When Your IT Provider Becomes Regulated: The Cyber Security and Resilience Bill
On 1 September 2026, a Bill entered Committee Stage in the House of Lords that will, for the first time, make organisations like ours directly accountable to a regulator for how we secure your systems.
The Cyber Security and Resilience (Network and Information Systems) Bill has cleared all its Commons stages, entered the Lords on 25 June 2026 and completed Second Reading on 14 July. Royal Assent is expected before the end of the year. Most of its substance will then arrive through secondary legislation, so the practical effect lands somewhere around 2028.
That gap is the interesting part. The direction is settled, the detail is not, and there is a genuine planning window before anyone is being measured against it. For manufacturers carrying supply chain security obligations from their primes, that window is worth using.

The single biggest change is who is now in scope
The Bill amends the Network and Information Systems Regulations 2018, which currently cover operators of essential services in energy, transport, health, water and digital infrastructure, plus a narrow set of digital service providers.
The government's own factsheets confirm the expansion brings data centres, large load controllers and medium and large managed service providers meeting the Bill's thresholds into scope. Managed service providers get a new statutory category of their own: relevant managed service providers, or RMSPs, regulated by the Information Commission.
The policy logic is hard to argue with. An MSP (Managed Service Provider) holds privileged administrative access into every client environment it manages. That makes it a concentration point. Compromise one provider and you potentially reach every business behind it. Several of the most disruptive UK incidents of recent years have travelled exactly that route.
Whether Foundation IT meets the medium threshold is a question the secondary legislation will settle, and we do not yet know the answer. We have taken the view that it does not much matter. The standard being set is the right one for anyone holding this kind of access, and we would rather be working to it early than reading about it in 2028.
The 24 and 72 hour clock changes what "we are looking into it" means
The current regime only requires reporting once an incident has caused significant disruption, and only to the regulator, within 72 hours. The NCSC (National Cyber Security Centre) hears about it afterwards.
The Bill replaces that with a two-stage structure. A light-touch initial notification goes to the regulator within 24 hours of becoming aware that an incident is taking place, with the NCSC sighted at the same time. A fuller report follows at 72 hours. The initial notification is deliberately minimal: the organisation's name, the service affected, and brief details of what is happening.
It also widens what counts. Ransomware and pre-positioning attacks become reportable where they are likely to have a significant UK impact, even if nothing has visibly broken yet. An attacker sitting inside a network waiting to act is now an event, not a near miss.
The operational implication for any provider is uncomfortable and fair. A 24 hour clock is unworkable without detection that runs at night and at weekends, a triage process that can tell a real incident from a noisy alert, and a written escalation path that does not depend on one person answering their phone. Those are not things a provider can assemble after the fact.
The clause manufacturers should read twice
Buried in the incident reporting factsheet is the provision that matters most to you rather than to us.
Once an RMSP has filed its full notification, it must then identify which of its customers are likely to have been adversely affected, and tell them. Not just that something happened, but the reasons the provider believes that particular customer was caught, so the customer can take its own mitigating action.
Today, no such duty exists. A provider can suffer a breach that touches your environment and there is no statutory obligation to tell you it did. The Bill closes that gap, and in doing so it changes the question a board should be asking. It is no longer "has our IT provider had a problem". It is "would we be told, how quickly, and with what detail".
That question is worth asking now, well before the duty bites. A provider that can answer it clearly today is telling you something useful about how it operates. A provider that cannot is telling you something equally useful.
What to do with the planning window
Nothing here requires action this quarter. It does reward using the time.
Four things are worth getting straight, in roughly this order.
Know your own scope. Most manufacturers have never formally defined which systems, sites and cloud services make up their estate. That definition underpins everything else, including Cyber Essentials scoping, supplier questionnaires and any future regulatory conversation.
Get the baseline evidenced, not assumed. Cyber Essentials Plus (CE+) remains the most practical external check on whether the fundamentals are genuinely in place rather than believed to be. The 2026 changes made it a harder test, which is precisely what makes it a more useful one.
Write the incident runbook and test it. Who decides an incident is an incident, who contacts whom, in what order, with what facts. If your provider holds this and you have never seen it, ask to.
Turn supplier assurance into a process. The Bill makes supply chain resilience a statutory theme rather than a procurement formality. If you are a tier two or tier three supplier, the flow-down from your primes will arrive before the legislation does.
The honest summary
Regulation is arriving for the layer of the market that has historically sat outside it, and that is a good thing for the businesses that depend on it. The firms that will find 2028 straightforward are the ones that spent 2026 and 2027 building a defensible baseline rather than a compliance file.
That baseline is exactly what the Foundation phase of our Kepler framework exists to establish: risk reduction, improved resilience, modern infrastructure, and a defensible starting point you can actually evidence. Most businesses we assess are at Foundation without realising it. That is not a criticism, it is simply what reactive IT produces over time.
If you want an honest read on where your own foundations sit, our Kepler Compass session is a free 45 minutes and covers exactly this ground. No agenda either way.
What would your answer be if your IT provider had a breach tonight? Would you know by tomorrow?



Comments