The UK Cyber Law That Will Change IT Support For Good
A significant piece of UK legislation is making its way through Parliament – and if your business uses an IT support company, it matters to you directly. The Cyber Security and Resilience Bill passed the House of Commons on 10 June 2026 and received its first reading in the House of Lords on 17 June. Peers are due to debate its principles at second reading on 14 July 2026, with Royal Assent expected later this year.
When it comes into force – implementation is expected to be phased through to 2028 – it will do something that has not happened before in UK law: it will place IT companies like ours under direct government regulation.
What Is This Bill?
The Cyber Security and Resilience Bill updates the Network and Information Systems (NIS) Regulations 2018. To put that in plain terms: the NIS Regulations are the existing rules that set minimum cyber security and incident reporting standards for organisations running critical national infrastructure – large utilities, hospitals, financial services, and digital infrastructure providers. Until now, IT companies that manage other businesses’ systems have mostly sat outside those rules.
The new bill changes that significantly. It expands who is covered, raises the bar on what is required, and hands the Information Commissioner’s Office (ICO) new oversight powers.
What Is Changing
Managed Service Providers come under ICO regulation for the first time. Companies that manage IT systems, networks, and software on behalf of other businesses will fall directly under the ICO. An estimated 900 to 1,100 IT managed service providers across the UK will be in scope. They will be required to demonstrate that appropriate and proportionate security measures are in place across the services they deliver to clients.
Faster incident reporting becomes mandatory. When a cyber incident occurs, in-scope organisations will be required to submit a 24-hour early warning to the relevant regulator and the National Cyber Security Centre (NCSC), followed by a full incident report within 72 hours. There will also be mandatory notification of affected customers in relevant circumstances. These timelines are significantly faster than what is currently required.
Supply chain security obligations will flow down. Organisations that fall under the new rules will be able – and in some cases required – to pass security obligations down through their supply chains. In practice, this means businesses that use in-scope IT providers may begin to receive requests to demonstrate their own cyber hygiene, provide security certifications, or make contractual commitments about how they handle data.
Why This Matters to Your Business
Having your IT provider regulated is, on balance, good news if you are a client. It means:
- Your IT company is legally accountable for maintaining defined security and resilience standards – not just promising to in a sales brochure.
- Incident reporting becomes faster and more structured, so you should be informed promptly if something goes wrong that affects your systems.
- The bar rises across the IT industry, which means less variation in security practice quality among providers and more consistent protection for the businesses that rely on them.
The bill also signals where UK cyber regulation is heading more broadly. The government has built in powers to extend the scope further through secondary legislation over time – potentially drawing more businesses and their suppliers into its reach in the years ahead.
Where System Force IT Already Stands
Because we take the security of the businesses we look after seriously, we have been working to the standards this bill requires well ahead of it becoming law.
System Force IT is accredited to ISO/IEC 27001 – the international standard for information security management, audited annually by a UKAS-accredited certification body. We also hold Cyber Essentials certification, the UK government-backed scheme that verifies essential technical controls are in place. These are not marketing badges: they represent ongoing, independently verified commitments to how we manage our own security and our clients’ data.
The Cyber Security and Resilience Bill’s requirements for managed service providers largely align with what ISO 27001 already demands. Our clients are therefore already working with a provider that is positioned to meet the new regulatory requirements without any significant change to how we operate.
What to Think About If You Are Reviewing Your IT Arrangements
If you are currently evaluating your IT support or wondering whether your existing provider is properly prepared, here are some practical questions to ask:
- Are they certified to ISO 27001 or Cyber Essentials? These are the clearest independent indicators that a provider’s own security practices meet a defined standard.
- Do they have a tested incident response process? Under the new law, incidents must be reported within 24 hours. Your provider should be able to tell you clearly what they would do if something went wrong at 2am on a Friday night.
- Can they explain how they manage your data and access? Providers that will come under ICO oversight should be able to answer this confidently and transparently.
You can read more about how we approach security for our clients and what our managed IT service includes. If you would like to discuss what this legislation means for your business specifically, please get in touch with our team – we are happy to talk it through.
The Timeline to Watch
To be clear about where things stand: the bill is not yet law. The Lords second reading on 14 July 2026 is when peers debate the overall intent and principles. There will be further committee and report stages before Royal Assent, which is expected later this year. Full implementation for managed service providers is expected to be phased in during 2028.
That sounds some way off – but building a compliant supplier relationship takes time. Businesses that start asking the right questions of their IT providers now will be far better placed when the rules come into force. And businesses that are already working with a provider like System Force IT, which holds ISO 27001 accreditation and delivers IT support to the standard the new law envisions, are already ahead of the curve.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


