How this links to the Cyber Security and Resilience Bill
Managed service providers are not regulated under the NIS Regulations 2018 at all. The Cyber Security and Resilience Bill brings them in as a new category, the RMSP, with a security duty, registration, incident reporting to a 24-hour and 72-hour timetable, and a duty to tell affected customers. For many mid-sized MSPs and MSSPs this is the single biggest change in the Bill.
- Cl.9(4) inserts reg 1(3)(ea), the four-limb RMSP test, applying whether or not the provider is established in the UK.
- Cl.9(5) inserts reg 1(3B)-(3D), defining managed service and excluding data centre services and telecoms.
- Cl.10 inserts reg 14B: a duty to take appropriate and proportionate measures to manage risk, with regard to Information Commission guidance.
- Cl.14 inserts regs 14C and 14D: register with the Information Commission within 3 months, and nominate a UK representative if based abroad.
- Cl.15 and cl.16 insert regs 14E and 14G: 24-hour and 72-hour incident notifications from first awareness, then notification of likely affected UK customers.
Who counts as a relevant managed service provider?
Under new reg 1(3)(ea), an RMSP is a person which:
- provides a managed service in the United Kingdom, whether or not it is established in the UK;
- is not designated as a critical supplier under reg 14H in relation to that service;
- is not a micro or small enterprise as defined in Commission Recommendation 2003/361/EC; and
- either is not subject to public authority oversight, or is but derives more than half its income from activities of a commercial nature.
What must an RMSP do?
Reg 14B requires an RMSP to identify and take appropriate and proportionate measures to manage risks to the systems it relies on to provide managed services in the UK. The measures must, having regard to the state of the art, ensure security appropriate to the risk and prevent and minimise the impact of incidents.
An RMSP must register with the Information Commission before the registration date, which is 3 months after section 14 commences or after it first meets the test, and report changes within 7 days. It must notify significant incidents within 24 hours and give a full notification within 72 hours, both counted from first awareness, copying each to the NCSC. After the full notification it must identify and inform UK customers likely to be adversely affected (customer notification).
How are RMSPs penalised?
Under new reg 18, breaches of the reg 14B security duty, incident notification and its timing and content, directions and inspection requirements sit in the higher band: the greater of £17m and 4% of turnover. Registration, UK representative and CSIRT copying failures sit in the standard band: the greater of £10m and 2% of turnover. Both are maximums set as the greater of the two figures, so for a large group the percentage is the effective ceiling.
Worked example (illustrative)
Illustrative example
A UK IT support company with 120 staff monitors and patches servers for 300 clients through a remote management tool. It provides ongoing management of client IT systems under contract, with access to those systems, and it is above the small enterprise ceiling. Once the provisions commence it is likely to be an RMSP and must register with the Information Commission. A five-person IT consultancy doing the same work would be exempt as a micro enterprise, subject to any group aggregation.
Common misconceptions
Myth: Only cyber security firms are RMSPs.
Reality: The definition covers any ongoing IT management under contract with system access, including support, maintenance, monitoring and administration. Traditional MSPs, MSSPs and outsourced IT teams can all qualify.
Myth: Colocation and telecoms providers are RMSPs.
Reality: No. Reg 1(3D) says providing a data centre service or a public electronic communications network or service is not, of itself, providing a managed service.
Where it appears in the Bill
- cl.9(4), new reg 1(3)(ea)The RMSP test.
- cl.9(5), new reg 1(3B)-(3D)Definition of managed service and its exclusions.
- cl.9(7), reg 3(2)Information Commission becomes competent authority for RMSPs.
- cl.10, new reg 14BDuty to manage risks.
- cl.14, new regs 14C-14DRegistration and UK representative.
- cl.15-16, new regs 14E and 14GIncident reporting and customer notification.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
When do RMSP duties start?
Not at Royal Assent. The RMSP provisions come into force on days the Secretary of State appoints by regulations. Royal Assent is expected between late 2026 and spring 2027, with most duties expected to commence towards 2028. Registration is due 3 months after section 14 commences, so MSPs should prepare well before then.
Does an MSP based outside the UK have to register?
Yes, if it provides a managed service in the UK and meets the rest of the test. The RMSP definition applies whether or not the provider is established in the UK. An RMSP with its principal office abroad must also nominate a UK representative and notify the Information Commission of their contact details within the same 3-month window.
Must an RMSP tell its customers about incidents?
Yes. Under new reg 14G, after giving the Information Commission a full notification, an RMSP must take reasonable steps to establish which UK customers are likely to be adversely affected and then notify them. The notice must describe the incident and explain why the RMSP thinks that customer is likely to be affected.
Is a small MSP owned by a large group exempt?
That is not settled. The exemption uses Commission Recommendation 2003/361/EC, which normally aggregates the staff and finances of linked and partner enterprises. The Bill neither applies nor disapplies that rule expressly, and no UK guidance has yet resolved it. A group-owned MSP should not rely on the exemption without advice.