Managed service providers operating in the UK could face stricter cybersecurity and incident-reporting obligations under the proposed Cyber Security and Resilience (Network and Information Systems) Bill, as policymakers move to strengthen protections across increasingly interconnected digital supply chains.
The Bill completed committee stage in the House of Lords on 7 September 2026. Its current version, HL Bill 49, was amended in Grand Committee, and report stage is scheduled for 26 October 2026. It has not yet become law, and the final obligations and implementation timetable may still change before Royal Assent.
One of the Bill’s key changes would bring qualifying medium and large managed service providers (MSPs) directly within the scope of the UK’s Network and Information Systems Regulations as Relevant Managed Service Providers (RMSPs).
Under the proposed framework, RMSPs would be required to put appropriate and proportionate cybersecurity measures in place, register with the Information Commission and report significant incidents to the regulator.
Roy Shelton, Group CEO of Connectus Business Solutions, said, “This Bill formalises what has been best practice for us for years – the difference now is that a supply-chain breach at one provider can no longer be treated as somebody else’s problem.”
MSPs frequently have extensive access to customer networks, infrastructure and data. The UK government has highlighted that this privileged access can create a ‘one-to-many’ cybersecurity risk, where compromising a single service provider could potentially expose multiple organisations.
Shelton added, “We hold the keys to hundreds of client networks, and regulation catching up with that responsibility is overdue.”
24-Hour Initial Reporting Window
The legislation would also expand incident-reporting requirements. Under the proposed two-stage system, regulated organisations would need to provide an initial notification within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours.
The National Cyber Security Centre would be informed at the same time as the relevant regulator. The proposed framework would also widen reporting beyond traditional service disruption to cover certain incidents affecting the confidentiality or integrity of systems and data where the impact is, or is likely to be, significant.
On the proposed reporting timetable, Shelton said, “A 24-hour reporting window sounds demanding if you haven’t already built the incident response playbook to meet it, which is exactly where Connectus clients sit today.”
Smaller Providers May Not Be Entirely Outside the Framework
The RMSP classification is primarily aimed at medium and large managed service providers. Small and micro-enterprise MSPs are exempt from the standard RMSP measure.
However, size alone may not remove every smaller technology supplier from the wider regulatory landscape. The Bill would allow certain suppliers, including smaller MSPs, to be designated as critical suppliers if they meet the statutory conditions for designation. That mechanism is intended to address situations where disruption at a supplier could create significant knock-on risks for regulated entities or essential services.
This reflects a broader policy focus on supply-chain cybersecurity rather than concentrating solely on organisations that directly provide the end service.
Higher Cybersecurity Penalties
The proposed enforcement regime would also increase the financial consequences of serious non-compliance. For higher-band breaches, regulators could impose penalties of up to £17 million or 4% of a regulated entity’s worldwide turnover, whichever is higher. A standard band would allow penalties of up to £10 million or 2% of worldwide turnover, whichever is higher.
Some technical details, including the calculation of turnover and supplementary incident-reporting thresholds, are expected to be set through secondary legislation and regulatory guidance.
For MSPs, the direction of travel is clear: cybersecurity obligations are increasingly extending across the technology supply chain, particularly where third-party providers have privileged access to multiple customer environments.
Shelton said, “We’re not scrambling to react to this legislation; we’re already operating to the standard it’s about to make law. Those who’ll struggle are the ones who’ve treated cyber security as a checkbox exercise rather than a discipline.”
Shelton also said Connectus clients are covered by Cyber Essentials Plus and ISO 27001 certification. Those certifications can support an organisation’s security posture, but they do not by themselves establish compliance with the proposed legislation; that will depend on the final statutory requirements and supporting secondary regulations once the measures come into force.
If the Bill receives Royal Assent, the government says the RMSP and incident-reporting measures would be brought into force through secondary legislation. The phased approach is intended to give regulators and affected providers time to prepare before the new duties take effect.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.
