CSRB Radar — July 2026: The Bill Clears the Commons, Now It's the Lords' Turn
Share
It's been a while since the last update on this blog, and in that gap the Bill has kept moving. If you've been heads-down running client environments instead of tracking Hansard, here's the state of play as of today, grounded in what's actually been published rather than what's been guessed at.
Where the Bill actually is
The Cyber Security and Resilience (Network and Information Systems) Bill had its First Reading in the House of Commons on 12 November 2025, Second Reading on 6 January 2026, and then went through Public Bill Committee — clause-by-clause scrutiny and evidence sessions — from 3 February 2026. It has now completed its remaining Commons stages — Report Stage and Third Reading, both on 16 June 2026 — and moved across to the House of Lords, where it had its First Reading the next day, 17 June 2026, and has been renumbered HL Bill 32 for the 2026-27 session.
That renumbering is just process, not a restart: the Bill was carried over from the 2024-26 session into 2026-27 (Parliament's own tracker records a formal "Bill reintroduced" step on 14 May 2026 as part of that process), which is why you'll see it referenced under two different bill numbers depending on which chamber's tracker you're looking at. It's the same Bill throughout.
Update, checked directly against Parliament's own bill-stages tracker: the Lords Second Reading is currently scheduled for 14 July 2026. Parliament's own page flags that dates more than a week out can still move, so treat that specific date as the current plan rather than a lock — but the direction of travel is settled: Commons stages are done, and the Bill is now with the Lords.
Bill progress snapshot
Commons complete · Lords scrutiny now active
The one document worth reading if you read nothing else
GOV.UK's factsheet on "Relevant Managed Service Providers" was last updated 30 June 2026 — that's the freshest primary-source material tied to MSPs specifically, and it's where the actual scope and duties are defined, not in secondary commentary. Key points:
- An RMSP is any entity providing ongoing management of IT systems under contract — support, maintenance, monitoring, active administration, on-prem or remote.
- Medium and large MSPs providing UK managed services are in scope. Small and micro enterprises are exempt, as are certain public authority bodies.
- Data centre services, public electronic communications networks, and pure operational-technology management (without IT management) are excluded from the RMSP definition — data centres get their own regulated category instead.
- Duties include: registering with the Information Commission (the regulator), appointing a UK representative if you're overseas-based, running appropriate and proportionate risk-management measures, keeping security proportionate to risk using state-of-the-art methods, and notifying the regulator of significant incidents.
- Once the relevant provisions commence, RMSPs get three months to register — but security duties apply from commencement, not after registration.
The wider Bill-level incident reporting regime — which applies to RMSPs too — is a two-stage process: initial notification to the regulator and NCSC/CSIRT within 24 hours of becoming aware of a significant incident, then a fuller report within 72 hours. Affected customers have to be told "as soon as reasonably practicable" if they're likely to be hit.
What's still genuinely open
Two things the factsheet does not settle, and that nobody should be claiming are settled: exactly what counts as a "significant" incident triggering the 24/72-hour clock, and the precise size or turnover thresholds that separate an in-scope RMSP from an exempt small/micro provider. Both are left to secondary legislation that hasn't been published yet. Anyone telling you the exact numbers right now is speculating — including some of the penalty figures (the £10m/2%, £17m/4% turnover-based tiers you may have seen quoted) which are consistently reported across law-firm trackers but haven't been independently verified against the Bill's actual clauses in this update.
Estimates of how many MSPs will end up in scope also vary by source — figures ranging from roughly 900 to over 1,200 firms have been cited depending on which threshold assumptions are used. There isn't one definitive number yet, and there won't be until the secondary legislation lands.
What this means for your business today
None of the above changes what's sensible to do right now: know whether you'd plausibly count as medium/large under current thinking, and know what a registration and incident-reporting workflow would need to look like for your stack. Trackers following the Bill's overall pace suggest Royal Assent in 2026, with commencement phased in — some estimates put full enforcement as late as 2028. Gap-analysis and registration-readiness work doesn't need to wait for a commencement date to be useful.
If you want a fast, structured way to see where your MSP currently stands against what's confirmed so far, run the free Product Selector quiz — it's self-serve, takes about 90 seconds, and needs no email. If you'd rather read first before doing anything interactive, the Free MSP Briefing is the lower-commitment starting point.
If you'd rather this kind of update land automatically, CSRB-WATCH is Secordit's monthly regulatory monitoring subscription for UK MSPs — each issue is agent-drafted, human-reviewed, versioned, and delivered on a schedule. It doesn't include bespoke advisory support, legal advice, or direct analyst access; it's a monitoring product, not a consulting engagement.
Secordit Intelligence products are operational intelligence and compliance readiness materials. They do not constitute legal advice and do not guarantee regulatory outcomes.
Last reviewed: 1 July 2026.