Cyber Security and Resilience Bill: What It Means for UK SMEs

Every few weeks someone forwards me an article about the Cyber Security and Resilience Bill with a one line question attached: does this apply to us? It is usually a business with somewhere between fifteen and eighty staff, no in-house IT team, and a growing pile of security questionnaires from customers who never used to send them.
For most of those businesses the direct answer is no. The Bill does not regulate small companies. The more useful answer is that it will still change what their customers ask of them, what their insurer expects at renewal, and what they need their IT provider to be able to prove.
This post explains what the Bill does, who it covers, where it has reached in Parliament, and what a small or medium-sized business should sensibly do about it now. I have kept the legal detail to what matters in practice, and every figure is linked to its source at the end.
Cyber Security and Resilience Bill: the short answer
The Cyber Security and Resilience (Network and Information Systems) Bill is a UK government bill that reforms the Network and Information Systems Regulations 2018. It widens the range of organisations that must meet legal cyber security standards, shortens incident reporting deadlines to 24 hours, and raises the maximum fine to £17 million or 4 per cent of worldwide turnover.
It brings managed service providers, data centre operators and designated critical suppliers under direct regulation for the first time. Micro and small businesses, including small managed service providers, are exempt.
| Type of organisation | Directly regulated? |
|---|---|
| Operator of essential services (energy, water, transport, health, digital infrastructure) | Yes |
| Relevant digital service provider (online marketplaces, search engines, cloud computing) | Yes |
| Managed service provider with 50 or more staff and turnover above €10 million | Yes |
| Third party data centre at 1MW or above, or enterprise data centre at 10MW or above | Yes |
| A supplier formally designated as a critical supplier by a regulator | Yes |
| A managed service provider below the size threshold | No |
| A micro or small business in any other sector | No |
The Bill is still going through Parliament. It entered House of Lords committee stage on 1 September 2026, Royal Assent is expected late in 2026, and most of the detailed duties will arrive later through secondary legislation.
What the Cyber Security and Resilience Bill changes
The existing rules are the Network and Information Systems Regulations 2018, usually shortened to NIS. They were written to implement an EU directive, they cover a narrow list of sectors, and they have been enforced lightly. The government's own position is that they have not kept pace with how much of the economy now depends on third party IT. The Bill changes that in five ways.
It widens who is covered
NIS 2018 applies to operators of essential services and to a small group of digital service providers. The Bill keeps both categories and adds managed service providers, data centres and a new category of designated critical supplier. The Impact Assessment estimates that around 900 to 1,100 managed service providers will be brought into regulation by the Information Commissioner's Office.
It regulates managed service providers for the first time
This is the change that has drawn the most attention in our industry, and it is the reason I have read the Bill more carefully than I read most legislation. A managed service, under the Bill, is one that meets four tests. It is provided to another organisation rather than delivered in-house. It relies on network and information systems. It involves ongoing management support, active administration or monitoring of IT systems. And it involves a network connection or access to the customer's systems.
That description covers a great deal of what an IT support company does day to day. The government's reasoning is straightforward. If an attacker compromises one provider, they gain a route into every customer that provider connects to, so the provider is a sensible place to set a standard.
It creates designated critical suppliers
A regulator will be able to formally designate a supplier as critical. Four conditions apply. The supplier provides goods or services to an operator of essential services or a digital service provider. Disruption to that supply would have a significant disruptive effect. The goods or services depend on network and information systems. And the supplier is not already regulated under another part of the regime.
Once designated, a critical supplier carries broadly the same duties as the operators it supplies. This matters more than the headline scope figures suggest, because designation is not tied to company size. A specialist supplier can be small and still be designated.
It brings data centres into scope
Third party data centres with a capacity of 1MW or above are covered, as are enterprise data centres at 10MW or above. Government research puts this at roughly 182 third party sites operated by 64 operators.
It replaces vague guidance with a named standard
Under NIS, the security duty is written in general terms. The Bill moves the regime towards the National Cyber Security Centre's Cyber Assessment Framework, which sets out objectives, principles and contributing outcomes that a regulator can measure an organisation against. The practical effect is that "appropriate and proportionate measures" stops being a matter of opinion and starts being a matter of evidence.
Who does the Cyber Security and Resilience Bill apply to?
The scope question is where most of the confusion sits, so it is worth going through the categories one at a time.
Operators of essential services
These are organisations delivering services the country depends on: electricity, gas, oil, drinking water, healthcare, air, rail, water and road transport, and digital infrastructure. They are already regulated under NIS 2018 and stay in scope, with stronger duties.
Relevant digital service providers
Online marketplaces, online search engines and cloud computing services. Also already in scope under NIS, and also facing stronger duties.
Managed service providers, and the size threshold
This is the part most often reported inaccurately, so it is worth being precise. The Bill does not regulate every IT company. It applies the standard medium enterprise test: 50 or more employees, and annual turnover or balance sheet total above €10 million. Micro and small providers are excluded.
The government's justification is a revenue argument rather than a risk argument. Medium and large managed service providers are fewer than one in ten of the providers active in the UK, but they account for around 97.6 per cent of the sector's revenue. Regulating that small group covers most of the market by value while leaving several thousand small firms outside the regime.
Regulated providers will need to register with the Information Commissioner's Office, put appropriate and proportionate security measures in place, and notify incidents that substantially affect their service.
Why most small businesses are not directly in scope
If you run an accountancy practice, a recruitment firm, a manufacturer or a legal practice, the Bill does not impose duties on you. There is no registration to complete and no fine waiting for you. Some commentators have criticised the government for this, on the grounds that it leaves the great majority of UK businesses outside a law written in response to attacks that frequently start at smaller suppliers.
I think the criticism is fair as a point about policy. As a point about what you should do next, it is beside the point, because being out of scope does not mean being unaffected. That is covered further down.
Cyber Security and Resilience Bill timeline: where it has reached
The Bill has been in progress for over two years, which is part of why so many businesses are unclear about its status.
| Date | Stage |
|---|---|
| 17 July 2024 | Announced in the King's Speech |
| 1 April 2025 | Cyber security and resilience policy statement published |
| 12 November 2025 | First reading in the House of Commons |
| January 2026 | Second reading in the House of Commons |
| 25 June 2026 | Passed to the House of Lords |
| 14 July 2026 | Second reading in the House of Lords |
| 1 September 2026 | Committee stage begins in the House of Lords |
| Expected late 2026 | Royal Assent |
| Expected 2027 to 2028 | Duties take effect through secondary legislation |
When does the Cyber Security and Resilience Bill come into force?
Not on Royal Assent, and this is the single most misunderstood point about it. The Bill is largely a framework. It grants powers, and the detail of who is covered, what the thresholds are and what the duties require will be set out in regulations and regulator codes of practice that follow.
The government has said implementation will be phased, with a consultation on implementation planned before the substantive duties commence. Current expectations point to full effect around 2028. That timing is not confirmed, and anyone telling you there is a hard compliance deadline next year is guessing.
The gap between Royal Assent and enforcement is genuinely useful. It is time to prepare at a sensible pace rather than time to ignore.
The 24 hour reporting rule, and why it is harder than it sounds
Under the Bill, a regulated organisation that becomes aware of a significant incident must send an initial notification within 24 hours to both its regulator and the National Cyber Security Centre, followed by a full report within 72 hours.
The definition of a reportable incident also widens. It moves beyond incidents that have caused disruption to include incidents capable of having a significant impact, and those that significantly affect the confidentiality, integrity or availability of a system. In plain terms, a serious near miss can become reportable.
Why 24 hours is a demanding standard
Twenty four hours sounds generous until you have sat through the first day of an incident. Most of that day is spent working out what has happened. Which accounts were touched, whether data left the business, whether the attacker is still inside, whether backups are clean.
Answering those questions inside a day depends on things that must be in place beforehand. You need audit logs that go back far enough and are retained somewhere the attacker cannot reach. You need to know who declares an incident and who has authority to report it, including at two in the morning on a Saturday. You need an asset inventory, so you know what you are looking at. And you need a named contact at whoever provides your IT support, with an agreed response time written into the contract rather than assumed.
Only 25 per cent of UK businesses have a formal incident response plan. Among small businesses the figure is lower still. That is the gap this rule exposes.
How it compares with the reporting you already do
If you handle personal data, you already have a reporting duty under UK GDPR: 72 hours to the Information Commissioner's Office where a breach is likely to result in a risk to people's rights and freedoms. The Bill's 24 hour early warning is separate, faster, and triggered by different criteria. An organisation in scope of both would need to satisfy both, from the same incident, on two different clocks.
Penalties under the Cyber Security and Resilience Bill
The fines are a significant increase on the NIS regime and are structured in two bands.
| Band | Maximum penalty | Applies to |
|---|---|---|
| Higher | £17 million or 4 per cent of worldwide turnover, whichever is greater | Failures of security duties and of incident notification |
| Standard | £10 million or 2 per cent of worldwide turnover, whichever is greater | Administrative failures, such as not registering as a digital or managed service provider |
| Daily | Up to £100,000 per day | Continuing contraventions |
There is also a reserve power allowing turnover-based penalties to be raised further for the most serious failures connected to national security. Alongside the fines, regulators gain powers to carry out proactive inspections, issue information notices and serve enforcement notices requiring specific action.
The change in enforcement posture matters as much as the numbers. NIS penalties have rarely been used. A regime with inspection powers and GDPR-scale maximums is a regime regulators are expected to use.
Why the Cyber Security and Resilience Bill reaches SMEs that are out of scope
Here is the part that affects the businesses I speak to most often. You can be entirely outside the legal scope of this Bill and still find that it changes your commercial life within a year or two. There are four routes by which that happens.
1. Supplier contracts and procurement questionnaires
Regulated organisations will have a legal duty to manage supply chain risk, and the only way any organisation discharges that duty is by pushing requirements down to its suppliers. That arrives as contract clauses, security schedules and questionnaires.
The scale of the coming change is visible in the current numbers. Only 15 per cent of UK businesses review the cyber security risks posed by their immediate suppliers, and just 6 per cent look at the wider supply chain. Those figures cannot stay where they are once supply chain risk management becomes a statutory duty for large regulated organisations. The questionnaires that reach you will get longer and more specific, and the answers will start being checked.
2. Your IT provider's obligations become your paperwork
If your managed service provider is above the size threshold, it will be regulated. Its duties will show up in your relationship with them as changes to contracts, tighter access controls on the tools it uses to reach your systems, mandatory multi-factor authentication, and requests for information it needs in order to report incidents on time.
If your provider is below the threshold, it will not be regulated, and it is reasonable to ask what standard it holds itself to instead. Being exempt from a law is not the same as being secure.
3. Cyber insurance renewals
Around 47 per cent of UK businesses hold some form of cyber insurance. Insurers follow regulation closely, because regulation changes what a defensible security posture looks like and therefore what they are willing to underwrite. Expect proposal forms to start asking about incident response testing, logging retention and supplier assurance rather than only about antivirus and backups.
4. The level of risk has not changed just because the law has
It is worth keeping the risk in proportion. In the most recent Cyber Security Breaches Survey, 43 per cent of UK businesses, around 612,000 organisations, identified a breach or attack in the previous twelve months. The rate was 46 per cent for small businesses and 42 per cent for micro businesses.
Most of that is phishing. It was experienced by 38 per cent of businesses and named the most disruptive type of attack by 69 per cent of those affected. Ransomware fell to 1 per cent, down from 3 per cent in each of the two previous years.
The costs are lower than most headlines suggest. The average cost of the most disruptive breach was £1,600 across all businesses, rising to £3,550 once you exclude those reporting no cost at all. I would rather quote those numbers than inflated ones, because a security case built on exaggeration falls apart the first time someone checks it. The honest case is that the common attack is cheap to suffer and cheaper still to prevent, and the rare one is what closes a business for a fortnight.
What SMEs should do now
None of the following depends on the Bill passing, and all of it is worth doing regardless. That is deliberate. Preparing for a regulation that is still being amended is a poor use of money, but the underlying controls are the same ones your customers and insurers are already asking about.
1. Establish whether you are in scope
Check your headcount and turnover against the medium enterprise test, and check whether you supply anyone who is an operator of essential services or a digital service provider. If you do, ask them whether they expect to designate suppliers, and what that would mean for you. Write the answer down. Most businesses will finish this exercise in an afternoon and conclude they are out of scope, which is a useful thing to have documented when a customer asks.
2. Get Cyber Essentials
Only 5 per cent of UK businesses hold Cyber Essentials, rising to 12 per cent among small businesses. It remains the most efficient way to demonstrate a baseline, it answers a large share of what supplier questionnaires ask, and it is aligned with the direction the Bill is taking. Our guide to Cyber Essentials certification covers the five controls, the fee bands and the April 2026 changes, and we explain the difference between the two levels on our Cyber Essentials and Cyber Essentials Plus pages.
3. Write an incident response plan you could run at 2am
A plan that lives in a folder nobody has opened is not a plan. It needs names, phone numbers, a decision on who can declare an incident, a decision on who can authorise reporting it, and a short list of the first six things to do. Then it needs testing once, in a meeting room, against a scenario someone made up. Businesses that have done this once respond noticeably better than those that have not, and it takes an afternoon.
4. Fix your logging before you need it
The 24 hour clock is only achievable if you can reconstruct events quickly. For most SMEs running Microsoft 365 this means turning on audit logging, extending the retention period, and confirming that sign-in and mailbox activity are being captured. It is a configuration task rather than a purchase, and it is the single most common gap I find.
5. Ask your IT provider three questions
Ask whether they will be regulated under the Bill and what they are doing about it. Ask what their contractual response time is when you report a suspected incident, and whether it is written into the agreement. Ask how they secure their own access to your systems, specifically whether the accounts they use to reach your environment are protected by multi-factor authentication and reviewed. A provider who answers these easily is a provider who has thought about it.
6. Read your contracts before the renewal, not during it
Security schedules are being rewritten across the market. Check what you have already agreed to on incident notification, because some clauses now require you to tell a customer within 24 hours of becoming aware of an incident, which is a duty you have taken on privately whatever the law says.
How the Bill sits alongside the rules you already follow
It does not replace anything. It sits next to obligations you may already carry.
| Regime | What it governs | Reporting deadline |
|---|---|---|
| Cyber Security and Resilience Bill | Security of network and information systems for regulated entities | 24 hours initial, 72 hours full report |
| UK GDPR | Personal data | 72 hours to the ICO where risk is likely |
| Cyber Essentials | Voluntary baseline of five technical controls | Not applicable |
| ISO 27001 | Voluntary information security management system | Not applicable |
The Bill is often compared with the EU's NIS2 Directive. They share an intent and a good deal of structure, but they are separate instruments with different scopes, and NIS2 does not apply in the UK. If you trade into the EU, you may need to consider both. We cover the certification side of this in our comparison of ISO 27001 and Cyber Essentials, and the data protection side in our guide to UK GDPR and your IT infrastructure.
Getting the groundwork done
The six steps above are the ones that matter, and none of them takes long on its own. Where businesses lose time is deciding who owns each one. If you would rather hand the list to someone, we will work through it with you: the scope check, Cyber Essentials, an incident response plan you could run at two in the morning, and logging configured so that reconstructing an incident takes hours rather than days.
We work with businesses across Essex and London, and there is no charge for the first conversation.
How AIS Technology helps businesses prepare
AIS Technology provides managed IT support and cyber security services to small and medium-sized businesses in Essex and London. As a managed service provider, we have been following this Bill since the policy statement, because the parts of it dealing with our own sector set the standard we will be held to.
The work that matters here is not exotic. It is access control and multi-factor authentication, audit logging with sensible retention, tested backups, patching on a defined cycle, endpoint protection, and a documented incident response process with someone accountable for running it. We help clients get Cyber Essentials certified, build a business continuity plan, and answer the supplier security questionnaires that arrive from their customers. For firms in regulated sectors, our IT support for financial services aligns the same controls with sector expectations on operational resilience.
Frequently Asked Questions
Has the Cyber Security and Resilience Bill been passed?
Not yet. It was introduced to Parliament on 12 November 2025, cleared all its Commons stages, and passed to the House of Lords on 25 June 2026. It had its Lords second reading on 14 July 2026 and entered committee stage on 1 September 2026. Royal Assent is expected in late 2026, at which point it becomes the Cyber Security and Resilience Act.
When does the Cyber Security and Resilience Bill come into force?
Not immediately on Royal Assent. The Bill is a framework that grants powers, and the detailed duties will be set out in secondary legislation and regulator codes of practice that follow. The government has committed to a consultation on implementation and to phased commencement. Current expectations point to full effect around 2028, though that timing is not confirmed.
Who does the Cyber Security and Resilience Bill apply to?
Operators of essential services in sectors such as energy, water, transport, health and digital infrastructure. Relevant digital service providers, meaning online marketplaces, search engines and cloud computing services. Managed service providers with 50 or more staff and turnover above €10 million. Data centre operators at 1MW or above, or 10MW for enterprise data centres. And suppliers formally designated as critical by a regulator.
Does the Cyber Security and Resilience Bill apply to small businesses?
No. Micro and small enterprises are exempt, including small managed service providers. However, being out of scope does not mean being unaffected. Regulated organisations will have a duty to manage supply chain risk, which they will discharge through contract clauses and security questionnaires sent to suppliers of any size. A small business can also be brought into scope if a regulator designates it as a critical supplier, since designation is not based on company size.
What are the penalties under the Cyber Security and Resilience Bill?
Two bands. Higher band failures, covering security duties and incident notification, carry a maximum of £17 million or 4 per cent of worldwide turnover, whichever is greater. Standard band failures, such as failing to register, carry a maximum of £10 million or 2 per cent of worldwide turnover. Regulators can also impose daily penalties of up to £100,000 for continuing contraventions.
What is the 24 hour reporting rule?
A regulated organisation that becomes aware of a significant incident must notify both its regulator and the National Cyber Security Centre within 24 hours, then submit a full report within 72 hours. The definition of a reportable incident also widens to include incidents capable of having a significant impact, not only those that have already caused disruption.
Is the Cyber Security and Resilience Bill the same as NIS2?
No. NIS2 is an EU directive and does not apply in the UK. The Bill has a similar purpose and a broadly similar structure, since both update the original NIS framework, but the scopes, thresholds and reporting duties differ. A UK business trading into the EU may need to consider both.
Does the Bill replace the NIS Regulations 2018?
It reforms and expands them rather than repealing them outright. Organisations already regulated under NIS 2018 remain regulated, with wider duties, shorter reporting deadlines and considerably higher penalties.
Sources
- UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, https://bills.parliament.uk/bills/4035
- GOV.UK, Cyber Security and Resilience Bill collection, https://www.gov.uk/government/collections/cyber-security-and-resilience-bill
- GOV.UK, Cyber security and resilience policy statement, April 2025.
- GOV.UK, Cyber Security and Resilience Bill factsheet: enforcement, https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/enforcement
- House of Lords Library, Cyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026-27, July 2026.
- National Cyber Security Centre, Cyber Security and Resilience Bill policy statement, https://www.ncsc.gov.uk/blog-post/cyber-security-resilience-bill-policy-statement
- GOV.UK, Cyber security breaches survey 2025/2026, https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
- Information Commissioner's Office, Information Commissioner's response to the Cyber Security and Resilience Bill, December 2025.
- ChannelPro, How the Cyber Security and Resilience Bill could impact MSPs, https://www.itpro.com/business/policy-and-legislation/how-the-cybersecurity-and-resilience-bill-could-impact-msps
- PwC UK, Understanding the Cyber Security and Resilience Bill, https://www.pwc.co.uk/services/technology/cyber-security-services/insights/understanding-cyber-security-and-resilience-bill.html

