·Senserity

The Cyber Security and Resilience Bill enters the Lords: what it means when vetting IT and managed service suppliers

supplier due diligencecyber securitymanaged service providersNIS regulationscomplianceUK legislation

The UK Cyber Security and Resilience (Network and Information Systems) Bill completed all its stages in the House of Commons and formally entered the House of Lords on 25 June 2026. Its second reading in the Lords took place on 14 July 2026. For procurement professionals and compliance teams who vet IT and managed service suppliers, this is not a distant procedural update. The Bill's core architecture is settled, and its obligations will reshape what you should be asking of technology suppliers before you sign a contract.

What the Bill actually does

The Bill updates the Network and Information Systems (NIS) Regulations 2018, described as "the UK's only cross-sector cyber regulations", by extending their reach to additional bodies and providing regulators with powers to discharge their obligations under the regulations. The 2018 NIS Regulations impose duties on providers of essential services and relevant digital services to have cyber security measures in place and to promptly report serious incidents. The problem is that those rules were written before the current threat environment took shape, and the Bill responds to that directly.

The Bill amends and substantially expands the existing NIS Regulations, bringing more organisations into regulatory scope, tightening incident reporting timelines, introducing a two-tier penalty regime, and giving regulators significantly stronger enforcement powers. Royal Assent is expected in late 2026, with phased implementation of the new duties running through to 2028. The detail of most obligations will follow in secondary legislation, but the broad shape is clear enough for procurement teams to act on now.

Managed service providers are in scope for the first time

The most significant change for anyone who relies on an outsourced IT provider is the formal inclusion of managed service providers (MSPs) in the regulatory perimeter. This marks the first time MSPs will be directly regulated under UK cyber law. The government rationale is straightforward: MSPs typically have persistent privileged access to client environments, making them a high-impact "one-to-many" attack vector.

Large and medium MSPs providing ongoing services, such as remote IT support or cyber security threat management, are being brought into scope of the NIS Regulations. MSPs have deep access into their customers' systems, and as more organisations rely on them, they become an increasingly attractive entry point for disruption. The Lords heard a pointed illustration of this during the second reading debate. The April 2025 cyber attack on Marks & Spencer involved a managed service provider being socially engineered, with attackers gaining access and compromising systems.

Not all MSPs are automatically in scope: micro and small enterprises are currently exempt, unless later designated as critical suppliers. Medium and large MSPs providing ongoing managed services are most likely to qualify as Relevant Managed Service Providers (RMSPs). The UK government estimates there will be an additional 900 to 1,100 in-scope MSP entities. Large and medium MSPs comprise fewer than one in ten of the MSPs active in the UK but account for around 97.6% of UK MSP revenue. So the exemption for smaller providers is targeted: the reach of regulation will cover almost all managed IT customers.

Once in scope, an RMSP faces concrete obligations. Regulation 14B requires RMSPs to identify and take appropriate measures to manage risks to network and information systems used to provide managed services. Regulation 14C requires RMSPs to provide information to the Information Commission within three months of becoming regulated, including company details, services provided, and UK representative where applicable. Incident reporting requires a 24-hour early warning and a 72-hour full report to both the sector regulator and the National Cyber Security Centre (NCSC), with mandatory customer notification in relevant circumstances.

The penalties are not token. The Bill introduces a two-tier penalty structure: up to £10 million or 2% of global turnover for standard breaches, and up to £17 million or 4% of global turnover for serious breaches, with up to £100,000 per day for ongoing contraventions.

The designated critical supplier category matters too

Beyond MSPs, the Bill creates a new "designated critical supplier" category that procurement teams should understand, because it can pull almost any IT supplier into the regime regardless of size. Regulators will be able to designate critical suppliers to ensure the most important suppliers to essential and digital services are subject to mandatory cyber requirements. Organisations that supply goods or services to support the delivery of essential or digital services are attractive targets for cyber criminals, because attacks on a single part of a supply chain can cause widespread disruption.

In limited circumstances, small and micro-businesses supply critical goods or services to the essential and digital services on which the economy relies. The Bill therefore enables businesses, including smaller companies supplying critical goods or services, to be designated as critical suppliers. The specific duties that designated critical suppliers will face are to be set out in secondary legislation.

The 2024 ransomware attack on Synnovis, a pathology provider to a number of NHS trusts, was cited in the Lords debate as a direct example of how a single supply chain compromise cascades into service disruption at scale. Criminals deployed ransomware that made Synnovis's files unusable, delaying 11,000 appointments, demonstrating the ripple effect a compromised supply chain can have on services at the far end. The designated critical supplier power is Parliament's direct response to that kind of incident.

What this means when you vet IT and managed service suppliers

The practical consequence for anyone running supplier due diligence is that your IT suppliers now carry a regulatory identity: either they are, or could be, an RMSP or designated critical supplier, or they are exempt. That distinction matters for how you assess and monitor them.

The Cyber Security Breaches Survey 2025/2026 reports that 43% of UK businesses, roughly 612,000 organisations, identified a cyber breach or attack in the previous 12 months. Only 31% of businesses assign board-level responsibility for cyber security, just 15% review risks from their immediate suppliers, and a mere 6% extend that review to their broader supply chain. The Bill is, in part, a legislative response to those figures.

For procurement and compliance teams, a few things follow directly from where the Bill stands.

First, ask your MSP whether they expect to fall within the RMSP definition. A medium or large provider that has not yet thought through its regulatory position is not demonstrating the governance discipline you would want in a supplier with privileged access to your network.

Second, review your contracts. The most immediate practical consequence for businesses using managed IT is that their MSP is now a directly regulated entity. An RMSP connecting to your network to deliver ongoing IT management carries statutory duties of its own, and it will protect its compliance position by revising the contracts it holds with you. Security warranties, audit rights, incident notification timelines and cooperation obligations are all likely to surface at the next renewal.

Third, look beyond the MSP to their sub-suppliers. The Bill aims to bolster supply chain security for operators of essential services and relevant digital service providers. Additionally, regulators will have the power to identify suppliers of critical services whose disruption could cause significant impacts, and these will be classed as designated critical suppliers, bringing them within scope of core security requirements and reporting obligations. If your MSP has not mapped its own supply chain, that is a gap worth probing.

We check company structure, filing behaviour, officer records, and sanctions screening as standard across all suppliers on your Senserity watchlist. For IT and managed service suppliers specifically, the governance signals we surface: who controls the company, whether Persons with Significant Control (PSCs) are properly disclosed, whether filing deadlines are being met, sit alongside the cyber compliance questions this Bill raises. A supplier that cannot keep its Companies House filings in order is unlikely to have the organisational discipline the new NIS regime demands. You can read more about how we approach compliance monitoring on our compliance page.

The window to prepare is open

Most operational obligations under the Bill will not take immediate effect on Royal Assent. The government has confirmed a phased implementation approach, with key requirements brought into force through secondary legislation following further consultation. Full implementation is not expected until 2028. That creates a window, but it is not a reason to wait. The contractual and commercial effects of MSP regulation are already filtering through to supplier conversations before any duty formally bites.

The general principle of the Bill has received cross-party support and has been welcomed by industry and regulators. Key points of contention in the Lords include whether more sectors should be brought in scope, such as retail and manufacturing, and the potential impacts of increased administrative burdens for businesses. Some have also criticised a lack of legal clarity, as many details would be determined later in secondary legislation. The detail will sharpen as the Bill progresses through committee and report stage in the Lords. Monitoring that progress, and asking your IT suppliers what they are doing about it, is the sensible position right now.