The Cyber Security and Resilience Bill has produced a good deal of anxious marketing aimed at small businesses, most of it overstating the direct effect and understating the indirect one.

Here is the accurate position, and what is genuinely worth doing about it.

What the Bill actually does

It updates and extends the UK's existing network and information systems regulations, which were inherited from EU law and have been widely regarded as too narrow.

The main changes bring more organisations into scope — notably data centres and managed service providers — strengthen incident reporting duties, and give regulators broader powers to set and enforce requirements. Secondary legislation is expected to include duties on in-scope organisations to manage cyber risk in their supply chains through appropriate and proportionate measures.

The Bill cleared the Commons and moved to the Lords during 2026, with implementation phased over the following period.

Who is directly in scope

Operators of essential services — energy, water, transport, health, digital infrastructure — along with digital service providers, data centre operators and managed service providers.

If you are a ten-person joinery firm, an accountancy practice or a marketing agency, you are almost certainly not directly in scope. Anyone telling you otherwise is selling something.

How it reaches you anyway

Through your customers.

An organisation that is in scope has to manage supply chain risk. It cannot do that by hoping, so it does it the way large organisations always do: contractual security commitments and questionnaires, flowed down to suppliers of every size.

This is already happening and the Bill accelerates it. The practical consequences for a small business supplying larger clients:

  • More security questionnaires, more detailed, with less tolerance for vague answers.
  • Contractual security clauses in supplier agreements, including incident notification obligations with tight deadlines.
  • Evidence rather than assertion. Certification, policies, evidence of testing, rather than a tick in a box.
  • Cyber Essentials as a floor, particularly given the government's April 2026 open letter urging organisations to certify and to embed it across their supply chains.
The Bill will not send a regulator to your door. It will send your biggest customer a questionnaire, and they will send it to you.

What to do now

Four things, in order, and none of them is expensive.

1. Get Cyber Essentials, or align to it

It is the recognised UK baseline and it answers a large proportion of what questionnaires ask. Certification costs a few hundred pounds for a small business plus the remediation work, and the gap analysis is worth doing even if you stop there. The detail is in this guide.

2. Write down an incident response plan

Two pages. Who decides, who to call, what to do first, who must be told and within what deadline and how you would keep working.

Questionnaires ask whether you have one. More importantly, contracts increasingly require you to notify a client within a specified time of an incident affecting their data, and you cannot meet a 24-hour notification duty without knowing in advance who makes the call. There is a workable format in this article.

3. Know your own suppliers

The duty flows both ways. List the suppliers who hold your data or have access to your systems: your accountant, your IT provider, your cloud services, your payroll bureau.

For each, know what they hold, what security they claim and how you would find out if they had an incident. A one-page register is enough and it is what a client's due diligence will ask for.

4. Prepare your answers

Write your responses to a standard security questionnaire once, properly and reuse them. Access control, patching, backup, encryption, staff training, incident response, subprocessors.

Businesses that do this answer a questionnaire in an hour. Businesses that do not spend two days on each one and give inconsistent answers across clients, which is worse than a slow answer.

What not to do

Do not buy compliance software. A ten-person business does not need a governance platform. It needs four documents and Cyber Essentials.

Do not panic about direct regulation. You are almost certainly not in scope, and acting as though you are wastes money that should go on actual controls.

Do not ignore it either. The supply chain effect is real, it is already visible in procurement and businesses that cannot answer a security questionnaire credibly are quietly losing tenders without being told why.

The genuine upside

Everything on the list above is worth doing regardless of legislation. Cyber Essentials makes you meaningfully harder to attack. An incident response plan turns a bad week into a manageable one. A supplier register tells you where your actual exposure is.

The Bill is simply the reason it will now be asked about, which for most small businesses is the prompt that was missing.

Our security solutions team helps UK businesses get to a position where a client questionnaire is an hour's work rather than a fortnight's anxiety. Get in touch if you would like a hand with the four steps above.