In full

The Cyber Security and Resilience Bill cleared the Commons and entered the Lords on 25 June 2026. Most of the reporting framed it as an update to the UK's critical-infrastructure rules. The more consequential change is quieter: it regulates the suppliers.

Does this reach you?

Two questions. Do you administer any part of a client's IT environment, host their systems, or run managed security for them? If so, assume you may be designated a relevant managed service provider, and take advice now rather than waiting to be told. Are you a regulated business that lets a supplier reach into your environment? If so, your obligations do not shrink because theirs have arrived. Either way the same evidence is needed: who holds privileged access, what that access can reach once inside, and whether you could actually report an incident within a fixed clock.

Managed service providers become a regulated category

The Bill creates a designation of relevant managed service provider and brings MSPs and data-centre operators into scope for the first time. Estimates put the number at between 900 and 1,100 organisations coming under direct oversight from the Information Commissioner's Office.

Designated providers pick up statutory duties to implement appropriate and proportionate security and resilience measures across the services they provide, explicitly including the systems they use to manage client environments. They will also have to report incidents within prescribed timeframes.

The systems a supplier uses to manage your environment are now in scope. That is the part most contracts never mentioned.

Why regulators went after the supply chain

Because that is where the incidents come from. Supply chain compromise has become the primary route into regulated sectors, and it is easy to see why it is attractive: an attacker who compromises one managed service provider gains privileged access to every client that provider administers. The provider is not the target. It is the door.

Regulators also gain powers to designate specific high-impact suppliers as designated critical suppliers, carrying obligations equivalent to those of operators of essential services. That is a meaningful shift. A supplier can be pulled into a regime by virtue of who its customers are, not what sector it thinks it is in.

The question to ask about your own business

If you provide IT services, managed security, cloud hosting, or other technology services to organisations in regulated sectors, you may be in scope even though your own business is not in a regulated sector. That sentence catches a great many firms who have never thought of themselves as regulated entities.

It cuts the other way too. If you are a regulated business, your suppliers' obligations do not replace yours. You still need to know who has privileged access to your environment, what they can reach, and what happens when they are the ones breached. A supplier being regulated is useful evidence. It is not a transfer of responsibility.

What to do before it lands

  • Work out whether you are in scope. If you administer client environments, assume you may be and take advice rather than waiting to be told.
  • Inventory privileged access in both directions. Who can reach into your environment, and whose environments can you reach into. Most organisations can only answer one of those.
  • Look at the management plane specifically. The Bill names the systems used to manage client environments. That is remote access tooling, jump hosts, and administrative accounts, which is exactly the surface that tends to be least governed.
  • Check your incident reporting can actually meet a clock. A reporting duty with a timeframe is an operational commitment, not a policy paragraph.
  • Read your contracts now. Supplier agreements written before this will not carry the obligations the regime assumes.

The reasonable reading

The Bill is still moving through the Lords, so the detail can change and anyone telling you the final shape with certainty is ahead of the facts. The direction is not in doubt. Suppliers who hold privileged access to regulated businesses are being brought inside the perimeter, and the management plane is named explicitly.

For most firms the useful work is the same either way: know who can reach your systems, know what they can do once inside, and be able to show it. That is worth doing whether or not the designation lands on you.

The takeaway

The Bill regulates suppliers, not just operators. An estimated 900 to 1,100 managed service providers come under ICO oversight, with duties covering the systems they use to manage client environments and a clock on incident reporting. If you supply technology to regulated businesses you may be in scope regardless of your own sector, and if you are regulated, your supplier's new obligations do not move yours.

The Fourths · Engineering for regulated industries