Your IT provider probably is not being regulated. The ones that are will owe you a phone call
- Technology
- IT consultancy
- Cyber security
- Warrington
If a security questionnaire has landed from your largest customer, or an IT company has emailed you about new cyber legislation and a deadline, here is the short version. The Cyber Security and Resilience Bill is real, it is most of the way through Parliament, and it is aimed at a specific and fairly small population. Your business is almost certainly not in it. Your IT provider probably is not either.
Both of those statements come with an "unless", and the unless is worth ten minutes.
Where the Bill has got to
It amends the Network and Information Systems Regulations 2018, which already impose security and reporting duties on providers of essential services: energy, water, healthcare, transport, digital infrastructure. The Bill widens that list, brings managed IT services inside it, tightens incident reporting, and hands the Secretary of State powers to fill in a great deal of the detail later through secondary legislation.
It cleared the Commons on 16 June and is in the Lords now. Committee stage finished at the start of September, the report stage date has not been announced, and it has not received Royal Assent. Anything you read that gives you a date to comply by is guessing, because most of the substantive requirements will arrive as regulations that have not been written yet.
Who it actually catches
The Bill defines a managed service as one provided under a contract for the ongoing management of a customer's IT systems, where the provider connects to or otherwise gets access to the systems that customer relies on. On-site or remote makes no difference. Support, maintenance, monitoring and active administration are all named.
That sounds like it covers every IT company in the country, and it would, except for the carve-outs. Data centre services and public telecoms networks are excluded from the definition. The government's own working definition also puts outsourced HR and payroll outside it, along with consultants who have only infrequent access to systems. Most importantly, micro and small enterprises are excluded from being a regulated managed service provider at all.
Research commissioned by the Department for Science, Innovation and Technology, quoted in the House of Commons Library briefing on the Bill, put numbers on what that leaves.
- 11,000+
- MSPs active in the UK in 2023
- 1,500–1,700
- Medium or large, and so in scope
Around one IT provider in seven. If your IT support is a handful of people working out of an office somewhere in Cheshire, they fall outside this, and so does the IT department you do not have.
The penalties point the same way. The Bill sets maximum fines of £10 million or 2% of global turnover for lesser breaches, and £17 million or 4% for serious ones. Numbers of that size are not designed with a twelve-person firm in mind.
Our own position, since it is a fair question
We are a small firm. Read against the definitions above, we are not a regulated managed service provider, and nothing in this Bill as it stands changes what we owe our clients.
We are saying that plainly because the incentive runs the other way. An IT company that tells you new legislation obliges you to buy something from it this quarter is describing its sales target, not the law. The Bill is not law yet, the duties fall on providers rather than on their customers, and the parts that would reach further down the chain are still blank pages. Ask anyone selling you urgency which clause they mean.
What genuinely changes if your provider is one of the 1,500
This is the part worth knowing, because it is a real improvement and nobody is marketing it.
A regulated provider that suffers a significant incident would have to give the Information Commission an initial notification within 24 hours of becoming aware of it, and a fuller one within 72 hours, copying the National Cyber Security Centre both times. Then, after that full notification, it must take reasonable steps to work out which of its UK customers are likely to have been adversely affected, and tell them.
Today, when your IT provider has a bad week, you find out when you find out.
That duty to notify affected customers is the clause a small business should care about. It converts a conversation that currently depends on your provider's conscience into one it has to have. If your provider is large enough to be caught, you get told. If it is not, you are relying on the relationship, which is a reason to know which side of the line yours sits on.
The questionnaire is real. The rule behind it is not, yet
Here is where the coverage has run ahead of the text.
There is no general duty in this Bill requiring regulated organisations to police their suppliers. The phrase "supply chain" does not appear in the current version. What exists is a power for the Secretary of State to make regulations later, supply chain risk management among them, and a narrow, separate mechanism letting a regulator designate one specific company as a critical supplier, after giving it notice and hearing its representations. A firm cannot be designated by accident, and the duties that would follow have not been written.
So when a customer sends you a security questionnaire, it is not enforcing a rule you are breaking. It is doing its own risk management, or getting ahead of where it thinks this is going. That should change how you answer it. The document is commercial, not legal, and the deadline on it is your customer's, not Parliament's.
It is also going to become more common whatever the Bill finally says. The Cyber Security Breaches Survey found only 15% of UK businesses had reviewed the risks from their immediate suppliers in the previous twelve months, which is exactly the kind of gap that gets closed by asking everybody to fill in a form.
- 01Write down who has access to your systems: staff, former staff, suppliers, the person who set up the accounts software in 2019
- 02Decide now what you would do in the first day of an incident, and who makes the call
- 03List which suppliers touch your data, and what would break if one of them stopped answering
- 04Keep the answers in one document and update it when they change
None of that is technology. It is the same four questions in every assurance questionnaire we have seen, and the firms that can answer them in two days win work from the firms that take three weeks, quite independently of which is actually more secure. That is unfair and it is also how procurement works.
If you want the other half of this, the questions worth putting to your own IT provider do not depend on any of this legislation and are worth asking anyway. And if a questionnaire has arrived and you would rather not guess at the answers, send it to us and we will tell you which parts are substantive and which are boilerplate.
We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.
If any of this sounds like your business, we will tell you plainly whether we can help.
