What is the Cyber Security and Resilience Bill?
The Bill updates the Network and Information Systems (NIS) Regulations 2018 the rules that currently govern cyber security for essential services like energy, transport, health and digital infrastructure. It was announced in the 2024 King's Speech, introduced to Parliament in November 2025, and has been working through both Houses since.
As Technology Secretary Liz Kendall put it when the government's Cyber Action Plan launched alongside the Bill's second reading: "Cyber security is national security."
Where the Bill stands right now
- Cleared all House of Commons stages on 16 June 2026
- Passed its Lords second reading on 14 July 2026, with cross-party support in principle
- Entered Lords committee stage on 1 September 2026, where it remains under line-by-line scrutiny
- 65 amendments tabled at Lords stages so far, including proposals for personal liability for company directors and an AI "kill switch" provision
None of that is settled yet. But the direction of travel is a tighter scope, tougher enforcement, more board-level accountability isn't likely to reverse.
Who's coming into scope
The Bill's biggest single change is a new statutory category: Relevant Managed Service Providers (RMSPs). For the first time, MSPs themselves come under direct regulation, alongside:
- Operators of data centres above a specified size threshold
- Large-scale electricity load controllers (300MW or more)
- "Critical suppliers" - any direct supplier to a regulated organisation, where an incident on that supplier's systems could seriously disrupt the economy or day-to-day life
Small and micro MSPs are excluded. But mid-market and larger providers, the kind most UK businesses actually rely on for connectivity and IT are squarely in scope.
What happens if you don't comply
The Bill introduces a two-tier penalty regime, with enforcement powers well beyond the current NIS Regulations. Less serious breaches, such as failing to register as a regulated provider, could carry fines of up to £10 million or 2% of global annual turnover, whichever is greater. That's nearly double the equivalent penalty under the EU's NIS2 Directive, and it's before you factor in the more serious breach tier or the reputational cost of a regulator finding your supply chain wasn't in order.
The NCSC's Cyber Assessment Framework is also being placed on a statutory footing as the baseline standard in-scope organisations will be measured against, which gives businesses (and their suppliers) a concrete framework to benchmark themselves against now, rather than waiting for the Bill to pass.
The real change: your suppliers are now your problem
Under the current rules, your obligations mostly stop at your own systems. The Bill changes that. Regulators will be able to designate a supplier as "critical" if a failure on their end could cause serious knock-on disruption, which means the resilience of your IT and connectivity provider isn't just their concern anymore. It's a question you may need to answer for a regulator, a client, or your own board.
That's a meaningfully different position to be in if you've never actually asked your provider how they'd handle a serious incident.
What this means for your IT and connectivity setup
Every additional vendor in your stack is another entity whose resilience, reporting duties and compliance status you're implicitly vouching for. A business running connectivity through one supplier and managed IT through another effectively doubles that exposure, two separate providers to question, two separate sets of assurances to chase down, and a gap between them that's hard to see until something goes wrong.
Businesses consolidating to a single, tailored connectivity-and-IT partner aren't just simplifying admin. They're cutting the number of supplier relationships they'd need to defend if a regulator, insurer or client ever asked "how resilient is your setup, really?" with one team accountable for uptime, backup and failover, rather than two pointing at each other.
How to start preparing now
- List every supplier with access to your network or systems. If you can't do this quickly, that's the first gap to close.
- Ask your IT and connectivity providers directly how they'd handle a serious incident — not whether they have a backup, but whether it's automatic, tested, and fast enough to matter.
- Flag this at board level. With personal liability for directors on the table as a Lords amendment, this is no longer purely an IT conversation.
- Consider what consolidating vendors would actually remove from your risk picture — fewer relationships, clearer accountability, less to explain when the questions start.
The bottom line
The Cyber Security and Resilience Bill isn't law yet, and it may still change before it is. But the underlying shift, accountability extending into your supply chain is already shaping how UK businesses are expected to operate. Getting ahead of it now costs a lot less than scrambling once it's enforceable.
How many of your suppliers could you actually vouch for if a regulator asked?
See how a single connectivity and IT partner simplifies compliance