If you run a managed service ā hosting, monitoring, IT support, security operations, anything you operate on an ongoing basis for UK clients rather than selling as a one-off product ā a bill moving through the House of Lords this month puts you in a regulatory category that did not exist before. The Cyber Security and Resilience Bill entered committee stage in the Lords on 1 September 2026, with further sitting days on 7 and 9 September, and it creates a new class of regulated entity built specifically around what you do.
Where the bill actually is
This is not yet law. The bill cleared all its Commons stages, entered the Lords on 25 June 2026, completed its Lords second reading on 14 July, and is now working through line-by-line committee scrutiny across four scheduled sitting days. Royal Assent is expected in late 2026, which is worth noting precisely because it means the obligations below are not yet in force ā but the shape of the bill is largely settled at this stage, and the direction it is heading is clear enough to plan around now rather than wait for.
The new category: Relevant Managed Service Provider
The bill introduces Relevant Managed Service Providers (RMSPs) as a distinct regulated category, alongside new coverage for designated critical suppliers, large data centres and large load controllers. If your business manages IT infrastructure, security monitoring, or similar ongoing services for other organisations ā rather than just selling them software they operate themselves ā this is the category being built with you in mind, regardless of your size.
RMSPs get statutory duties to implement appropriate and proportionate security and resilience measures across the services they provide, including the systems used to manage client environments specifically ā not just their own internal systems.
The 24-hour clock
The bill's incident-reporting regime is a two-stage duty. RMSPs must send an initial notification within 24 hours of becoming aware of a significant incident, to their regulator and the National Cyber Security Centre, containing the entity's name, the affected service, and brief details. A full report follows within 72 hours. That is a materially faster clock than most UK businesses currently run their incident response against, and it applies from the moment you become aware, not from when you have finished investigating.
Penalties follow a two-tier structure: up to £10 million or 2% of global turnover for standard breaches, rising to £17 million or 4% of global turnover for serious ones, plus up to £100,000 per day for an ongoing contravention that is not fixed.
Why this is worth acting on before Royal Assent, not after
Building a 24-hour incident notification process is not something you assemble the week a law takes effect ā it requires a defined escalation path, a named person who can authorise a regulatory notification without waiting for a committee meeting, and clarity on which of your services actually counts as in scope. Waiting for Royal Assent to start that work means starting it under time pressure, against a deadline you will not control.
What to actually do now
Work out whether you are an RMSP under the bill's current drafting. If you provide ongoing management of client IT or security infrastructure, rather than selling software your customers operate themselves, assume you are in scope until you have a specific reason to think otherwise.
Draft the 24-hour notification path now, while there is no deadline pressure. Decide who can send that first notification, what the minimum viable content of it is, and how you would produce it inside 24 hours of a genuine incident, using a table-top exercise rather than a real one to test it.
Watch the committee stage amendments rather than assuming the current drafting is final. Committee stage exists specifically to change details like scope and thresholds ā the core shape (RMSPs, 24/72-hour reporting, the two-tier penalty structure) is unlikely to disappear, but exact thresholds for what counts as "significant" could still move.
The bottom line
The UK's Cyber Security and Resilience Bill is not law yet, but it entered Lords committee stage on 1 September with its core structure ā a new Relevant Managed Service Provider category, 24-hour incident notification, and fines up to Ā£17 million ā largely intact. If you manage infrastructure or security for UK clients on an ongoing basis, build the reporting process this bill will require before Royal Assent forces the timeline on you.