Scope and in-scope entities

Who the Cyber Security and Resilience Bill applies to

The Cyber Security and Resilience Bill is expected to widen the range of organisations covered by the UK's cyber rules. If you run an essential service, operate a digital service, or deliver a managed service that others depend on, you are the kind of organisation the Bill is designed to bring into scope.

Last reviewed 14 July 2026 · all sources linked in the text

The short answer

Does the Bill apply to me?

The Bill has not yet received Royal Assent, so there are no statutory duties or deadlines yet. What the government has set out, in the King's Speech and the published policy statement, is a clear direction: more organisations in scope, stronger incident reporting, and stronger regulator powers, updating and expanding the Network and Information Systems (NIS) Regulations 2018. The most reliable way to know whether you are likely to be caught is to look at the entity model and the sectors below, then check the signals. For the full background, read what the Bill is.

The entity model

Essential entities and important entities

The Bill is widely described as the UK's equivalent of the EU NIS2 Directive, and it is expected to use a similar split between essential entities and important entities. This categorisation decides how heavily an organisation is regulated. See how the two regimes line up on our NIS2 and the UK Bill comparison.

Essential entities

The highest-impact organisations

Operators of the services the country most depends on, in sectors such as energy, transport, water, health and digital infrastructure. Under a NIS2-style model this group is expected to carry the fullest set of duties and the closest regulatory supervision.

Important entities

Significant, but a step below

A broader group of significant organisations, expected to include many managed service providers and digital service providers, that matter to the wider economy without sitting in the essential tier. They are expected to carry duties too, with supervision that is lighter touch.

Sectors and organisation types

Who is likely to be in scope

The Bill is expected to build on the sectors already covered by the NIS Regulations 2018 and to reach further into the digital supply chain. The organisation types below are the ones most likely to be caught, though the definitive list is set by the Bill.

  • Energy, including electricity, oil and gas
  • Transport, including air, rail, water and road
  • Drinking water and wastewater
  • Health and healthcare providers
  • Digital infrastructure, such as data centres and internet exchange points
  • Digital services, such as cloud platforms, online marketplaces and search engines
  • Managed service providers delivering IT and security services to others
  • Public sector and government service providers

First person, not the sidelines

What it means for MSPs

Managed service providers are one of the groups the government has signalled it intends to bring into scope. If you deliver IT, cloud or security services that other organisations depend on, the expected duties are likely to apply to you directly, not just through your customers.

CyPro is itself an in-scope MSP. We are preparing for this Bill too, so the guidance on this site comes from an organisation that expects to sit inside the same rules, not one selling from the outside. That is the lens we bring to helping other in-scope organisations get ready.

Digital service providers

How digital service providers are treated

Digital service providers are already partly covered today. The current NIS Regulations 2018 reach certain relevant digital service providers, such as cloud computing services, online marketplaces and online search engines. The Bill is expected to keep digital service providers in scope and to strengthen what is required of them, in line with the direction set out in the policy statement.

A quick self-check

Signals you are likely in scope

The more of these that describe your organisation, the more likely the Bill is to reach you when it commences.

  • You run an essential service in a regulated sector such as energy, transport, water, health or digital infrastructure.
  • You are a managed service provider (MSP) delivering IT, cloud or security services that other organisations rely on.
  • You operate a digital service such as a cloud platform, an online marketplace or a search engine.
  • You are already covered by the current Network and Information Systems (NIS) Regulations 2018.
  • You supply critical services into organisations that are themselves in scope, so their duties flow down to you through contracts.
  • You sit above the size threshold that is expected to be set for essential or important entities.

This is a plain guide, not a definitive ruling. The in-scope list is set by the Bill itself and by the secondary legislation (statutory instruments) that will follow Royal Assent, so the precise thresholds and definitions can still change. An interactive scope self-check will be added here once the Bill receives Royal Assent and the duties are set.

Quick answers

Scope questions, answered

Who does the Cyber Security and Resilience Bill apply to?

The Bill is expected to widen the range of organisations covered by the UK's cyber rules, building on the sectors already caught by the NIS Regulations 2018. On the government's published policy statement it is expected to bring more organisations into scope, including managed service providers, and to use an essential entities and important entities style of categorisation. The definitive list is set by the Bill and by the secondary legislation that follows it.

Am I in scope if I am a managed service provider?

Managed service providers are one of the groups the government has signalled it intends to bring into scope. If you deliver IT, cloud or security services that other organisations depend on, you should plan on the basis that the Bill is likely to reach you. CyPro is itself an in-scope MSP, so we are preparing for this alongside the organisations we advise.

What is the difference between an essential entity and an important entity?

The essential and important split is the NIS2-style model the UK Bill is expected to follow. Essential entities are the highest-impact operators of critical services and are expected to face the fullest duties and closest supervision. Important entities are a broader group of significant organisations that carry duties too, with supervision expected to be lighter touch. The exact definitions will be set out in the Bill and its secondary legislation.

Compare the UK Bill with NIS2

Does the Bill apply to digital service providers?

The current NIS Regulations 2018 already cover certain relevant digital service providers, such as cloud computing services, online marketplaces and online search engines. The Bill is expected to keep digital service providers in scope and to strengthen the requirements on them. As with every category, the precise scope is confirmed by the Bill and its secondary legislation.

Find more answers on the full FAQ page.

3D rocket illustration for booking a free discovery call about the Bill

Prepare early, not in a panic

Not sure if you are in scope?

Book a discovery call to talk through where your organisation is likely to sit and how to prepare before the duties arrive.