UK connected devices IoT security regulation

The UK's Cyber Resilience Bill Hardens the Enterprise Supply Chain, but Enterprise IoT Still Sits Between Two Regimes

The Cyber Security and Resilience Bill covers MSPs and data centres, while the PSTI Act covers consumer devices. Connected equipment inside enterprises falls between them.

UK Cyber Resilience Bill: Scope at a Glance People of Internet Research · UK 900-1,100 MSPs expected in scope Estimated managed service provider… 24 hrs Initial incident notification Notice to regulator and NCSC after… 1MW Data centre threshold Enterprise-only sites are caught a… peopleofinternet.com
UK Cyber Resilience Bill: Scope at a G… People of Internet Research · UK 900-1,100 MSPs expected in scope 24 hrs Initial incident notification 1MW Data centre threshold peopleofinternet.com

Key Takeaways

A Bill that reaches the suppliers, not the devices

On 10 September 2026 the Scottish Government posted a supplementary Legislative Consent Memorandum on the UK Cyber Security and Resilience (Network and Information Systems) Bill. The Scottish Parliament's Economy, Tourism and Energy Committee then took evidence on 22 and 29 September. The Bill was introduced in the Commons on 12 November 2025 and is now in the Lords. According to GOV.UK's Bill page, it will reform and add to the Network and Information Systems (NIS) Regulations 2018.

The scope is where the Bill matters. Legal analysis, including Pennington's summary, says the 2018 Regulations covered five sectors. The Bill adds managed service providers (MSPs), data centres and a power to designate critical suppliers. The estimates are 900 to 1,100 MSPs and roughly 182 third-party data centre sites run by 64 operators. Data centres at or above 1MW are caught, and enterprise-only facilities only at 10MW. Incident reporting moves to two stages: notice within 24 hours of awareness and a full report within 72 hours.

The strongest case for the Bill

The case for legislating is solid. MSPs hold privileged network access to many customers at once, so one compromised provider becomes many compromised customers. Voluntary assurance has not kept up with that concentration. A regulator that can see incidents within 24 hours, and can designate a supplier whose failure would ripple through essential services, closes a real blind spot in a supply chain that regulators have so far mostly looked at one sector at a time. If you accept that these providers are infrastructure in practice, some statutory duty is hard to argue against.

Where it sits beside the PSTI regime

The other half of UK connected-device policy is the Product Security and Telecommunications Infrastructure (PSTI) regime. The government's policy paper says it applies to relevant connectable consumer products and has been in force since 29 April 2024. It has three requirements. Devices must not ship with universal default passwords. Manufacturers must publish a vulnerability-reporting contact. Manufacturers must state a minimum security-update period. The Office for Product Safety and Standards (OPSS) enforces it, using its existing risk-based processes.

The two instruments are designed around different objects. PSTI regulates a product at the point of sale. The Bill regulates a service provider's resilience as an ongoing duty. Neither reaches the connected equipment that an enterprise buys, installs and relies on: building controllers, cameras, sensors and similar devices managed by a third party. An MSP in scope has duties over its own security. Whether it must secure the IoT estate it manages for a customer depends on how the duties are applied, and I have not found a source that settles that.

A regime still untested

There is also little evidence on how PSTI enforcement works in practice. The OPSS enforcement page I fetched was last updated on 8 August 2025 and listed no actions. My searches found no UK enforcement action under the regime in 2026. That is not proof that compliance is perfect. Enforcement may be happening without being published, or there may simply be nothing to enforce yet. Either way, it means the UK has little public track record to draw on when asking whether baseline device rules work. Parliament should want that record before it layers a larger supplier-security apparatus on top.

This is the pro-innovation concern. Proportionate rules are those whose costs are matched by observable benefits. Each new duty falls on firms that range from large cloud operators to small MSPs with a handful of staff. A 24-hour reporting clock is workable for a firm with a security operations function. For a ten-person MSP it can mean diverting scarce engineers during the first hours of an incident, which is exactly when they are needed to contain it. The Bill's design choices should reflect that. Thresholds like the 1MW and 10MW data centre lines are a sensible way to keep small operators out. Designation powers should come with published criteria and a route to challenge, so that the label does not become a de facto licence.

What to watch in the Lords

Three points are worth pressing as the Bill is examined.

The devolution question that Holyrood is working through is secondary to this, but it points the same way. The Bill touches matters on which Scotland must consent, and the more instruments and regulators a firm deals with, the more consent and coordination points there are. Clarity about who regulates what is a cybersecurity benefit in itself.

The Bill is a reasonable response to a real concentration risk. It would be better still if it were paired with an honest accounting of what the consumer-device regime has achieved and a clear answer on the enterprise gap it leaves.

Sources & Citations

  1. GOV.UK: Cyber Security and Resilience Bill
  2. Scottish Parliament: Cyber Security and Resilience Bill LCM
  3. GOV.UK: UK product security regime policy paper
  4. Pennington Manches Cooper: what the Bill will do