If you run a business in the UK, the rules on cyber security are about to get firmer. The Cyber Security and Resilience Bill has cleared the House of Commons and is now being scrutinised in the House of Lords, and it represents the most significant overhaul of UK cyber regulation since the current rules came in back in 2018.
Most of the coverage so far has focused on critical national infrastructure. That undersells it. The Bill deliberately widens the net to include the technology supply chain that ordinary businesses depend on every day, and that includes managed IT providers, data centres and suppliers judged critical to essential services. Even if your own organisation never becomes directly regulated, the way your suppliers work, and what they owe you when something goes wrong, is set to change.
What the Bill actually does
The Bill updates and strengthens the Network and Information Systems (NIS) Regulations 2018. Those original rules were written for a narrower world, largely energy, transport, health, water and digital infrastructure, and they have not kept pace with how businesses now buy and run technology. The government has grouped the reform into three broad aims:
- Expanded scope. Bringing new categories of organisation into the regime, most notably managed service providers and data centres.
- Stronger regulators. Giving the twelve sector regulators better enforcement powers and a more consistent approach, including cost recovery so oversight is properly funded.
- Faster adaptation. Allowing government to update requirements as threats evolve, rather than waiting years for new primary legislation.
Underlying all of it is a simple observation: attackers increasingly get in through suppliers rather than through the front door. Regulating only the biggest organisations leaves the route in wide open.
Where the Bill stands right now
The timeline matters, because it tells you how much runway you have:
- 12 November 2025. The Bill is introduced to Parliament.
- 6 January 2026. Second reading in the Commons.
- 25 June 2026. The Bill completes all of its Commons stages and moves to the House of Lords.
- Later in 2026. Royal Assent is expected, subject to the Lords stages.
Crucially, Royal Assent is not the moment everything switches on. A lot of the detail, including the duties that will apply to managed service providers, incident reporting and cost recovery, comes through secondary legislation after government consultation. In practice that means the obligations phase in over a period rather than landing overnight. The direction of travel, though, is already clear enough to plan around.
Who comes into scope
The existing sectors stay in: energy, transport, health, drinking water, digital infrastructure and certain digital services. The Bill then adds several new categories:
- Managed service providers, medium and large. Regulated by the Information Commissioner's Office. This captures providers who manage customers' IT systems and have privileged access into those systems, which is precisely why they are seen as a risk worth regulating.
- Data centres, medium and large. Treated as an essential service and regulated by Ofcom.
- Designated critical suppliers. Regulators gain the power to designate a specific supplier as critical to an essential or digital service, which brings that supplier into the regime regardless of its sector.
- Large load controllers. Organisations managing electrical load for smart appliances, overseen by the energy regulators.
The "medium and large" qualifier is worth reading carefully. Most small organisations will not be directly regulated. That is not the same as being unaffected.
Why it still matters if you are not directly regulated
This is the part that catches people out. There are three routes by which the Bill reaches businesses that are not themselves in scope.
First, the critical supplier designation. If you provide something a regulated organisation genuinely depends on, a regulator can bring you into the regime, and you will be expected to meet the same standards of security and reporting.
Second, the contract route, which is likely to be the most common. Regulated organisations have to manage their supply chain risk, and the practical way they do that is by pushing requirements down through contracts and procurement questionnaires. Expect more due diligence questions, more evidence requests and more security clauses, whether or not the law applies to you directly. Businesses that can answer those questions cleanly will win work more easily than those that cannot.
Third, the transparency route. Data centres and digital and managed service providers will be required to notify customers who are likely to be affected by a significant incident. If you buy managed IT, that is a genuine improvement: you should find out sooner when something upstream has gone wrong.
The new incident reporting clock
One of the most concrete changes is what has to be reported, and how quickly. The Bill widens the range of incidents that must be reported, covering breaches with the potential for significant impact rather than only those that have already disrupted a service. Reporting then follows a two-stage timetable:
- Within 24 hours. An initial notification to your regulator.
- Within 72 hours. A fuller report with more detail.
Twenty-four hours is not long. It is comfortably achievable if you already know who declares an incident, who contacts the regulator, and where your logs and evidence live. It is close to impossible if you are working that out for the first time while systems are down and the phone is ringing. In our experience this is the single most common gap, and it is a process problem far more than a technology one.
Penalties
The Bill simplifies the penalty bands and raises the maximum financial penalties so they sit more in line with data protection and product security legislation. Reported figures put the top of the range at up to seventeen million pounds or four per cent of global turnover, though the precise levels depend on the final legislation and the supporting regulations.
For most organisations the fine is not really the point. The bigger risks are operational: the downtime itself, the cost of responding, contractual exposure to your own customers, and the reputational damage of handling an incident badly in public.
A practical readiness checklist
You do not need to wait for the final regulations to make progress. Almost everything worth doing is good practice anyway, and much of it maps onto Cyber Essentials, which remains a sensible baseline.
- Establish whether you are in scope. Check your sector, your size and whether you could plausibly be designated a critical supplier to a regulated customer.
- Build an accurate inventory. You cannot protect or report on systems you do not know you have. That includes cloud services and anything shadow IT has quietly introduced.
- Write the first 24 hours down. Who declares an incident, who contacts the regulator, who tells customers, who talks to staff. One page is enough, as long as it exists and people have read it.
- Make sure you can actually investigate. Reporting within 24 hours means having logging and monitoring in place before the incident, not scrambling for evidence afterwards.
- Review your suppliers and contracts. Ask your IT provider directly whether they expect to be regulated, and what they will tell you, and how quickly, if they are breached.
- Get the fundamentals right. Multi-factor authentication everywhere it matters, prompt patching, least-privilege access, tested backups. These prevent most incidents from becoming reportable in the first place.
- Test it. Run a short tabletop exercise. Walk through a plausible scenario and see where the plan falls apart while the stakes are low.
- Give it an owner. Resilience needs a named person at senior level, not a shared inbox.
The bottom line
The Cyber Security and Resilience Bill formalises something that has been true for a while: your security is only as good as the technology supply chain behind it. Bringing managed service providers and data centres into regulation is a recognition that the weak point is often the trusted connection into a business, not the business itself.
If you are directly in scope, now is the time to be reading the detail and preparing for consultation. If you are not, the practical impact will most likely arrive through your customers' contracts and your suppliers' obligations, and the organisations that can evidence solid security will find that a commercial advantage rather than a burden.
Either way, the sensible work is the same work: know what you run, protect it properly, monitor it, and know exactly what you would do in the first 24 hours. We are always happy to review where you stand and help you close the gaps that matter.



