Home › Blog › The Cyber Security and Resilience Bill: What small businesses need to know
The UK government is strengthening its national cyber defences through new legislation. If you run a small business, charity, or organisation in Sussex, you may wonder whether the Cyber Security and Resilience Bill affects you—and what you should be doing about it now.
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is a reformed version of existing network security regulations. It aims to increase UK defences against cyber attacks and better protect the essential services that the public relies on—everything from electricity grids to hospitals to water supplies. The Bill introduces tougher requirements on critical infrastructure operators and their suppliers.
The government introduced the Bill to Parliament for its first reading on 12 November 2025, describing it as a step change in the UK’s national security. It follows a policy statement the government published in April 2025, after several years of research and consultation with industry.
Who is covered by the new rules?
Not every small business is directly regulated by the Bill. It targets organisations in critical sectors—energy, water, transport, health, and digital infrastructure—plus managed service providers (MSPs) that support them. If your firm is an MSP or works as a supplier to one of these critical services, the new requirements will likely apply to you.
However, even if the Bill doesn’t regulate your business directly, the ripple effects matter. Larger organisations receiving the new rules will pass compliance requirements down to their suppliers. A small IT support firm, accountant, or marketing agency working with critical-sector clients may suddenly need to demonstrate stronger security controls.
What changes for organisations?
The Bill introduces three key changes:
Stronger incident reporting – Organisations covered by the rules must report serious cyber incidents to their regulator more quickly and in greater detail than before.
Enhanced regulator powers – Regulators gain authority to investigate incidents, audit compliance, and issue enforcement notices if standards aren’t met.
Supplier accountability – Larger organisations must check that their suppliers—including freelancers and consultants—meet basic cyber security standards.
What should your small organisation do now?
If the Bill doesn’t directly regulate you, don’t wait passively. Start with two practical steps:
Adopt Cyber Essentials – The government’s Cyber Essentials scheme is a self-assessment certification framework covering the most common internet-based security threats through five technical controls: firewalls, secure configuration, security update management (patching), user access control, and malware protection. It was designed with small organisations in mind, and NCSC provides free guidance and a readiness tool to help you prepare. If clients in regulated sectors ask whether your firm meets standards, Cyber Essentials certification is the credible answer.
Set up regular backups – The National Cyber Security Centre (NCSC) emphasises that backups are the foundation of resilience. Keep copies of your most important data—customer files, financial records, email—on removable media (external hard drives, USB sticks) disconnected from your network when not in use. Consider cloud backups as well (such as OneDrive, Google Drive, or iCloud), which offer automatic updates and redundancy.
For MSPs and critical-sector suppliers
If your business is an MSP or supplier to energy, water, health, or other critical sectors, review your service agreements now. Your larger clients will soon require evidence that you meet the Bill’s standards. Document your security practices: patch schedules, incident response procedures, staff training, and access logging. If you haven’t conducted a risk assessment in the past year, now is the time.
The practical difference for your organisation
Cyber Essentials, the government-backed framework, asks organisations to address five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. NCSC guidance notes that most cyber attacks are basic in nature, so getting these fundamentals right closes off the routes criminals use most often. The Cyber Security and Resilience Bill will eventually require evidence of similar practices from suppliers in critical sectors. Starting now means you won’t be caught scrambling when clients ask for it.
Backups, too, are a foundation. The NCSC’s small business guidance emphasises that data loss is inevitable in a long career—hardware fails, ransomware strikes, files are deleted by accident. A backup regime costs almost nothing to start. A USB drive with copies of your most critical files, stored off-site, is the fastest insurance against disaster.
Timeline and next steps
The Bill is working through Parliament, having passed its early Commons stages since its introduction in November 2025. Once it receives royal assent, organisations will typically be given a transition period to implement changes, with secondary legislation and regulator guidance expected to set out the exact timeframes—generally allowing longer for structural upgrades than for reporting procedures. Monitor the NCSC and gov.uk websites for guidance updates, particularly if you’re in an affected sector.
If you’re in a critical sector or work as a supplier to one, ask your regulator or larger clients what they’re planning. Early questions now prevent last-minute panic when compliance deadlines arrive. If you’re an MSP, audit your own practices now: patch schedules, incident response procedures, staff training records, and audit logs. Document everything. When clients ask whether you meet the standards, documentation is your answer.
In the meantime, improving your backups and considering Cyber Essentials certification will put you ahead. The cost of acting now is far lower than the cost of remediation later—or the cost of a cyber incident that could have been prevented.
Key points
- The Cyber Security and Resilience Bill reforms existing network security regulations for critical-sector organisations and their suppliers.
- Small businesses may be indirectly affected if they work with or support larger organisations in regulated sectors.
- Start now with Cyber Essentials principles and regular backups—both are simple, low-cost, and recommended by the NCSC.
- MSPs and suppliers to critical sectors should document their security practices and prepare for new compliance questions from clients.
- Monitor gov.uk and NCSC updates as the Bill progresses through Parliament.
Related: Guides