UK Cyber Security & Resilience Bill

Regulation is coming. Know your exposure before it lands.

The Cyber Security and Resilience Bill will pull managed service providers into direct regulation and push new duties down the supply chain to the businesses they serve: 24-hour incident reporting, evidenced controls, and penalties reaching up to 4% of global turnover. CyberPostura scores where you stand today and what to fix first.

Start the free posture check No login · ~6 minutes · 8 weighted domains

24 hrs

Incident reporting window

Initial notification to your regulator and the NCSC after becoming aware of a significant incident.

4%

Maximum penalty

Proposed upper limit on fines, calculated against global annual turnover.

~1,100

MSPs expected in scope

Government estimate of managed service providers to be designated as relevant MSPs.

Built for two audiences

Mid-market firms of 50–500 staff, and the MSPs that run their IT.

Different obligations, one dependency. We score both sides of the relationship against the same control framework so the conversation between you is evidence-based.

Managed service providers

Likely regulated from around 2027–28

MSPs with 50 or more staff are expected to be designated as “relevant managed service providers”, with security duties, 24-hour incident reporting and the obligation to evidence controls on request. Privileged access into customer estates will be a focal point.

Businesses consuming IT services

Squeezed by suppliers, insurers and customers

You are unlikely to be designated directly, but your providers will be. Their duties arrive at your door as contract clauses, evidence requests and incident cooperation obligations — alongside tightening insurer and enterprise scrutiny.

Eight weighted domains

Scored against Cyber Essentials, NCSC CAF and CIS Controls v8.

Domains are weighted by how strongly they drive real-world loss and regulatory exposure, so your score reflects risk rather than a checklist.

Gov×1.0

Governance

Board ownership of cyber risk, policy, certification and assurance.

CSR Bill relevant
IAM×1.3

Identity & access

Authentication strength, privilege control and joiner-mover-leaver hygiene.

Endpoint×1.0

Devices & endpoint

Endpoint protection, device management and configuration baselines.

Vuln×1.2

Patching & vulnerabilities

Update cadence, vulnerability discovery and remediation of exposure.

Backup×1.1

Backup & resilience

Backup coverage, immutability and proven restore capability.

IR×1.2

Incident readiness

Response planning, exercising and regulator notification readiness.

CSR Bill relevant
Supply×1.0

Supply chain

Supplier assurance, critical dependency mapping and contractual control.

CSR Bill relevant
People×0.9

People

Security awareness, phishing resistance and reporting culture.

How it works

Six minutes to a defensible starting point.

01

Answer 20 questions

Two scoping questions, then 18 control questions across eight weighted domains. No login, roughly six minutes.

02

See your score and exposure

A 0–100 posture score, domain breakdown and a regulatory readout written for your organisation type and size.

03

Get a prioritised roadmap

Your weakest domains become sequenced initiatives, weighted by risk, with CSR Bill relevance flagged.

Start now

Find out where you stand before someone else asks.

The free check gives you a score, a domain breakdown and a prioritised roadmap. Then get certification-ready — the detailed assessment with Cyber Essentials gap analysis is a one-off £299 +VAT, and a Remediation Roadmap you can track. Answer for your organisation, and if IT is outsourced, answer for what your IT provider does on your behalf.