The UK’s Cyber Security and Resilience (Network and Information Systems) Bill entered Committee Stage in the House of Lords on 1 September 2026, marking a critical milestone toward the most significant overhaul of UK cyber regulation since 2018. For Kent SMEs and the managed service providers who support them,
Royal Assent is expected in late 2026
, with substantive effect likely around 2028 following implementation consultation.
This legislation introduces changes that will fundamentally alter the compliance landscape for IT service providers and their clients across the South East. Here’s what you need to know now, while there’s still time to prepare.
What the Cyber Security and Resilience Bill Changes
The existing NIS Regulations cover operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers
such as online marketplaces, search engines and cloud computing services. The new Bill significantly expands this scope.
Most critically for Kent businesses,
the Bill extends direct regulation to relevant managed service providers (RMSPs), a new statutory category distinct from RDSPs, representing the single largest scope expansion
.
The policy rationale is straightforward and well evidenced: an MSP with privileged access into hundreds of client environments is a concentration point
, making MSP compromise a systemic risk.
The Bill extends the existing NIS regulatory framework to cover managed service providers and data centres for the first time
. If your business relies on an IT support provider—or if you are that provider—this legislation will apply to you.
24-Hour Incident Reporting and Financial Penalties
The Bill introduces significantly tougher obligations than the current framework:
- 24-hour incident reporting requirements
- A broader definition of regulated entities and a two-band, turnover-based financial penalties regime that was not available under the existing NIS framework
- Fines based on £17 million turnover thresholds
The 24-hour reporting clock represents a fundamental shift. Currently, many businesses discover incidents days or weeks after initial compromise. Under the new regime, regulated entities will be legally required to report qualifying incidents within a single day—a deadline that demands continuous monitoring, clear escalation procedures, and documented incident response playbooks.
Who Must Comply
While final definitions will be set through secondary legislation following consultation, the Bill targets managed service providers with privileged access to client IT environments. This likely includes providers offering:
- Remote monitoring and management (RMM) services
- Managed endpoint detection and response
- Privileged access management
- Cloud infrastructure management
- Network operations and security operations centre (SOC) services
Data centres also fall within scope, affecting businesses that operate colocation facilities or on-premises hosting infrastructure.
How This Connects to Other Compliance Obligations in 2026
The Cyber Security and Resilience Bill does not operate in isolation. Kent SMEs face an increasingly complex compliance environment where multiple obligations intersect.
Cyber Essentials is now mandatory for public sector contracts over £5 million, required across the MOD supply chain under the DCC framework, and a condition for NHS Supply Chain suppliers handling NHS data, where Cyber Essentials Plus is the required level
.
The Cyber Resilience Pledge extends that further, asking signing organisations to require CE across their own supply chains
.
This creates a cascading compliance model: regulated MSPs will need to demonstrate security controls, and those same MSPs will increasingly require their suppliers—including hardware vendors, software providers and sub-contractors—to hold Cyber Essentials or equivalent certification.
SMEs in Kent should also be aware of overlapping requirements. As we discussed in our recent article on supply chain cyber attacks doubling to 18% in 2026, third-party risk is now a board-level concern, and vendor security assessments are becoming routine.
What Kent SMEs Should Do Before 2028
Although substantive effect is not expected until around 2028, waiting is not a strategy.
Incident volumes are up, with the majority of nationally significant incidents now attributed to nation-state activity, and the Cyber Security and Resilience Bill is advancing toward Royal Assent and will bring MSPs into regulatory scope for the first time
.
For SMEs Using Managed IT Services
- Ask your MSP about their compliance roadmap. Providers who will fall under the new regulations should already be planning their response. Ask whether they are tracking the Bill’s progress and what changes they anticipate making.
- Review your service-level agreements (SLAs). Incident notification timelines, escalation procedures and forensic preservation requirements may need updating to align with the 24-hour reporting obligation.
- Verify privileged access controls. Understand who has administrative access to your IT environment, how that access is monitored, and whether session recording or privileged access management (PAM) tools are in use.
- Prepare for stricter vendor due diligence. Larger clients and public sector contracts will increasingly require evidence that your IT provider meets regulatory standards.
For MSPs and IT Support Providers
- Map your current security posture against likely requirements. Even without final secondary legislation, you can begin implementing continuous monitoring, security information and event management (SIEM) tools, and incident response playbooks.
- Document privileged access. Maintain an up-to-date inventory of which clients you hold administrative credentials for, what access methods are used, and how that access is protected.
- Implement 24-hour detection capability. If you cannot currently detect and report a significant incident within 24 hours, that gap must close before 2028.
- Prepare for client conversations. Your clients will ask questions about compliance, penalties and regulatory risk. Have clear, documented answers ready.
Broader Context: Why MSP Regulation Matters Now
The inclusion of MSPs in the Cyber Security and Resilience Bill reflects the reality of modern cyber threats. High-profile attacks in recent years have exploited trusted IT providers to gain access to hundreds of downstream clients simultaneously—a pattern that has driven incidents across healthcare, local government and critical national infrastructure.
This legislative focus aligns with broader trends we’ve covered recently, including Microsoft’s accelerated patching guidance requiring deployment of Windows updates within three days, and the record patch volumes driven by AI-powered vulnerability discovery in 2026.
Regulated MSPs will be expected to maintain security controls at a level commensurate with the access they hold. That includes not only technical measures but also governance, staff vetting, incident response capability and regular third-party audits.
Timeline and Next Steps
The Bill’s progress through Parliament is advancing on schedule:
- 1 September 2026: Committee Stage begins in the House of Lords
- Late 2026: Royal Assent expected
- 2026 (post-Assent): Government implementation consultation
- Around 2028: Substantive effect through secondary legislation
This timeline provides a window of roughly 18 to 24 months for preparation once final regulations are published. For businesses that have not yet begun planning, that window will close quickly once detailed compliance requirements are known.
Authentication and access management will play a central role in meeting the new obligations. We recently covered Microsoft’s automatic migration from SMS and voice MFA to passkeys starting 1 September 2026, a change that directly supports the stronger identity verification MSPs will need under the new regulatory framework.
Get Expert Guidance on Compliance and Cyber Resilience
The Cyber Security and Resilience Bill represents the most significant regulatory shift for UK IT providers in nearly a decade. Whether you’re an SME relying on managed IT services or a provider preparing for new compliance obligations, understanding the requirements and planning your response now will determine whether you meet the 2028 deadline with confidence or scramble at the last minute.
Meridian Micro Limited supports businesses across Kent and the South East with IT infrastructure, security monitoring, incident response planning and regulatory compliance. If you need guidance on how the Cyber Security and Resilience Bill will affect your business, or you want to ensure your IT environment is ready for the new requirements, call us on 01303 883111 to discuss your specific situation.
