TL;DR:
- The UK Cyber Security and Resilience Bill will update and expand the existing Network and Information Systems (NIS) Regulations, potentially bringing more sectors and suppliers into scope
- Key changes include broader coverage of digital supply chains, stronger incident reporting requirements, and new powers for regulators to impose security standards
- Small businesses supplying regulated organisations should pay attention now — supply chain security requirements can flow down to you even if your business isn’t directly in scope
The UK’s existing cyber regulations — the Network and Information Systems (NIS) Regulations 2018 — were designed to protect critical infrastructure: energy, water, transport, health, and digital services. For most small businesses, they’ve been background noise. The Cyber Security and Resilience Bill changes that calculus, particularly if your business supplies, or aspires to supply, organisations in regulated sectors.
What the Current NIS Regulations Cover
Before explaining what’s changing, it helps to know where things stand. The NIS Regulations require “operators of essential services” and certain “digital service providers” to take appropriate security measures and report significant incidents to their regulator. The threshold for being an operator of essential services is high — you need to be providing a service whose disruption would have significant societal or economic impact.
If you run a plumbing company, a marketing agency, an accountancy practice, or a software consultancy, you’re almost certainly not directly covered by the NIS Regulations. But if you provide software, IT services, or critical supplies to an NHS trust, a water company, or a major digital infrastructure provider, their NIS obligations include requirements about who they use as suppliers.
That indirect pressure is where the new legislation matters most for small businesses.
What the Cyber Security and Resilience Bill Changes
The Bill has several main thrusts:
Expanding the scope of regulated entities. The government’s stated intent is to bring more types of organisations into the regulatory framework — including managed service providers (MSPs) and IT suppliers to critical sectors. If your business provides IT services or software to organisations in regulated sectors, you may become directly regulated, not just indirectly pressured through supply chain requirements.
Stronger supply chain security requirements. The existing NIS Regulations are relatively silent on supply chain. The Bill will put supply chain risk management on a more formal footing — regulated organisations will be required to assess and manage the security of their suppliers. For small businesses in these supply chains, this means your customers will be asking harder questions about your security practices, and may require evidence of controls rather than just self-certification.
Incident reporting improvements. The timeframes and scope for incident reporting are expected to tighten. Regulated organisations will need to report incidents faster (24-48 hours is the direction of travel, compared to 72 hours under current NIS Regulations) and report a broader category of incidents. This matters to you if you’re a supplier, because incidents affecting your systems that impact your customer’s service may trigger their reporting obligations — which in turn creates pressure on you to detect and disclose quickly.
New regulatory powers. The Bill gives regulators (the sector-specific competent authorities and the NCSC) stronger powers to investigate, inspect, and impose requirements on regulated entities. This includes proactive powers to require security assessments rather than only acting after an incident.
Is Your Business Directly Affected?
Direct applicability depends on whether you fall within the expanded scope. The categories most likely to be brought in:
- Managed service providers supplying IT services to critical sectors
- Software providers whose products are used by regulated entities as part of their essential service delivery
- Data centre operators providing hosting or co-location to regulated sectors
- Cloud service providers with significant presence in regulated sectors
For most small businesses — retail, hospitality, professional services, construction, manufacturing — direct regulatory scope under the Bill is unlikely unless you specifically serve regulated sectors in a technical capacity.
The Supply Chain Effect (Which Affects More Businesses)
Here’s where more small businesses feel the impact. Whether or not your business is directly in scope, if you supply regulated organisations, their obligations flow to you through procurement and contract requirements.
This is already happening under existing NIS Regulations. NHS procurement now routinely includes cyber security questionnaires and requirements for suppliers. Central government procurement through frameworks like G-Cloud requires suppliers to meet Cyber Essentials certification as a baseline. The Cyber Security and Resilience Bill formalises and expands this — regulated organisations will have stronger reasons to impose requirements on their supply chains and to actually audit whether those requirements are met.
If you’re currently supplying a regulated sector without any formal security accreditation, now is the time to get ahead of this. The practical minimum:
- Cyber Essentials certification — the UK government’s baseline scheme, self-assessed or independently verified. Required for many government contracts and increasingly a baseline expectation in other regulated sectors.
- A documented approach to security — if you can’t explain your password policy, how you keep software updated, or how you back up data, you’ll struggle with supplier questionnaires regardless of what you actually do in practice.
- A way to detect and report security incidents — if a regulated customer experiences an incident that they traced back to your systems, they need to be able to tell their regulator what happened. If you can’t give them an accurate timeline, that creates problems for both of you.
Timeline
The Bill was introduced to Parliament in 2025. The legislative timeline for complex bills like this is typically one to two years from introduction to Royal Assent, with implementation dates set after that. The regulations that implement the Bill’s provisions — which is where the actual details appear — will follow after Royal Assent.
That timeline means 2026-2027 for the Bill to pass, potentially 2027-2028 for the implementing regulations to take effect. This is not an immediate compliance deadline. It is the right window to get your security basics in order so that compliance, when it arrives, is a documentation exercise rather than a programme of work.
What to Do Now
If you supply regulated sectors or aspire to: Get Cyber Essentials certified. It’s affordable (the basic self-assessed version starts at a few hundred pounds), credible, and specifically what regulators and procurement teams look for. Use the NCSC’s free tools (Board Toolkit, Cyber Action Toolkit) to assess where gaps are.
If you’re not sure whether you’re in scope: The NCSC publishes sector-specific guidance and the government will consult extensively on the expanded scope. Stay on the NCSC mailing list and watch for consultation documents if you operate in or adjacent to regulated sectors.
If you’re well ahead of Cyber Essentials: ISO 27001 certification or SOC 2 are the next tier that regulated sector customers and enterprise procurement will ask for. They’re more involved to achieve but provide stronger credibility for higher-value supply relationships.
The most important thing to understand about the Cyber Security and Resilience Bill from a small business perspective is that it accelerates a trend that’s already underway: regulated organisations taking supply chain security seriously. Getting ahead of it is easier than being forced to comply under contract pressure.