Back to blog MSSP

The UK Cyber Security and Resilience Bill: What It Means for Your MSP

The Cyber Security and Resilience Bill will regulate UK managed service providers directly for the first time. Even if your MSP falls below the threshold, your regulated clients will push the requirements onto you through questionnaires and contract clauses.

Neil Cameron
· 11 min read
The Cyber Security and Resilience Bill will regulate UK managed service providers directly for the first time. Even if your MSP falls below the threshold, your regulated clients will push the requirements onto you through questionnaires and contract clauses.

Key Takeaways

  • The Cyber Security and Resilience Bill brings medium and large managed service providers into the UK’s NIS regulatory regime for the first time, with the ICO acting as the enforcement body.
  • As of September 2026, the bill has cleared the House of Commons and entered Lords committee stage. It is not yet law.
  • In-scope providers, called “relevant managed service providers” (RMSPs), will face mandatory security measures, incident reporting obligations, and direct regulator oversight.
  • Smaller MSPs that fall below the threshold still face indirect pressure: their regulated clients will push supply-chain security requirements down through due-diligence questionnaires and contract clauses.
  • By 2025, 45% of organisations worldwide were expected to have experienced attacks on their software supply chains, a three-fold increase from 2021 (Gartner). The bill is the UK government’s response to that trajectory.

This article is for informational purposes only and does not constitute legal advice. Confirm the bill’s current parliamentary stage at bills.parliament.uk/bills/4035 before making compliance decisions.


The cyber security and resilience bill is the most significant change to UK network and information systems regulation since the original NIS Regulations came into force in 2018. For MSP and MSSP owners, the bill’s central proposition is straightforward: if your business provides managed IT or security services above a certain size threshold, you will soon be directly regulated, with enforceable duties around security practices, incident reporting, and cooperation with the ICO. If you are still in the middle of that shift, our guide to what changes when an MSP starts selling security covers the operational and contractual groundwork the bill now puts a regulator behind. The commercial impact is real. Failing to prepare means potential enforcement action, but more immediately it means losing enterprise and public-sector contracts to competitors who are already getting ready.

What the Bill Is and Where It Stands in Parliament

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to modernise the UK’s NIS framework, which until now has applied primarily to operators of essential services (energy, transport, health, water, digital infrastructure) and relevant digital service providers. The bill expands that scope to include a new category: relevant managed service providers.

The government’s stated rationale is that the supply-chain risk posed by MSPs has grown faster than the regulatory framework designed to manage it. When a single MSP handles IT infrastructure or security operations for dozens of organisations, including those already regulated under NIS, a compromise at the MSP level can cascade across an entire sector.

As of publication (September 2026), the bill has passed through the House of Commons and has been in Lords committee stage since 1 September 2026. It is not yet law, and further amendments may emerge during the Lords stages. That said, the direction of travel is clear, and secondary legislation will follow Royal Assent to fill in the technical detail around thresholds and reporting procedures.

Who Counts as a Relevant Managed Service Provider?

Not every MSP is caught by the bill. The government’s factsheet on relevant managed service providers sets out the criteria.

To be classified as an RMSP, a provider must meet conditions relating to:

  • The nature of the service: the provider delivers IT or security services to other organisations on a managed, ongoing basis. This covers managed IT infrastructure, managed security operations (SOC-as-a-service, SIEM management, endpoint detection and response), managed networking, and similar offerings.
  • Dependency: the client organisation depends on the MSP’s service in a way that means a disruption to the MSP would materially affect the client’s own operations.
  • Size thresholds: the bill is expected to apply size criteria (likely aligned with existing NIS conventions around headcount and turnover) to focus regulation on medium and large providers. The exact thresholds will be confirmed in secondary legislation after Royal Assent.

Who Is Out of Scope

Smaller MSPs that fall below the size threshold, sole-trader consultants, and providers of one-off project-based IT work are expected to sit outside the RMSP definition. Providers who supply commodity software licences or hardware without an ongoing managed service element are also likely out of scope.

The table below summarises the broad distinction:

Table: Who Is Out of Scope
CharacteristicLikely In Scope (RMSP)Likely Out of Scope
Service modelOngoing managed IT or security servicesOne-off projects, staff augmentation, resale only
Client dependencyClients rely on the MSP for continuity of operationsAd-hoc or easily substituted services
Organisation sizeMeets medium/large thresholds (to be set in secondary legislation)Below threshold
Regulatory oversightICONone (under this bill)
Incident reporting dutyYes, mandatoryNo direct duty under NIS

New Duties for In-Scope RMSPs

Once the bill receives Royal Assent and the secondary legislation is in place, RMSPs will face three categories of obligation.

1. Security Measures

RMSPs must implement appropriate and proportionate technical and organisational measures to manage risks to their network and information systems. This aligns with the existing duty on operators of essential services but applies it directly to the managed service provider, not just to the end client. In practice, expect requirements around access controls, vulnerability management, patching, encryption, business continuity, and supply-chain risk management.

2. Incident Reporting

RMSPs will be required to report significant security incidents to the ICO within prescribed timeframes. The government has indicated that reporting thresholds and timelines will be set out in secondary legislation, but early indications from the GOV.UK factsheet suggest alignment with the existing NIS reporting model: an initial notification within a short window (likely 24 to 72 hours) and a fuller report to follow.

3. Regulator Oversight

The ICO will act as the competent authority for RMSPs. That means the ICO can request information, conduct assessments, issue guidance, and take enforcement action where an RMSP fails to meet its duties. For MSP owners accustomed to operating without a sectoral regulator, this is a meaningful shift. You will have a named authority with the power to audit your security posture.

Timeline: What Happens After Royal Assent

The bill must complete its passage through the Lords (committee stage, report stage, third reading), return to the Commons for consideration of any Lords amendments, and then receive Royal Assent. Based on the current parliamentary schedule, most observers (including analysis from law firms such as Clifford Chance and Travers Smith) anticipate Royal Assent in late 2026 or early 2027, though the exact date depends on parliamentary timetabling.

After Royal Assent, the government will need to lay secondary legislation to define the specific thresholds, reporting timelines, and technical standards that apply to RMSPs. This means there will be a gap between the bill becoming an Act and the duties becoming enforceable. How long that gap lasts is uncertain, but a period of 12 to 18 months for secondary legislation and implementation is common for regulatory changes of this kind.

Table: Timeline: What Happens After Royal Assent
StageStatus (September 2026)Expected Timing
House of Commons stagesCompleteDone
Lords committee stageIn progress (since 1 September 2026)Autumn 2026
Lords report and third readingPendingLate 2026 / early 2027
Royal AssentPendingLate 2026 / early 2027 (estimated)
Secondary legislation (thresholds, reporting rules)Not started2027 (estimated)
Duties enforceable on RMSPsNot yet2027 or 2028 (estimated)

Dates beyond Lords committee stage are estimates based on typical parliamentary timelines, not confirmed government commitments.

The Supply-Chain Effect: Why Out-of-Scope MSPs Are Not Off the Hook

If your MSP falls below the size threshold, you might assume the bill does not affect you. Technically, you would be right: you will not be a regulated entity. Practically, you will still feel the effects.

Here is why. The bill strengthens the supply-chain risk management duties of organisations that are regulated, whether they are operators of essential services, digital service providers, or now RMSPs themselves. Those organisations need to demonstrate to the ICO that they are managing third-party risk effectively. And they demonstrate that by pushing security requirements onto their suppliers, including smaller MSPs.

What does that look like in practice?

  • Security questionnaires: Expect more of them, and expect them to be more detailed. Regulated clients will need to evidence that their MSP suppliers meet specific security standards, so the questionnaires will map directly to the NIS measures their regulator expects.
  • Contract clauses: Incident notification clauses, right-to-audit provisions, and minimum security requirements will become standard rather than optional in MSP contracts with regulated buyers.
  • Annual reassessments: Where a client previously sent you a questionnaire once at onboarding, they will now reassess you annually or even quarterly to satisfy their own compliance obligations.

For a smaller MSP handling 20 or 30 regulated clients, this creates a serious operational burden. Each client may send a different questionnaire format, with different timelines and different expectations. Tools like ResponseHub exist precisely for this situation: building a single knowledge base from your policies and past responses, then auto-completing incoming questionnaires so your team is not spending days on each one.

The bottom line: the bill creates a two-tier effect. Large MSPs are regulated directly. Smaller MSPs are regulated indirectly, through the purchasing and due-diligence requirements of their clients.

The RMSP Readiness Checklist

Whether you expect to be in scope or not, the following steps help you prepare for the bill’s direct and indirect effects. Think of this as the Five-Point RMSP Readiness Framework.

1. Determine Your Likely Classification

Review the GOV.UK RMSP factsheet and assess your service model, client dependencies, and organisation size against the criteria. If you are close to the expected thresholds, plan as if you are in scope.

2. Map Your Current Security Posture Against NIS Requirements

The NIS framework’s security principles (risk management, asset management, supply chain, service protection, detection, response) are well documented by the NCSC. Run a gap analysis against these principles now, before the secondary legislation locks in the specifics. If you have not settled on a risk management framework to structure that analysis, choose one before you start: the gap analysis is far more useful when it maps to something you will keep maintaining.

3. Build or Update Your Incident Reporting Process

If you do not already have a documented incident response plan and reporting process with defined timelines, create one. Align it to a 24-hour initial notification and 72-hour follow-up structure, which reflects both the existing NIS model and the direction indicated in the bill.

4. Audit Your Own Supply Chain

You will be expected to manage risk from your suppliers too. Document who your critical vendors are, what security assurances you hold for each, and where the gaps sit.

5. Prepare for Inbound Due Diligence

Start consolidating your security documentation, policies, certifications, and past questionnaire responses into a single, maintainable source of truth. When regulated clients come asking questions (and they will), you want to respond in hours, not weeks. Providers who have already added vCISO services will recognise the pattern: the same consolidated evidence base serves your own due diligence and your clients’.

Why This Matters Now

The bill is not yet law, and the specific thresholds and timelines will only become clear once secondary legislation is published. It would be easy to wait. But MSP owners who have been through regulatory transitions before know that the organisations best positioned when the rules take effect are the ones that started preparing while the bill was still in Parliament.

Your regulated clients are already planning for the new requirements. Some are already updating their supplier questionnaires and contract templates. If you can demonstrate readiness now, you differentiate yourself in every procurement conversation. If you wait until enforcement begins, you are scrambling alongside everyone else.

The effort compounds. Every policy you document today, every gap you close, every incident process you rehearse feeds into the evidence base you will rely on when the ICO (or your clients’ auditors) come asking.

Frequently Asked Questions

Is the Cyber Security and Resilience Bill law yet?

No. As of September 2026, the bill has passed through the House of Commons and is in Lords committee stage. It must complete the Lords stages, receive Royal Assent, and then secondary legislation must be laid before the new duties become enforceable. You can track its progress at bills.parliament.uk/bills/4035.

Does the bill apply to all UK managed service providers?

No. The bill introduces the concept of “relevant managed service providers” (RMSPs) and applies to those that meet specific criteria around service type, client dependency, and organisation size. Smaller MSPs that fall below the size thresholds are expected to be out of scope for direct regulation, though they will face indirect pressure from regulated clients.

What regulator will oversee RMSPs?

The Information Commissioner’s Office (ICO) will act as the competent authority for relevant managed service providers under the bill. The ICO will have powers to request information, conduct assessments, and take enforcement action.

What should out-of-scope MSPs do to prepare?

Even if you are not directly regulated, your clients who are in scope will push NIS-aligned security requirements onto you through questionnaires, contract clauses, and annual reassessments. Prepare by consolidating your security documentation, mapping your posture against NIS principles, and building a repeatable process for responding to supplier due-diligence requests.

When will RMSPs need to comply?

The exact compliance date depends on when the bill receives Royal Assent and when the secondary legislation setting out thresholds and technical requirements is published. A reasonable estimate is that duties will become enforceable in 2027 or 2028, but this is not confirmed. Monitor the bill’s progress and any government announcements for definitive dates.

How does the bill relate to existing certifications like ISO 27001 or Cyber Essentials?

The bill does not replace existing certifications. Holding ISO 27001 or Cyber Essentials Plus will likely support your compliance position, as there is significant overlap between those frameworks and the NIS security principles. However, certifications alone may not satisfy every requirement, particularly around incident reporting timelines and regulator cooperation, which are specific to the NIS regime.

Get back to closing deals and shipping product

Upload your policies, let AI draft cited answers, and get your team reviewing instead of writing. No sales call — self-serve in under 5 minutes.

  • 7-day free trial
  • Cancel anytime
  • Full product