
The Cyber Security and Resilience Bill just moved again, here's what's actually changed
10 September 2026
We covered the Cyber Security and Resilience Bill back in our very first week of posts, when it had just had its Second Reading in the House of Lords. It's moved since, and this week is a good moment to update anyone tracking it, particularly if you're a hedge fund, family office or insurer keeping an eye on your IT provider's regulatory position.
Where it stands now
The Bill entered Committee Stage in the House of Lords on 1 September 2026, having cleared the Commons entirely and completed its Lords Second Reading back in July. Committee Stage is where the detail gets picked apart line by line, and it's a genuine signal that the Bill is moving with intent rather than sitting in a queue. Royal Assent is still expected later this year.
What's got sharper since we last covered it
A few things are now clearer than they were in July:
- Scope has been confirmed to include not just managed service providers, but data centres and "large load controllers" too, entities that can control the energy use of things like batteries and connected devices. The Bill is casting a wider net across the digital dependency chain than the earlier drafts suggested.
- Penalty figures are now public. Fines tied to a percentage of turnover, reported at up to £17 million or more for the most serious failures, are attached to the new Relevant Managed Service Provider category specifically.
- The gap between Royal Assent and actual effect has widened, not narrowed. Even once the Bill passes, substantive obligations aren't expected to bite until around 2028, delivered through secondary legislation following a government implementation consultation planned for later this year.
Why the timing gap matters more than the headline
It's tempting to read "not in force until 2028" as a reason to file this under "later." That's the wrong read for two reasons.
First, the direction is now settled, even if the detail isn't. A provider who waits for the secondary legislation before doing anything is starting the actual work two years later than a provider who starts now, and due diligence processes (see this week's other post) are already starting to ask about it.
Second, the consultation on implementation detail is expected this year, meaning the shape of the final rules, exact thresholds, exact reporting windows, gets decided in the next few months, not in some distant future. Firms who want a say in what "reasonable" looks like have a narrowing window to engage with that process.
What this means if you outsource your IT
If your provider manages your systems on an ongoing basis, ask them plainly whether they expect to fall inside the Relevant Managed Service Provider category once the thresholds are set, and what they're doing about it now rather than in 2028. A provider who's thought this through, and can point to independent certification they already hold, is telling you something useful about how seriously they take regulatory change generally.
We'll keep tracking Committee Stage as it progresses through the autumn.
Source:
UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill
Coverage of the 1 September 2026 Lords Committee Stage (MSP/data centre scope, fine figures).