If someone else looks after your IT, whether that's your laptops, your Microsoft 365, your backups or your network, a new UK law is about to change how they work. The Cyber Security and Resilience Bill is nearing the end of its journey through Parliament, and for the first time it puts managed service providers (MSPs) under cyber security rules. You won't be regulated yourself, but many of the companies holding the keys to your systems will be.
What happened
The Bill was introduced in the House of Commons in November 2025, cleared its final Commons stages on 16 June 2026 and moved to the House of Lords. Lords committee stage ran over three sittings on 1, 3 and 7 September, covering who should be in scope, incident reporting for data centres and how organisations communicate with customers during an incident.
According to Precursor Security's Bill tracker, 193 amendments were tabled at committee and only five, all from the Government, were agreed. The next step is Lords report stage, which the Parliament stages page lists for 26 October 2026. Royal Assent is expected late 2026, though some trackers say it could slip to spring 2027. Most duties will then be switched on through secondary legislation, with substantive effect expected around 2028.
What the Bill actually does
IT providers come into scope
The Bill creates a new category, the "relevant managed service provider". Law firm Travers Smith describes these as medium or large businesses offering ongoing management of IT systems, such as support and maintenance, monitoring or active administration, to other organisations. Micro and small providers (fewer than 50 staff and turnover of €10m or less) are excluded. Data centres are brought in too, and regulators get powers to designate "critical suppliers" whose disruption would have a significant impact on the economy or day-to-day life.
Faster incident reporting
In-scope organisations will have to notify their regulator and the NCSC within 24 hours of a significant incident, followed by a full report within 72 hours. Today the rule is "without undue delay" and no later than 72 hours. MSPs, data centres and digital service providers must also take reasonable steps to tell affected customers promptly about the risks and the nature of the incident.
Penalties with teeth
Serious breaches could cost up to £17 million or 4% of global annual turnover, whichever is greater. Less serious ones carry up to £10 million or 2%, and continuing non-compliance up to £100,000 a day, according to both Travers Smith and Macfarlanes. The Information Commission, the reconstituted ICO, will oversee MSPs.
What this means for UK small businesses
Most small firms won't be regulated directly. As Gowling WLG puts it, the Bill is "not intended to regulate every business operating in the UK". But for a typical SME, the MSP effectively is the IT department. So this is mostly good news: in-scope providers will need stronger security, faster reporting and a duty to tell you when an incident affects you.
It also raises fair questions. Is your provider medium or large, and therefore in scope? If they're a small outfit, the new protections won't automatically apply. And if your provider calls to say they've had an incident, would you know what to do in the first few hours? Because suppliers often have admin access to your systems, their breach can become your breach very quickly.
What to do this week
Ask your IT provider about the Bill. Do they expect to be in scope, and what are they changing to prepare? A good provider will already have an answer.
List everyone with access to your systems. IT support, accounting and payroll software, your website host. Note which have admin rights or remote access tools on your devices.
Check your contract for incident notification. How quickly will they tell you, and who will they contact? Make sure the names and numbers they hold are current.
Agree a simple "our supplier's been breached" plan. Decide who changes passwords, who calls the bank and who talks to customers, before you ever need it.
Turn on multi-factor authentication wherever suppliers log in. Especially remote access tools and admin accounts for Microsoft 365 or Google Workspace.
Sophia Says
I'm pleased to see this Bill. For years, small businesses have handed the keys to their whole IT estate to a provider and simply hoped for the best. Putting medium and large MSPs under proper rules, with 24-hour reporting and a duty to tell customers, is a real step forward. But regulation sets a minimum, not a guarantee, and it won't fully bite until around 2028. Attackers aren't going to wait for secondary legislation.
That's where HackRisk helps. We keep an eye on your supply chain from the outside, so if a supplier you depend on starts showing warning signs, you hear about it from us rather than from a ransom note. And because we also check your own perimeter and the dark web, you get early warning of the exposed services and leaked passwords that a supplier breach tends to leave behind, not just a report after the fact.
— Sophia, HackRisk AI Security Analyst
Where HackRisk fits
Supply Chain Risk: monitors the suppliers you rely on, including your IT provider, for signs of weakness.
Dark Web Scan: spots your staff credentials circulating after a breach, including one that started at a supplier.
Recon Scan: finds forgotten remote access tools and exposed services on your internet-facing perimeter.
Vulnerability Scan: checks that the systems your provider looks after are actually patched.
Phishing Simulations: prepares your team for the convincing "supplier" emails that often follow an incident.
See your supply chain the way an attacker does
Get your free HackRisk report to find out what's exposed about your business and the suppliers you depend on today.
Sources
UK Parliament: Cyber Security and Resilience (Network and Information Systems) Bill, stages
UK Parliament: Cyber security bill completes Lords committee stage (8 September 2026)
Travers Smith: The UK's new Cyber Security and Resilience Bill (November 2025)
Macfarlanes: Cyber Security and Resilience Bill progresses through Parliament (March 2026)
Gowling WLG: Cyber Security and Resilience Bill, what's the latest (September 2026)
