Get a free audit

Field Notes / Compliance

The Cyber Security and Resilience Bill Puts Your MSP in Scope. Here Is What You Will Have to Prove.

If you manage IT for other businesses under contract and you can reach their systems, the Bill makes you a "relevant managed service provider": registered with the Information Commission, held to appropriate and proportionate security measures, and reporting significant incidents within 24 hours. Small and micro firms are out. Everyone else is in, wherever they are based. Here is what the regulator will ask you to show, and why a policy will not answer it.

Author
Red Team Partners
Read
11 MIN READ
Filed
17 Sep 2026
London at dusk seen from above, the city whose IT is run, in large part, by managed service providers about to be regulated for the first time.

01 What the Bill is

The government published the Cyber Security and Resilience (Network and Information Systems) Bill and its factsheets on 12 November 2025 DSIT factsheets 2025 . It updates the NIS Regulations 2018, which currently cover operators of essential services such as energy, water, transport and health, plus a narrow set of digital service providers. The Bill widens that net in three directions: managed service providers, data centres, and suppliers a regulator designates as critical. It also raises the security bar for everyone already inside, and rewrites incident reporting around a 24-hour clock.

The government's reasoning is blunt. In 2024 the UK was the most targeted country in Europe for cyber attacks; over 40 per cent of UK businesses, more than 600,000 organisations, experienced one; and the cost to UK business runs at an estimated £14.7 billion a year, about 0.5 per cent of GDP DSIT summary factsheet . The MSP factsheet adds the incident that made the case inside Whitehall: in May 2024 an attack on a managed service provider let hackers reach the Ministry of Defence's payroll DSIT RMSP factsheet .

That is the shape of the problem the Bill exists to fix. An MSP holds trusted, standing access to many client networks at once. Compromise one provider and you compromise its book. The factsheet calls this the "one to many" impact, and it is why MSPs stopped being a supplier category and became a regulated one.

02 Are you a relevant managed service provider?

The definition has three parts, and most UK IT providers with more than a handful of staff meet all three DSIT RMSP factsheet .

  • You provide a managed service. A service under a contract with another organisation, involving ongoing management, support or monitoring, that relies on access to the customer's network and information systems. Helpdesk, patching, backup, monitoring, firewall management, endpoint management and incident response all qualify.
  • You provide it in the UK. Whether or not you are established here. An overseas provider serving UK customers is in scope and must appoint a UK representative.
  • You are not a small or micro enterprise. The small and micro exemption is the only size test. Above it, headcount and turnover do not change the answer.

Two details catch people out. First, it does not matter whether your access is on the customer's premises or remote; the factsheet says so in as many words. Second, security providers are not exempt because they are the good guys: the government's own example of an in-scope firm is an IT security company delivering firewall management, intrusion detection and incident response through a connection to a customer's systems DSIT RMSP factsheet . An MSSP is an RMSP.

03 The duties, in plain terms

Once the RMSP regulations commence, four obligations apply DSIT RMSP factsheet .

  1. Register. Within three months of commencement, with the Information Commission (the former ICO), giving your legal name, contact details and an address for service of documents. Overseas providers name a UK representative.
  2. Secure the systems the service relies on. Appropriate and proportionate measures to manage risks to the networks and information systems your managed service depends on, including data stored or processed on them. The detail arrives in secondary legislation and regulator guidance.
  3. Report significant incidents. An initial notification within 24 hours of becoming aware, a fuller report within 72 hours DSIT incident reporting . What counts as significant is defined in secondary legislation; the Bill's direction is that disruption to the service and to customers is the test.
  4. Tell your customers. Where a significant incident is likely to have affected them. For an MSP that is the whole client list, in writing, inside the same 72 hours.

On penalties, the current NIS regime caps fines at £17 million for the most serious failures NIS Regulations 2018, reg. 18 . The government's summary says that maximum will be amended upward, aligned with comparable regimes such as UK GDPR DSIT summary factsheet . Read that as a floor, not a ceiling.

04 "Appropriate and proportionate" is a question, not a checkbox

Every MSP reading the Bill lands on the same two words and asks the same thing: proportionate to what? The honest answer is that the regulator will decide case by case, and it will decide with hindsight, after an incident, with your client list in front of it. Proportionate for a provider holding domain admin in forty customer environments is not the same as proportionate for a two-person web agency.

The test the regulator will actually apply is simpler than the wording. Can you show that the measures you claim exist, and that they work? A policy shows intent. A Cyber Essentials certificate shows five controls were in place on the day of assessment, and Cyber Essentials v3.3 already gives you 14 days to install a high-risk patch Cyber Essentials v3.3 . Neither shows that a stolen technician credential could not reach a client's backups.

The numbers argue for testing rather than attesting. Mandiant put the median time an attacker spent inside a victim network in 2025 at 14 days before discovery Mandiant M-Trends 2026 . Only 13 per cent of UK businesses ran a penetration test in the last twelve months, while 43 per cent reported a breach or attack DSIT CSBS 2025/26 . The gap between those two figures is the gap the Bill is trying to close, and for an MSP it is a gap in the one place the regulator will look: the paths from your estate into your clients'.

05 What to do before commencement

The duties commence through secondary legislation after Royal Assent, and the government has said it will coordinate that so guidance exists before compliance begins DSIT summary factsheet . That is your window. Use it in this order.

Start with the scope question and write the answer down: which contracts involve access to client systems, and which entity holds them. Then map the estate your managed service relies on, not your clients' estates, yours: RMM, remote access, identity, privileged accounts, backups. Have an independent team attack that estate from the position an intruder would take, a phished engineer or a leaked credential, and prove what it reaches. Fix what opens, re-test, and keep the record current. When the registration window opens you will have the one thing the regulator cannot get from a policy: proof, dated this month.

That is the work we do, and for MSPs it does double duty. The same CREST-certified test that answers the Information Commission is the test your clients will start asking you for, because the Bill puts the question in front of every board you serve. We deliver it under your brand if you want to keep the account, with a year of re-tests so the proof does not age. Get a free audit of your own estate first and see what an attacker reaches from outside.

References

Sources

  1. Department for Science, Innovation & Technology. Cyber Security and Resilience (Network and Information Systems) Bill: factsheets. Published 12 November 2025, updated 30 June 2026. gov.uk
  2. DSIT. Factsheet: Relevant managed service providers. gov.uk
  3. DSIT. Factsheet: Summary of the Bill. gov.uk
  4. DSIT. Factsheet: Incident reporting. gov.uk
  5. The Network and Information Systems Regulations 2018, regulation 18 (penalties). legislation.gov.uk
  6. DSIT. Cyber Security Breaches Survey 2025/2026. Official statistics, 30 April 2026. gov.uk
  7. Mandiant. M-Trends 2026, drawn from over 500,000 hours of incident response in 2025. cloud.google.com
  8. NCSC / IASME. Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026. ncsc.gov.uk