Compliance

Cyber Security & Resilience Bill: What UK Firms Must Do

The UK Cyber Security and Resilience Bill expands regulation to MSPs. Learn what this means for your business and what to demand from your IT provider.

Nerdster Team

If you outsource your IT — and most London firms do — the Cyber Security and Resilience Bill changes who is accountable when something goes wrong.

The Bill is the widest expansion of UK cyber regulation since the NIS Regulations of 2018. Its headline change is simple. For the first time, managed service providers fall directly inside the rules. Your IT provider stops being a supplier you trust and becomes a regulated entity you can hold to a standard.

That is good news for you, but only if you use it. Here is what to ask for, and when.

What the Cyber Security and Resilience Bill changes

The Bill updates the UK’s version of the NIS Directive, which we kept after Brexit and then left to age. Four changes matter if you buy managed IT.

Expect your MSP to be regulated for the first time

Today’s NIS Regulations cover operators of essential services — energy, water, transport, health — and a narrow set of digital service providers. MSPs sit outside them completely.

The CSRB names managed service providers as a regulated category. Your provider will be legally required to run appropriate security measures and to report significant incidents to the regulator.

A 24-hour incident reporting clock

The Bill brings faster, fuller incident reporting. Regulated entities, MSPs now among them, report a significant incident within 24 hours of detection and file the full report inside 72 hours. “Significant” is drawn more broadly than before, and covers anything that hits availability, integrity, or confidentiality.

Read that as your deadline too. If your provider takes three days to tell you something happened, neither of you meets it.

Who sits behind your IT provider

Regulators gain powers to look through the supply chain of a regulated entity. In practice your MSP will have to show oversight of its own suppliers: the security tools it runs, the cloud platforms it depends on, and any subcontractor with a route into your data.

Ask for that list now. If a provider cannot produce it, that is worth exploring further, because a supplier map is the groundwork for managing your risk as well as their own.

Expect regulators to act before an incident, not after

The Information Commissioner’s Office and sector regulators get stronger enforcement powers, including the ability to issue compliance directions in advance rather than waiting for a breach to investigate.

Why the CSRB reaches you even if you are not regulated

You may read the scope and conclude none of this applies to you. Two things make that a risky read.

First, the definition of an important entity has widened, and FCA operational resilience expectations run alongside it. Plenty of mid-sized professional services, financial services, and technology firms will find themselves newly in scope, or serving clients who are and who will pass the questions down.

Second, your MSP is in scope whatever you are. Its obligations flow into the service you receive, so how well your provider meets the CSRB becomes part of your own regulatory position.

Expect four things from a CSRB-ready MSP

A real security management system

Your provider should run a documented information security management system, aligned to ISO 27001 or an equivalent. Treat Cyber Essentials Plus certification as the floor rather than the achievement.

Incident response times written into your contract

The reporting clock only works if detection and escalation already work. Ask for their mean time to detect and mean time to respond, as numbers. If those numbers do not exist yet, that is the first thing to get in place, because the reporting clock cannot be met without them.

The full list of tools your provider runs on

You should be able to name the platforms underneath your service: the remote monitoring and management tool, the backup infrastructure, the security stack, and any outsourced labour. Ask for it in writing, and ask where each one stores your data.

Replace a two-page contract with a security schedule

Vague MSP contracts are on their way out. Yours should set out security obligations, incident notification timelines, data processing locations, audit rights, and what happens when you leave. If your current agreement runs to two pages with no security schedule, that is your first job.

Act before the Bill becomes law

The CSRB is moving through Parliament with cross-party support, and the expectation is that it becomes law in mid-2026, with a transition period for newly regulated entities.

Waiting for the final text is the wrong call. The direction is settled, and every requirement in it describes something a competent provider should already be doing. You lose nothing by asking early, and you gain a year.

Five steps to take now

  1. Ask your MSP directly whether they are preparing for the CSRB, and what their timeline is.
  2. Read your contract for security obligations, incident notification commitments, and audit rights.
  3. Work out your own exposure. Are you an essential or important entity under the wider definitions? Do your clients expect you to answer as if you are?
  4. Write down your IT supply chain, including everyone with access to your systems or your data.
  5. Build an incident response plan that assumes a 24-hour reporting window and names who makes the call.

Ask us the questions you will be asking your MSP

We have followed the CSRB since the consultation stage and have already aligned how we work to the requirements it sets. Our clients get documented cybersecurity governance, contractual response times, and a full list of the tools and platforms in our stack, shared as a matter of course.

If you want to know how the CSRB lands on your business and whether your current setup holds up, get in touch for a free IT assessment. We will talk you through what we find and what we would do about it.

CSRBregulationMSPcybersecurity

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report