Glossary · Who is regulated

Managed service

Definition

Under the Cyber Security and Resilience Bill, a managed service is a service provided under contract for the ongoing management of a customer’s IT systems, such as support, maintenance, monitoring or active administration, delivered by connecting to or accessing the customer’s network and information systems, whether on site or remotely. It is defined in new NIS reg 1(3B).

What counts as a managed service?

New reg 1(3B) sets two conditions. First, the service is provided by a person (P) under a contract with a customer “for the provision of ongoing management of information technology systems for the customer (whether in the form of support and maintenance, monitoring, active administration or other activities)”. Second, it is provided by P, or someone acting for P, “connecting to or otherwise obtaining access to network and information systems relied on by the customer”.

The list of activities is illustrative, not exhaustive, so outsourced IT support, remote monitoring and management, managed security and SOC services, and managed network administration are all likely to meet it. Reg 1(3C) confirms access can be on site or remote.

What is not a managed service?

Reg 1(3D) says a person does not provide a managed service merely by providing a data centre service or a public electronic communications network or service. Data centres are regulated as OES instead, and telecoms sits outside the regime.

The definition of cloud computing service also excludes managed services, so a single service cannot be both. One-off projects with no ongoing management element, and services that never touch the customer’s systems, fall outside the words of reg 1(3B). Outsourced bookkeeping or payroll alone is not a managed service unless it includes managing the client’s IT.

Worked example (illustrative)

Illustrative example

A firm that installs a new firewall for a client and leaves is doing a one-off project. The same firm signing a three-year contract to monitor that firewall, apply updates and respond to alerts through remote access is providing ongoing management with system access, which fits the reg 1(3B) definition.

Where it appears in the Bill

  • cl.9(3), reg 1(2)Adds the defined term.
  • cl.9(5), new reg 1(3B)The two-part definition.
  • cl.9(5), new reg 1(3C)On-premises or remote access both count.
  • cl.9(5), new reg 1(3D)Data centre and telecoms exclusions.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does a managed service need a written contract?

Reg 1(3B)(a) requires the service to be provided under a contract between the provider and the customer for ongoing IT management. The Bill does not require the contract to be in writing, so an informal but ongoing arrangement to manage a client’s systems could still meet the definition.

Is a managed security or SOC service a managed service?

It is likely to be. Monitoring is expressly listed as a form of ongoing management, and a SOC service normally connects to or accesses the customer’s systems through agents, log feeds or remote tooling. The provider would then be an RMSP unless it is a micro or small enterprise or otherwise exempt.

Does providing a SaaS product make me a managed service provider?

Not usually. A SaaS product is more likely to be a cloud computing service, which is a relevant digital service regulated through RDSP status. The cloud definition expressly excludes managed services, so the two are mutually exclusive. It becomes a managed service if you also manage the customer’s own IT systems under contract.

Related guidance

Official sources

More in Who is regulated

Full glossary