Quentin CasaresData and AI leadership for regulated growth
Insights

2026-09-21 / 7 min

Your suppliers are getting their own regulator

The Cyber Security and Resilience Bill reached Lords committee on 1 September 2026. It turns managed service providers and data centres into regulated entities with a 24 hour reporting clock and turnover-linked fines. Boards should establish which of their suppliers are in scope.

In brief: the Cyber Security and Resilience Bill had its Lords second reading on 14 July 2026 and went into committee on 1 September, and it changes who is regulated rather than only what is required. Managed service providers, data centres above 1MW of rated IT load, designated critical suppliers and large load controllers become regulated entities in their own right, with a 24 hour reporting clock and penalties of up to £17 million or 4 per cent of global turnover. Boards should establish which of their suppliers fall in scope and what those suppliers will shortly be obliged to tell them.

Most third-party risk registers rest on a quiet assumption: the supplier is unregulated, so the firm carries the consequence and the supplier carries a contract. Legislation now in the House of Lords removes that assumption for the part of the data estate that most organisations depend on and least directly control.

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to Parliament on 12 November 2025, had its second reading in the Lords on 14 July 2026 and entered committee stage on 1 September 2026. Royal Assent is expected late in 2026, with the substantive duties arriving through secondary legislation and taking effect around 2028. The lead time matters less than the design, because the design moves the regulatory boundary outwards to include the firms your platform runs on.

The Bill regulates the layer beneath you

The NIS Regulations 2018 reach operators of essential services and a narrow set of digital service providers. The Bill widens that perimeter to four further categories, each with its own test and its own named regulator.

CategoryTest for being in scopeRegulatorFirst obligation
Data centresThird-party and colocation sites at 1MW or more of rated IT load; enterprise facilities at 10MW or moreOfcomNotification and structured information to Ofcom within three months of designation
Relevant managed service providersAny person providing managed services in the UK, whether or not established in the UK, that is not a small or micro enterpriseThe Information Commission, formerly the ICORegistration of name, contact details and address within three months of commencement, and a UK representative if based overseas
Designated critical suppliersDesignation by a sector regulator of a supplier whose failure would significantly disrupt an essential serviceThe designating regulator, from twelve sector regulatorsSecurity measures proportionate to the risk, and incident reporting
Large load controllersAggregate control of 300MW or more of electricity flow to smart appliancesSector regulatorSecurity measures and incident reporting

The managed service provider definition is the one worth reading twice. It is drawn by size and location of service rather than by criticality, it reaches providers with no UK establishment, and it covers ordinary IT outsourcing: remote support and helpdesks, application and email management, infrastructure management, and managed security services such as a security operations centre. A firm that outsourced its data platform operations has almost certainly bought a managed service inside this definition.

The reporting clock starts with your supplier

Under the Bill, an in-scope entity must make an initial notification to its regulator and the National Cyber Security Centre within 24 hours of becoming aware of an incident with the potential for significant impact, followed by a fuller report within 72 hours. The category of notifiable event widens to include near misses. Data centres, digital service providers and managed service providers must also tell affected customers about the risk and the nature of the incident.

That customer notification duty is the provision boards should read most closely, because it inverts today's information flow. At present a firm learns about a supplier incident when the supplier decides to tell it, usually after the supplier's own lawyers have formed a view. In the new regime, disclosure becomes an obligation owed to the customer alongside the one owed to the regulator, and it arrives on a clock the supplier does not control.

Enforcement is calibrated to make that credible. Serious contraventions attract penalties of up to £17 million or 4 per cent of global annual turnover, whichever is greater; less serious ones reach £10 million or 2 per cent, and continuing non-compliance can draw £100,000 a day. The government puts the whole-economy compliance cost at under £150 million a year, which indicates how modest it considers the burden per firm.

Concentration is the reason the Bill exists

The case made at second reading was about concentration rather than volume. Introducing the Bill on 14 July, Baroness Lloyd of Effra told the Lords that more than 600,000 UK businesses had been subject to cyber attack in the preceding year, and that 97.6 per cent of managed service provider revenue sits with large and medium providers making up fewer than one firm in ten by count. The government's own factsheet makes the same point about data infrastructure: ten operators generate 80 per cent of data centre revenue and control two-thirds of live capacity. Data centres were designated critical national infrastructure in 2024.

The worked example offered to peers was the Synnovis ransomware attack, which delayed more than 11,000 NHS appointments through a pathology supplier rather than any hospital's own systems. That is the shape of the exposure: a few providers sit beneath a great many services, and the entity that fails is often not the entity that holds the regulatory relationship.

The controls already exist under other names

None of this requires a new framework. It requires applying disciplines most data functions already run to a boundary they have treated as somebody else's.

What the board will needExisting discipline that supplies it
A named list of which suppliers fall in scope and who owns each relationshipCritical Data Elements thinking, applied to suppliers rather than fields: a short list, an accountable owner, a defined threshold
Which reports, services and numbers stop working if a given supplier failsData lineage extended through the supplier boundary, which is the same evidence BCBS 239 asks for at the firm level
A route for a supplier notification that arrives at 2am to reach a decision makerOperational resilience and incident management, with the supplier feed treated as a monitored input
A named individual answerable for the dependencySM&CR statements of responsibilities in regulated firms
Evidence of what the customer actually experienced during an outageConsumer Duty outcome monitoring

The gap between that list and current practice is measurable. In the Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 from fieldwork carried out between August and December 2025, 15 per cent of UK businesses had reviewed the cyber risks posed by their immediate suppliers and 6 per cent had looked at their wider supply chain. Among large businesses the immediate-supplier figure was 48 per cent, which still leaves half of the largest firms without a supplier risk review of any kind. Thirty-one per cent of businesses had a board member with explicit responsibility for cyber security, and 25 per cent held a formal incident response plan.

Five questions before the next board meeting

  1. Which of our suppliers would be a relevant managed service provider, an in-scope data centre, or a candidate for critical supplier designation, and has anyone written that list down?
  2. If a supplier is required to notify us of an incident within its own 24 hour window, who receives that notification, and what decision are they empowered to make?
  3. Which of our regulatory reports, customer journeys and board metrics depend on those suppliers, and can we show the lineage without rebuilding it by hand?
  4. Do our contracts with these suppliers already require the notification the Bill will require, and are the two timelines compatible?
  5. Could we ourselves be designated a critical supplier to somebody else's essential service, and if so, who in the firm owns that possibility today?

The perimeter of regulation is moving to where the dependency actually sits, and the firms that map it first will be answering questions rather than absorbing them.

Sources

Related service: Advisory

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.