https://www.noxia.co.uk/field-notes/a-twenty-four-hour-clock · printed from noxia.co.uk · sources checked 18 September 2026
Field note · Security
A 24-hour clock, and your IT supplier is in scope.
Most small firms will never be regulated under this bill. Almost all of them buy from somebody who will be — and the way a supply-chain obligation reaches a small firm is not through a statute, it is through a contract renewal with a new schedule attached.
- Security
- Supplier due diligence
- Incident response
- Regulation
The short answer
The Cyber Security and Resilience Bill brings medium and large managed service providers, medium and large data centres and large load controllers into the UK’s network and information systems regime, and lets regulators designate critical suppliers. Reporting is two-stage: a light-touch notification within 24 hours to the regulator with the NCSC copied in, and a full report within 72 hours. The government estimates the cost of the legislation at less than £150 million per year.
On this page · 6 sections
There is a specific way that a regulation aimed at large infrastructure arrives at a twelve-person brokerage, and it is worth naming because it is entirely predictable.
It arrives as an email from your IT provider, eight months from now, attaching a revised service schedule. The schedule contains new obligations on you: to report suspected incidents to them within a fixed period, to maintain particular controls, to permit audit, and to notify them of changes to your systems. You will read it in four minutes and sign it, because the alternative is finding another IT provider.
Who comes into scope
Three new categories, plus a mechanism. Medium and large data centres, including enterprise data centres meeting the thresholds. Medium and large managed service providers — the outsourced IT function a great many UK professional firms rely on entirely. Large load controllers, which manage electrical load for smart appliances. And the mechanism: regulators gain the ability to designate critical suppliers, bringing an important supplier into scope by decision rather than by category.
That last one is the interesting one, because it means scope is no longer fully knowable from a list. A supplier can become regulated because of who it supplies.
What reportable actually means
For most regulated entities the test has three parts: the incident has adversely affected the operation or security of network or information systems; the impact is, or is likely to be, significant; and it relates to the whole or part of the UK. The factsheet is explicit that ransomware is reportable, and — this is the part people miss — so are pre-positioning attacks that are likely to have significant impacts even if they have not had one yet.
"Likely to" is doing a great deal of work in that sentence. An organisation that discovers an intruder has been present for six weeks without doing anything visible has a reportable incident, and it has twenty-four hours.
Three things a small firm should do, none of which are expensive
- Find out which of your suppliers will be in scope. Your IT provider, your hosting, your practice management system's hosting. Ask them directly, in writing, whether they expect to be a relevant managed service provider and what they expect to require of clients. The quality of the answer is itself a supplier check — and the supplier signals we watch are the other half of it.
- Write down who gets the call at 2am on a Saturday. A 24-hour clock that starts on awareness means someone must be able to be made aware. One name, one number, one deputy.
- Know what you have. The most common reason a firm cannot report inside 24 hours is not slowness; it is that nobody can say what systems exist or what they connect to. The stack check and the cleanup work both start here, because you cannot assess an impact on an inventory you do not have.
What this does not tell you
It is a bill, not an Act. The detail, the thresholds for "medium and large", and the commencement dates will move, and anyone quoting you a compliance date today is guessing. The government's own estimate is that the legislation costs less than £150 million per year across everyone in scope, which is a small number for a national regime and tells you the direct burden is concentrated on relatively few organisations.
What is not a guess is the direction: the obligations flow down the supply chain by contract faster than they arrive by statute, and they arrive at the small firm as paperwork it did not negotiate. The firms that handle this well are the ones that already know what they run and who answers the phone. That is not a security project; it is an operations one.
Questions people actually ask
What are the incident reporting deadlines in the Cyber Security and Resilience Bill?
Two stages: a light-touch notification to the relevant regulator within 24 hours, with the National Cyber Security Centre copied in, followed by a full detailed report within 72 hours. It applies to operators of essential services, relevant managed service providers, relevant digital service providers and data centre operators.
Are managed service providers in scope of the Cyber Security and Resilience Bill?
Yes. Medium and large managed service providers are brought into scope, along with medium and large data centres including qualifying enterprise data centres, and large load controllers. Regulators also gain the ability to designate critical suppliers, which brings an important supplier into scope by decision rather than by category.
What counts as a reportable incident?
For most entities, an incident that has adversely affected the operation or security of network or information systems, where the impact is or is likely to be significant, and where it relates to the whole or part of the UK. Ransomware is named as reportable, as are pre-positioning attacks likely to have significant UK impacts even if they have not yet had one.
Does the bill apply to a small professional firm?
Most small firms will not be directly regulated. The practical effect reaches them through their suppliers: an IT provider or hosting company in scope will pass obligations down by contract, typically as a revised service schedule requiring prompt incident notification, particular controls and audit rights. That arrives as paperwork rather than as law.
Sources
- GOV.UK, “Incident reporting” factsheet, Cyber Security and Resilience (Network and Information Systems) Bill, updated 30 June 2026: two-stage reporting with a light-touch notification to the regulator within 24 hours, NCSC copied in, and a full report within 72 hours; applies to operators of essential services, relevant managed service providers, relevant digital service providers and data centre operators; the three-part significance test; ransomware and “pre-positioning attacks that are likely to have significant impacts in the UK, even if they have not had an impact yet” named as reportable. gov.uk ↗ — primary; the government’s own factsheet on its own bill re-checked every 6 months
- GOV.UK, “Summary of the Bill” factsheet, first published 12 November 2025 and updated 30 June 2026: medium and large data centres, including qualifying enterprise data centres, brought into scope; “Medium and large managed service providers will be brought into scope”; large load controllers; a designated critical suppliers mechanism; “the cost of this legislation is estimated to be less than £150 million per year”. gov.uk ↗ — primary. The bill is not yet an Act, so thresholds, detail and commencement can still change re-checked every 6 months
- The prediction that the obligation arrives as a contract schedule rather than as a statute, and the three things to do, are ours. — our own argument, labelled as such
Checked 18 September 2026. Next scheduled check 17 March 2027. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.
Cite this note
Noxia, “A 24-hour clock, and your IT supplier is in scope”, Field notes, 18 September 2026; sources checked 18 September 2026. https://www.noxia.co.uk/field-notes/a-twenty-four-hour-clock
You cannot report in 24 hours what you cannot list.
Most firms cannot produce a current inventory of what they run, what it connects to and who owns it. We build that list, keep it current automatically, and put one name against each system — so that when the clock starts, the first hour is spent deciding rather than searching.
Talk to us about thisRead next
Security
£320 buys five controls, and £25,000 of cover if you tick the box.
Five controls, £320 plus VAT to certify, and £25,000 of cyber liability cover for organisations under £20m turnover that opt in when they apply. It is the cheapest security decision a small firm makes.
Getting started
What to automate first in an advice firm — and what to never automate.
Two questions decide it: if it is wrong, can you undo it, and would you notice? Everything else is detail. The second is the one firms get wrong — a mistake nobody sees is not a small mistake, it is a slow one.
Security
The Online Safety Act applies to all sizes. Including yours.
The duties apply to regulated user-to-user and search services regardless of size. The categories with extra duties start at 3 million UK users; the base duties do not.