The Cyber Security and Resilience Bill: what it means for small businesses
20 September 2026 · 5 min read
The Cyber Security and Resilience Bill, introduced to Parliament in 2025, updates the UK's approach to protecting essential services and their supply chains. It is proposed legislation, so the final scope depends on the organisation and the services provided — but the direction of travel is clear: more organisations will need to show they manage cyber risk properly, and more will be asked to prove it by their customers.
For most small businesses the direct legal duties are unlikely to apply. The indirect effect is what matters: larger companies and public bodies covered by the rules will pass requirements down to their suppliers. Expect more tender documents and security schedules asking for certification, evidence and prompt incident reporting.
Cyber Essentials is the natural answer to most of those questions. It is the baseline UK buyers already recognise, it covers the five controls the Bill's expectations map onto, and it gives you a certificate to attach rather than a paragraph of reassurance.
The practical move now is to get certified before you are asked, and to keep the evidence current. A business that can produce a valid certificate, current policies and a dated evidence register answers a supplier security questionnaire in minutes instead of days.
Kept keeps that pack ready all year: a scan of your cloud services, the policies assessors ask for, a dated evidence register and renewal reminders — so new requirements are a formality, not a project.
Kept