The Cyber Security and Resilience Bill is nearly law, and your suppliers are in it
Lords report stage is scheduled for 26 October. The detail can still change there, but the shape of the obligations is clear enough to plan against now.
The Cyber Security and Resilience Bill finished its Lords committee stage on 7 September after three sittings. Parliament's own list shows 193 amendments tabled; by Precursor Security's count of that list, only five were agreed, all of them the government's own. That says more about procedure than about the Bill. The committee sat in Grand Committee, where decisions must be unanimous, so amendments can be probed and withdrawn but not voted through. Report stage, scheduled for 26 October, is different: it happens in the main chamber, and peers can vote amendments in against the government. Royal Assent has been widely expected before the end of the year, although a government consultation in June pointed to spring 2027, depending on parliamentary time.
So the detail can still move. The government is expected to bring back proposals for new powers over risky technology suppliers, and the thresholds that decide who is in scope will follow in secondary legislation. But the core shape has been stable since the Commons, which makes this the right moment to plan, rather than waiting for the commencement regulations.
What changes
The Bill amends rather than replaces the NIS Regulations 2018. Three changes matter most for regulated organisations.
The first is the reporting clock. Significant incidents will need an initial notification within 24 hours of becoming aware of them, followed by a fuller report within 72 hours. That mirrors the EU's NIS2 directive and is far tighter than most incident processes are built for.
The second is scope. Data centres with a rated IT load of 1MW or more (10MW for enterprise-only sites) are brought in as essential services, and medium and large managed service providers become regulated as relevant managed service providers. Your outsourced IT provider stops being only a contractual risk you manage and becomes a regulated entity with its own obligations and its own regulator, including a duty to tell affected customers about breaches.
The third is reach. The government gains powers to direct regulated organisations to take specified action where a threat gives rise to a national security risk, and regulators gain stronger tools for oversight of the supply chain. That reach may grow. In August the government tabled more than 60 amendments creating a vendor-related direction power, which would let ministers require in-scope organisations to restrict, remove or modify a risky supplier's goods or services. It debated them but did not move them, so they are not yet in the Bill and are expected back at report stage. During committee, the government also resisted calls to bring AI vendors into scope, so AI supply chains remain, for now, a matter for contracts and existing sector regulators.
Most substantive obligations will arrive through secondary legislation, with full effect widely expected around 2028. That sounds distant. It isn't, for the reason below.
Why 24 hours is a design problem, not a process tweak
A 24-hour notification only works if the decision about whether something is reportable has been made before the incident happens. In most organisations I've seen, incident severity is decided by a technical on-call team, and regulatory notification is decided days later by legal and compliance, after the facts are clear. Under a 24-hour clock, the facts are never clear in time.
The organisations that handle this well pre-agree thresholds in business terms: which services, what level of disruption, how many customers, for how long. The on-call engineer doesn't decide whether to notify the regulator; they decide whether a pre-agreed threshold has been crossed, and the notification follows automatically. That's the same principle I use across all of our work: decide from the business down, so the technical decision at 3am is a lookup, not a judgement call.
What MSP scope means for buyers
Bringing managed service providers into scope will help, eventually, because it raises the floor. In the short term it creates friction. MSPs will need to evidence their own controls, build their own reporting processes and absorb the cost of doing so, and much of that cost will be passed on.
If you buy managed services, three things are worth doing before Royal Assent. Map which of your critical services depend on which providers, because the regulator will expect you to know. Check your contracts for incident notification timings that are compatible with a 24-hour clock, including notification from the provider to you. And ask your providers now how they intend to comply, because the quality of the answer is a good proxy for their maturity.
One programme, not three
Many regulated firms are already running operational resilience programmes for the FCA and PRA, and some have DORA obligations through EU operations. This Bill adds a third set of expectations with a similar shape: map critical services, understand dependencies, test, report quickly. The temptation is to run each as a separate compliance project. The better approach is one resilience capability, with a single map of important services and their dependencies, feeding each regulator the evidence it asks for in the format it wants.
Preparing for the 24-hour clock?
A short conversation on your reporting thresholds and supplier dependencies.