How this links to the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill carries the size exemption over to the new managed service provider regime and restates it for digital services. The Bill gives no numbers of its own. It points to an EU Recommendation, so the test in UK law depends on figures set in euro, and on EU aggregation rules the Bill neither adopts nor disapplies.
- Clause 7(8): limb (iii) of the relevant digital service provider definition excludes micro and small enterprises.
- Clause 9(4): the same limb (iii) applies to the relevant managed service provider definition.
- The wording in both is "is not a micro or small enterprise as defined in Commission Recommendation 2003/361/EC".
- The exemption is separate from the public authority oversight exemption in limb (iv).
- There is no size exemption for operators of essential services or for a designated critical supplier.
What are the size ceilings?
Commission Recommendation 2003/361/EC sets the ceilings. A small enterprise has fewer than 50 staff and either annual turnover or an annual balance sheet total of no more than €10 million. A micro enterprise has fewer than 10 staff and turnover or balance sheet of no more than €2 million.
The headcount test must always be met. The financial test is either/or, so a business with 40 staff, €15 million turnover and a €6 million balance sheet is still small. Because the Bill excludes micro and small enterprises together, the practical line is the small enterprise ceiling. A medium-sized business is not exempt.
Which organisations does the exemption help?
It matters most for smaller managed service providers, which are being brought into the NIS regime for the first time, and for small cloud, online marketplace and search providers. An IT support firm with 30 staff and £5 million of revenue is very likely to be exempt, provided it is not part of a larger group.
The exemption does not remove an exempt provider from its customers’ contracts. Regulated customers must manage supply chain risk, so small suppliers should expect security questions and incident notification clauses from them.
What questions does the Bill leave open?
Two points are not settled, and no UK source yet answers them.
- Currency. The ceilings are in euro. Neither the Bill nor the Government factsheets give a sterling figure or a rule for conversion.
- Group aggregation. The Recommendation’s Annex requires staff and financial data from linked and partner enterprises to be added together. The Bill neither applies nor disapplies those rules expressly, so whether a small UK subsidiary of a large group is exempt is uncertain. On the Recommendation’s own terms, it probably is not.
Common misconceptions
Myth: Any business with fewer than 50 staff is exempt.
Reality: Headcount is only one limb. The business must also have turnover or a balance sheet total of €10 million or less, and group data may be aggregated.
Myth: Small businesses are outside the Cyber Security and Resilience Bill entirely.
Reality: The exemption applies only to RDSP and RMSP status. A small business that runs an essential service above a threshold, or is designated as a critical supplier, is not covered by it.
Where it appears in the Bill
- Clause 7(8)New reg 1(3)(e)(iii): micro or small enterprise exclusion for RDSPs.
- Clause 9(4)New reg 1(3)(ea)(iii): the same exclusion for RMSPs.
- Commission Recommendation 2003/361/ECSource of the staff, turnover and balance sheet ceilings.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is there a sterling threshold for the small enterprise exemption?
No. The Cyber Security and Resilience Bill refers only to Commission Recommendation 2003/361/EC, whose ceilings are set in euro: €10 million turnover or balance sheet for a small enterprise. Neither the Bill nor the Government factsheets give a sterling equivalent or say which exchange rate to use. Businesses close to the line should document their figures and take advice.
Is a small subsidiary of a large group exempt?
Probably not, but it is not settled. The Recommendation requires data from linked and partner enterprises to be aggregated, which would usually push a subsidiary of a large group over the ceilings. The Cyber Security and Resilience Bill does not say expressly whether those aggregation rules apply, so group companies should not assume they are exempt.
Does the small enterprise exemption apply to operators of essential services?
No. The exemption appears only in the definitions of relevant digital service provider and relevant managed service provider. Operators of essential services are identified by the sector thresholds in Schedule 2 to the NIS Regulations, which measure the service, such as customers or megawatts, rather than the size of the business. There is no general size exemption for them.