Updated 28 September 2026 · By Yann Davies, Managing Director, ABCOM IT Solutions
The Cyber Security and Resilience (Network and Information Systems) Bill is the biggest update to UK cyber law since 2018. It extends the current NIS Regulations to cover more of the digital supply chain, including, for the first time, managed IT service providers. Here’s where the Bill is now, who it affects, and what small businesses should do.
Where the Bill is now
Source: UK Parliament bill page. Main duties expected to apply from around 2028, via secondary legislation.
The Bill has passed all its House of Commons stages and is at report stage in the House of Lords. Royal Assent is widely expected between late 2026 and spring 2027. Most practical duties will follow through secondary legislation, currently expected from around 2028. You can follow progress on the UK Parliament bill page.
Why the UK needs it
- The NCSC handled 204 nationally significant cyber incidents in 2024/25, up 130% on the previous year, around four a week.
- Recent attacks on NHS suppliers, retailers and local councils showed how one supplier breach can disrupt thousands of organisations.
- The current NIS Regulations (2018) don’t cover many of the IT suppliers that essential services now depend on.
Who the new rules cover
What the Bill introduces
- Faster incident reporting: significant incidents reported to the regulator and the NCSC within 24 hours, with a fuller report within 72 hours.
- Wider reporting: more types of incident must be reported, including some that could have caused significant disruption.
- Stronger regulators: more powers to investigate, plus turnover-based penalties for serious failures.
- Registration for managed service providers, and security duties aligned with NCSC guidance such as the Cyber Assessment Framework.
What it means for small businesses
Most small businesses won’t be regulated directly. The Bill mainly targets essential services and their key suppliers. But it will reach you in two ways:
- Through your IT provider: managed service providers will need stronger security and reporting, which raises standards for everyone they support.
- Through your customers: if you supply the NHS, local councils, energy, transport or other essential services, expect tougher security questionnaires and requirements such as Cyber Essentials to become standard.
What to do now
- Get Cyber Essentials, which is quickly becoming the minimum supply-chain requirement.
- Ask your IT provider how they’re preparing for the Bill and whether they’re an NCSC Assured Service Provider.
- Write an incident response plan that could support 24-hour reporting.
- Review supplier access to your systems and data.
- Keep evidence: policies, MFA settings, patching records and backup tests.
Where ABCOM stands
ABCOM is an NCSC Assured Service Provider and already works to NCSC standards. We’ll keep clients updated as the Bill completes its passage and secondary legislation is published. If you supply essential services and want to be ready for tougher supplier requirements, talk to our team.
Frequently asked questions
What is the Cyber Security and Resilience Bill?
It is a UK Government Bill that updates the Network and Information Systems Regulations 2018. It brings more of the digital supply chain into scope, including managed service providers, data centres and designated critical suppliers, with faster incident reporting and stronger regulator powers.
When will the Cyber Security and Resilience Bill become law?
As of September 2026 the Bill is at report stage in the House of Lords. Royal Assent is expected between late 2026 and spring 2027, with most practical duties applying later through secondary legislation, currently expected from around 2028.
Does the Cyber Security and Resilience Bill apply to small businesses?
Most small businesses will not be regulated directly, but they will feel it through their IT providers, which are brought into scope, and through customers in essential services, who are likely to demand stronger security such as Cyber Essentials.
How quickly must incidents be reported under the new Bill?
The Bill proposes that significant incidents are reported to the regulator and the NCSC within 24 hours, followed by a fuller report within 72 hours.
Supplying essential services? Get ready now
We help Sussex and UK organisations meet tougher supplier security requirements, from Cyber Essentials to incident response planning.
Sources
- UK Parliament: Cyber Security and Resilience (NIS) Bill
- NCSC Annual Review 2025: incident management
Do not just read it. Act on it.
Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.


