The Cyber Security and Resilience Bill is not yet law. It was introduced in December 2025, passed its second reading in January 2026, and reached House of Lords committee stage on 1 September 2026. The detail can still change before Royal Assent.
This article is written around the direction of travel rather than final wording, because the direction is already changing what customers ask of their suppliers.
Cyber security has quietly stopped being an IT problem and become a governance one. The question a director gets asked now is not “is it secure?” but “how do you know, and can you show me?”
The Cyber Security and Resilience Bill is the clearest expression of that shift. It is the most significant update to UK cyber legislation since the NIS Regulations in 2018, and while most smaller businesses sit outside its direct scope, very few will be untouched by it.
What the Bill actually does
It widens who is regulated and tightens what regulated organisations must do. Three changes matter most.
Managed service providers come into scope for the first time. An estimated 900 to 1,100 MSPs would fall under ICO oversight — a category that did not previously exist in UK cyber regulation. If you outsource your IT, your provider may well be regulated even where you are not.
Data centre operators are brought in. The physical infrastructure underneath “the cloud” gets treated as critical national infrastructure rather than as somebody else’s problem.
Reporting gets faster and firmer. In-scope organisations would notify their regulator and the NCSC within 24 hours of becoming aware of a significant incident, with a full report inside 72 hours.
The penalties, for context
For the most serious breaches the Bill proposes fines of up to £17 million or 4% of global annual turnover, whichever is higher. A lower tier sits at £10 million or 2%. Where non-compliance continues, daily fines of up to £100,000 can apply.
These are regulator-scale numbers aimed at regulated entities. The reason they matter to everyone else is what they do to behaviour further down the chain.
If you are a smaller business, this is the part that affects you
You probably have no direct obligation. What you will have is customers who do.
Organisations facing 24-hour reporting deadlines and turnover-based fines become considerably more interested in who they buy from. That interest arrives as contract clauses, security questionnaires and requests for evidence — and it tends to arrive at the moment you are trying to win or renew the work, which is the worst possible time to start assembling it.
In practice the three things asked for most often are Cyber Essentials certification, a written incident response plan, and a straight answer about who has access to what.
How well do you know where this is heading?
Four questions. You get the answer and the reasoning straight after each one.
What to do about it now
Usefully, none of the sensible preparation depends on the Bill’s final wording.
Get certified, and stay certified. Cyber Essentials is the common currency of supply chain due diligence in the UK, and the cheapest way to answer a long questionnaire with a single document.
Write down what happens in an incident. Not a policy — a short practical note of who is called first, who can authorise taking systems offline, who speaks to customers, and where the phone numbers live if email is the thing that is down. A 24-hour clock is survivable with a plan and brutal without one.
Know what you have. An accurate list of systems, data and who has access underpins every answer you will be asked to give. It is also the thing most businesses find they do not have at the worst possible moment.
Ask your IT provider where they stand. If they are likely to be regulated as an MSP, that is a fair question to put to them now. If they have not considered it, that is informative in itself.
The honest summary
None of this warrants panic. The Bill is still in Parliament and the detail may yet move. But the underlying expectation — that a business can evidence how it manages cyber risk rather than assert it — is already here, and it is being enforced commercially through contracts long before it is enforced legally through regulators.
If you would like a straight assessment of where you currently stand against that expectation, it is a conversation we have most weeks and it carries no obligation.





