The Rules Are Changing: What the Cyber Security and Resilience Bill Means Before It Becomes Law
The Sekhmet Scribe | Team Sekhmet
YOUR IT PROVIDER IS ABOUT TO BECOME REGULATED INFRASTRUCTURE.
For most UK businesses, the Cyber Security and Resilience Bill will not arrive as a letter from a regulator. It will arrive as a clause in a contract renewal.
The Bill cleared the House of Commons in June and is now before the Lords, with Royal Assent expected later this year and obligations phased in over the period that follows. It is the most significant reform of UK cyber law since the NIS Regulations of 2018 — and for the first time it pulls managed service providers, data centres and designated critical suppliers directly into a statutory regime.
This edition of The Sekhmet Scribe is about what changes, who it reaches, and why waiting for the commencement date is the wrong plan.
Protect • Empower • Evolve
WHAT’S HOT 🔥
The Supply Chain Is Now In Scope
The old regime regulated operators of essential services and a narrow band of digital providers. The new one recognises what attackers worked out years ago: the fastest route into a well-defended organisation is through a less well-defended supplier that already has legitimate access.
MSPs, data centres and critical suppliers move inside the perimeter of the law. Reporting timelines tighten sharply — a 24-hour early warning, followed by a fuller report within 72 hours, to both the sector regulator and the NCSC. The penalty regime runs to £10 million or 2% of global turnover for standard contraventions, rising to £17 million or 4% for serious ones, with daily penalties available for ongoing breaches.
If your provider is in scope, you are in scope by contract long before you are in scope by statute.
WHAT’S HOT 🔥
Compliance Pressure Arrives Early
Regulation of this kind changes behaviour well ahead of commencement. Insurers reprice. Procurement teams rewrite their questionnaires. Buyers in a deal process start asking whether a target could actually survive a 24-hour reporting clock. Large customers push obligations down their supply chain, because that is the cheapest way to discharge their own.
The organisations that will find this straightforward are the ones already running the fundamentals: an asset inventory that is current rather than aspirational, incident response that has been rehearsed rather than merely written, logging that can genuinely reconstruct an event, and a supplier register that records who has access to what.
None of that is new. The Bill simply makes it enforceable.
WHAT’S NOT ❄️
Waiting for secondary legislation before starting anything. Assuming “we’re too small” — scope reaches through contracts, not only through thresholds. Incident response plans that have never been tested against a clock. Not knowing which of your suppliers hold privileged access into your environment. Discovering mid-incident that nobody is clear on who notifies the regulator, or when the clock started.
Twenty-four hours is not enough time to build a process. It is barely enough time to follow one.
THE SEKHMET STANCE
We read the Bill as a floor rather than a ceiling — and as a compelling argument for doing now what good practice already demanded.
At Sekhmet we help clients map their scope, tighten incident response to the new reporting clocks, evidence controls against the NCSC Cyber Assessment Framework, and get supplier oversight into a state that survives scrutiny. For portfolio businesses we do it once and apply it consistently, rather than fourteen times at fourteen different standards.
The lioness moves before the season turns, not after.
The deadline that matters isn’t the date it commences. It’s the date your biggest customer asks.
Protect • Empower • Evolve
Team Sekhmet