The Cyber Security and Resilience Bill Has Reached Committee Stage: What UK SMEs Need to Do Now
On 1 September 2026, the Cyber Security and Resilience (Network and Information Systems) Bill entered detailed, line by line scrutiny in the House of Lords. If that sentence sounds like a distant Westminster process, it is worth pausing on, because this is the biggest overhaul of UK cyber security law since 2018, and its effects will not stay confined to the large infrastructure operators it is nominally written for.
Here is what the Bill actually does, where it stands right now, and what your business should be doing about it while it is still working its way through Parliament rather than waiting for it to become law.
What the Bill Actually Changes
The Cyber Security and Resilience Bill updates the Network and Information Systems Regulations 2018, the UK’s core cross sector cyber security rules, which until now applied mainly to operators of essential services like energy, water, health and transport. You can read the Bill’s full text and current status on the official UK Parliament bill tracker.
The update brings three groups into direct regulatory scope for the first time: medium and large managed service providers, data centres above a certain size, and a new category called designated critical suppliers, meaning any supplier whose failure could seriously disrupt an essential service. Regulators gain the power to name a business as a designated critical supplier and, once named, that business must meet duties similar to the essential service operators it supports.
For businesses that fall directly into one of these categories, the headline requirements are strict. Serious breaches carry fines of up to £17 million or 4% of global turnover. Incident reporting now runs on a tight clock: an initial notification within 24 hours of discovering an incident, followed by a full report within 72 hours. For any organisation without a round the clock security operations centre, that 24 hour window is a genuinely hard operational target to hit.
Why This Matters Even If You Are Not Directly Regulated
Most UK SMEs are not managed service providers or data centres, so it is tempting to read this as someone else’s problem. That reading misses how the Bill actually reaches most businesses: through the supply chain, not through direct regulation.
If your business supplies goods or services to a larger organisation, or if your IT is delivered by an external provider, expect that relationship to change. Larger, regulated organisations will need to demonstrate that their suppliers meet baseline security standards, which means more security clauses in contracts, more assurance questionnaires, and procurement teams asking for proof of certification before they will sign.
The government’s own April 2026 open letter to UK businesses made this connection explicit, calling for organisations to certify to or align with Cyber Essentials and embed it across their supply chains, well ahead of the Bill actually becoming law.
The government has also been running a parallel voluntary track. In July 2026, the Technology Secretary launched the Cyber Resilience Pledge, and more than 60 organisations, including several major UK brands, signed on the first day, committing to the same kinds of practices the Bill will eventually make mandatory. Getting ahead of that curve voluntarily, rather than scrambling once the law lands, is exactly the position most SMEs should be aiming for over the next twelve months.
The Numbers Behind the Urgency
It helps to understand why Parliament is moving on this now. The government’s own Cyber Security Breaches Survey, run by the Department for Science, Innovation and Technology, has consistently found that around 43% of UK businesses report experiencing a cyber breach or attack in the past year.
The more concerning figures sit just beneath that headline number: a large share of businesses that suffer a breach never report it to anyone outside the organisation, and only a minority hold a formal, documented incident response plan. You can see the full breakdown in the government’s Cyber Security Breaches Survey.
Put plainly, the 24 and 72 hour reporting clock the Bill introduces is being layered onto a business population where most organisations currently have no formal plan for responding to an incident at all. That gap, between what the law will soon require and what most businesses currently have in place, is the single biggest reason to start preparing now rather than after Royal Assent.
Where the Bill Stands and What Happens Next
The Bill was introduced to the House of Commons in November 2025, cleared all its Commons stages by June 2026, and had its Second Reading in the House of Lords on 14 July 2026.
Committee Stage, the detailed clause by clause scrutiny where amendments get debated, began on 1 September 2026 and is ongoing. Royal Assent is expected later in 2026, but the practical, day to day obligations are not expected to take full effect until around 2028, once the detailed secondary legislation and consultation process are complete.
That gap between Royal Assent and real world enforcement is worth taking seriously rather than treating as breathing room. Some duties, particularly incident reporting, are widely expected to be among the first provisions actually switched on. And well before any of it is legally required, larger clients and regulated partners will start asking their suppliers to demonstrate readiness anyway, simply because the direction of travel is now unmistakable.
What to Do Before the Law Actually Bites
A few concrete steps make sense regardless of exactly when full commencement lands:
- Get Cyber Essentials certified or renewed. It is the baseline the government is explicitly pointing businesses toward, and it is increasingly becoming a hard requirement in procurement processes even outside regulated sectors. The NCSC’s official Cyber Essentials scheme is the definitive place to start.
- Write down an actual incident response plan. If a breach happened tomorrow, who gets notified, in what order, and within what timeframe? Most businesses have never put this on paper, which is precisely the gap the survey data above highlights.
- Ask your current IT provider where they stand. If you rely on a managed service provider, they may fall directly into the Bill’s expanded scope. Understanding how they are preparing tells you a great deal about how exposed your own business is by extension. Our IT solutions team can run this kind of readiness review alongside your existing setup.
- Extend the same scrutiny to your SaaS tools. Cloud and SaaS platforms sit outside a lot of traditional IT audits, yet they hold real customer and operational data. A proper SaaS security review closes a gap that a standard network audit will usually miss entirely.
The Bottom Line
The Cyber Security and Resilience Bill will not directly regulate most SMEs on day one. But it is already reshaping what larger clients, regulated partners, and insurers expect from every business in their supply chain, and that shift started well before Committee Stage and will keep accelerating well before Royal Assent.
Businesses that treat the next twelve months as preparation time, rather than waiting for the law to force their hand, will be the ones still winning contracts when procurement teams start asking harder questions.
Not sure where your business currently stands against Cyber Essentials or the direction the CSRB is heading? Book a free consultation and we will run through exactly what your current setup covers, and what it does not.

