Cyber Security & Resilience Bill: What UK Firms Must Do
Now in the House of Lords, the Cyber Security and Resilience Bill brings medium and large MSPs into regulation. What it means for firms that outsource IT.
Nerdster Team
If you outsource your IT — and most London firms do — the Cyber Security and Resilience Bill changes who is accountable when something goes wrong.
The Bill, formally the Cyber Security and Resilience (Network and Information Systems) Bill, is the biggest update to UK cyber regulation since the NIS Regulations of 2018. One of its headline changes is simple. For the first time, medium and large managed service providers fall directly inside the rules. If your IT provider is one of them, it stops being a supplier you trust and becomes a regulated entity you can hold to a standard.
That is good news for you, but only if you use it. Here is what to ask for, and when.
What the Cyber Security and Resilience Bill changes
The Bill updates the UK’s version of the NIS Directive, which we kept after Brexit and then left to age. Four changes matter if you buy managed IT.
Expect your MSP to be regulated for the first time
Today’s NIS Regulations cover operators of essential services — energy, water, transport, health — and a narrow set of digital service providers. MSPs sit outside them completely.
The Bill creates a new regulated category, the “relevant managed service provider”: a business providing managed services in the UK that is not a small or micro enterprise. Those providers will have to register with the Information Commission (which replaces the ICO on 30 September 2026), take appropriate and proportionate measures to manage the risks to the systems their service relies on, and report significant incidents. Smaller MSPs sit outside that category, although regulators can still designate one as a critical supplier.
A 24-hour incident reporting clock
The Bill brings faster, fuller incident reporting. Regulated entities, medium and large MSPs now among them, will send an initial notification to their regulator and the NCSC within 24 hours, and a fuller report within 72 hours. Reporting also widens from incidents that have already caused disruption to those with the potential to cause a significant impact. The thresholds will be set in secondary legislation.
Data centres, digital service providers and MSPs will also have to tell customers who are likely to have been affected. Read that as your deadline too. If your provider takes three days to tell you something happened, neither of you meets it.
Who sits behind your IT provider
Regulators will be able to designate critical suppliers: the suppliers that essential and digital services depend on most, brought inside the regime even when they would not otherwise qualify. In practice a regulated MSP will need to show oversight of its own suppliers: the security tools it runs, the cloud platforms it depends on, and any subcontractor with a route into your data.
Ask for that list now. If a provider cannot produce it, that is worth exploring further, because a supplier map is the groundwork for managing your risk as well as their own.
Stronger powers for regulators and government
The maximum penalty is being amended to allow higher fines where appropriate, in line with data protection law, and the Secretary of State gains powers to direct regulators or regulated entities to act when there is a threat to national security.
Why the CSRB reaches you even if you are not regulated
You may read the scope and conclude none of this applies to you. For most professional services firms, directly, it does not. Financial services have their own regime through the FCA’s operational resilience rules. Two things still bring the Bill to your door.
First, if you are a supplier to an operator of an essential service, a data centre or a digital service provider, your customers will pass the questions down, and a regulator can designate a supplier it considers critical.
Second, if your MSP is medium or large, it is in scope whatever you are. Its obligations flow into the service you receive, so how well your provider meets the Bill becomes part of your own risk position.
Expect four things from a CSRB-ready MSP
A real security management system
Your provider should run a documented information security management system, aligned to ISO 27001 or an equivalent. Treat Cyber Essentials Plus certification as the floor rather than the achievement.
Incident response times written into your contract
The reporting clock only works if detection and escalation already work. Ask for their mean time to detect and mean time to respond, as numbers. If those numbers do not exist yet, that is the first thing to get in place, because the reporting clock cannot be met without them.
The full list of tools your provider runs on
You should be able to name the platforms underneath your service: the remote monitoring and management tool, the backup infrastructure, the security stack, and any outsourced labour. Ask for it in writing, and ask where each one stores your data.
Replace a two-page contract with a security schedule
Vague MSP contracts are on their way out. Yours should set out security obligations, incident notification timelines, data processing locations, audit rights, and what happens when you leave. If your current agreement runs to two pages with no security schedule, that is your first job.
Where the Bill stands in September 2026
The Bill was introduced in the House of Commons on 12 November 2025 and carried over into the new parliamentary session. It completed its Commons stages on 16 June 2026 and moved to the House of Lords, where it had its second reading on 14 July 2026 and its committee stage in early September. Lords report stage is scheduled for 26 October 2026. It is not yet law.
Even after Royal Assent, most of the new duties will be switched on by secondary legislation, and medium and large MSPs will have three months to register once their provisions come into force.
Waiting for the final text is still the wrong call. The direction is settled, and every requirement in it describes something a competent provider should already be doing. You lose nothing by asking early.
Five steps to take now
- Ask your MSP directly whether it expects to be in scope, what it is doing to prepare, and on what timeline.
- Read your contract for security obligations, incident notification commitments, and audit rights.
- Work out your own exposure. Do you supply operators of essential services, data centres or digital service providers, and do those clients expect you to answer as if you were regulated?
- Write down your IT supply chain, including everyone with access to your systems or your data.
- Build an incident response plan that assumes a 24-hour reporting window and names who makes the call.
Ask us the questions you will be asking your MSP
Our clients get documented cybersecurity governance and a full list of the tools and platforms in our stack, shared as a matter of course.
If you want to know how the Bill lands on your business and whether your current setup holds up, book a free IT assessment. We will talk you through what we find and what we would do about it.