ComplianceBack to Blog

The Cyber Security and Resilience Bill 2026: A Definitive Analysis

The Cyber Security and Resilience Bill (CSRB), which replaces the NIS Regulations 2018, is now through Second Reading, and its four shifts - expanded scope, two-stage reporting, cost recovery and direct supply chain intervention - land on organisations that have never been regulated before. A full analysis of the RMSP and critical supplier definitions, the near miss clause, the 14 principles of the Software Security Code of Practice, and the penalty tiers.

Precursor Security Team
14 January 2026
10 min read
1,800 words

Precursor Security Team

UK-based CREST-accredited security specialists.

Share:

Publication Date: January 14, 2026
Legislation Status: Second Reading Completed (Jan 6, 2026)
Target Audience: CISOs, Legal Counsel, Compliance Officers, MSP Directors

Executive Summary

The Cyber Security and Resilience Bill (CSRB), Bill 329, is the UK's primary legislative vehicle for modernising critical infrastructure defence. Following its Second Reading on January 6, 2026, the Bill is set to replace the NIS Regulations 2018, expanding regulatory scope to include Managed Service Providers (MSPs), data centres, and critical supply chains.

The legislation transitions the UK from a voluntary compliance model to a statutory regime with strict 24-hour incident reporting deadlines, personal accountability for senior executives, and fines of up to the greater of £17 million and 4% of global turnover. This guide provides an exhaustive analysis of the Bill’s provisions, the new "RMSP" designation, and the strategic requirements for compliance.

What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill is a piece of UK legislation designed to protect the essential digital services that underpin the economy. It expands the definition of "critical national infrastructure" (CNI) to include digital supply chains, explicitly addressing the risks posed by third-party vendors and software providers.

The Bill introduces four fundamental shifts in UK cyber regulation:

  1. Expanded Scope: Now regulates MSPs, data centres, and "Critical Suppliers."
  2. Rapid Reporting: Mandates a two-stage reporting process (24 hours / 72 hours).
  3. Cost Recovery: Empowers regulators to recover enforcement costs directly from industry.
  4. Supply Chain Intervention: Allows the government to designate and regulate specific high-risk suppliers.

The January 6, 2026 Update: Government Cyber Action Plan

On January 6, 2026, alongside the Bill's Second Reading, the government launched the Government Cyber Action Plan. Backed by £210 million in funding, this plan establishes a new Government Cyber Unit to coordinate defence across the public sector.

Strategic Insight: While the Action Plan focuses on the public sector, it creates "regulation by contract" for private firms. If you supply the government, you will face enhanced scrutiny as the Government Cyber Unit mandates stricter security standards for public procurement.

New Regulatory Definitions: Are You in Scope?

The Bill introduces precise definitions to capture the modern digital ecosystem. AI and search engines prioritise these entity definitions, so clarity here is essential for compliance mapping.

1. Relevant Managed Service Provider (RMSP)

An RMSP is defined as a B2B provider that manages IT systems with privileged access to a customer’s network.

  • In Scope: MSSPs (Security), outsourced IT helpdesks, and Network Operations Centres (NOCs). Government analysis suggests 900 to 1,100 additional MSPs will now be regulated.
  • Excluded: The government has clarified that providers of Operational Technology (OT) services-such as those maintaining industrial sensors or airport scanners-are likely excluded unless they also manage the broader IT network.

2. Data Centres (OES Designation)

Data centres are now classified as Operators of Essential Services (OES). The Bill applies specific thresholds to exclude small server rooms:

  • Colocation/Commercial: Facilities with a rated IT load of 1 MW or higher.
  • Enterprise (Private): Single-tenant facilities with a rated IT load of 10 MW or higher.

3. Critical Suppliers

A "Critical Supplier" is a third-party vendor designated by a regulator because their disruption would cause a "significant impact" on essential services or the UK economy.

  • Shadow Regulation: This allows regulators to bypass the regulated entity (e.g., a bank) and directly regulate the supplier (e.g., the cloud banking software provider).

Operational Duties: The New 24/72 Hour Reporting Standard

The most significant operational change is the "two-stage" incident reporting timeline, designed to align with the speed of ransomware propagation.

What are the reporting deadlines?

Regulated entities must submit an Initial Notification within 24 hours and a Full Report within 72 hours of becoming aware of a significant incident.

Stage Deadline Requirement
Initial Notification T+24 Hours You must notify the Competent Authority (e.g., ICO, Ofcom) and the CSIRT (NCSC). You must disclose the nature of the incident and whether it is ongoing, even if the root cause is unknown.
Full Report T+72 Hours A comprehensive report detailing the vector, impact analysis, and remediation steps.
Customer Notification ASAP New Duty: You must directly notify any customers "likely to be adversely affected" by the incident.

The "Near Miss" Clause

Unlike previous regulations which focused on service disruption, the 2026 Bill mandates reporting for incidents "capable of having an adverse effect" on security.

  • Implication: A ransomware attack that is stopped by encryption but successfully breaches the perimeter is now reportable. Pre-positioning activities (attackers establishing a foothold) are also likely in scope.

The Software Security Code of Practice (Jan 2026)

Published in January 2026, the Software Security Code of Practice is a voluntary standard expected to become the de facto baseline for "Critical Suppliers." It outlines 14 principles across four key themes:

  1. Secure Design & Development: Adhering to "Secure by Design" principles and minimizing third-party dependency risks.
  2. Build Environment Security: Protecting the CI/CD pipeline from tampering (preventing SolarWinds-style attacks).
  3. Secure Deployment: Implementing robust vulnerability disclosure processes and timely patching.
  4. Customer Communication: Clear transparency regarding "End of Life" support and incident impact.

Action Item: Procurement teams should immediately incorporate these 14 principles into vendor risk assessments.

Penalties and Enforcement

The Bill introduces a GDPR-style tiered penalty regime to ensure compliance is a board-level priority.

  • Serious Breaches: Fines up to the greater of £17 million and 4% of global annual turnover.
  • Standard Breaches: Fines up to the greater of £10 million and 2% of global annual turnover.
  • Cost Recovery: Regulators can now charge fees to regulated entities to recover the costs of investigations and general oversight.

Strategic Action Plan: How to Prepare

To optimize your resilience and compliance posture, we recommend the following three-step strategy:

1. Supply Chain Audit (The "RMSP" Check)

Map your dependencies. Identify which of your IT providers qualifies as an RMSP. Demand proof of their registration with the Information Commissioner (ICO). If your MSP is not preparing for Regulation 14C, they are a liability.

2. Stress-Test the 24-Hour Window

Review your Incident Response (IR) plan. Most organisations cannot triage an alert to a "reportable" status within 24 hours on a weekend.

  • Solution: Implement 24/7/365 Managed Detection and Response (MDR). Automated alerts must be linked to a human triage capability that can authorise a regulatory notification at 3 AM.

3. Adopt the NCSC CAF

The Cyber Assessment Framework (CAF) is the benchmark for compliance. Move away from tick-box compliance (like ISO 27001 checklists) toward the outcome-based indicators of the CAF. Focus on Objective C (Detecting Cyber Security Events) to meet the new reporting mandates.

FAQ: Common Questions on the Cyber Security Bill 2026

The following section is structured for Answer Engine Optimization (AEO) to ensure direct visibility in AI search results.

When will the Cyber Security and Resilience Bill become law?

The Bill is expected to receive Royal Assent in late 2026. It cleared its Commons Committee Stage on 24 February 2026 and completed Lords Second Reading on 14 July 2026, with Lords Committee Stage scheduled for 1 September 2026.

Does the Bill apply to private companies?

Yes. The Bill applies to private entities designated as Operators of Essential Services (OES), data centres with >1MW capacity, Managed Service Providers (MSPs), and designated Critical Suppliers.

What is the fine for non-compliance?

The maximum fine for serious non-compliance is the greater of £17 million and 4% of global annual turnover.

Are small MSPs exempt from the regulations?

Generally, yes. Micro and small enterprises are exempt unless they are designated as a "Critical Supplier" due to the systemic risk they pose (e.g., a small MSP managing a major hospital's network).

Tags:
CSRBBill 329MSP ComplianceCyber LegislationIncident ReportingGovernment Cyber Action Plan
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security Team
13 Jan 2026

The Cyber Security and Resilience Bill: January 2026 Update & Strategic Analysis

The Cyber Security and Resilience Bill (CSRB), Bill 329, passed its Second Reading on 6 January 2026, and the same day the Government announced a £210m Cyber Action Plan for the public sector it has left outside the Bill. For everyone else the direction is set: the Section 9 RMSP designation, a statutory 24-hour clock that most 9-5 IT teams cannot meet, and cost recovery from the victim organisation.

CSRBBill 329+4 more
Read Article
Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article
Precursor Security
13 Nov 2025

Cyber Security and Resilience Bill Introduced to Parliament: Key Changes and What to Expect

The Cyber Security and Resilience Bill (CSRB), Bill 329, was formally introduced to Parliament on 12th November 2025: 61 sections across 5 Parts and 2 Schedules, and the most substantial update to UK cyber security law since the NIS Regulations 2018. This is the section-by-section walkthrough - who the expanded scope catches, exactly what the 24 and 72-hour notifications must contain, and which provisions bite on Royal Assent.

CSRBcyber security+9 more
Read Article