether or not the law applies to you directly. Businesses that can answer those questions cleanly will win work more easily than those that cannot.

Third, the transparency route. Data centres and digital and managed service providers will be required to notify customers who are likely to be affected by a significant incident. If you buy managed IT, that is a genuine improvement: you should find out sooner when something upstream has gone wrong.

The new incident reporting clock

One of the most concrete changes is what has to be reported, and how quickly. The Bill widens the range of incidents that must be reported, covering breaches with the potential for significant impact rather than only those that have already disrupted a service. Reporting then follows a two-stage timetable:

  • Within 24 hours. An initial notification to your regulator.
  • Within 72 hours. A fuller report with more detail.

Twenty-four hours is not long. It is comfortably achievable if you already know who declares an incident, who contacts the regulator, and where your logs and evidence live. It is close to impossible if you are working that out for the first time while systems are down and the phone is ringing. In our experience this is the single most common gap, and it is a process problem far more than a technology one.

Penalties

The Bill simplifies the penalty bands and raises the maximum financial penalties so they sit more in line with data protection and product security legislation. Reported figures put the top of the range at up to seventeen million pounds or four per cent of global turnover, though the precise levels depend on the final legislation and the supporting regulations.

For most organisations the fine is not really the point. The bigger risks are operational: the downtime itself, the cost of responding, contractual exposure to your own customers, and the reputational damage of handling an incident badly in public.

A practical readiness checklist

You do not need to wait for the final regulations to make progress. Almost everything worth doing is good practice anyway, and much of it maps onto Cyber Essentials, which remains a sensible baseline.

  • Establish whether you are in scope. Check your sector, your size and whether you could plausibly be designated a critical supplier to a regulated customer.
  • Build an accurate inventory. You cannot protect or report on systems you do not know you have. That includes cloud services and anything shadow IT has quietly introduced.
  • Write the first 24 hours down. Who declares an incident, who contacts the regulator, who tells customers, who talks to staff. One page is enough, as long as it exists and people have read it.
  • Make sure you can actually investigate. Reporting within 24 hours means having logging and monitoring in place before the incident, not scrambling for evidence afterwards.
  • Review your suppliers and contracts. Ask your IT provider directly whether they expect to be regulated, and what they will tell you, and how quickly, if they are breached.
  • Get the fundamentals right. Multi-factor authentication everywhere it matters, prompt patching, least-privilege access, tested backups. These prevent most incidents from becoming reportable in the first place.
  • Test it. Run a short tabletop exercise. Walk through a plausible scenario and see where the plan falls apart while the stakes are low.
  • Give it an owner. Resilience needs a named person at senior level, not a shared inbox.

The bottom line

The Cyber Security and Resilience Bill formalises something that has been true for a while: your security is only as good as the technology supply chain behind it. Bringing managed service providers and data centres into regulation is a recognition that the weak point is often the trusted connection into a business, not the business itself.

If you are directly in scope, now is the time to be reading the detail and preparing for consultation. If you are not, the practical impact will most likely arrive through your customers' contracts and your suppliers' obligations, and the organisations that can evidence solid security will find that a commercial advantage rather than a burden.

Either way, the sensible work is the same work: know what you run, protect it properly, monitor it, and know exactly what you would do in the first 24 hours. We are always happy to review where you stand and help you close the gaps that matter.

Good to know

Frequently asked questions

Most small businesses are not directly regulated. The new duties target medium and large organisations in the named sectors, along with medium and large managed service providers and data centres. Smaller organisations can still be pulled in indirectly, either because they are designated as a critical supplier to a regulated organisation, or because regulated customers start asking them to evidence their security as a condition of doing business.
Medium and large managed service providers are brought into scope for the first time and will be regulated by the Information Commissioner's Office. In practice that means your IT partner will have its own security standards, registration and incident reporting duties to meet, and will need to tell affected customers when a significant incident hits. It is a fair question to put to any provider you use now.
The Bill completed its Commons stages on 25 June 2026 and is currently being scrutinised in the House of Lords, with Royal Assent expected later in 2026. Most of the detailed duties, including those covering managed service providers and incident reporting, arrive through secondary legislation after government consultation, so the obligations are expected to phase in over the following period rather than all at once.
The Bill widens the range of incidents that must be reported and sets a two-stage clock: an initial notification to your regulator within 24 hours, followed by a fuller report within 72 hours. Data centres and digital and managed service providers will also need to notify customers who are likely to be affected.
Work out whether you are in scope, then write down who does what in the first 24 hours of an incident. Most organisations discover the gap is not technology but process: nobody is sure who declares an incident, who contacts the regulator or where the evidence lives. A short, tested incident response plan plus an accurate inventory of your systems and suppliers puts you most of the way there.
Technology partners

Brands we partner with

We hold partner status with the vendors behind the tools we deploy, so your licensing, support and escalation come direct from the source rather than through a reseller chain.

Fortinet Authorized Partner
Pax8 partner
Dell Technologies Authorized Partner
Acronis Cloud Backup Provider Partner
NinjaOne partner
Ready when you are

Not sure where the new rules leave you?

Book a free consultation and we'll review your security, suppliers and incident response, then help you close the gaps that matter.

Send us a message

Tell us what you need and we'll reply the same working day.

Please enter your name.
Please enter a valid email.
Please let us know how we can help.
Thanks, your message has been sent. We'll be in touch shortly.
Sorry, something went wrong. Please call 020 4634 2518 or email info@whizzit.co.uk.
Call us Book a consultation