What the Cyber Security and Resilience Bill Means for Mid-Market Businesses
Sep 08, 2026For years, the UK's core cyber security legislation for businesses outside government and critical national infrastructure has been light touch: UK GDPR obligations around personal data, and the Network and Information Systems (NIS) Regulations, which mostly reached large operators of essential services. Most mid-market businesses fell outside its direct scope, even if their customers or supply chain partners were affected.
That's changing. The Cyber Security and Resilience Bill is designed to extend NIS-style duties further down the supply chain, including to categories such as managed service providers and, depending on final scope, other suppliers to regulated sectors.
Why this matters even if you're not directly in scope
Three things make this relevant to a scaling business, even one that isn't itself a "critical" operator.
First, if you supply technology, data or managed services to a business that is in scope, you can be pulled in through supply chain due diligence, contractually or as a direct duty, regardless of your own size.
Second, regulators and enterprise customers increasingly treat "is this supplier following current best practice" as a procurement gate, independent of whether a law technically applies to you yet. Security questionnaires already ask about incident reporting, patch cadence and third-party risk management, and that trend only tightens as the Bill's obligations bed in across larger organisations.
Third, the direction of travel in UK cyber regulation over the past several years, from UK GDPR through to this Bill, has consistently been toward wider scope and tighter incident reporting timelines. A business that waits for the law to name it directly is usually a year or two behind the standard its customers already expect.
What the Bill is expected to require
In broad terms, in-scope organisations are expected to face duties around maintaining and demonstrating a baseline level of security across their systems and supply chain, reporting significant incidents to a regulator within a defined window, and, for certain supplier categories such as managed service providers, extending those obligations contractually down to their own customers and vendors.
What a mid-market business should actually do now
You don't need to wait for Royal Assent to start closing the gap between where you are and where the regulatory direction of travel is heading:
- Know where your business sits in your customers' and suppliers' compliance chains, not just your own
- Have a real incident response process, not a document that has never been tested
- Be able to answer a security questionnaire from evidence, not from memory
- Treat vendor and cloud risk as a standing item for review, not a one-off
The real risk isn't the Bill
The Bill matters less as a compliance deadline than as a signal. UK cyber regulation is moving toward treating security as a whole-supply-chain responsibility, not just a duty for the largest operators. Businesses that treat security as something to bolt on when a law names them directly tend to be the ones scrambling when it does. Businesses that treat it as an ongoing discipline tend to already be close to compliant by the time anyone asks.
If you don't have someone at board level who owns that discipline full-time, that's usually the actual gap, not the specific wording of any one Bill.