Compliance, Standards and Contracts
UK Cyber Security and Resilience Bill: What SMBs Need to Know
The Cyber Security and Resilience Bill is the biggest shake-up of UK cyber regulation in years, and plenty of small business owners have read the headlines about £17 million fines and assumed it lands on them. For most SMBs it does not, at least not directly. But the way the Bill reaches down through supply chains means a lot of small firms will feel it anyway, through the security questions their larger customers start asking.
This guide explains what the Cyber Security and Resilience Bill actually does, who falls inside its scope, and the practical steps a smaller business should take now.
Where the Bill is up to
The Cyber Security and Resilience Bill received its first reading in Parliament on 12 November 2025 and moved through the committee stage in early 2026. It is expected to receive Royal Assent during 2026, but the detailed rules come through secondary legislation and a phased rollout, so some requirements may not fully bite until closer to 2028. In short: the direction is set, the fine detail is still being written, and you have time to prepare rather than panic.
The Bill updates and widens the existing Network and Information Systems (NIS) Regulations rather than replacing them. You can follow its progress on the UK Parliament Bills page.
Who is actually in scope
The old NIS rules covered operators of essential services (energy, transport, health, drinking water, digital infrastructure) and some digital service providers. The Cyber Security and Resilience Bill pulls new categories in:
- Medium and large managed service providers (MSPs), the IT firms that remotely manage and support other companies’ systems.
- Data centres above a size threshold, broadly those with 1MW or more of IT capacity.
- Existing essential-service and digital-service operators, now with tighter duties.
If you are a typical small shop, agency, trade firm or professional practice, you are almost certainly not a regulated entity under the Bill. The exception worth checking is if you run a managed service provider, because the MSP definition is where a lot of otherwise ordinary IT businesses get caught.
The part that reaches ordinary SMBs
Here is the mechanism that matters even if you are not directly regulated: supply chain duties. Regulated organisations will be expected to take “appropriate and proportionate measures” to stop weaknesses in their suppliers from undermining essential or digital services. In practice that means your in-scope customers will push obligations down their contracts.
Expect more of the following if you supply larger or regulated organisations:
- Security clauses written into contracts and renewals.
- Requests for evidence such as Cyber Essentials certification.
- Longer, tougher supplier security questionnaires before you win the work.
So the Bill can shape your obligations second-hand, through the buyers you want to keep.
Faster incident reporting
The Bill tightens the clock on breach reporting for in-scope organisations. Where a cyber incident has, or could have, a significant adverse effect on network and information systems, the expectation is notification to the regulator within 24 hours, followed by a fuller report within 72 hours. That is quicker than many response plans are built for. Even if you are not directly regulated, a customer who is may expect you to alert them fast enough for them to meet their own deadline. Our guide on building a cyber incident response plan covers how to be ready.
The penalties (and who they apply to)
The numbers that grabbed the headlines apply to regulated entities, not the corner shop:
- Up to £17 million or 4% of worldwide turnover for the most serious breaches, whichever is higher.
- Up to £10 million or 2% of turnover for less serious breaches.
- Up to £100,000 per day for ongoing breaches.
Regulators would also gain stronger investigatory powers and the ability to recover certain costs. For an SMB, the realistic financial exposure is not a regulator’s fine, it is a lost contract or an uninsured breach, which is where cyber insurance and solid controls earn their keep.
What a small business should do now
- Work out whether you are in scope. If you run an MSP or a data centre, take advice early. If not, you are likely affected only through customers.
- Get your evidence in order. Cyber Essentials, multi-factor authentication and a written incident response plan are exactly what buyers will ask for.
- Review supplier and customer contracts. Expect new security clauses, and make sure any obligations you accept are ones you can actually meet.
- Tighten your reporting reflexes. Decide now who declares an incident, to whom, and how fast.
Frequently asked questions
Does the Cyber Security and Resilience Bill apply to small businesses? Usually not directly. It targets essential-service operators, digital service providers, medium and large managed service providers, and larger data centres. Most SMBs are affected only indirectly, through security requirements passed down by regulated customers.
When does the Cyber Security and Resilience Bill come into force? It is expected to receive Royal Assent in 2026, but the detailed obligations arrive through secondary legislation and a phased rollout, with some requirements potentially not fully in force until around 2028.
Who are the new organisations brought into scope? The main additions are medium and large managed service providers and data centres above a size threshold (broadly 1MW or more of IT capacity), alongside the essential-service and digital-service operators already covered by the NIS Regulations.
What are the fines under the Bill? For regulated entities, penalties can reach up to £17 million or 4% of worldwide turnover for the most serious breaches, up to £10 million or 2% for less serious ones, and up to £100,000 per day for continuing breaches.
How should my SMB prepare? Confirm whether you are in scope, achieve Cyber Essentials, turn on multi-factor authentication, write and test an incident response plan, and review contracts for new security clauses from larger customers.
The bottom line
The Cyber Security and Resilience Bill is aimed at the organisations that keep the country running and the IT providers behind them, not the average small business. But its supply chain reach means smaller suppliers should treat strong, evidenced cyber hygiene as the price of doing business with larger clients. Get Cyber Essentials, enable MFA and write a response plan now, and the Bill becomes a competitive edge rather than a threat.