Is Your Organisation In Scope for the Cyber Security and Resilience Bill?
The UK's Cyber Security and Resilience Bill expands regulation to many previously unregulated sectors. Learn if your organization falls within scope.
Organisations Affected by the Cyber Security and Resilience Bill
Select your organisation type below to understand how the Cyber Security and Resilience Bill (CSRB) will affect you.
Managed Service Providers
If you provide ongoing IT management, support, or monitoring services, you're now regulated under the Cyber Security and Resilience Bill.
Sector Overview
Managed Service Providers (MSPs) deliver critical IT and security services to businesses and public sector organisations.
Why MSPs Are In Scope
The Cyber Security and Resilience Bill brings Managed Service Providers into scope for the first time. If you provide ongoing IT management, support, maintenance, or monitoring services under contract - and you connect to or access your customers' systems (whether on-site or remotely) - you're likely regulated. This applies whether you're based in the UK or not, as long as you provide services in the UK. Small businesses (micro or small enterprises) are exempt, but you need to monitor if you grow beyond those thresholds.
You're likely in scope if you:
- Provide ongoing IT management services under contract (support, maintenance, monitoring, or active administration)
- Connect to or access your customers' network and information systems (on-site or remotely)
- Are not a small business (micro or small enterprises are exempt)
- Provide services in the UK (even if your company is based elsewhere)
- Provide IT services to regulated sectors like healthcare, finance, or government
- Have administrative access to client networks or critical systems
- Support essential services or critical infrastructure operators
- Manage security tools, backups, or business continuity systems for customers
Key Requirements & Obligations
As an MSP, you must comply with security duties, register with regulators, report incidents quickly, and allow inspections. Here's what you need to do:
Security Requirements
- Identify and manage risks to the network and information systems you use to provide your services
- Implement security measures appropriate to the level of risk you face
- Prevent and minimise the impact of security incidents
- Follow guidance issued by the Information Commission
- Manage supply chain risks - you may be designated as a critical supplier if you supply to other regulated organisations
Registration Requirements
- Register with the Information Commission within 3 months of becoming regulated
- Provide your company name, address, directors, and contact details
- Update the Information Commission within 7 days if any details change
- If you're based outside the UK, nominate a UK representative within 3 months
- Update representative details within 7 days if they change
Incident Reporting Requirements
- Report incidents to the Information Commission within 24 hours of becoming aware of them
- Provide a full detailed report within 72 hours, including impact assessment
- Send a copy to CSIRT (Computer Security Incident Response Team) at the same time
- An incident counts if it affects your systems' operation or security and has significant impact in the UK
- You may be required to publicly disclose incidents if necessary to manage the threat or prevent future attacks
- Notify affected customers as soon as reasonably practicable after reporting to regulators, explaining why they're affected
Information Requests & Inspections
- You must comply with information requests from the Information Commission
- You may be required to generate or collect new information for regulatory purposes
- Regulators can inspect your premises, examine documents, test your systems, and interview your staff
- Information requests can be sent to you whether or not you're based in the UK
Risks of Non-Compliance
Failing to comply with Cyber Security and Resilience Bill requirements can result in serious financial and operational consequences:
- Financial penalties up to the greater of £17 million and 4% of your global turnover for serious failures (like security breaches or failing to report incidents)
- Penalties up to the greater of £10 million and 2% of turnover for standard failures (like registration issues or late notifications)
- Daily penalties of up to £50,000 a day for continuing failure to meet a Part 4 information or inspection requirement
- Enforcement notices requiring immediate action to fix problems
- Failure to comply with information requests is a breach that can result in penalties
- Reputational damage and loss of contracts with regulated clients
- Exclusion from public sector procurement and regulated sector contracts
Benefits of Being Compliant
- Stand out from competitors who aren't compliant
- Access high-value contracts with regulated sectors
- Build stronger client trust and improve retention
- Reduce your cyber risk and incident costs
References from the Bill
The following sections and regulations from the Cyber Security and Resilience (Network and Information Systems) Bill specifically relate to Managed Service Providers:
Part 2, Section 9 - Managed Service Providers
Defines "relevant managed service provider" (RMSP) and "managed service" - a service which involves ongoing IT management, support, maintenance, or monitoring under contract, where the provider connects to or accesses customer systems.
Part 2, Section 10 - Duties of Managed Service Providers
Regulation 14B requires RMSPs to identify and take appropriate measures to manage risks to network and information systems used to provide managed services, and to have regard to guidance from the Information Commission.
Part 2, Section 14 - Provision of Information
Regulation 14C requires RMSPs to provide information to the Information Commission within 3 months of becoming regulated, including company details, services provided, and UK representative (if applicable).
Part 2, Section 15 - Incident Reporting
Regulation 11A requires RMSPs to report incidents within 24 hours and provide detailed reports within 72 hours to both the Information Commission and CSIRT.
Part 2, Section 12 - Critical Suppliers
Regulation 14H allows designation of suppliers to RMSPs as critical suppliers if their failure could disrupt essential services, subjecting them to additional regulatory requirements.
How Precursor Can Help
Our expert team helps organisations implement and prove compliance with the Cyber Security and Resilience Bill - and do so in a way that enhances security without slowing innovation.
Talk to Our Compliance ExpertsTalk to ExpertsAm I in Scope? Thresholds, Exemptions and Regulators
Scope is decided by Schedule 2 to the NIS Regulations 2018. The Bill adds three new thresholds and leaves the rest as they stand. The figures below are taken from the Bill and the Regulations themselves.
New thresholds introduced by the Bill
These bring entities into scope for the first time.
| Service | Threshold |
|---|---|
| Data centre service, not on an enterprise basis | Rated IT load of 1 MW or greater |
| Data centre service on an enterprise basis | Rated IT load of 10 MW or greater |
| Electricity load control | Potential electrical control of 300 MW or greater |
Existing sector thresholds
Unchanged by the Bill. If you already met these under the 2018 Regulations, you remain in scope and the Bill's new duties apply to you.
Energy - electricity
| Service | Threshold |
|---|---|
| Electricity supply (GB) | More than 250,000 final customers, or generation capacity of 2 GW or more input to a transmission system |
| Electricity supply (NI) | More than 8,000 consumers; generation licence holders at 350 MW or more |
| Transmission and distribution (GB) | Potential to disrupt supply to more than 250,000 final customers. Interconnectors at 1 GW or more; offshore transmission at 2 GW or more |
Energy - gas
| Service | Threshold |
|---|---|
| Gas supply | More than 250,000 final customers (GB); more than 2,000 customers (NI) |
| Transmission, storage and LNG (GB) | Potential to disrupt supply to more than 250,000 final customers, or technological capacity above 20 million cubic metres per day |
Energy - oil
| Service | Threshold |
|---|---|
| Upstream pipelines and processing facilities | Throughput above 3,000,000 tonnes of oil equivalent per year |
| Oil transmission, production, refining and storage | Above 500,000 tonnes per year or 500,000 tonnes capacity (GB); above 50,000 tonnes (NI) |
Transport - air
| Service | Threshold |
|---|---|
| Aerodrome owners and managers | More than 10 million annual terminal passengers |
| Air carriers | More than 30% of passengers at a UK airport handling more than 10 million, and more than 10 million passengers across all UK airports |
Transport - water
| Service | Threshold |
|---|---|
| Harbour authorities and port facilities | More than 10 million annual passengers, or more than 15% of UK ro-ro or lo-lo traffic, 10% of liquid bulk, or 20% of biomass fuel |
| Shipping companies | Over 5 million tonnes of annual freight at UK ports and over 30% at a qualifying individual port |
Transport - rail and road
| Service | Threshold |
|---|---|
| Mainline rail and high speed rail | No numeric threshold - any operator of a mainline railway asset is in scope |
| Metro, tram, light rail and underground | More than 50 million annual passenger journeys |
| Road authorities and intelligent transport systems | Roads carrying more than 50 billion vehicle miles per year |
Health
| Service | Threshold |
|---|---|
| NHS and HSC bodies | No numeric threshold - scope is by entity type: NHS Trusts and Foundation Trusts (England), Local Health Boards and NHS Trusts (Wales), Health Boards and the Common Services Agency (Scotland), HSC Trusts (Northern Ireland) |
Drinking water
| Service | Threshold |
|---|---|
| Supply and distribution of potable water | Supply to 200,000 or more people |
Digital infrastructure
| Service | Threshold |
|---|---|
| Top-level domain name registry | 14 billion or more queries from UK devices in any 168-hour period |
| DNS resolver service | 500,000 or more distinct UK IP addresses in any 168-hour period |
| DNS authoritative hosting | 100,000 or more domains registered to UK addresses |
| Internet exchange points | 30% or more share of UK IXP operators by interconnected autonomous systems |
Sectors that are not in Schedule 2
Financial services, universities and public services do not appear in Schedule 2 and get no threshold from this Bill. They can only be brought into scope as a relevant digital service provider, a relevant managed service provider, a designated critical supplier, or through future regulations made under Part 3. Being a large organisation in one of those sectors does not by itself make you an operator of essential services.
The micro and small enterprise exemption
Digital service providers and managed service providers are out of scope if they are a micro or small enterprise. The Bill states the test only by reference to Commission Recommendation 2003/361/EC and contains no figures of its own. The Recommendation defines it as:
Fewer than 50 staff, and either annual turnover or balance sheet total of EUR 10 million or less.
A micro enterprise is fewer than 10 staff and EUR 2 million or less. The headcount test must be met; the financial test is satisfied by either limb.
Two points that are genuinely unresolved, and worth planning around rather than assuming:
- The ceilings are in euro. Neither the Bill nor any DSIT factsheet gives a sterling equivalent or a conversion method.
- Group structure matters. The Recommendation requires linked and partner enterprise data to be aggregated, so a small UK provider owned by a larger group is unlikely to qualify. The Bill neither applies nor disapplies those provisions expressly.
A separate exemption is often confused with this one: an entity is also out of scope if it is subject to public authority oversight and derives half or less of its income from commercial activities.
Who regulates you
Competent authorities are named in Schedule 1 to the NIS Regulations. The regime is more centrally run than is often assumed: the Secretary of State is the competent authority, or one of two joint authorities, across energy, transport, health and drinking water.
| Sector | Competent authority |
|---|---|
| Electricity, and most gas services | Secretary of State for Energy Security and Net Zero and Ofgem (GEMA), acting jointly |
| Oil; gas storage, LNG, gas processing and petroleum production | Secretary of State for Energy Security and Net Zero alone |
| Air transport | Secretary of State for Transport and the Civil Aviation Authority, acting jointly |
| Rail, water and road transport | Secretary of State for Transport, with devolved variations |
| Health care | Secretary of State for Health (England); Welsh Ministers; Scottish Ministers |
| Drinking water | Secretary of State for Environment, Food and Rural Affairs (England); Welsh Ministers; Drinking Water Quality Regulator (Scotland) |
| Digital infrastructure and data centres | Ofcom, UK-wide |
| Load control | Falls under electricity: DESNZ and Ofgem jointly. Not separately named in Schedule 1 |
| Digital service providers and managed service providers | The Information Commission, UK-wide |
| All Northern Ireland subsectors | Department of Finance (Northern Ireland) |
The Bill refers throughout to "the Information Commission". That renaming of the Information Commissioner's Office comes from the Data (Use and Access) Act 2025, not from this Bill.
Frequently Asked Questions
Which organisations are affected by the CSRB?
The Cyber Security and Resilience Bill affects managed service providers, cloud service providers, data centres, NHS organisations, public services, financial services, telecommunications providers, universities, private healthcare providers, digital infrastructure operators, large SaaS platforms, transport infrastructure, utilities and energy providers, and designated critical suppliers. Each sector is regulated through a different route into scope, so the obligations that apply depend on the services your organisation provides in the UK.
Are small businesses exempt from the CSRB?
Micro and small enterprises are exempt from being Relevant Digital Service Providers or Relevant Managed Service Providers under the Cyber Security and Resilience Bill. You need to monitor whether you grow beyond those thresholds, because the exemption falls away once you do. Suppliers to regulated organisations can also be brought into scope separately through designation as a critical supplier under Regulation 14H.
Does the CSRB apply to organisations based outside the UK?
The Cyber Security and Resilience Bill applies to organisations that provide services in the United Kingdom even if the company is based elsewhere. A regulated provider based outside the UK must also nominate a UK representative within 3 months and update the Information Commission within 7 days if those details change.
How quickly must an incident be reported under the CSRB?
Regulated organisations must report an incident within 24 hours of becoming aware of it and provide a full detailed report, including an impact assessment, within 72 hours. A copy must be sent to CSIRT at the same time as the regulator. Affected customers must be notified as soon as reasonably practicable after reporting to the regulator, with an explanation of why they are affected.
What are the maximum penalties under the CSRB?
The maximum penalty for serious failures under Part 2 of the Cyber Security and Resilience Bill is the greater of £17,000,000 and 4% of global turnover, covering failures such as breaching security duties or failing to report an incident. Standard failures, including information provision and notification timing, carry a maximum of the greater of £10,000,000 and 2% of turnover. Part 3 regulations have not yet been made; when they are, Section 32(3) caps any penalty at the greater of £17,000,000 and 10% of global turnover.