Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Cyber Security Regulations Are Changing: Is Your Business Ready?

Where this stands, September 2026

The Cyber Security and Resilience Bill is not yet law. It was introduced in December 2025, passed its second reading in January 2026, and reached House of Lords committee stage on 1 September 2026. The detail can still change before Royal Assent.

This article is written around the direction of travel rather than final wording, because the direction is already changing what customers ask of their suppliers.

Cyber security has quietly stopped being an IT problem and become a governance one. The question a director gets asked now is not “is it secure?” but “how do you know, and can you show me?”

The Cyber Security and Resilience Bill is the clearest expression of that shift. It is the most significant update to UK cyber legislation since the NIS Regulations in 2018, and while most smaller businesses sit outside its direct scope, very few will be untouched by it.

What the Bill actually does

It widens who is regulated and tightens what regulated organisations must do. Three changes matter most.

Managed service providers come into scope for the first time. An estimated 900 to 1,100 MSPs would fall under ICO oversight — a category that did not previously exist in UK cyber regulation. If you outsource your IT, your provider may well be regulated even where you are not.

Data centre operators are brought in. The physical infrastructure underneath “the cloud” gets treated as critical national infrastructure rather than as somebody else’s problem.

Reporting gets faster and firmer. In-scope organisations would notify their regulator and the NCSC within 24 hours of becoming aware of a significant incident, with a full report inside 72 hours.

The penalties, for context

For the most serious breaches the Bill proposes fines of up to £17 million or 4% of global annual turnover, whichever is higher. A lower tier sits at £10 million or 2%. Where non-compliance continues, daily fines of up to £100,000 can apply.

These are regulator-scale numbers aimed at regulated entities. The reason they matter to everyone else is what they do to behaviour further down the chain.

If you are a smaller business, this is the part that affects you

You probably have no direct obligation. What you will have is customers who do.

Organisations facing 24-hour reporting deadlines and turnover-based fines become considerably more interested in who they buy from. That interest arrives as contract clauses, security questionnaires and requests for evidence — and it tends to arrive at the moment you are trying to win or renew the work, which is the worst possible time to start assembling it.

In practice the three things asked for most often are Cyber Essentials certification, a written incident response plan, and a straight answer about who has access to what.

Quick check

How well do you know where this is heading?

Four questions. You get the answer and the reasoning straight after each one.

1. Does the Cyber Security and Resilience Bill apply directly to most small businesses?
The Bill targets operators of essential services, data centres and managed service providers. Most SMEs have no direct obligation — but their larger customers do, and those customers pass the requirement down the supply chain in contracts and due diligence questionnaires.
2. How quickly would an in-scope organisation have to report a significant incident?
The proposed regime is an initial notification within 24 hours of becoming aware, followed by a full report within 72 hours. Twenty-four hours is not long if you do not already know who decides, who writes it, and where the evidence lives.
3. Which of these is a larger customer most likely to ask you for?
Supply chain due diligence asks for recognised, checkable evidence rather than technical detail. Cyber Essentials certification and a written incident response plan are the two that come up most consistently.
4. What is the headline maximum penalty proposed for the most serious breaches?
The Bill proposes up to £17 million or 4% of global annual turnover, whichever is higher, for the most serious cases, with a lower tier at £10 million or 2%. Daily fines of up to £100,000 can apply while non-compliance continues.
Score: 0 of 4

What to do about it now

Usefully, none of the sensible preparation depends on the Bill’s final wording.

Get certified, and stay certified. Cyber Essentials is the common currency of supply chain due diligence in the UK, and the cheapest way to answer a long questionnaire with a single document.

Write down what happens in an incident. Not a policy — a short practical note of who is called first, who can authorise taking systems offline, who speaks to customers, and where the phone numbers live if email is the thing that is down. A 24-hour clock is survivable with a plan and brutal without one.

Know what you have. An accurate list of systems, data and who has access underpins every answer you will be asked to give. It is also the thing most businesses find they do not have at the worst possible moment.

Ask your IT provider where they stand. If they are likely to be regulated as an MSP, that is a fair question to put to them now. If they have not considered it, that is informative in itself.

The honest summary

None of this warrants panic. The Bill is still in Parliament and the detail may yet move. But the underlying expectation — that a business can evidence how it manages cyber risk rather than assert it — is already here, and it is being enforced commercially through contracts long before it is enforced legally through regulators.

If you would like a straight assessment of where you currently stand against that expectation, it is a conversation we have most weeks and it carries no obligation.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading