The UK Cyber Security and Resilience Bill cleared the House of Commons on 25 June 2026 and is now being scrutinised in the House of Lords. It’s the most significant piece of cybersecurity legislation the UK has introduced in years, and while most of the headlines focus on large regulated organisations, small businesses need to pay attention — particularly if you supply goods or services to regulated sectors.
What the Bill Actually Does
The bill is the UK’s response to the EU’s NIS2 Directive, updating and expanding the Network and Information Systems (NIS) Regulations from 2018. The original NIS regulations applied to a relatively narrow set of essential service operators — energy, transport, health, and digital infrastructure — with relatively high thresholds for inclusion. The new bill expands the scope considerably.
Key changes:
More sectors fall under mandatory cyber resilience requirements than under NIS 2018. The exact list of regulated sectors is still being refined through secondary legislation, but water, financial market infrastructure, and managed service providers are among those likely to face new obligations.
Supply chains become explicitly regulated. If you supply a regulated entity, your security posture becomes their concern and potentially a compliance issue for both parties. This is the change that affects SMEs most directly.
Incident reporting timelines tighten. Significant incidents must be reported to the relevant regulator within 24 hours of discovery, with a full technical report following within 72 hours. Under current NIS regulations, reporting timelines are considerably more relaxed.
Mandatory security audits and risk assessments apply to in-scope organisations, rather than the more advisory approach of the current framework.
Why Small Businesses Should Pay Attention
If your company doesn’t operate critical infrastructure, you might assume this bill doesn’t affect you. That’s only partly right.
The supply chain provisions are where SMEs get caught. A small software firm that builds custom systems for NHS trusts, or a managed IT service provider with local authority clients, is part of a regulated entity’s supply chain. The bill creates obligations on those regulated entities to assess and manage the security of their suppliers — which means suppliers will face security questionnaires, contractual requirements, and potentially third-party audits.
This pattern is already familiar from GDPR. When the regulation came in, large organisations imposed data protection requirements on their suppliers, and SMEs either met those requirements or lost the contract. Cyber resilience requirements are following exactly the same path.
The 24-hour incident reporting window is also likely to flow down informally through supply chain contracts. A regulated entity that needs to report incidents within 24 hours needs to know about incidents affecting their suppliers within that window. Expect contract language requiring suppliers to notify regulated clients of breaches affecting shared systems or data within 24 hours, regardless of whether the supplier is directly regulated.
What Supply Chain Obligations Look Like in Practice
If you supply regulated sector clients, expect to receive requests for:
Evidence of a security baseline. Cyber Essentials certification is the clearest, most widely recognised signal. It demonstrates you’ve addressed the five most common attack vectors — phishing defences, secure configuration, user access control, malware protection, and patch management — and it gives clients a certificate they can point to in their own compliance documentation.
A documented incident response plan. Not a policy document that lives in a shared drive — an actual procedure covering what happens in the first hour, four hours, and 24 hours of a potential breach.
Information about your own suppliers who have access to your systems or the client’s data. Fourth-party risk is increasingly on the agenda.
Annual or periodic security assessments, particularly for suppliers with privileged access to client systems.
If you haven’t yet got Cyber Essentials certification, this bill is additional motivation to get it. Certification costs £300–£500 for the self-assessment and is valid for a year. It directly addresses the most common attack paths against SMEs and produces documentation that satisfies the most common supplier questionnaire requirements.
The Supply Chain Attack Context
The bill comes against a backdrop of rising supply chain attacks. Threat actors increasingly compromise smaller, less-defended suppliers as a route into their larger clients. The MOVEit vulnerability in 2023 compromised organisations across multiple sectors simultaneously through a single shared file-transfer software provider. Similar patterns have continued since.
NCSC data shows supply chain attacks now account for a significantly larger share of serious incidents than they did five years ago. The legislation is a direct regulatory response to this trend.
What to Do Now
The bill is still working through Parliament and implementation guidance hasn’t been published. But there are sensible steps to take before it receives Royal Assent, likely in late 2026 or early 2027.
Get Cyber Essentials certified if you haven’t already. It’s the baseline your regulated clients will look for, and annual renewal keeps it current.
Write a basic incident response plan. Who makes decisions, who communicates with clients, what systems get isolated first, how do you preserve evidence. Keep it to one or two pages — something people will actually use under pressure.
Map your own supply chain. Which of your suppliers have access to your systems or your clients’ data? What’s your answer when a client asks about your third-party risk?
Talk to your regulated clients now. Find out what their compliance programmes are already requiring of suppliers. Being proactive in these conversations is much better than receiving surprise contract amendments.
NCSC’s free resources for small organisations — including the Cyber Action Plan tool at ncsc.gov.uk and the Small Business Guide — are worth working through while you wait for the formal guidance to land.