How MPSs could become a ‘critical supplier’ under new UK legislation 

Even if MSPs are not directly regulated, there’s a second way The UK’s Cyber Security and Resilience Bill may affect them 

In part one of our blog, we introduced the Cyber Security and Resilience Bill (CSBR) and explained how it updates 2018 NIS legislation. One significant change is how companies may become a regulated MSP (RMSP) under the new legislation. 

There is, however, another way that MSPs could be affected by the legislation – as a designated critical supplier (DCS). 

How you could become a designated critical supplier 

If you’re not an RMSP, you may still become a DCS. The most important criterion is that you need to supply goods or services to one of the core regulated categories.   

You then need to meet three threshold criteria: 

  • The regulator judges that a failure or disruption in your goods or services — or an incident affecting your network or systems — could significantly disrupt an essential service.  
  • Your goods or services depend on networks and information systems, making them relevant to the scope of the regulatory framework. 
  • You’re not already subject to equivalent cyber resilience obligations under other regulatory frameworks; for example, telecoms providers regulated under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021. 

Regulators will let you know their decision about whether or not they’ll designate you as a DCS. 

However, you can build a picture of your customer base now to understand if you are supplying an essential service. OES and RDSP are already in scope of UK NIS, so you can already tell if you are working with a company in those groups. Then if you are working for an MSP, whether they meet the criteria above in terms of employee number and revenue/balance sheet will give you a good idea if they will be designated an RMSP.   

The changes that CSRB will add to NIS regulation 

These are some of the core areas that the new legislation will add or strengthen. 

Enforcement of CAF 

The Cyber Assessment Framework (CAF) is a tool to help organisations assess and improve their cybersecurity and resilience by managing cyber risks. There are two profile levels, the Basic Profile and the Enhanced Profile, which set out principles and objectives that organisations should meet to assess and manage their cyber security. 

The new legislation intends to establish these principles and objectives on a firmer footing, making it essential for firms to follow best practice and easier for them to do understand their obligations. They specifically state these will be aligned closely with NIS2 requirements

Improved incident reporting 

The new legislation will require both the NCSC and relevant regulators to be informed of a significant incident no later than 24 hours after becoming aware of that incident, followed by an incident report within 72 hours. Alignment with NIS2 reporting deadlines is intended.  

The requirement will also change from reporting an incident that had an adverse effect to reporting one that it is potentially capable of doing so.  

The intention is that NCSC and regulators are kept in the loop at the same time of any incidents so they can understand the threat landscape and provide assistance to affected companies. They also hope the requirements will raise standards across the industry.   

Regulated providers of digital services, managed services and data centers will be required to notify their customers who may be affected by a significant incident to encourage “openness and accountability.” 

Other changes 

The ICO’s remit will be broadened by the legislation and companies will have an expanded duty to share information once they have registered as a regulated entity. As part of separate legislation, the ICO will also be restructured and renamed the Information Commission.  

Regulators also have new powers to impose charges and recover costs, so there may be further additional recurring costs for regulated companies in the future. 

Judging if you are in scope for CSRB 

You can reasonably judge now if you will be classed as an RMSP. By looking at your client base, you can start to determine if you meet the criteria of a DCS and prepare for compliance.  

Even if you are not likely a DCS, it may be beneficial to bring your company into compliance where possible. The legislation provides a framework for cybersecurity readiness and improved resilience, which can reassure customers and provide a competitive advantage. It also improves your readiness to work with a regulated category. 

The legislation is expected to expand over time. NIS expansion in both the EU and UK has already seen an increase in the number of companies entering scope.  

Indeed, another change with CSRB will make it easier for future expansions. The Secretary of State will be able to update the regulatory framework without requiring an Act of Parliament, subject to certain safeguards. The government explicitly states that an example of these powers is the ability to bring new sectors and sub-sectors in scope of the regulations. 

CSRB offers benefits for competition 

Legislation or not, now is the time to address potential gaps in your security posture, so you are ready for the legislation and in a better competitive position. 

The government expects the bill to have a “positive impact on competition by ensuring that all businesses, regardless of size or sector, adhere to consistent minimum cyber security standards.” 

It also hopes that the bill will reduce the ability of firms underinvesting in resilience to undercut safer and more competent MSPs, creating fairer market competition. 

Preparing for CSRB — there’s no need to wait 

There are still many things to be decided and finalized with the CSRB. But the time from gaining royal assent to implementation should be one to two years. 

We can safely assume that there will be:  

  • A call for appropriate backups with immutable copies 
  • A clear disaster recovery plan 
  • Proactive security monitoring with tools like SIEM 
  • A clear understanding of the risks your company faces 
  • The ability to proactively identify and address security issues with tools such as penetration testing 
  • Full documentation of your processes and how you respond to an emergency 
  • Focus on having the right team members in place augmented by external tools and services to bolster your cyber security 

You don’t need to wait. Now is the best time to address potential gaps in your security posture, leaving you ready for legislation such as CSRB. 

Seizing competitive advantage with CaaS 

MSPs that address any security gaps with the right tools will be in a strong position to offer Compliance as a Service (CaaS) to their clients. 

Many SMBs are facing the same security pressures as larger companies, but don’t have the capability to respond. Meanwhile, most MSPs will have a lot of these security systems already in place internally due to the nature of their business.  

MSPs that can package them as a service for their clients will have an opportunity to boost margin, increase loyalty and, most importantly, help keep them secure.  

Find out more about Kaseya CaaS

One Complete Platform for IT & Security Management

Kaseya 365 is the all-in-one solution for managing, securing, and automating IT. With seamless integrations across critical IT functions, it simplifies operations, strengthens security, and boosts efficiency.

One platform. Everything IT.

Kaseya 365 customers experience the benefits of the best IT Management and Security tools in a single solution.

Explore Kaseya 365

Your success is our #1 priority

Partner First is a commitment to flexible terms, shared risk and dedicated support for your business.

Explore Partner First Pledge

2026 Kaseya State of the MSP Report

Kaseya - 2026 State of the MSP Report - Web Graphic - 1200x800-UPDATED

Get 2026 MSP insights from 1,000 plus providers and learn how to grow revenue, adapt to market pressure, and stay competitive.

Download Now

What is NIST compliance? A practical guide for IT teams and MSPs

“NIST” gets used to refer to several different things, often interchangeably and not always accurately. The agency. The Cybersecurity Framework.

Read blog post

IT compliance for MSPs: how to build a practice that scales

Compliance has quietly become one of the most commercially important capabilities an MSP can develop. The combination of rising regulatory

Read blog post

ISO 27001: What it is, what certification requires, and whether your organization needs it

ISO 27001 is the international standard for information security management systems. It is the most widely recognized security certification globally,

Read blog post