" /> Cyber Security and Resilience Bill: MSP and RMSP Checklist
Guide

Cyber Security and Resilience Bill: What MSPs Must Do (RMSP Checklist)

Updated · Sep 2026 By ITSECOPS Free · No signup

Updated: September 2026. The Cyber Security and Resilience Bill entered Lords Committee Stage on 1 September 2026, with Royal Assent expected late 2026 and substantive duties following through secondary legislation.

The Cyber Security and Resilience Bill (CSRB) is the biggest change to UK cyber regulation since NIS 2018, and its sharpest edge points at managed service providers. The bill creates a new regulated category, the Relevant Managed Service Provider (RMSP), covering MSPs with privileged access to client environments. If you run an MSP serving UK businesses, this page tells you what is coming and what to do before it lands. The context is loud: the 2026 Companies House WebFiling breach touched director data across roughly 5 million businesses, and the NCSC called the retail attack wave on M&S and Co-op a national wake up call.

Am I a Relevant Managed Service Provider?

You likely qualify if you provide ongoing management of IT infrastructure, networks or security for customers, with privileged or administrative access to their systems, as a service. That is the working definition of most MSPs, MSSPs and outsourced IT providers. Data centres and designated critical suppliers are also pulled into scope.

What the bill changes for MSPs

  • Registration: RMSPs register with their regulator rather than operating unnoticed.
  • Security duties: demonstrable risk management across your own estate and your access into client estates.
  • Two stage incident reporting: an initial report within 24 hours and a full report within 72 hours, to the regulator and NCSC, plus notification to affected customers.
  • Penalties: up to £17 million or 4 percent of global turnover for the most serious failures, £10 million or 2 percent below that, with daily penalties for continuing breaches.

The RMSP readiness checklist

  • Map every client environment where you hold privileged access, and how that access is secured (MFA, PAM, session recording).
  • Get your own house certified: Cyber Essentials Plus at minimum, ISO 27001 if you serve regulated clients.
  • Stand up 24/7 detection across your estate and your RMM and management tooling: a 24 hour reporting clock is unworkable if nobody watches nights and weekends.
  • Write and test the incident reporting runbook: who notifies the regulator, NCSC and customers, with what facts, inside 24 hours.
  • Review supply chain: your own vendors will be asked about under your registration.
  • Put evidence in order: asset inventory, patching cadence, backup and restore tests, access reviews.

The economics: build 24/7 or buy it

A credible in house 24/7 SOC needs at least five analysts to cover shifts, which in UK salaries alone is £250,000 to £400,000 a year before tooling. That is why most MSPs under a few hundred seats buy the capability instead. ITSECOPS runs white label NOC and SOC for MSPs in the US, UK and Ireland with follow the sun coverage from CET and IST time zones: your brand, our analysts, and the 24 hour CSRB reporting clock covered while your team sleeps. See our white label MSP support service and the ranked list of top white label NOC and SOC providers.

Why ITSECOPS: we partner with every industry standard vendor, so EDR, MDR, backup and Microsoft 365 licences typically cost less through us than buying direct, and we publish prices instead of hiding them behind a sales call. Compare for yourself with the cybersecurity price comparison, the security stack recommender and the Microsoft 365 and Google Workspace licence recommender. Prices display in your local currency automatically.

Book a free CSRB readiness call

Frequently asked questions

When does the Cyber Security and Resilience Bill take effect?

The bill is in the House of Lords now, with Royal Assent expected late 2026. Substantive duties arrive through secondary legislation, expected around 2028, but regulators and insurers are already asking MSPs about readiness.

Does the bill apply to small MSPs?

The RMSP definition turns on what you do, ongoing management with privileged access, not on headcount. Small MSPs should assume they are in scope and prepare proportionately.

What is the incident reporting deadline under the bill?

Two stages: an initial report within 24 hours of becoming aware of a significant incident and a full report within 72 hours, to the regulator and NCSC, plus notifying affected customers.

How do MSPs meet a 24 hour reporting clock without a night shift?

By buying detection as a service: a white label SOC watches your estate and your clients around the clock, triages alerts and hands your team a documented incident with the facts a report needs.

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation
Popular guides and pricingCybersecurity price comparison 2026  ·  EDR pricing per endpoint  ·  MDR pricing per device  ·  Veeam vs Acronis vs Datto  ·  Remote IT support pricing  ·  White-label help desk pricing  ·  24/7 SOC monitoring cost  ·  Top MDR providers  ·  White-label NOC and SOC for MSPs  ·  Top ISO 27001 consulting firms  ·  ISO 27001 implementation plan  ·  CMMC readiness services  ·  Top CMMC consulting firms  ·  ISO 42001 AI certification  ·  Global laptop provisioning and MDM  ·  Security stack recommender  ·  Managed IT services Norway