Summary of the Cyber Security & Resilience Bill

September 23, 2026
Category:
Cybersecurity

​The Cyber Security and Resilience (Network and Information Systems) Bill is the UK's proposed overhaul of the existing NIS Regulations 2018. Its purpose is to strengthen the resilience of critical services and digital infrastructure against cyber attacks. Parliament introduced it in November 2025, and it is currently progressing through the House of Lords.

Key Highlights

1. Much Wider Scope

The Bill expands the range of organisations that may fall under cyber-security regulation.

Expected additions include:

  • Medium and large Managed Service Providers (MSPs)
  • Certain data centre operators
  • Additional digital and infrastructure providers
  • Organisations supporting critical national infrastructure.

This is the area most relevant to security service providers and MSSPs. Your own presentations note that the UK intends to bring medium and large managed service providers into NIS scope.

2. Greater Board-Level Accountability

The direction of travel is clear: cyber security is moving from an IT issue to a governance issue.

Boards and executives will be expected to:

  • Demonstrate oversight of cyber risk.
  • Evidence resilience planning
  • Support compliance reporting
  • Ensure appropriate security controls are implemented.

This is consistent with the messaging already used in SecQube investor materials that "regulation is moving accountability into the boardroom."

3. Tougher Incident Reporting

The Bill strengthens reporting obligations and gives regulators better visibility of significant cyber incidents.

Organisations can expect:

  • Faster notification requirements
  • Additional reporting detail
  • Increased regulatory scrutiny

The objective is to give government and regulators a better picture of national cyber threats.

4. Critical Supplier Designation

Government will gain powers to designate certain suppliers as "critical suppliers."

Where this occurs:

  • Security requirements may be imposed directly on suppliers.
  • Supply-chain resilience becomes a regulatory concern.
  • Third-party risk management becomes more important.

This could have major implications for providers supporting healthcare, utilities, defence supply chains and other critical sectors.

5. Stronger Enforcement Powers

Regulators will receive enhanced powers to:

  • Gather information
  • Investigate security weaknesses
  • Enforce compliance
  • Take action against organisations that fail to meet obligations.

The government intends to create a more sustainable and effective enforcement regime.

6. National Security Powers

The Bill introduces additional powers enabling government intervention during serious cyber-security events affecting national security.

7. Increased Focus on Operational Resilience

The emphasis is shifting beyond prevention to:

  • Detection
  • Response
  • Recovery
  • Evidence of resilience

Organisations will need to demonstrate not only that they have controls in place, but that they can continue operating and recover quickly following an attack.

​The UK Cyber Security & Resilience Bill is expected to be the most significant UK cyber regulation update since NIS 2018.

The biggest impacts are:

  1. More organisations, especially MSPs and digital providers, will fall within scope.
  2. Boards will be held more accountable for cyber governance.
  3. Incident-reporting requirements will become stricter.
  4. Supply-chain and third-party risk management will become regulatory priorities.
  5. Regulators will gain stronger enforcement powers.
  6. Organisations will need to demonstrate not just security controls, but measurable cyber resilience.

For healthcare, defence manufacturing, critical infrastructure and MSP/MSSP markets, this Bill is likely to become a significant driver of cyber-security spending and resilience programmes over the next few years.

Written By:
Cymon Skinner