The UK’s cyber security laws are getting their biggest update since 2018. The Cyber Security and Resilience Bill will expand the existing Network and Information Systems (NIS) Regulations and, for the first time, bring many managed IT service providers into scope. Even if your organisation won’t be regulated directly, it’s likely to affect the suppliers you rely on.

Key takeaways
- Many managed IT providers will be regulated for the first time.
- Significant incidents must be reported within 24 hours, with a full report in 72.
- Fines of up to £17 million or 4% of worldwide turnover.
- Most duties are expected to apply from around 2028.
What is the Cyber Security and Resilience Bill?
The Bill was introduced to Parliament in November 2025 to strengthen the UK’s defences against attacks on essential services and the digital supply chains behind them. At the time of writing, it is progressing through the House of Lords. Royal Assent is expected in late 2026, with many of the detailed requirements to follow in secondary legislation, so most duties are not expected to apply until around 2028. You can follow its progress on GOV.UK.
Why managed service providers are included
Many of the most damaging attacks of recent years didn’t target organisations directly. They targeted the IT suppliers with trusted access to many organisations at once. The Bill responds by creating a new category of regulated business: “relevant managed service providers”. In broad terms, these are businesses that provide ongoing management, monitoring or support of a customer’s IT systems, with privileged access to them. The exact definition and thresholds will be confirmed through consultation and secondary legislation.
What the Bill requires
For organisations in scope, the main duties include:
- Faster incident reporting. An initial notification to the regulator and the NCSC within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours.
- Telling customers. A duty to notify customers who are likely to be affected by an incident.
- Appropriate security measures. Managing risks to the security of the systems and services provided.
- Significant penalties. Fines for the most serious failures of up to £17 million or 4% of worldwide turnover, whichever is higher.
What it means for SMEs
Most small and medium-sized businesses won’t be regulated by the Bill themselves. But if you use an IT provider, it raises a useful question: how well does your provider protect the access it has to your systems?
Whether or not the new rules apply to them yet, it’s reasonable to expect your IT provider to:
- hold recognised certifications, such as Cyber Essentials and ISO 27001;
- use multi-factor authentication and named accounts for every engineer who can access your systems;
- log and monitor remote access to your environment;
- have a documented incident response process, and tell you promptly if something affects you; and
- be clear about which of its own suppliers can reach your data.
Our approach
LevelUp Networks is certified to ISO 27001 and holds Cyber Essentials, and we already apply many of the principles the Bill sets out, from controlled, logged access to client systems through to documented incident management. We’ll keep clients updated as the detail of the new regime is confirmed.
If you’re not confident in how your current provider manages security, read about switching IT provider, try our free cyber security checklist, or get in touch.