FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

MSP regulation guide

The Cyber Security and Resilience Bill: what it means for MSPs

The Cyber Security and Resilience (Network and Information Systems) Bill is not law yet. As of 28 September 2026 it is in the House of Lords, with report stage scheduled for 26 October 2026. As drafted, it would bring medium and large managed service providers (MSPs) under the NIS Regulations 2018 for the first time, regulated by the Information Commission. In-scope MSPs would have to register, manage cyber risks, report significant incidents within 24 and 72 hours, and tell affected customers.

In short

The Bill was introduced on 12 November 2025, passed the Commons on 16 June 2026 and was amended in Lords Grand Committee in September 2026. It has not received Royal Assent. It would regulate “relevant managed service providers”: businesses that manage a customer’s IT systems on an ongoing basis by connecting to them, excluding micro and small enterprises. The MSP duties would start through secondary legislation after Royal Assent. The most serious breaches could bring penalties of up to the greater of £17 million or 4% of worldwide turnover. The Bill does not require MSPs to hold insurance.

Is the Cyber Security and Resilience Bill law yet?

No. The Bill has passed the House of Commons but has not finished its passage through the House of Lords or received Royal Assent. Its stages so far, from the Parliament bill page:

StageDate
First reading, House of Commons12 November 2025
Second reading, Commons6 January 2026
Committee stage, Commons3 to 26 February 2026
Carried over and reintroduced in the new session14 May 2026
Report stage and third reading, Commons16 June 2026
First reading, House of Lords17 June 2026
Second reading, Lords14 July 2026
Grand Committee, Lords1, 3 and 7 September 2026
Report stage, LordsScheduled for 26 October 2026

Even after Royal Assent, the MSP rules would not start straight away. The government’s MSP factsheet says the measure will be brought into force through secondary legislation, which will also set out technical detail such as security requirements and the thresholds for reportable incidents. The government has said it intends to consult on implementation in 2026 and will give businesses an adjustment period (Bill summary).

The details on this page come from the latest print of the Bill, HL Bill 49, as amended in Grand Committee. They may still change.

Which managed service providers would the Bill cover?

The Bill would add “relevant managed service providers” (RMSPs) to the NIS Regulations. A managed service is one provided under a contract for the ongoing management of a customer’s IT systems, “whether in the form of support and maintenance, monitoring, active administration or other activities”, delivered by connecting to or accessing the customer’s network and information systems. It makes no difference whether that access is on site or remote.

You would be an RMSP if you provide a managed service in the UK, wherever you are based, unless:

Providing a data centre service, or a public electronic communications network or service, does not count as providing a managed service.

The government’s factsheet gives examples. In scope: an IT company managing a customer’s applications, networks and infrastructure through a connection to its systems; a security company providing ongoing firewall management, intrusion detection and incident response; and ongoing management of a customer’s cloud service. Out of scope: installing or integrating systems with no ongoing management; selling software as a product, even with ad hoc remote patches; and consultancy delivered by email, phone or meetings.

Small and micro MSPs would be exempt from the RMSP rules, but a regulator could still designate one as a critical supplier if it meets the conditions for designation.

What would in-scope MSPs have to do?

The Information Commission, formerly the Information Commissioner’s Office, would be the regulator. Further security and resilience requirements would follow in secondary legislation.

How quickly would an MSP have to report an incident?

Under the Bill’s new regulation 14E, an RMSP that is aware of a reportable incident must send the Information Commission:

  1. an initial notification within 24 hours of first becoming aware, giving its name, the managed service affected and brief details; and
  2. a full notification within 72 hours of that time, covering when the incident happened and whether it is ongoing, its nature, any link to an incident at another regulated organisation, and its impact, so far as known.

A copy goes to the national computer security incident response team at the same time. The government’s incident reporting factsheet says the National Cyber Security Centre (NCSC) will be informed alongside the regulator.

An incident is reportable if it has affected, or is affecting, the operation or security of the systems behind your managed service, and its impact in the UK has been, is or is likely to be significant. The factors include the extent of disruption, the number of users affected, how long it lasts, the area affected, whether data has been compromised, any impact on customers’ own systems, and any impact on the economy or day-to-day life. The government plans to set thresholds for a “significant” impact in secondary legislation.

After the full notification, regulation 14G would require you, as soon as reasonably practicable, to take reasonable steps to find out which UK customers are likely to be adversely affected, then tell them about the incident and why you think they are affected.

What penalties could MSPs face?

The Bill replaces the current three penalty bands with two. For a business, the maximum penalty would be:

The Bill lists which failures fall into each band. The government’s enforcement factsheet says failures relating to incident notification and security duties fall in the higher band, and a failure to register as an RMSP falls in the standard band. A penalty must be appropriate and proportionate, taking account of the impact of the failure, any steps taken to remedy it and the business’s compliance record. Penalties can be appealed to the First-tier Tribunal.

Where do cyber insurance and tech PI fit?

The Bill does not require MSPs to hold insurance, and no policy takes over your legal duties. Insurance helps with the cost when something goes wrong. For an MSP, two covers do most of the work, always subject to the policy terms:

Because the Bill would require fast reporting and customer notification, affected customers would hear about a reportable incident from you directly. Check three things with your broker:

Apex arranges cyber insurance and professional indemnity insurance for IT firms and MSPs. See cyber insurance explained, MSP insurance and IT professionals’ PI insurance.

Sources

Frequently asked

Is the Cyber Security and Resilience Bill law yet?

No. As of 28 September 2026 it has passed the House of Commons and completed Grand Committee in the House of Lords, with Lords report stage scheduled for 26 October 2026. It still needs its remaining stages and Royal Assent, and the MSP duties would then start through secondary legislation.

Does the Bill apply to small MSPs?

Not as relevant managed service providers. The Bill excludes micro and small enterprises as defined in Commission Recommendation 2003/361/EC. A regulator could still designate a small or micro MSP as a critical supplier if it meets the conditions for designation.

Who would regulate MSPs under the Bill?

The Information Commission, formerly the Information Commissioner’s Office. MSPs in scope would register with it, report significant incidents to it and have regard to its guidance.

How long would an MSP have to register?

Three months from the day the relevant provisions come into force, or from the day you first meet the definition if that is later. You would give your name, address, directors’ names and contact details, and report any changes within seven days.

Does the Bill require MSPs to buy cyber insurance?

No. The Bill does not mention insurance. It sets security, incident reporting and customer notification duties. Customers may still ask for evidence of cover, and insurance can help with the costs of an incident, subject to the policy terms.

Would cyber insurance pay a fine under the new rules?

Do not assume it would. Whether a policy responds to a regulatory investigation or penalty depends on its wording and on the law, so check the policy with your broker before relying on it.

Cyber and tech PI for MSPs

Apex arranges cyber and technology professional indemnity insurance for managed service providers, subject to the policy terms. Or call 0117 325 0027.

Get a quote Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not legal or tax advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.