UK Cyber Security & Resilience Bill
Regulation is coming. Know your exposure before it lands.
The Cyber Security and Resilience Bill will pull managed service providers into direct regulation and push new duties down the supply chain to the businesses they serve: 24-hour incident reporting, evidenced controls, and penalties reaching up to 4% of global turnover. CyberPostura scores where you stand today and what to fix first.
24 hrs
Incident reporting window
Initial notification to your regulator and the NCSC after becoming aware of a significant incident.
4%
Maximum penalty
Proposed upper limit on fines, calculated against global annual turnover.
~1,100
MSPs expected in scope
Government estimate of managed service providers to be designated as relevant MSPs.
Built for two audiences
Mid-market firms of 50–500 staff, and the MSPs that run their IT.
Different obligations, one dependency. We score both sides of the relationship against the same control framework so the conversation between you is evidence-based.
Likely regulated from around 2027–28
MSPs with 50 or more staff are expected to be designated as “relevant managed service providers”, with security duties, 24-hour incident reporting and the obligation to evidence controls on request. Privileged access into customer estates will be a focal point.
Squeezed by suppliers, insurers and customers
You are unlikely to be designated directly, but your providers will be. Their duties arrive at your door as contract clauses, evidence requests and incident cooperation obligations — alongside tightening insurer and enterprise scrutiny.
Eight weighted domains
Scored against Cyber Essentials, NCSC CAF and CIS Controls v8.
Domains are weighted by how strongly they drive real-world loss and regulatory exposure, so your score reflects risk rather than a checklist.
Governance
Board ownership of cyber risk, policy, certification and assurance.
CSR Bill relevantIdentity & access
Authentication strength, privilege control and joiner-mover-leaver hygiene.
Devices & endpoint
Endpoint protection, device management and configuration baselines.
Patching & vulnerabilities
Update cadence, vulnerability discovery and remediation of exposure.
Backup & resilience
Backup coverage, immutability and proven restore capability.
Incident readiness
Response planning, exercising and regulator notification readiness.
CSR Bill relevantSupply chain
Supplier assurance, critical dependency mapping and contractual control.
CSR Bill relevantPeople
Security awareness, phishing resistance and reporting culture.
How it works
Six minutes to a defensible starting point.
Answer 20 questions
Two scoping questions, then 18 control questions across eight weighted domains. No login, roughly six minutes.
See your score and exposure
A 0–100 posture score, domain breakdown and a regulatory readout written for your organisation type and size.
Get a prioritised roadmap
Your weakest domains become sequenced initiatives, weighted by risk, with CSR Bill relevance flagged.
Start now
Find out where you stand before someone else asks.
The free check gives you a score, a domain breakdown and a prioritised roadmap. Then get certification-ready — the detailed assessment with Cyber Essentials gap analysis is a one-off £299 +VAT, and a Remediation Roadmap you can track. Answer for your organisation, and if IT is outsourced, answer for what your IT provider does on your behalf.