The cyber security bill reaches committee stage in the Lords
Regulation would extend to data centres and managed IT service providers. Small businesses will meet it indirectly — through their contracts with suppliers.
The Cyber Security and Resilience (Network and Information Systems) Bill has cleared the Commons and is in the House of Lords. As at 4 September 2026 it is at committee stage, with report stage and third reading still to come, followed by consideration of amendments and Royal Assent. It is not yet law, and the text can still change before it is.
Who it covers
Regulation currently reaches energy, transport, health, drinking water, digital infrastructure and some digital services. The Bill would add four categories: data centres, managed service providers — firms that run other organisations' IT under contract — large load controllers, which manage the energy use of smart appliances, and critical suppliers without whom a regulated organisation cannot deliver its service.
What changes in substance
More incidents would have to be reported. Regulators would be able to recover their costs, share information and impose higher fines. The Secretary of State would gain powers to set strategic priorities for regulators and to direct organisations to act in the interests of national security.
Where the money is for a small firm
The Bill imposes nothing directly on a café, a tailor or a law practice. But if your IT supplier falls within the definition of a managed service provider, the duties land on them — and compliance costs usually reach the client as a revised contract and a revised monthly price. This is how GDPR obligations travelled down the market too.
There is one practical step for today: know who holds your email, your CRM and your backups, and under what contract. Once the Bill passes, that conversation with your supplier will happen anyway — better to start it knowing your own arrangements.
We will follow the Bill and report when it receives Royal Assent and when secondary legislation sets the specific thresholds.


