Is Your MSP in Scope for the Cyber Security and Resilience Bill?
Share
If you run a UK managed service provider, the question "does the Cyber Security and Resilience Bill apply to us?" is probably the single most urgent thing on your compliance radar right now. The Bill creates a new legal category — the Relevant Managed Service Provider, or RMSP — and if your business falls into it, you will have new registration and security duties to meet. This article walks through exactly what an RMSP is, the in-scope and exempt criteria published by GOV.UK, a practical self-assessment checklist, and what's still genuinely unresolved.
What Is an RMSP?
According to the GOV.UK "Relevant managed service providers" factsheet (last updated 30 June 2026), the Cyber Security and Resilience Bill amends and expands the existing Network and Information Systems (NIS) Regulations 2018 — it does not replace them outright. Within that expanded framework, it creates a new regulated category: the Relevant Managed Service Provider.
An RMSP is defined as an entity that provides ongoing management of IT systems under contract. That includes activities such as:
- Support and maintenance of client IT systems
- Monitoring of client environments
- Active administration of client infrastructure, whether delivered on-premises or remotely
This is a deliberately broad definition aimed at capturing the day-to-day reality of managed service delivery — not just a narrow slice of it. If your contracts involve ongoing, active management of a client's IT systems rather than one-off project work, you are exactly the kind of business this category was written to describe.
Who's In Scope, and Who's Exempt
The factsheet sets out both sides of the line reasonably clearly, even though some of the fine detail is still pending (more on that below).
In scope
Medium and large MSPs providing UK managed services fall within the RMSP category as currently described. If your business meets the ongoing-management definition above and isn't a small or micro enterprise, you should assume you are being asked to plan as if this applies to you.
Exempt
Small and micro enterprises are exempt, as are certain public authority bodies. The factsheet also explicitly excludes several categories of provider from the RMSP definition:
- Data centre services — these get their own separate regulated category, defined instead by Rated IT Load (broadly, 1MW or more for third-party/colocation facilities, and 10MW or more for enterprise-operated facilities)
- Public electronic communications networks and services — already regulated under separate frameworks
- Pure operational-technology (OT) management without IT management — providers managing OT alone, without an IT management component, fall outside the RMSP definition
If your business sits in one of these excluded categories, the RMSP duties described below won't apply to you directly, though you may still need to consider other parts of the Bill depending on your services.
Self-Assessment Checklist: Are You Likely an RMSP?
Based directly on the GOV.UK criteria above, ask yourself the following. This isn't a legal determination, but it will give you a structured read on where you likely sit.
- Do you provide ongoing (not one-off) management of client IT systems under a contract?
- Does that management include support, maintenance, monitoring, or active administration — delivered either remotely or on-site?
- Is your business classed as medium or large, rather than small or micro?
- Are your managed services delivered to UK clients?
- Is your core offering IT management, rather than data centre hosting, public electronic communications, or standalone OT management?
If you answered yes to most of these, you are likely to fall within the RMSP category once the relevant provisions commence. If you're unsure on the size threshold, the incident-notification detail, or how your specific service mix maps against the criteria, that uncertainty is exactly what a structured gap analysis is designed to resolve — more on that below.
What Happens If You're In Scope
The factsheet sets out a defined set of duties for RMSPs once the relevant provisions of the Bill commence:
- Register with the Information Commission (the regulator), providing entity details
- Appoint a UK representative if your business is based overseas
- Implement "appropriate and proportionate" risk-management measures
- Keep security proportionate to risk, using state-of-the-art methods
- Act to prevent or minimise the impact of incidents
- Notify the regulator of "significant" incidents
Once relevant provisions commence, RMSPs get three months to register — but importantly, the security duties apply from commencement, not after registration. In other words, registration is a compliance deadline, but your underlying security obligations start on day one regardless of whether you've registered yet.
On incident reporting specifically, the wider Bill framework (corroborated across multiple industry sources, though not confirmed on a single GOV.UK page in the way the RMSP factsheet is) describes a two-stage process: an initial notification to the regulator and the NCSC/CSIRT within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours. Affected customers must also be told "as soon as reasonably practicable" if they're likely to be adversely affected. Industry commentary — not primary-source-verified, but worth noting as a planning signal — flags privileged access management as a likely major regulatory focus area for MSPs, given how a single incident in an MSP's environment can trigger notification obligations across many client relationships at once.
What's Still Pending
It's important to be honest about what isn't settled yet. The GOV.UK factsheet explicitly leaves the following to secondary legislation that has not yet been published:
- The exact numeric thresholds distinguishing in-scope medium/large MSPs from exempt small/micro enterprises
- The exact definition of a "significant incident" that triggers notification duties
Separately, penalty figures and MSP-population estimates are circulating in law-firm trackers and industry commentary, but these are not confirmed on GOV.UK or Parliament's own pages, so treat any specific numbers you see quoted elsewhere with appropriate caution until secondary legislation lands.
On timing: the Bill is progressing through Parliament, having had its Report stage and 3rd reading in the Commons on 16 June 2026, its 1st reading in the Lords on 17 June 2026, and its 2nd reading in the Lords currently scheduled for 14 July 2026 — though Parliament's own tracking page notes that dates more than a week out may still be provisional. Royal Assent is suggested by trackers to land sometime in 2026, though phased commencement could stretch implementation into 2028. None of this is a reason to panic, but it is a reason to start understanding your position now rather than waiting for every last detail to be confirmed.
Working Out Where You Stand
Given how much of this hinges on your specific service mix, size, and client base, the fastest way to get a structured read on your position is Secordit's free Product Selector quiz — it takes about 90 seconds, requires no email address, and points you toward the resources most relevant to your situation based on how you answer.
If you've worked through the checklist above and believe you're likely in scope as an RMSP, the natural next step is documenting exactly where your gaps are before secondary legislation arrives. CSRB-BRIDGE (£297) is a self-serve gap analysis toolkit structured specifically around the CSRB expectations described above, with a Cyber Essentials/CE+ cross-reference and a prioritised remediation worksheet — giving you a documented starting point rather than a guess.
And if you want a broader, no-cost overview of what the Bill means for MSPs before committing to anything, the Free MSP Briefing is a good place to start.
Secordit Intelligence products are operational intelligence and compliance readiness materials. They do not constitute legal advice and do not guarantee regulatory outcomes.
Last reviewed: 1 July 2026
Matthew Protheroe-Hill, Founder, Secordit Intelligence