Compliance · UK · Supply chain
UK Cyber Security and Resilience Bill
The UK's modernised cyber law — expanding scope to managed service providers and critical suppliers, with tight incident-reporting deadlines and supply-chain mandates.
All frameworks
Who's in scope
Operators of essential services, Relevant Managed Service Providers (RMSPs), large data centres, and designated critical suppliers to national infrastructure.
What it requires
- Notify your regulator and the NCSC of a significant incident within 24 hours, with a detailed report within 72 hours — including systemic near-misses.
- Systematically map, monitor and manage cyber risk across your digital supply chain.
- Enforce minimum security standards within vendor contracts.
- Expect on-site inspections; penalties reach up to £17m or 4% of global turnover for serious failures.
How TrustQuant helps
- Continuous monitoring aligned to the NCSC Cyber Assessment Framework (CAF) so posture evidence is always current.
- A shareable Trust Passport that demonstrates supplier resilience to enterprise procurement in seconds.
- Real-time alerts that shorten the path from detection to your 24/72-hour reporting obligations.
This guide is for preparation only and is not legal advice. Confirm your specific obligations with qualified counsel.
Demonstrate UK CSRB with verified evidence
Continuous, real-time posture evidence — mapped to the standards your buyers ask about.