Cyber Essentials vs CSRB: gap-analysis cover graphic. Five annual technical controls versus a continuous, governance-level regime as drafted. Secordit Intelligence.

Cyber Essentials vs the Cyber Security and Resilience Bill: Why Certification Alone Isn't Enough

For many UK managed service providers, Cyber Essentials (CE) or Cyber Essentials Plus (CE+) has long been the default answer to "are we secure enough?" It's a well-understood scheme, it's often a client contractual requirement, and it's relatively quick to renew each year. So when MSPs first hear about the Cyber Security and Resilience Bill, a natural assumption follows: "we're CE+ certified, so we're probably fine." That assumption is the single most common misconception we're seeing among MSPs preparing for the Bill, and it's worth unpacking carefully, because CE and the Cyber Security and Resilience Bill are not competing standards. They operate at different levels, and the gap between them is exactly where MSPs are most exposed.

Where the Cyber Security and Resilience Bill Actually Stands Right Now

Before comparing frameworks, it's worth being precise about the Bill's status, since a lot of commentary online overstates how settled things are. According to UK Parliament's own bill-stages page, the Cyber Security and Resilience Bill had its First Reading in the Commons on 12 November 2025, Second Reading on 6 January 2026, and Committee stage began 3 February 2026. The Bill was reintroduced in the Commons on 14 May 2026 as part of the carry-over from the 2024-26 session into 2026-27, followed by Report stage and Third Reading, both on 16 June 2026, and First Reading in the Lords on 17 June 2026. It's now numbered HL Bill 32 of session 2026-27, and Second Reading in the Lords is currently scheduled for 14 July 2026 -- though Parliament's own page explicitly flags that dates more than a week out may be provisional, so that date should be treated as indicative rather than fixed. Royal Assent is expected sometime in 2026 according to trackers, though phased commencement could realistically stretch into 2028. None of this is a reason to wait -- but it is a reason to be accurate about what's confirmed and what isn't.

What Cyber Essentials Actually Covers

Cyber Essentials and CE+ were designed to verify baseline technical hygiene, and they do that job well. The scheme focuses on five core technical controls: boundary firewalls, secure configuration, access control, malware protection, and patch management. CE+ adds independent technical verification on top of self-assessment, which is meaningfully more rigorous than CE alone -- but the scope is still the same five areas.

This is genuinely valuable. A significant share of real-world breaches trace back to failures in exactly these areas: unpatched systems, weak access control, misconfigured perimeters. CE and CE+ are a solid technical floor, and nothing about the Cyber Security and Resilience Bill changes that or makes them redundant. If anything, having CE/CE+ in place gives an MSP a head start, because the underlying technical hygiene it verifies is a sensible foundation for the governance layer the Bill is adding.

What the Cyber Security and Resilience Bill Adds on Top

The Bill works by amending and expanding the existing Network and Information Systems (NIS) Regulations 2018 -- it does not replace them outright. Its most significant change for MSPs is the creation of a new legal category: the Relevant Managed Service Provider (RMSP), defined as an entity providing ongoing management of a customer's IT systems under contract, covering support, maintenance, monitoring, and active administration, whether delivered on-premises or remotely. According to the GOV.UK "Relevant managed service providers" factsheet (last updated 30 June 2026), medium and large MSPs providing UK managed services fall into scope, while small and micro enterprises and certain public authority bodies are exempt. Data centre services, public electronic communications networks, and pure operational-technology management without IT management are explicitly excluded from the RMSP definition -- data centres instead get their own separate regulated category.

Where CE stops at technical hygiene, the Bill operates at a governance and resilience level entirely of its own:

Regulator Registration

In-scope RMSPs must register with the Information Commission (the regulator for this regime) and provide entity details. Overseas-based providers must appoint a UK representative. Once the relevant provisions commence, RMSPs get three months to register -- but critically, the underlying security duties apply from commencement, not from the point of registration. There's no grace period on the substance of the obligations.

Incident Reporting on a Strict Clock

This is the area with the least overlap with CE at all. Industry commentary describes a two-stage incident reporting process: an initial notification to the regulator and to the NCSC/CSIRT within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours. Affected customers must also be told "as soon as reasonably practicable" if they're likely to be adversely affected. CE certification says nothing about how, or how fast, you report an incident once one occurs -- and for MSPs, whose access spans multiple client environments, a single incident can trigger a cascade of separate client-notification obligations that a CE-focused security programme simply isn't built to handle.

Supply Chain and Vendor Risk Management

The Bill expects "appropriate and proportionate" risk-management measures and ongoing due diligence across supply chains and vendor relationships -- not just the MSP's own perimeter. CE's scope is largely confined to the certified entity's own environment; it doesn't assess how an MSP evaluates or monitors the tools and subcontractors it relies on.

Continuous Monitoring and Evidence Trails

Where CE/CE+ certification is effectively a point-in-time snapshot, renewed annually, the Bill's expectation is closer to continuous: security kept proportionate to risk using state-of-the-art methods, with the ability to demonstrate ongoing diligence rather than a single certificate.

Board-Level Accountability

The governance expectations implicit in the Bill push cyber risk into a board-level conversation, not just an IT function. That's a cultural and organisational shift that a technical certification scheme was never designed to measure.

It's worth being clear that some of the operational detail here isn't fully settled yet. The exact thresholds for what counts as a "significant" incident, and the precise size or turnover thresholds distinguishing in-scope RMSPs from exempt small and micro enterprises, are explicitly left to secondary legislation that has not yet been published. Any numbers you see quoted for these thresholds right now should be treated as speculative, not settled.

Cyber Essentials vs the Cyber Security and Resilience Bill: A Side-by-Side View

  • Scope of assessment: CE/CE+ -- five technical controls (firewalls, configuration, access control, malware protection, patching). CSRB -- governance, incident response, supply chain, and technical controls together.
  • Assessment cadence: CE/CE+ -- annual certification, point-in-time. CSRB -- continuous, evidence-based, ongoing.
  • Incident handling: CE/CE+ -- not addressed. CSRB -- 24-hour initial notification, 72-hour full report, plus client notification duties.
  • Supply chain oversight: CE/CE+ -- not addressed. CSRB -- vendor due diligence and supply chain risk management expected.
  • Accountability level: CE/CE+ -- IT/technical function. CSRB -- board-level accountability implied.
  • Regulator relationship: CE/CE+ -- certifying body, no ongoing regulator registration. CSRB -- registration with the Information Commission required for in-scope RMSPs.

The takeaway from that comparison isn't that one framework is "better" than the other -- it's that they answer different questions. CE/CE+ answers "is our technical hygiene sound?" The Cyber Security and Resilience Bill answers "can we detect, report, and govern our way through an incident, and can we prove it?" An MSP genuinely needs both answers, and holding CE or CE+ does not mean the second question has already been answered.

Where This Leaves MSPs Today

Because the secondary legislation defining exact thresholds hasn't been published, and because Royal Assent and commencement timing remain genuinely uncertain, no MSP can yet claim full compliance with a regime whose fine details don't exist yet. What MSPs can do now is figure out, honestly, where their existing CE/CE+ coverage overlaps with the direction of travel the Bill has already made clear through its published factsheet -- and where the gaps are.

That's precisely the exercise CSRB-BRIDGE (£297) is built for. It's a self-serve gap-analysis toolkit that cross-references your existing Cyber Essentials / CE+ coverage against Secordit's own CSRB-BRIDGE assessment framework -- a 16-area structure developed by Secordit to map anticipated CSRB-relevant requirement areas, not an official government-defined count -- and produces a prioritised remediation worksheet showing exactly where technical hygiene ends and governance readiness needs to begin.

If you're not yet sure how exposed your current setup is, or where CE/CE+ coverage genuinely stops, the free Product Selector quiz takes about 90 seconds, requires no email address, and points you to the most relevant starting resource for your situation. Or start with the Free MSP Briefing for a broader overview first.

Secordit Intelligence products are operational intelligence and compliance readiness materials. They do not constitute legal advice and do not guarantee regulatory outcomes.

Last reviewed: 1 July 2026

Matthew Protheroe-Hill, Founder, Secordit Intelligence

Back to blog