The UK’s Cyber Security and Resilience Bill reached report stage in the Commons in May 2026, which means it is now close enough to becoming law that businesses should stop treating it as background noise.

Most of the coverage has focused on the headline provisions, and understandably so. But for the small and medium-sized businesses that make up most of the UK economy, the interesting part is not what the Bill says. It is what the Bill sets in motion.

Most SMEs will never be directly regulated by this legislation. Almost all of them will feel it anyway.

What the Bill actually says

Stripped of the parliamentary language, the Bill does four big things.

First, it expands the scope of regulated sectors. The existing regime covered a fairly narrow set of essential services; the new one pulls in a wider range of digital and infrastructure providers, reflecting how much of the economy now depends on services that were never classed as critical before.

Second, it introduces mandatory incident notification with a 24-hour window. Regulated organisations will have to report significant incidents fast, not after weeks of internal deliberation. Twenty-four hours is not long. It forces organisations to know, in advance, who detects an incident, who assesses it and who reports it.

Third, ransomware attacks become reportable incidents in their own right. The era of quietly paying and moving on is being closed off for regulated firms, and the government will get real visibility of the scale of the problem for the first time.

Fourth, the penalties have teeth: regulators will be able to fine up to £17 million or 4% of global turnover. Those are figures designed to reach board level, and they will.

If your business falls inside the expanded scope, you have direct homework to do and should start now. But most SMEs do not, and that is where the more interesting story begins.

Regulation flows downhill

Here is the pattern that plays out every time a regime like this lands. A regulated organisation looks at its new obligations, then looks at its supply chain, and realises that its own compliance depends on companies it does not control.

If a regulated firm must report incidents within 24 hours, it needs its suppliers to tell it about incidents fast. If it must demonstrate resilience, it needs to know its suppliers are patched, backed up and recoverable. Its regulator will not accept “our web agency went down and we do not know why” as an answer, so it will stop accepting that level of opacity from the web agency.

The result is predictable: security questionnaires, contractual security clauses, requests for incident response plans and evidence of patching discipline, flowing from regulated customers down to their smaller suppliers.

This is not speculation. It is exactly what already happens with Cyber Essentials in public sector procurement, where certification quietly became a ticket to entry for suppliers who are not themselves government bodies. The Bill will do the same thing at greater scale across the private sector.

The compliance obligation lands on the regulated firm. The compliance pressure lands on everyone who sells to it.

If your customers include utilities, healthcare, logistics, financial services, managed service providers or anyone else in or near the expanded scope, their compliance problem is about to become your sales problem.

The questionnaire is becoming a commercial document

It is tempting to file all this under risk and grudge-spend. That is the wrong frame.

When a regulated customer sends a security questionnaire to five competing suppliers, the questionnaire is not really a compliance exercise. It is a filter. The supplier who answers quickly, specifically and with evidence looks like a safe pair of hands. The supplier who goes quiet for three weeks and returns vague answers looks like a future incident report.

Being able to answer a security questionnaire well is becoming a commercial advantage, not just risk management. It shortens procurement, it survives due diligence, and it quietly disqualifies competitors who cannot do the same. For an SME selling into larger organisations, that is one of the cheapest differentiators available, because the bar is currently low. Most small suppliers answer these documents badly.

The questions themselves are rarely difficult. What do you run? Who keeps it updated? What happens when something goes wrong? Who do we call? Can you show us? The difficulty is that most businesses have never written the answers down, and some genuinely do not know them.

What good answers look like

You do not need a compliance department to be ready for this. You need four things, none of them expensive.

An asset list. A simple, current record of what you actually run: domains, websites, servers, key software, third-party services. Most businesses discover forgotten systems the first time they write this down, which is rather the point.

A named owner for patching. Not a vague sense that updates happen, but a person or provider who is responsible for keeping each item on that list current, and a rhythm they follow. “Who patches this?” is the single most revealing question in any security questionnaire.

An incident plan that names a human. One page is enough. Who notices, who decides, who communicates, who fixes, and the phone numbers. A plan that names roles nobody holds is theatre; a short plan with real names is worth more than a long one with none.

Evidence. Records of updates applied, backups taken, restores tested. When a customer asks for assurance, “we take security seriously” is worth nothing. A dated log is worth a great deal.

What to do about it

Start with an hour, not a project. Write the asset list. Against each item, write who patches it and when it was last done. If every line has a confident answer, you are in better shape than most of your competitors, and turning that into questionnaire-ready answers is a short exercise.

If your website and systems are professionally hosted and maintained, most of the answers should come straight from your provider: what is running, how it is patched, how it is backed up, how incidents are detected and communicated. Ask your provider for exactly that, in writing. A good one will already have it. A blank look is information too.

And if you work through the list and find that nobody, internal or external, can actually say who patches your stack, then you have not wasted the hour. That gap is the finding, and it is far better to discover it in a planning exercise than in a customer’s due diligence process, or in an incident.

Then close the gap: assign the owner, write the one-page plan, start keeping evidence. None of it requires new legislation to be worthwhile. The Bill just means the questions are coming whether you prepare or not.

The quiet advantage

The Cyber Security and Resilience Bill will not knock on most SME doors directly. It will arrive by email, from a customer, as a questionnaire with a deadline. The businesses that treat that moment as an ambush will lose time and occasionally contracts. The ones that prepared will win work for the least glamorous reason imaginable: they could answer the questions.


Flux Dynamics builds, hosts and maintains client systems with the patching discipline, backups and documentation that supply chain security reviews now expect. Start a project if you want questionnaire-ready answers to come from your provider rather than from a scramble.

Flux Dynamics
Software & AI Consultancy

Flux Dynamics is a UK software and AI consultancy: a fractional CTO who also builds, shipping custom web applications and software for businesses.