The Cyber Security and Resilience Bill may not be law yet, but its direction is clear. The Government is raising expectations around cyber security, supplier assurance and incident reporting, and organisations that prepare now will be in a much stronger position when the new requirements arrive.
Whether your business is directly regulated or not, the changes are likely to affect you. Clients and suppliers will expect more evidence of your security posture, reporting timeframes are becoming much tighter, and ransomware reporting requirements could eventually extend much more widely. The good news is that getting ahead doesn’t mean starting from scratch. Strengthening your security foundations today will put you in a better position whatever the final legislation looks like.
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is proposed UK legislation that aims to strengthen the UK’s existing cyber security legislation by updating the Network and Information Systems (NIS) Regulations by introducing tougher requirements for organisations that provide important services or digital infrastructure.
The Bill updates the Network and Information Systems (NIS) Regulations 2018, the UK’s existing cyber security law for essential services. It does three things: it widens who’s regulated, bringing managed service providers, cloud platforms, data centres and other digital suppliers into scope for the first time; it raises the security baseline expected of essential and digital services; and it tightens the rules on reporting incidents.
As of August 2026, the Bill has passed the Commons and is at Committee stage in the House of Lords, with Royal Assent expected later this year and the detailed rules following through secondary legislation into 2027 and 2028.
Requirements of the Cyber Security Resilience Bill
The Cyber Security and Resilience Bill isn’t just a small update to existing cyber security legislation. It signals a clear shift in what’s expected of organisations when it comes to managing cyber risk and building resilience.
Some of the biggest changes include:

Faster incident reporting
Organisations will be expected to report significant cyber incidents much sooner, with an initial notification within 24 hours and a more detailed report within 72 hours. Meeting those timescales means having the right monitoring, escalation and incident response processes in place long before an attack happens.

Greater focus on supply chain security
Cyber resilience is no longer just about protecting your own organisation. The Bill places much greater emphasis on the security of suppliers, giving regulators the power to designate certain organisations as Designated Critical Suppliers (DCS). Those organisations will be expected to meet the same cyber resilience standards as Operators of Essential Services (OES).

Stronger regulatory oversight
Regulators will have broader powers to request information, carry out inspections and take enforcement action where organisations fall short. For serious failings, financial penalties linked to turnover could also apply

Demonstrating good cyber governance
The Bill also reinforces the importance of the NCSC’s Cyber Assessment Framework (CAF). Rather than simply having security controls in place, organisations will increasingly need to demonstrate that they are effectively managing cyber risk across areas such as governance, protection, detection, response and recovery.
Perhaps the biggest change is the wider expectation around resilience. It’s no longer enough to focus on preventing cyber attacks. Organisations will be expected to show they can continue operating when incidents happen, with robust business continuity planning, effective risk management and governance that aligns with recognised national standards.
What it means for your organisation today and how to get ahead
Whether or not your organisation sits within the Bill’s direct scope, you’ll feel its effects through the suppliers you depend on. The MSPs, cloud platforms and IT providers that most organisations rely on are facing tighter obligations, and they’re passing tighter security expectations, contract clauses and evidence requests on to their customers. Expect more security questionnaires, more due diligence, and more requests to evidence your own security posture, both from suppliers and from clients who are themselves in scope.
You don’t need to wait to close the gaps that matter most. Here’s where to start:
- Get an honest read on where you stand with a security gap assessment.
- Map your critical suppliers and check who’s likely to be pulled into scope, and what assurance they can already evidence.
- Revisit client contracts and data clauses so they reflect what you can genuinely guarantee on security and breach notification.
- Test your incident response plan against a realistic scenario.
- Agree your stance on ransom payments now, before you’re under pressure to decide it mid-attack.
The Bill isn’t the only piece of this. In its own summary of the Bill, the government points to the Cyber Governance Code of Practice as complementary support, voluntary guidance published by DSIT and the NCSC that sets out what good cyber governance looks like at board level: risk management, strategy, people, incident planning and assurance. It’s aimed squarely at directors and boards rather than IT teams, which makes it the natural next step once the technical gaps are being closed. We’ve written previously about what the Code asks of your board and how to get ahead of it.
How we can help
Preparing for the Cyber Security and Resilience Bill isn’t about ticking another compliance box. It’s about making sure your organisation can respond confidently when something goes wrong and demonstrate that you’re taking cyber resilience seriously.
As a Microsoft Solutions Partner accredited to ISO 27001, ISO 9001 and Cyber Essentials Plus, we help organisations strengthen their cyber resilience in a practical, achievable way. Whether you’re reviewing your security controls, improving incident response, understanding supply chain risks or building a roadmap towards compliance, we’ll help you focus on what matters most.
For some organisations, that starts with a Secure Audit to understand where they stand today. For others, it’s implementing managed security services, strengthening Microsoft 365 security, improving backup and disaster recovery, or developing and testing an incident response plan that your team knows how to follow when it counts.
Find out where you stand
Not sure how prepared your organisation is? Our free Security Scorecard takes less than 10 minutes to complete and gives you a personalised view of your current cyber resilience. You’ll receive a security score, practical recommendations and clear next steps to help you strengthen your defences before new regulatory expectations become reality.
Frequently asked questions
No. As of August 2026, it’s before Parliament, currently at Committee stage in the House of Lords, with Royal Assent expected later in 2026 and duties phased in afterwards.
Operators of essential services, such as energy, water, transport and health, and digital services, plus managed service providers, data centres and other digital suppliers.
A security gap assessment against Cyber Essentials Plus, ISO 27001 and your regulator’s expectations, so you know exactly where you stand before mapping your suppliers and testing your incident response plan.