The UK’s most significant cybersecurity legislation in nearly a decade is working its way through Parliament. The Cyber Security and Resilience (Network and Information Systems) Bill — commonly called the CSR Bill — is expected to receive Royal Assent in 2026, with phased implementation running into 2028. For UK SMEs, now is the time to understand what is coming and start preparing.

The Bill replaces the 2018 Network and Information Systems Regulations, which were themselves an adaptation of an EU directive. The update is long overdue: the threat landscape has changed beyond recognition in eight years, and the original regulations left significant gaps in coverage. The government’s April 2026 open letter to UK businesses made clear that cyber resilience is now a strategic priority — not just a technical concern for IT teams.

What the Bill actually changes

Three changes matter most for businesses.

Expanded scope. The original NIS Regulations focused on operators of essential services — energy, water, transport, health, digital infrastructure. The new Bill adds managed service providers (MSPs) and data-centre operators for the first time, and creates a new category of “designated critical suppliers” who support essential services. If your business provides IT services, cloud hosting, or software to larger organisations in regulated sectors, you may fall into scope for the first time.

Shorter incident reporting windows. The Bill introduces a 24-hour initial notification requirement for cyber incidents, followed by a 72-hour full report. This mirrors the GDPR breach reporting regime — and creates a compliance pinch-point. If you are an MSP or critical supplier, your incident response plan must be fast enough to hit those windows. That means documented procedures, clear escalation routes, and ideally automated alerting before humans start writing the report.

Supply chain obligations. Essential service operators and regulated digital service providers will face new duties to manage cyber risk in their supply chains. In practice, this means they will pass those requirements down to their suppliers — including SMEs. If you supply goods, software, or services to organisations in regulated sectors, expect requests for security assessments, Cyber Essentials certification, and contractual security clauses to become standard.

Does this apply to your business right now?

Directly, the Bill primarily targets MSPs, data centres, and critical infrastructure operators. Most SMEs are not in that first wave of regulation. But the indirect effects are real and worth preparing for now.

If you supply into the NHS, energy sector, financial services, or local government, your customers will soon start asking questions about your cyber posture. If you use third-party IT services, their obligations under the Bill may affect your service continuity. If you process significant volumes of personal data, the shorter incident reporting timescales affect how you run your breach response.

The government has explicitly called for all UK businesses to achieve or refresh Cyber Essentials certification as a minimum baseline. It is increasingly a hard requirement for public sector contracts and a growing expectation in private sector procurement.

What to do in the next 90 days

Achieve Cyber Essentials if you haven’t already. The basic certification costs a few hundred pounds and demonstrates you meet five core technical controls: firewalls, secure configuration, access control, malware protection, and patch management. If you already hold it, check your renewal date.

Review and test your incident response plan. Most small businesses don’t have one. A basic one-pager covering who gets called when something goes wrong, how you log the incident, and when you notify customers or regulators is far better than nothing. The 24-hour reporting window under the CSR Bill leaves no room for working out the process on the day.

Audit your supply chain exposure. If you supply to organisations in regulated sectors, map out what data you handle on their behalf and what security assurances you could provide if asked. Getting ahead of the question is always easier than scrambling when a contract renewal depends on it.

KeepSafe.Report helps UK businesses monitor their compliance posture and flag where they are exposed under incoming regulations — useful for staying ahead of requirements like the CSR Bill without having to read every parliamentary briefing yourself. For businesses needing hands-on implementation, from securing systems to building incident response automation, CoolCoding.co.uk works with UK SMEs on the technical side of cyber resilience projects.

The CSR Bill is not yet law, but its direction is clear and the window for preparation is open. The businesses that act now will spend far less time and money than those who wait for the enforcement deadline to arrive.