You are using an outdated browser. For a faster, safer browsing experience, upgrade for free today.

The Cyber Security and Resilience Bill: the supply chain is the part most organisations underestimate

The Cyber Security and Resilience Bill cleared its third reading in the House of Commons on 16 June 2026 and has moved to the House of Lords. It is not law yet, and the detail will continue to move – much of the substance will land in secondary legislation and regulator guidance rather than in the Bill itself. But the shape of it is now clear enough to plan against, and we would encourage organisations to start doing exactly that.

What it does

In broad terms, the Bill modernises and widens the UK’s existing network and information systems regime. It applies directly to five sectors – transport, energy, drinking water, health and digital infrastructure – and extends the perimeter to bring in a further population of organisations estimated at around a thousand, including data centre operators, managed service providers, online marketplaces, search engines and cloud computing providers.

For those in scope, the practical obligations are recognisable: demonstrable compliance with defined security standards, strengthened risk assessment, regular audit and reporting, and mandatory incident reporting – including ransomware reporting, which is intended in part to give government a genuine picture of a threat that has been chronically under-reported. Enforcement powers include daily penalties, with figures of up to £100,000 per day discussed since the policy was first trailed in 2025.

The clause that will affect the most organisations

The provision with the widest reach is not the one about regulated sectors. It is the expectation that regulated entities ensure their partners and suppliers meet the standards set under the regime.

That single idea changes the population affected by an order of magnitude. If you supply software, professional services, logistics, facilities management or anything else to an NHS trust, a water company, an energy provider or a large managed service provider, you will feel this regime – not through a regulator, but through your customer’s procurement and contract management teams. You will be asked to evidence controls, accept audit rights, commit to notification timeframes, and demonstrate that your suppliers are held to something equivalent.

In our experience this is where organisations get caught out. Being out of direct scope feels like an exemption. It usually is not. It simply means the requirement arrives as a contractual clause with a commercial deadline attached, rather than as a regulatory obligation with a consultation period and a transition window.

The fundamentals problem

It is worth reading the Bill alongside what the National Cyber Security Centre has been saying about the current threat picture. In June 2026 the NCSC’s chief executive, Dr Richard Horne, noted that the organisation had handled more than 200 incidents in the year to May, and made a point that we think deserves more attention than it received: too many significant incidents remain possible because the fundamentals are not in place.

That is not a comfortable observation for a market that has spent heavily on detection and response tooling. But it matches what we find. Unsupported software still running because a business process depends on it. Administrative access that was granted for a project three years ago and never withdrawn. Backups that exist but have never been restored under realistic conditions. Asset inventories that were accurate at the point they were compiled.

None of that is solved by procurement. It is solved by ownership, discipline and a willingness to fund unglamorous work.

What we would do between now and Royal Assent

  • Establish whether you are in scope, and whether your customers are. The second question matters more for most organisations than the first, and it is the one people forget to ask.
  • Map your critical suppliers properly. Not a procurement list – a view of which third parties could stop you operating, and what you would actually do if one of them was offline for a fortnight.
  • Test the reporting path. Mandatory reporting within tight timeframes is a process problem before it is a legal one. Who decides an incident is reportable? At what hour of the night? On what evidence?
  • Rehearse recovery, not just detection. The regime is called resilience for a reason. Being able to restore service is the outcome regulators, customers and boards actually care about.
  • Fix the fundamentals now. Patching, privileged access, segmentation, tested backups, and knowing what you own. This work has a long lead time and every version of the final legislation will require it.

The organisations that will find this regime straightforward are the ones already doing most of it. For everyone else, the eighteen months between now and meaningful enforcement is a reasonable, but not generous, amount of time.

APHS supports organisations across ICT strategy, information and data governance, security, and programme delivery. If you would like a view on where you stand against the direction of travel – whether as a regulated entity or as a supplier to one – get in touch.


Sources