Signal UK Cyber Security and Resilience Bill 2026: MSPs, Data Centers, Critical Suppliers Covered
Summary
The UK Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025, passed its Commons second reading on 6 January 2026 with cross-party support, moved through committee stage from February 2026, and formally entered the House of Lords on 25 June 2026; it is not expected to fully take effect until 2028. The bill creates a new regulated category, the 'Relevant Managed Service Provider' (RMSP), bringing an estimated 900 to 1,100 managed service providers under direct oversight by the Information Commissioner's Office. Parliament has debated provisions that would bar an RMSP from managing technology systems across a whole sector or subsector once it exceeds a critical-risk customer threshold. Data centers, officially designated critical national infrastructure in the UK since September 2025, are brought into the bill's regulatory scope alongside a new 'critical supplier' designation for firms whose disrupted services could significantly impact essential services, such as a cloud infrastructure vendor serving a national transport operator. Penalties reach up to £17 million or 4% of global turnover, and regulated entities face a 24-hour clock to report incidents once the bill is fully in force. The ICO has stated the changes strengthen existing legislation by expanding scope, enhancing regulator powers, and improving incident-reporting visibility.
Classification
Evidence 1
- GovTech, FederalNewsNetwork 2026-01-01 accessed 2026-07-28T13:59:43+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-422b120900a9