Law Firms, Accountants and the Cyber Security and Resilience Bill
Professional services are not a regulated sector under HL Bill 32. This guide explains the indirect routes that still reach law firms and accountancy practices, and what to do about them.
Last updated: 14 September 2026
Law firms and accountancy firms are not a regulated sector under the Cyber Security and Resilience Bill (HL Bill 32). They are affected indirectly: as customers of managed service providers that will be regulated, as possible critical suppliers designated under regulation 14H, and directly only if they provide ongoing managed IT services to clients.
Is professional services a regulated sector under the Bill?
No. The sectors caught as operators of essential services are listed in Schedule 2 to the NIS Regulations 2018: energy, transport, health, drinking water and digital infrastructure, with data centres and large load controllers added by the Bill. Legal, accountancy, audit, tax and consulting services do not appear.
Professional services firms are not relevant digital service providers either. That category covers online marketplaces, online search engines and cloud computing services.
So there is no general duty on a law firm or accountancy practice to register, report incidents or meet security duties under the Bill simply because of what it does. The Bill reaches these firms through the suppliers they rely on, the regulated clients they serve, and the IT services some of them sell.
How can a law or accountancy firm be brought into scope?
There are six routes. Only the second and third create statutory duties for the firm itself.
| Route into scope | Regulator | Threshold or test | What it means for the firm |
|---|---|---|---|
| Client of a regulated managed service provider | Information Commission regulates the MSP, not the firm | Your MSP is an RMSP: provides a managed service in the UK and is not a micro or small enterprise | Supplier incident notices under reg 14G, new contract terms, assurance requests |
| Designated critical supplier | Competent authority of the OES, or the Information Commission | Reg 14H: direct supply to an OES, RDSP or RMSP, and disruption likely to have a significant impact on the economy or society | Direct statutory duties, to be set in secondary legislation |
| Providing managed IT to clients | Information Commission | Cl.9 managed service definition and the four RMSP conditions | Registration, reg 14B security duties, 24h and 72h reporting, customer notification |
| Part 3 regulations | Secretary of State, by future regulations | Essential activities or activity-critical supplies, once regulations under s.29(1) are made | None yet: no Part 3 regulations exist |
| Part 4 national security direction | Secretary of State (s.43) | A threat to network and information systems poses a risk to national security | Only if a direction is given to the firm |
| Contract flow-down from regulated clients | None: this is contractual | Your client is an OES, RDSP or RMSP managing its supply chain risk | Security questionnaires, audit rights, incident notice clauses |
What changes when your IT managed service provider is regulated?
This is the route most firms will feel first. Many practices outsource IT support, hosting, case or practice management systems, and security monitoring. The 2023 attack on CTS, an IT provider to UK law firms, disrupted conveyancing firms across the country and showed how one supplier can take out many practices at once.
Under clause 9, an MSP that is not a micro or small enterprise becomes a relevant managed service provider (RMSP), regulated by the Information Commission. It must:
- Take appropriate and proportionate measures to manage risks to the systems it relies on to provide managed services (reg 14B)
- Give the Information Commission an initial notification within 24 hours and a full notification within 72 hours of first becoming aware of a significant incident, with both clocks running from awareness (reg 14E)
- After the full notification, identify UK customers likely to be adversely affected and notify them, explaining the nature of the incident and why they are affected (reg 14G)
For the firm, expect revised contracts, incident notice clauses tied to these duties, and more assurance material from your provider. It also works in reverse: you should be ready to act on a reg 14G notice within hours, including your own client, SRA and data protection reporting.
Could a law firm or accountancy firm be designated a critical supplier?
In principle, yes. Regulation 14H, inserted by clause 12, lets a designated competent authority designate a person if all of the following apply:
- It supplies goods or services directly to an OES for which that authority is responsible (reg 14H(1)(a))
- It relies on network and information systems for that supply (reg 14H(1)(b))
- An incident affecting those systems could disrupt essential services, and that disruption is likely to have a significant impact on the economy or the day-to-day functioning of society in all or part of the UK (reg 14H(1)(c))
- The designation is not prevented by regulation 14I (reg 14H(1)(d))
The Information Commission has a parallel power for suppliers to RDSPs and RMSPs (reg 14H(2)). Regulators must consider whether the customer could get the service elsewhere (reg 14H(3)), and whether the risk is already managed through the customer's own duties or another regulator (reg 14H(6)). They must consult and give the supplier notice and a chance to respond (reg 14J).
Risk Ledger has argued that firms giving material support to energy, water or health operators could be designated. That is a possibility, not a certainty. Most legal and accounting work can be sourced from another firm, which counts against designation. Financial services is not an OES sector, so a firm serving banks is not caught through that relationship alone.
Does running IT for clients make a firm a managed service provider?
It can. Some accountancy groups and legal businesses run IT, cloud hosting or cyber security arms for clients. Under new regulation 1(3B), a managed service is one provided under a contract with a customer for the ongoing management of the customer's IT systems, whether as support and maintenance, monitoring, active administration or similar, delivered by connecting to or accessing systems the customer relies on. On-site or remote access both count (reg 1(3C)).
A provider is an RMSP under new regulation 1(3)(ea) only if it meets all four conditions:
- It provides a managed service in the UK, wherever it is established
- It is not designated under regulation 14H for that service
- It is not a micro or small enterprise as defined in Commission Recommendation 2003/361/EC
- It is not subject to public authority oversight, or it is but derives more than half its income from commercial activities
Regulation 1(3D) excludes data centre services and public electronic communications networks and services. DSIT's factsheet also treats advice given only by email or phone, one-off installation without ongoing management, and software sold as a product as out of scope. Advising on a client's systems is not the same as managing them.
Does the micro and small enterprise exemption help?
Only for the RMSP and RDSP routes. The Bill gives no figures; it refers to Commission Recommendation 2003/361/EC. Under that Recommendation, a small enterprise has fewer than 50 staff and annual turnover or balance sheet total of no more than 10 million euro. A micro enterprise has fewer than 10 staff and no more than 2 million euro.
Two caveats matter for professional services:
- Group aggregation: the Recommendation aggregates data for linked and partner enterprises. A small IT subsidiary of a large accountancy or legal group is unlikely to qualify. The Bill neither applies nor disapplies those rules expressly, so this is not yet settled.
- Currency: the ceilings are in euro, and no UK source gives a sterling conversion rule.
The exemption does not protect against critical supplier designation. DSIT's critical suppliers factsheet confirms that small and micro enterprises can be designated.
What do the SRA and ICAEW expect on cyber security?
Professional regulation already applies, whatever happens to the Bill. The Solicitors Regulation Authority treats cyber security as a business-critical issue. Its Code of Conduct for Firms requires effective governance, systems and controls (paragraph 2.1) and the identification, monitoring and management of all material risks (paragraph 2.5). The SRA expects firms to report serious breaches, and its cyber security thematic review found that firms holding Cyber Essentials Plus had stronger policies and procedures overall.
ICAEW publishes cyber security guidance and resources for member firms. Neither body has changed its rules because of the Bill. Evidence you build for them, such as risk assessments, testing and incident plans, is the same evidence regulated clients will ask for.
What should law firms and accountants do now?
None of these steps depends on the Bill's final wording, and each helps with SRA, ICAEW and client expectations too.
- Map your IT suppliers and identify which are likely to be RMSPs or RDSPs
- Review MSP contracts for incident notice timings, reg 14G notice handling, audit rights and exit plans
- Send supplier questionnaires, and prepare answers to the questionnaires your OES and financial services clients will send you
- Build evidence against the NCSC Cyber Assessment Framework (CAF), which regulated clients are likely to use as their benchmark
- Put an incident response retainer in place so you can meet client, SRA and data protection reporting deadlines
- Commission penetration testing of internet-facing systems, remote access and case or practice management platforms, and record remediation
- Consider Cyber Essentials Plus as a baseline
- If you sell managed IT to clients, test the four RMSP conditions against your group structure now
When will the Bill affect professional services firms?
The Bill is HL Bill 32. Lords Committee Stage sat on 1, 3, 7 and 9 September 2026. Report Stage is next, and no date has been announced. Royal Assent is expected between late 2026 and spring 2027.
Most duties commence later, through secondary legislation, towards 2028. MSPs will need time to register and prepare, so contract changes and client questionnaires are likely to reach professional services firms before any statutory duty does. Critical supplier designation comes later still, because of the clause 60(5) link to Part 3 regulations.
What penalties apply if a firm is regulated?
Penalties apply only to a firm that is itself an RMSP or a designated critical supplier. Under new regulation 18, there are two Part 2 bands:
Higher maximum: the greater of £17,000,000 and 4% of turnover, for failures such as security duty and incident notification failures (reg 18(9)).
Standard maximum: the greater of £10,000,000 and 2% of turnover, for failures such as registration and information failures (reg 18(8)).
The £100,000 per day figure belongs only to Part 4 national security directions. The 10% of turnover figure applies to Part 4 directions only once regulations under clause 49(5) are in force, and clause 32(3) sets it as the cap on any future Part 3 penalties, none of which exist yet.
Frequently Asked Questions
Does the Cyber Security and Resilience Bill apply to law firms?
Not directly. Legal services are not an essential service in Schedule 2 to the NIS Regulations 2018 and are not a relevant digital service. A law firm is caught only if it provides managed IT services to clients, is designated as a critical supplier under regulation 14H, or later falls under Part 3 regulations or a Part 4 direction. Most firms will feel the Bill through their IT providers and regulated clients.
Are accountancy firms regulated under the Cyber Security and Resilience Bill?
Accountancy is not a regulated sector under the Cyber Security and Resilience Bill. An accountancy practice becomes regulated only by meeting a separate test: for example, running ongoing managed IT for clients as a relevant managed service provider, or being designated a critical supplier to an operator of essential services. Outsourced bookkeeping or payroll alone is not a managed service unless it involves ongoing management of the client's IT systems.
Can a law firm be designated as a critical supplier?
Yes, in principle. Regulation 14H lets a competent authority designate any person that supplies goods or services directly to an operator of essential services and relies on network and information systems to do so, if an incident could disrupt essential services with a significant impact on the economy or society. There is no size exemption. No designations have been made and the Bill is not yet law.
What will change when our IT managed service provider is regulated?
If your MSP is a relevant managed service provider, it must manage security risks under regulation 14B, report significant incidents to the Information Commission within 24 hours and 72 hours of becoming aware, and then notify customers likely to be adversely affected under regulation 14G. Expect revised contracts, clearer incident notice terms and more assurance evidence from your provider.
Does the small business exemption apply to a law firm with fewer than 50 staff?
The micro and small enterprise exemption only matters if the firm provides managed or digital services itself. It uses Commission Recommendation 2003/361/EC: fewer than 50 staff and turnover or balance sheet of no more than 10 million euro. Linked and partner enterprises are aggregated, so a small entity in a larger group may not qualify. The exemption does not apply to critical supplier designation.
Is our in-house IT team a managed service provider under the Bill?
No, if it only manages the firm's own systems. A managed service requires a contract with a customer for the ongoing management of that customer's IT systems, delivered by connecting to or accessing the customer's systems. An IT subsidiary or practice that manages client networks, endpoints or security under contract could meet the definition, subject to the size and other conditions in clause 9.
What does the SRA expect from law firms on cyber security?
The SRA treats cyber security as a business-critical risk. Its Code of Conduct for Firms requires effective systems and controls (paragraph 2.1) and the identification, monitoring and management of all material risks (paragraph 2.5). It expects serious breaches to be reported to it. These duties already apply today, whatever happens to the Cyber Security and Resilience Bill.
When will the Cyber Security and Resilience Bill affect professional services firms?
Lords Committee Stage sat on 1, 3, 7 and 9 September 2026 and Report Stage has no date yet. Royal Assent is expected between late 2026 and spring 2027, with most duties commencing later through secondary legislation, towards 2028. Critical supplier designation cannot commence until the first Part 3 regulations on activity-critical supplies come into force, under clause 60(5). Supplier and client contract changes are likely to arrive sooner.
Official sources
- Cyber Security and Resilience (Network and Information Systems) Bill: UK Parliament bill page
- Read the Bill text (HL Bill 32)
- DSIT factsheet: relevant managed service providers
- DSIT factsheet: designating critical suppliers
- The Network and Information Systems Regulations 2018
- SRA: how to reduce the risk of being affected by cybercrime
- ICAEW: cyber security resources
Related guidance
Need help preparing your firm for the Cyber Security and Resilience Bill?
We help law firms and accountancy practices answer client security questionnaires, test their systems and put incident response in place before regulated clients and suppliers ask.