Cyber Security & Resilience Bill: What UK Firms Must Do
The UK Cyber Security and Resilience Bill expands regulation to MSPs. Learn what this means for your business and what to demand from your IT provider.
Nerdster Team
If you outsource your IT — and most London firms do — the Cyber Security and Resilience Bill changes who is accountable when something goes wrong.
The Bill is the widest expansion of UK cyber regulation since the NIS Regulations of 2018. Its headline change is simple. For the first time, managed service providers fall directly inside the rules. Your IT provider stops being a supplier you trust and becomes a regulated entity you can hold to a standard.
That is good news for you, but only if you use it. Here is what to ask for, and when.
What the Cyber Security and Resilience Bill changes
The Bill updates the UK’s version of the NIS Directive, which we kept after Brexit and then left to age. Four changes matter if you buy managed IT.
Expect your MSP to be regulated for the first time
Today’s NIS Regulations cover operators of essential services — energy, water, transport, health — and a narrow set of digital service providers. MSPs sit outside them completely.
The CSRB names managed service providers as a regulated category. Your provider will be legally required to run appropriate security measures and to report significant incidents to the regulator.
A 24-hour incident reporting clock
The Bill brings faster, fuller incident reporting. Regulated entities, MSPs now among them, report a significant incident within 24 hours of detection and file the full report inside 72 hours. “Significant” is drawn more broadly than before, and covers anything that hits availability, integrity, or confidentiality.
Read that as your deadline too. If your provider takes three days to tell you something happened, neither of you meets it.
Who sits behind your IT provider
Regulators gain powers to look through the supply chain of a regulated entity. In practice your MSP will have to show oversight of its own suppliers: the security tools it runs, the cloud platforms it depends on, and any subcontractor with a route into your data.
Ask for that list now. If a provider cannot produce it, that is worth exploring further, because a supplier map is the groundwork for managing your risk as well as their own.
Expect regulators to act before an incident, not after
The Information Commissioner’s Office and sector regulators get stronger enforcement powers, including the ability to issue compliance directions in advance rather than waiting for a breach to investigate.
Why the CSRB reaches you even if you are not regulated
You may read the scope and conclude none of this applies to you. Two things make that a risky read.
First, the definition of an important entity has widened, and FCA operational resilience expectations run alongside it. Plenty of mid-sized professional services, financial services, and technology firms will find themselves newly in scope, or serving clients who are and who will pass the questions down.
Second, your MSP is in scope whatever you are. Its obligations flow into the service you receive, so how well your provider meets the CSRB becomes part of your own regulatory position.
Expect four things from a CSRB-ready MSP
A real security management system
Your provider should run a documented information security management system, aligned to ISO 27001 or an equivalent. Treat Cyber Essentials Plus certification as the floor rather than the achievement.
Incident response times written into your contract
The reporting clock only works if detection and escalation already work. Ask for their mean time to detect and mean time to respond, as numbers. If those numbers do not exist yet, that is the first thing to get in place, because the reporting clock cannot be met without them.
The full list of tools your provider runs on
You should be able to name the platforms underneath your service: the remote monitoring and management tool, the backup infrastructure, the security stack, and any outsourced labour. Ask for it in writing, and ask where each one stores your data.
Replace a two-page contract with a security schedule
Vague MSP contracts are on their way out. Yours should set out security obligations, incident notification timelines, data processing locations, audit rights, and what happens when you leave. If your current agreement runs to two pages with no security schedule, that is your first job.
Act before the Bill becomes law
The CSRB is moving through Parliament with cross-party support, and the expectation is that it becomes law in mid-2026, with a transition period for newly regulated entities.
Waiting for the final text is the wrong call. The direction is settled, and every requirement in it describes something a competent provider should already be doing. You lose nothing by asking early, and you gain a year.
Five steps to take now
- Ask your MSP directly whether they are preparing for the CSRB, and what their timeline is.
- Read your contract for security obligations, incident notification commitments, and audit rights.
- Work out your own exposure. Are you an essential or important entity under the wider definitions? Do your clients expect you to answer as if you are?
- Write down your IT supply chain, including everyone with access to your systems or your data.
- Build an incident response plan that assumes a 24-hour reporting window and names who makes the call.
Ask us the questions you will be asking your MSP
We have followed the CSRB since the consultation stage and have already aligned how we work to the requirements it sets. Our clients get documented cybersecurity governance, contractual response times, and a full list of the tools and platforms in our stack, shared as a matter of course.
If you want to know how the CSRB lands on your business and whether your current setup holds up, get in touch for a free IT assessment. We will talk you through what we find and what we would do about it.