The Cyber Security and Resilience Bill: what UK SMEs need to know in 2026

The Cyber Security and Resilience Bill is the most significant change to UK cyber regulation in nearly a decade. For UK SMEs in 2026, the most important thing to understand is not the headline clauses about critical infrastructure. It is the quieter point that the Bill brings managed service providers into the regulated security perimeter for the first time. That single change reshapes the question every SME should be asking about its IT and security supplier.

As of July 2026, the Bill has completed all its House of Commons stages, having passed third reading on 10 June 2026, and is now before the House of Lords, where it received its second reading on 14 July 2026. Royal assent is expected during 2026, with the detailed obligations phased in through secondary legislation over the period that follows, potentially into 2028. In other words, the direction is now set and the sensible time to prepare is now, not once the rules are in force.

This guide explains what the Bill does, what it means for an SME on a practical level, and what to do now, before it is in force. It is written for Managing Directors, Finance Directors and Operations Directors, not for IT specialists.

What the Cyber Security and Resilience Bill is, in plain English

The Bill was announced in the King’s Speech of July 2024. It updates and expands the Network and Information Systems Regulations 2018 (NIS Regulations), which currently cover operators of essential services and a narrow set of digital service providers. The Bill broadens the scope, tightens incident reporting, and increases the powers of the National Cyber Security Centre and the Information Commissioner’s Office to enforce.

The headline themes are familiar. More organisations brought into scope. Faster incident reporting. Tougher supplier due diligence. Larger fines for non-compliance. What is new for SMEs is the inclusion of managed service providers and managed security service providers in the regulated set. This is the change that ripples down to every SME that buys IT support, whether or not their own firm is directly in scope.

Why the Bill brings managed service providers into scope, and why that matters to SMEs

The reasoning is straightforward. A successful attack on a single managed service provider can compromise hundreds of client firms in one move. The 2020 SolarWinds incident in the United States is the canonical case. Similar patterns have played out in the UK. The Bill recognises this concentration risk and treats MSPs accordingly.

For an SME, the practical effect is that your MSP becomes part of your regulatory perimeter, not just your supplier base. The questions you ask before signing a managed services contract change. The evidence you keep on file changes. The expectation that your MSP can demonstrate its own cyber posture, in writing, becomes a board-level question.

If you are an FD or Ops Director, the implication is that “we have outsourced our IT” is no longer an answer to a cyber resilience question. You are accountable for the choice of partner, and you will need to evidence the basis for that choice.

The five practical changes SMEs should plan for

One: a wider definition of in-scope organisations. The Bill extends regulated status to a broader set of digital service providers, data centres, and managed service providers. Some SMEs that were outside NIS will now be inside, particularly those providing technology services to other businesses.

Two: tighter incident reporting timescales. The Bill introduces a two-stage regime, with an initial notification expected within 24 hours of a significant incident and a fuller report within 72 hours. SMEs that rely on their MSP for detection will need to know how their MSP’s response times line up with these obligations.

Three: mandatory supplier due diligence. In-scope organisations will be required to assess and manage the cyber risk in their supply chain. For SMEs that supply larger organisations, this means your client may now ask harder questions about your own cyber posture and the posture of your MSP.

Four: stronger enforcement powers. The Information Commissioner’s Office and sector regulators are expected to have enhanced powers to investigate, require remediation, and impose financial penalties. The penalty ceilings are expected to rise materially.

Five: alignment with EU NIS2 outcomes. The Bill is the UK’s response to the same risks the EU has addressed through NIS2. UK SMEs that supply EU regulated firms will need to demonstrate alignment with NIS2 expectations, and the Bill is the closest UK equivalent.

Supplier due diligence: the new question for your MSP

The single most important change for SMEs is the new weight on supplier due diligence. The questions you ask your MSP, and the answers you keep on file, will matter under both the Bill itself and the contractual cascade from clients who are in scope.

Practical questions an FD or Ops Director should be asking the current or prospective MSP:

  • Is the firm Microsoft-accredited at a level that demonstrates technical depth? Lanmark holds the Microsoft Support Service Designation, an accreditation held by only a handful of partners worldwide.
  • Is the firm a Microsoft Direct Cloud Solution Provider? This removes intermediaries from the Microsoft licensing position, which matters for evidence of control.
  • Does the firm operate a 24x7x365 security operations centre in-house, with named UK staff? Lanmark’s enterprise-grade managed detection and response and SOC service is delivered in-house at a price point that fits an SME budget.
  • What are the firm’s own incident response times, and how do they support the SME’s reporting obligations under the Bill?
  • Does the firm price predictably, or do incident response charges create surprise costs at the worst moment?

The MSP that can answer these in writing, with evidence, is the partner the Bill effectively requires SMEs to choose.

Incident reporting: what changes for SMEs and their providers

Under current NIS, in-scope organisations report significant incidents to the relevant competent authority. The Bill is expected to shorten the initial reporting window and broaden the definition of a reportable incident.

For an SME, this matters even when the SME itself is not directly in scope. If your MSP is in scope, their reporting obligations apply to incidents they detect on your estate. The clock on those reports starts running from the moment of detection, which means the speed at which your MSP can detect and triage an incident is now a regulatory question, not just a service one.

The shift from antivirus to managed detection and response (MDR) is the practical answer. MDR services watch the estate continuously, contain compromised endpoints within minutes, and provide the timestamped evidence the new reporting regime expects.

What to do now, before the Bill is in force

A useful 2026 action list:

  1. Identify whether your firm is likely to be in scope directly. If unsure, ask your trade body or legal adviser.
  2. Map your supplier dependencies, particularly your MSP, line-of-business platforms and data processors. Document the cyber posture you understand each to have.
  3. Ask your MSP, in writing, what their detection and response times are, what accreditations they hold, and how they will support your incident reporting obligations.
  4. Confirm endpoint detection and response (EDR) and a 24×7 managed detection and response (MDR) and SOC service are in place, with documented response time commitments.
  5. Review your Microsoft 365 licensing and configuration. A free Microsoft 365 licence review will surface the conditional access, identity and data protection gaps the Bill makes more important.
  6. If you are in a regulated sector, read our Financial services IT strategy 2026 guide alongside this one. The two regimes overlap.
  7. Sign up to gov.uk and NCSC updates so you see the Bill’s progress firsthand rather than through secondary commentary.

Where Lanmark fits

Lanmark is built for UK SMEs that need enterprise-grade cyber posture on an SME budget. We hold the Microsoft Support Service Designation, are a Microsoft Direct CSP, and run our 24x7x365 MDR and SOC in-house with named UK staff. Our pricing is per-user unlimited, which keeps cyber resilience predictable as a budget line rather than an open-ended risk.

If you would like a structured starting point, book a cyber resilience review. We will look at your current MSP arrangement against the supplier due diligence questions the Bill makes important, identify the gaps, and give you a written view you can keep on file.

Frequently asked questions

What is the Cyber Security and Resilience Bill?

A UK Bill that updates and expands the 2018 NIS Regulations. It widens the set of in-scope organisations, brings managed service providers into the regulated perimeter, tightens incident reporting, and increases enforcement powers. It is the UK’s response to the same cyber resilience risks the EU addressed through NIS2.

Does the Bill apply to my SME directly?

It depends on what your firm does. The Bill brings more digital service providers, data centres and managed service providers into scope. Many SMEs will not be in scope directly but will feel the effects through supplier relationships with in-scope clients or providers.

How does the Bill affect my MSP relationship?

Managed service providers are brought into the regulated set. The MSP you choose becomes part of your regulatory perimeter. The supplier due diligence you do, and the evidence you keep on file, will need to be more rigorous than before.

What is managed detection and response and why does the Bill make it important?

Managed detection and response (MDR) is a 24×7 service that watches an organisation’s estate for indicators of compromise, isolates affected endpoints within minutes, and provides timestamped evidence of detection and response. Under the Bill’s shorter incident reporting timescales, that speed of detection becomes a regulatory necessity, not just good practice.

Is the Bill the same as NIS2?

No, but it addresses the same risks. NIS2 is the EU directive that came into force across EU member states in October 2024. The UK has chosen to update its own framework through the Cyber Security and Resilience Bill rather than transpose NIS2 directly. The practical outcomes are broadly aligned.

What is the Microsoft Support Service Designation and why does it matter under the Bill?

The Microsoft Support Service Designation is an accreditation held by only a handful of Microsoft partners worldwide. It evidences deep capability in supporting Microsoft estates. Under the Bill’s supplier due diligence expectations, that level of external evidence helps an SME demonstrate it has chosen a credible IT partner.

How much will compliance cost an SME?

The cost depends on the gap between current posture and the Bill’s expectations. For many SMEs the largest cost is moving from antivirus and a firewall to a full MDR and SOC posture. A 50-user SME typically spends between £40 and £75 per user per month on a defensible 2026 cyber posture, with the exact figure depending on existing licensing.

When will the Bill be in force?

The Bill passed the House of Commons on 10 June 2026 and, as of July 2026, is before the House of Lords, having had its second reading there on 14 July 2026. Royal assent is expected during 2026. The exact commencement date and transitional period will be set out in the secondary legislation that follows, with phased implementation potentially running to 2028. SMEs should plan now and act in 2026 rather than wait for the in-force date.

Primary action: Book a cyber resilience review

Secondary action: Managed detection and response for SMBs