The UK’s Cyber Security and Resilience Bill is moving through Parliament and is expected to receive Royal Assent in the 2026–27 session. If you work in IT or security, you’ve likely already heard about it.
If your organisation isn’t a hospital, utility, or bank, you may assume it doesn’t apply to you.
However, no matter what field you are in, its worth taking a second look and closely evaluating how the legislation may affect you.
The bill significantly expands the number of organisations that will have direct legal obligations around cyber security. Even for those outside direct scope, the supply chain effects are already appearing in contract renewals, tender questionnaires, and security audits.
What Is the Cyber Security and Resilience Bill?
First, the basics.
The Cyber Security and Resilience (CS&R) Bill is the biggest overhaul of UK cyber security law since the Network and Information Systems (NIS) Regulations came into force in 2018. The new bill significantly expands and strengthens NIS, introduces new categories of regulated organisations, tightens incident reporting requirements, increases scrutiny of supply chain security and gives regulators considerably more enforcement power.
The government’s rationale for the new bill is simple: the UK is among the most targeted country in Europe for cyber attacks. High-profile incidents affecting the NHS, the Ministry of Defence, Marks & Spencer, and Jaguar Land Rover demonstrated in painful detail that the 2018 framework wasn’t keeping pace with the actual threat level. The new bill is the government’s substantive response to that.
Who Is Directly in Scope?
Here’s where to check your organization against the bill’s requirements.
There are five regulated categories:
| Category | Who It Covers |
|---|---|
| Operators of Essential Services (OES) | Energy, transport, water, health, digital infrastructure. Already regulated under NIS 2018, now with stricter requirements. |
| Relevant Digital Service Providers (RDSPs) | Cloud computing services, online marketplaces, search engines. |
| Relevant Managed Service Providers (RMSPs) | Medium and large MSPs providing outsourced IT, managed security, or cloud hosting services. An estimated 900–1,100 MSPs will come into scope. Small and micro businesses are excluded from direct regulation. |
| Data Centre Operators | Standalone data centres above specified capacity thresholds (1 MW rated IT load for non-enterprise facilities and 10 MW for enterprise facilities). These operators are expected to be classified as Critical National Infrastructure. |
| Designated Critical Suppliers (DCS) | Organisations designated by regulators because their failure could disrupt an OES or RDSP, regardless of sector. |
Am I an RMSP?
This is the category where most uncertainty sits. If your organisation provides outsourced IT services, managed security, or cloud hosting to other businesses, is classified as medium or large (broadly, 50+ employees or €10m+ turnover), and operates in the UK or serves UK customers, you are likely an RMSP under the bill. Small and micro businesses are excluded from direct regulation but but that doesn’t necessarily mean they avoid the impact of the bill.
Read the supply chain section below for more details.
The Supply Chain Effect – The Part That Catches People Out
Even if your organisation sits outside direct scope, the bill may still affect how you operate.
Regulated entities, including OES, RDSPs, RMSPs, data centres are required to manage cyber security risk throughout their supply chains, and that obligation flows downstream to their suppliers via contracts.
If you supply to a regulated organisation, expect:
- New contractual security requirements — minimum security standards, audit rights, and incident notification clauses appearing in renewals
- Cyber Essentials Plus certification requests — the government’s April 2026 open letter to UK businesses explicitly called for organisations to certify and embed Cyber Essentials across their supply chains
- Security questionnaires — longer, more technical, more frequent
- 24-hour breach notification clauses — your clients may now require you to notify them of incidents within the same window the bill requires of them
According to the UK Government’s own Cyber Security Breaches Survey 2025/2026, only 15% of businesses formally review the cyber risks posed by their immediate suppliers and even fewer look at the wider supply chain. That number needs to change, and fast.
What Does Being in Scope Actually Require?
For organisations directly regulated under the bill, the key obligations break down as follows.
Incident Reporting: 24 Hours and 72 Hours
- Initial notification to the government body responsible for overseeing cyber security requirements in your sector, as well as the National Cyber Security Centre (NCSC), within 24 hours of becoming aware of a significant incident.
- Full report within 72 hours
- The scope of reportable incidents is broader than NIS 2018. Near misses, pre-positioning attacks, and ransomware intrusions that are likely to cause significant impact must be reported even if services haven’t gone down yet
- If your incident is likely to affect customers, you must notify them too
Supply Chain Security as a Legal Duty
The bill expects organisations to take responsibility for cyber risks introduced by their suppliers. Organisations must put appropriate and proportionate measures in place to prevent supplier vulnerabilities from undermining their essential or digital services.
Continuous Security Standards
Alignment with the NCSC’s Cyber Assessment Framework (CAF) is moving from recommended to required for OES organisations. CAF 4.0 requires evidence that the controls you’ve put in place are doing what they’re supposed to do. Regulators and auditors will want proof that your hardening efforts weren’t a one-time exercise. You’ll need to show that the systems stayed hardened over time.
The Manual Configuration Problem Most Organisations Still Have
The CS&R Bill demands continuous resilience, not point-in-time compliance.
The CAF will ask you to demonstrate that your servers and systems are hardened and that they stay hardened. Regulators aren’t interested in “we ran a benchmark audit in January.” They want to know what your posture looks like today, and will likely look like tomorrow, and after your next infrastructure change.
That’s a real problem for organisations relying on manual hardening processes. Manual audits are snapshots, and configuration drift, i.e. the gradual erosion of your hardened baseline as patches are applied, services change, and new systems come online, happens between those snapshots. By the time your next scheduled review runs, your posture may look nothing like what you documented.
This is the gap CalCom Hardening Suite (CHS) is built to close. CHS automates server hardening against CIS Benchmarks on Windows and Linux, in production, without downtime, and continuously enforces your security policy in real time. When a configuration drifts, CHS detects and remediates it automatically, so when regulators ask for evidence of your compliance posture, you have it.
What Should You Do Right Now?
Whether you’re directly in scope or a supplier to someone who is, there are practical steps to take before Royal Assent, before secondary legislation, and before your next contract renewal arrives with new clauses you weren’t expecting.
- Determine your category. Work through the scope table above. If you’re unsure, err on the side of assuming you’re in scope and assessing from there.
- Map your supply chain exposure. Which of your clients are regulated entities? Which of your suppliers have privileged access to your systems?
- Check your incident response. Can you realistically detect, classify, and notify a significant incident within 24 hours? If you’re not certain, that’s your answer.
- Assess your configuration posture. Are your servers hardened against CIS Benchmarks, and are they staying hardened between audits?
- Get Cyber Essentials Plus on the roadmap. Whether or not you’re directly in scope, your regulated clients will increasingly require it.
If you want to talk through what the CS&R Bill means for your specific environment, we’re here.
Visit our Get a Demo page to watch a brief demonstration of how CalCom CHS detects and remediates server misconfigurations while continuously enforcing security baselines. If you have questions about your environment, you can also speak with one of our server hardening experts.