The UK government introduced the Cyber Security and Resilience Bill in the 2025 King’s Speech, and it’s been working its way through Parliament in 2025-2026. If you run a small business, you might be wondering whether this applies to you — and to be honest, for most very small businesses the direct obligations are limited. But the indirect impact through your supply chain and your managed IT service providers is worth understanding.
Here’s a plain-English breakdown of what the Bill does and what it means in practice.
Why This Bill Exists
The UK’s current cyber regulation framework for critical sectors — the Network and Information Systems (NIS) Regulations 2018 — was written when the threat landscape looked rather different. It covers “operators of essential services” (energy, transport, water, healthcare, digital infrastructure) and “digital service providers” (cloud services, online marketplaces, search engines). It doesn’t cover the managed service providers that most of those essential service operators actually rely on for their IT.
That gap became painfully obvious during incidents like the 2023 Clop ransomware campaign that hit organisations through their MOVEit file transfer service providers. An essential service operator can comply perfectly with NIS while remaining vulnerable to an attack through a supplier who faces no equivalent obligations.
The Cyber Security and Resilience Bill is the government’s response to that problem. It expands scope, strengthens incident reporting, and gives regulators more teeth.
What the Bill Changes
Expanding who’s in scope. The Bill extends mandatory security obligations to managed service providers (MSPs) — IT firms that manage technology infrastructure for other businesses. If you use an MSP to manage your IT, your MSP will now face formal security and reporting obligations under the legislation. That’s actually good news for you as a customer — it creates accountability that didn’t formally exist before.
It also expands the definition of essential service sectors to include more organisations in areas like public sector supply chains.
Stronger incident reporting. The existing NIS regulations require in-scope organisations to report significant incidents to their regulator. The Bill tightens these requirements, introducing a two-stage reporting process:
- A shorter initial notification window (likely 24 hours for significant incidents)
- A fuller report within 72 hours
The definition of what constitutes a reportable incident is also being clarified and expanded. Supply chain incidents — where a third-party supplier is breached and that breach affects your organisation — will need to be reported even if your own systems weren’t directly compromised.
More data sharing. Regulators will be able to require in-scope organisations to share threat intelligence with the NCSC to help build a picture of the national threat landscape. This is largely invisible to small businesses but improves the quality of NCSC’s guidance and warnings, which you benefit from.
Regulatory fines. The current NIS framework has enforcement powers but they’ve rarely been used and the fine levels haven’t deterred major organisations. The Bill increases the maximum fines for non-compliance and streamlines the enforcement process.
What This Means for Small Businesses
If you’re a small business that isn’t an essential service operator and isn’t an MSP, you’re probably not directly in scope for the new regulations. Most small businesses — a restaurant, a retail shop, a law firm, an accountant — aren’t covered by either the existing NIS framework or the expanded Bill.
But the indirect effects are significant.
Your MSP and cloud providers will face new obligations. If you use an IT managed service provider, or cloud services that qualify under the expanded scope, your suppliers will have formal security requirements they need to meet. For customers, this should translate into better security practices at your MSP and more consistent incident disclosure if your MSP is breached or experiences a significant security event affecting their customers.
In practice: ask your MSP how they’re preparing for the Bill. If they don’t know what you’re talking about, that’s useful information about their security maturity.
Supply chain security is becoming a formal accountability requirement. If you supply goods or services to organisations that are in scope — government contracts, NHS supply chains, utilities suppliers — you may start seeing enhanced security requirements in contracts and procurement questionnaires. In-scope organisations need to demonstrate they’re managing supply chain risk, and that often means passing requirements down to suppliers.
This is already happening in public sector procurement. The Cyber Essentials certification requirement in UK government contracts has been expanding, and the trend is toward more formal security attestation requirements for suppliers to regulated sectors.
The NCSC guidance ecosystem gets better. More mandatory incident reporting means the NCSC gets richer data on threats and attack patterns. That feeds into the NCSC’s guidance for all businesses — including small businesses that use resources like the Cyber Action Plan and Small Business Guide — and improves the quality of early warning signals.
What to Do Now
Most small businesses don’t need to take immediate action in response to the Bill itself. But it’s a useful prompt for a few things.
Have a conversation with your IT provider about their security practices and what obligations they’ll be operating under when the Bill takes effect. A reputable MSP should be actively preparing for the new regulatory environment and should be able to explain what that means for you as their customer.
If you supply to regulated sectors — NHS, local authority, central government, utilities — start familiarising yourself with Cyber Essentials. It’s the baseline certification most likely to be required in tender questionnaires as organisations implement supply chain security requirements. The NCSC’s website has straightforward guidance on what it involves and how to get certified.
And keep an eye on NCSC and DSIT (Department for Science, Innovation and Technology) communications as the Bill passes and implementation guidance is issued. The specifics of what’s required, and when, will become clearer through the second half of 2026 and into 2027 when implementation timelines are set.
The Bill isn’t a small business regulation directly. But it’s shaping the security expectations that flow through supply chains — and those expectations will reach most businesses eventually, one way or another.