Where it has got to and what it will require · Last reviewed 21 September 2026
The Cyber Security and Resilience Bill will bring managed IT providers under statutory regulation by the Information Commission, with duties to register, secure their own systems and report significant incidents. It is not law yet. This is what it says, where it has got to, and the part worth acting on now.
A word of caution before any of it. Until the Bill completes its passage and the secondary legislation is published, nobody outside the process knows the final detail. Do not rebuild anything around commentary, including this article. Build around the things that are useful either way, and there are several.
It was introduced to Parliament in November 2025, had its second reading in January 2026, went through committee in February and cleared the Commons in the summer. It is now before the Lords. Once it receives Royal Assent, the duties on managed service providers come into force through secondary legislation rather than immediately, and the government has said it intends to consult on implementation.
So the honest position is: this is coming, the direction is settled, and the date is not. Anyone offering you a compliance deadline for it today is guessing.
The government's factsheet on relevant managed service providers defines one as a person providing managed services in the UK, whether or not established in the UK, who is not a small or micro enterprise.
Managed services are drawn broadly, and cover the things most SMEs actually buy: IT outsourcing including remote support and helpdesks, management of applications such as email, IT infrastructure management, and managed security services such as a security operations centre.
Four duties, none of them exotic:
The regulator is the Information Commission, the body formerly known as the Information Commissioner's Office. That is a deliberate choice: the organisation that already regulates how your data is handled will also regulate the suppliers holding the keys to it.
For most SMEs, the provider rather than you. But the reason the Bill exists is worth understanding, because it explains why clients should care about a law aimed at somebody else.
Attackers worked out some time ago that compromising one managed service provider gives access to every client that provider supports. One set of credentials, dozens of businesses. Regulating the provider is an attempt to close that route, and it means the question "how do you secure your own systems?" stops being an awkward thing to ask a supplier and becomes a routine one.
No, and it is worth being clear about this because the exemption will be misrepresented. Small and micro enterprises sit outside the definition of a relevant managed service provider, which is a statement about who the regulator will oversee. It is not a statement about who is competent.
A small provider with rigorous practices may protect you considerably better than a large one doing the minimum required to stay registered. The reverse is also true. The useful question is never the size of the provider, it is what they actually do, and whether they will put it in writing.
Nothing that depends on the final wording. Everything that would be useful anyway:
These are three different instruments pointed at the same problem. Cyber Essentials certifies a baseline of technical controls. ISO 27001 certifies a management system for handling information risk. The Bill is statutory regulation with a named regulator and enforcement behind it.
A provider that already holds those certifications should find the duties familiar rather than disruptive, because the practices overlap heavily. A provider that holds neither, and tells you regulation will not apply to them, is telling you something useful.
No. At the time of writing it is still passing through Parliament. It was introduced in November 2025, cleared the Commons during 2026 and is now before the Lords. Even once it receives Royal Assent, the duties on managed service providers are brought into force through secondary legislation, and the government has said it intends to consult on implementation. There is no commencement date yet.
The government's factsheet defines an RMSP as a person providing managed services in the UK, whether or not they are established in the UK, who is not a small or micro enterprise. Managed services include IT outsourcing such as remote support and helpdesks, management of applications including email, IT infrastructure management, and managed security services such as a security operations centre. Small and micro providers are outside the definition.
Four things. Register with the Information Commission, giving name, contact details and an address for service. Appoint a UK representative if they are based overseas. Identify and take appropriate and proportionate measures to manage the risks to the networks and information systems the managed service relies on. And notify the Information Commission of significant incidents. Once the regulations commence, providers have three months to register.
For most SMEs, it regulates the provider rather than you. The reason it still matters is supply chain: the Bill exists because attackers have worked out that compromising one managed provider reaches all of its clients at once. The practical effect for a client is that questions about how your provider secures its own systems stop being awkward and start being routine.
Small and micro enterprises fall outside the definition of a relevant managed service provider, so the registration and reporting duties are not aimed at them. That is a statement about who the regulator will oversee, not a statement about who is secure. A smaller provider with strong practices may well protect you better than a larger one meeting a minimum, and the reverse is equally possible. Ask about the practices rather than the size.
Nothing that depends on the final wording, because nobody outside the process knows it yet. What pays off regardless is knowing which suppliers hold administrative access to your systems, what they would be required to tell you if they were breached, and how quickly. Most organisations cannot answer the first question, and that gap is a problem today, with or without the Bill.
They are different instruments aimed at the same problem. Cyber Essentials is a certification covering a baseline set of technical controls, ISO 27001 certifies a management system, and the Bill is statutory regulation with a named regulator behind it. A provider already holding certifications is likely to find the duties familiar rather than novel, because the underlying practices overlap heavily.
On the threat side of the same problem, AI-powered cyber attacks and server security covers what the attacks regulation is responding to actually look like.
Sources: the Bill's contents and progress follow the government's Cyber Security and Resilience Bill collection and the relevant managed service providers factsheet. Parliamentary stages are recorded in the House of Commons Library briefing on the Bill.
Most organisations cannot answer that in a hurry. We will produce the list, in writing, with what each supplier can reach and what they are contracted to tell you if something goes wrong.
ISO 27001 and ISO 9001 certified · Cyber Essentials · Same-day on-site engineer cover nationwide · Family owned since 1989