BLOG
The Cyber Security and Resilience Bill What Changes for MSPs
Published 25 July 2026 · By P Larner
Regulation & Legislation#Cyber Security and Resilience Bill#NIS Regulations#CAF#MSPs#NCSC#incident reporting
The Cyber Security and Resilience Bill: What Changes for MSPs and the People Who Secure Them
Illustration for: The Cyber Security and Resilience Bill
Where things stand. This article describes the Cyber Security and Resilience Bill as it stood in July 2026, after clearing the Commons and part way through the House of Lords. Bills are amended as they pass through Parliament, commencement will be phased through secondary legislation, and details described here may change before or after Royal Assent. This is practitioner commentary rather than legal advice, so before making compliance decisions, check the current text of the Bill and take advice from a qualified professional.
The UK’s rules for critical service security have been running on 2018 machinery. The NIS Regulations were written before the ransomware era properly began, before the supply chain became the favourite way in, and before the EU replaced its own version with NIS2. The Cyber Security and Resilience Bill is the overhaul, and if you work for or with a managed service provider, it is aimed at you.
Why the 2018 regulations needed replacing
The original NIS Regulations covered operators of essential services (energy, water, transport, health, digital infrastructure) and a set of digital service providers. They aged badly in two specific ways. First, the organisations attackers actually use as a way in, the IT providers holding admin credentials for hundreds of client networks, were largely out of scope. Second, the reporting duties were slow and unevenly applied, so regulators often learnt about serious incidents late or not at all.
Meanwhile the EU shipped NIS2 with broader scope and tighter clocks. The UK, having left before NIS2 applied, had a choice between drifting further from the European baseline and modernising on its own terms. The Bill is the modernisation, and in several places it deliberately mirrors what EU-regulated organisations already do.
Who is newly in scope
The headline expansion is managed service providers. If your organisation runs IT infrastructure, networks, security operations or similar services for other organisations, remotely and with privileged access, the Bill is designed to capture you. The logic is uncomfortable but sound, because an MSP with domain admin over two hundred client networks is critical infrastructure, whether or not it thinks of itself that way. Recent history, from the Kaseya compromise to the steady drumbeat of incidents reaching victims through their IT suppliers, made the case for the government.
Alongside MSPs, the Bill brings in data centres above a size threshold and creates a mechanism for designating individual critical suppliers whose failure would cascade into essential services. Just as importantly, it gives the Secretary of State power to extend scope through secondary legislation, which means the perimeter can grow without a new Act of Parliament. Organisations near the edge of scope should assume the edge moves towards them over time, not away.
The clocks, 24 hours and 72 hours
The reporting regime will feel familiar to anyone who has read NIS2 or UK GDPR. As the Bill stands, a significant incident triggers an initial notification within 24 hours of becoming aware, followed by a fuller incident report within 72 hours, to the relevant regulator and the NCSC. MSPs face an additional duty that deserves more attention than it gets, which is telling affected customers, so the organisations downstream of a compromise are not the last to know.
Two practical observations from the NIS2 experience apply directly. The 24 hour clock is an awareness test rather than a forensics test, because it demands that your organisation can recognise a significant incident and produce a basic account of it within a day, which is an operational capability, not a document. And nobody drafts a good report during an incident. The organisations that hit these deadlines are the ones with templates, decision trees and a named reporting owner agreed long before anything is on fire.
Timeline comparing NIS2 and UK Bill reporting deadlines side by side
Familiar clocks, though the UK lane stays provisional until Royal Assent.
Penalties with turnover attached
Enforcement moves from the polite end of the spectrum to something closer to data protection law, with a tiered penalty regime whose maximums are linked to turnover for the most serious failures, and stronger powers for regulators to demand information, inspect and direct improvement. The exact figures have shifted during the Bill’s passage and may shift again, so treat any specific number you read, including in commentary like this, as provisional until the Act is printed. The direction, though, is not in doubt. Ignoring this regime is becoming a board-level financial risk rather than a compliance footnote.
The CAF is the likely yardstick
The UK already has an assessment mechanism for NIS-regulated organisations, namely the NCSC Cyber Assessment Framework, used by regulators and by government through GovAssure. It is a safe working assumption that CAF-based assessment extends to the newly scoped organisations. For an MSP that has never met the CAF, that is the single most useful preparation. Read its four objectives and fourteen principles, run an honest self-assessment, and let the gaps drive the plan. An organisation that can evidence its CAF position will find whatever the final guidance says far less frightening.
What to do this quarter
Royal Assent is expected during 2026, with duties phased in through secondary legislation over the following years. That phasing is not a reason to wait, it is the preparation window, and the fundamentals are no-regrets moves whatever the final text says.
Decide whether you are in scope, in writing
Map your services against the Bill’s categories, record the reasoning, and revisit it as the text finalises. If you are near the boundary, plan as if you are inside it.
Get the asset register straight
Every reporting duty, risk assessment and regulator conversation stands on knowing what you run and for whom. For an MSP that means per-client asset and access records, not one undifferentiated pile.
Build the incident reporting capability now
You need a severity definition, a decision tree, report templates for the 24 and 72 hour submissions, a named owner, and one rehearsal. Half a day of work that transforms the worst day.
Run a CAF self-assessment
Honest scoring against the fourteen principles gives you the gap list and, later, the evidence trail a regulator will ask for.
The organisations that treat the passage period as lead time will meet the commencement dates with paperwork they already have. The rest will meet them with a consultancy invoice. And to repeat the caveat that matters, the Bill is still in Parliament, details will move, and this article is a practitioner’s reading of the direction of travel rather than a statement of what the law requires. Check the enacted text before you rely on any of it.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.
Register / Download Contact us