UK Cyber Security and Resilience Bill Advances in Lords, Expanding NIS Rules to MSPs
The Cyber Security and Resilience (Network and Information Systems) Bill, introduced in the House of Commons on 12 November 2025, passed its House of Lords second reading on 14 July 2026, with Lords committee stage scheduled for September 2026. The bill amends the NIS Regulations 2018 to bring medium and large managed service providers and data centres at or above 1 megawatt rated IT load into regulation for the first time. It also introduces two-stage incident reporting: an initial notification within 24 hours of becoming aware of an incident and a full report within 72 hours, with the NCSC informed at the same time as the regulator.
Key Analytics
Impact Analysis
If enacted as drafted, MSPs serving UK customers (whether or not established in the UK) would take on statutory security and incident reporting duties overseen by the Information Commission, while in-scope data centre operators would be regulated by Ofcom as providers of an essential service. Reportable incidents would expand to include ransomware and pre-positioning attacks that have not yet disrupted services, and providers would have a new duty to notify customers likely affected by a breach; the current flat GBP 17 million penalty cap would be replaced with turnover-based maximums. As of August 2026 the bill is not yet law: Royal Assent is expected in late 2026, and the substantive duties are expected to commence through secondary legislation phased in from 2027.
Recommended Actions
- Determine whether your organization would meet the proposed relevant managed service provider definition: a medium or large provider of ongoing contracted management of IT systems, networks, or infrastructure for UK customers
- Assess whether any data centre operations reach the proposed 1 megawatt rated IT load threshold that would trigger registration and security duties under Ofcom oversight
- Benchmark incident response runbooks against the proposed two-stage clock (24-hour initial notification, 72-hour full report), including detection and escalation of pre-positioning and ransomware intrusions that have not yet disrupted service
- Prepare customer notification procedures for breaches likely to affect clients, since the bill would make such notifications a statutory duty for data centres and managed and digital service providers
- Track the bill's Lords committee stage (September 2026) and subsequent secondary legislation for final thresholds, commencement dates, and regulator guidance before committing to a compliance architecture
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Scope analysis across MSP and data centre thresholds, including the 1 megawatt rated IT load test
- ›Runbook benchmarking against the proposed two-stage clock (24-hour initial, 72-hour full report)
- ›Customer notification procedure drafting ahead of the proposed statutory duty
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 40 to 85 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.