Skip to content
Back to Blog
compliance regulation||5 min read

Your IT provider may soon be regulated: what the Cyber Security and Resilience Bill means

The Cyber Security and Resilience Bill brings larger MSPs under UK cyber regulation for the first time. Who is in scope, what changes, and what to ask yours.

Dustin Rhodes
Dustin Rhodes

Stabilise

A dark indigo illustration of a Parliament-style document titled Cyber Security and Resilience Bill beside a checklist reading register, report within 24 hours, tell affected customers

For the first time, UK law is about to regulate the companies that run other businesses' IT. The Cyber Security and Resilience Bill brings managed service providers under the UK's network and information systems rules. In-scope providers will have to register with the regulator, secure the systems they use to reach your network, report serious incidents within 24 hours, and tell affected customers. Fines for the worst failures reach £17 million or 4% of turnover.

Two things are easy to miss. It isn't law yet, and even when it passes, most duties start later. And small MSPs are outside the automatic scope, including us. So the useful question for most businesses isn't "is my provider regulated?" It's "would my provider pass if it were?"

That's the short version. Here is the detail.

Where the bill is now

The bill, formally the Cyber Security and Resilience (Network and Information Systems) Bill, passed the House of Commons on 16 June 2026. It's now in the House of Lords, which went through it line by line in committee on 1, 3 and 7 September. Report stage is scheduled for 26 October (opens in a new tab).

After Royal Assent, a few parts start straight away. Most of the duties, including the ones for managed service providers, start on dates the government sets in regulations. So there's time, but not unlimited time.

Why MSPs are being brought in

The logic is simple. An MSP holds the keys to many businesses at once. If an attacker gets into the provider, they can reach every customer it manages. That's why the bill targets providers that manage IT for others by connecting to their systems, whether on site or remotely.

The bill defines a managed service as ongoing management of a customer's IT under a contract, "whether in the form of support and maintenance, monitoring, active administration or other activities", delivered by connecting to or accessing the customer's systems. Data centres and telecoms networks are dealt with separately.

Who is in scope, and who isn't

Larger MSPs are in automatically. The bill's definition of a "relevant managed service provider" covers anyone providing a managed service in the UK, wherever they're based, that "is not a micro or small enterprise". It uses the standard EU-derived definition, which draws the line at 50 staff and €10 million of turnover or balance sheet.

That's a minority of providers. Research commissioned by the government (opens in a new tab) counted 12,867 active MSPs in the UK in March 2025, and estimated that between 977 and 1,214 of them would be in scope based on their UK headcount. The large majority sit below the line.

Small MSPs are out, unless designated. A provider under that line isn't in scope automatically. But the bill also lets regulators designate a supplier as critical when a disruption to it could significantly affect essential services or other regulated providers. That power can reach smaller firms.

We're small, so we're not automatically covered. Stabilise has fewer than 10 people. We'd rather say that plainly than dress ourselves up as a regulated provider. What we can say is that we're Cyber Essentials Plus certified, which means our own controls are independently tested.

What a regulated MSP will have to do

From the bill text, an in-scope provider must:

  • Register with the Information Commission, which takes over from the ICO, and keep its details up to date.
  • Secure the systems it uses to deliver its services, taking appropriate and proportionate measures to manage the risks and to prevent or reduce the impact of incidents.
  • Report significant incidents fast. An initial notification to the Information Commission within 24 hours of becoming aware of an incident, and a full notification within 72 hours.
  • Tell affected customers. After the full notification, the provider must work out which UK customers are likely to be adversely affected and notify them, explaining why.

Penalties are real. The most serious failures can bring a fine of up to £17 million or 4% of worldwide turnover, whichever is higher. Lesser failures are capped at £10 million or 2%.

What changes for you as a customer

If your provider is in scope, you gain two things you may not have today: a legal duty on them to secure how they access your systems, and a legal duty to tell you when an incident is likely to affect you.

If your provider is small and out of scope, nothing is required of either of you. But the bill is a useful checklist all the same. These are the questions worth asking any provider:

  1. Do you expect to be in scope? A provider near the 50-staff line should already know.
  2. How would you tell us about an incident, and how fast? The bill sets 24 hours to the regulator for in-scope providers. A good provider should be able to describe how you'd hear.
  3. What access do you hold to our systems, and how is it protected? Admin accounts, remote access tools, shared passwords. Ask how each is secured and who can use it.
  4. Do you use MFA on every account that can reach our systems? It's the single control that stops most account takeovers.
  5. Can you show your own certification? Cyber Essentials Plus is independently tested. It's not the same as being regulated, but it's evidence rather than a promise.
  6. What happens to our access when someone at your firm leaves? The answer should be immediate and specific.

How we approach it

The bill won't automatically apply to us, and that's not a reason to ignore it. Every account we use to reach a client's systems is protected with MFA. When someone leaves Stabilise, their access to client systems is removed the moment they go. And we hold our own Cyber Essentials Plus certification, which independently tests controls like these. When a client needs to show their suppliers are secure, for a customer questionnaire or a supply-chain review, we help them answer with evidence rather than reassurance.

If you're reviewing your IT provider in light of the bill, or want your own setup to stand up to the same questions, that is work we do regularly. Our guide to what security investors check covers the questions your own customers are likely to ask you.

Frequently asked questions

Is the Cyber Security and Resilience Bill law yet?
No. As of 27 September 2026 it has passed the House of Commons and is in the House of Lords, with Report stage scheduled for 26 October 2026. Even after Royal Assent, most of the new duties start on dates the government sets later in regulations, so nothing changes for MSPs or their customers overnight.
Which managed service providers will be regulated?
Providers of managed services in the UK that are not micro or small enterprises. The bill uses the standard definition, which puts the line at 50 staff and 10 million euros of turnover or balance sheet. Larger MSPs are in scope automatically. A smaller provider can still be brought in if the regulator designates it as a critical supplier.
Is Stabilise covered by the new rules?
Not automatically. We are a small business under the bill's definition, so we fall outside the automatic scope for managed service providers. We protect every account that can reach a client's systems with MFA, remove a leaver's access the moment they go, and are Cyber Essentials Plus certified, but it would be wrong to claim a regulated status we do not have.
What will a regulated MSP have to do?
Register with the Information Commission, take appropriate measures to secure the systems it uses to deliver its services, report significant incidents to the Information Commission within 24 hours with a full report within 72 hours, and tell customers who are likely to be affected by an incident. Fines for the most serious failures can reach 17 million pounds or 4% of worldwide turnover.
Do I need to do anything as a customer?
Nothing is required of most customers. It is worth asking your provider whether it expects to be in scope, how it will tell you about an incident, and what access it holds to your systems. The answers are a good test of a provider whether or not the law applies to it.

Whether it is Cyber Essentials Plus, a customer's security questionnaire or a supplier review, we help businesses show their IT is secure with evidence rather than promises.

See how we get teams through security audits
macOS 27 upgrade checklist for UK businesses
Apple Mdm Security|27 August 2026|8 min

macOS 27 upgrade checklist for UK businesses

macOS 27 drops every Intel Mac, retires the old update controls, and lands mid-September. Here is the checklist to run before your fleet upgrades.

Read article