UK Legislation
Cyber Security and Resilience Bill: What UK SMEs Must Do
Published 6 July 2026
Why this matters now
Even before Royal Assent, regulated buyers, public sector frameworks and large enterprises are baking the Bill's expectations into procurement. If you supply any of them, expect contract clauses on incident reporting, baseline controls and assurance evidence.
Three ways you might be in scope
- Direct – you are an Operator of Essential Services, a Relevant Digital Service Provider, a Managed Service Provider or a Data Centre.
- Indirect – you supply a directly-regulated entity and your contract cascades the obligations.
- Cascading – you supply a supplier of a regulated entity. The obligations land via your customer's customer.
What you will need
- A baseline of cyber controls evidenced by certification. Cyber Essentials is the floor; Cyber Assurance sits above it.
- An incident response plan with named roles and the 24/72-hour reporting timeline.
- Supplier assurance covering your own critical providers.
- Board-level cyber governance and a documented risk register.
How CE and CA help
The Bill does not name a certification, but Cyber Essentials is the recognised UK baseline and Cyber Assurance is the SME-friendly governance layer. Holding both lets you answer procurement questions with a single certificate reference rather than a 200-question spreadsheet. See CSR Bill vs CE vs CA.
Practical next steps for an SME
- Check which of your customers are likely directly regulated.
- Read the cyber clauses in your top five customer contracts.
- Get Cyber Essentials in place now if you do not have it.
- Add Cyber Assurance Level 1 if you tender for public sector or regulated work.
- Write or refresh an incident response plan with reporting timelines.
