Skip to content
USE CASE: MANAGED SERVICE PROVIDERS

Cyber Security and Resilience Bill: MSP Readiness

STREAM® Cloud gives Relevant Managed Service Providers one workspace for the security measures, evidence and client assurance the Bill's new MSP category will expect, without waiting for the deadline to force the pace.

Request a Demo

The UK Cyber Security and Resilience Bill extends the Network and Information Systems Regulations 2018 to bring medium and large managed service providers into scope for the first time, as a new category the Bill calls Relevant Managed Service Providers. In-scope MSPs face new duties on security measures, incident reporting and regulatory oversight. STREAM Cloud is Acuity Risk Management’s configurable workspace for the compliance, evidence and assurance work that follows: security measures and gaps held as structured records, incident readiness evidenced and reviewable, and a client-facing assurance pack ready whenever a customer asks for one. It sets up in days, not months.

What the Bill changes for MSPs

The Bill brings Relevant Managed Service Providers into scope for the first time: independent government research estimates around 900 to 1,100 MSPs will meet the new definition, out of roughly 12,867 active MSPs across the UK. Scope turns on size and the nature of the services provided, not simply on being an MSP; smaller providers can still be drawn in individually as designated critical suppliers to a regulated client.

In-scope MSPs take on new duties: security measures appropriate to the risk they hold, incident reporting, and evidence they can show on request. The Bill's fines run up to £17 million or 4% of global annual turnover for the most serious breaches, broadly the same order of exposure as UK GDPR. For whoever signs off the budget, that figure is the board-defensibility question: can you show the measures were in place before something went wrong, not just after.

None of this needs to happen this quarter. The Bill passed its Commons stages in June 2026 and is currently progressing through the House of Lords; Royal Assent is expected later in 2026, with the specific duties phased in afterwards through secondary legislation. That is a genuine runway, not a compliance sprint, and it is the best time to build the evidence base: doing it now, calmly, produces a stronger record than doing it in the weeks before enforcement starts.

What STREAM Cloud gives you

  • Security measures and controls held as structured, evidence-backed records, not a spreadsheet that goes stale between audits.
  • Incident readiness: thresholds, actions and evidence logged and reviewable, so your team can assess and respond with a record behind it.
  • Supplier and subcontractor visibility through Vendor Management Hub, for the parts of your own supply chain the Bill’s duties reach into.
  • A client-facing assurance pack: the evidence an enterprise or public-sector customer’s due diligence team asks for, ready on request rather than assembled from scratch each time.
  • ISO 27001-aligned ISMS lifecycle support, for MSPs building or maintaining certification alongside the Bill’s duties.
  • A single leadership-ready view for the Managing Director or board, instead of the detail living in one compliance lead’s inbox.

STREAM Cloud is not a SIEM, security operations platform, or incident response tool. It is a configurable workspace for the compliance, evidence and assurance work that sits alongside your existing security tooling. It does not file regulatory reports or notifications on your behalf: it holds the evidence and threshold assessments your team uses to do that. And it is not a certification or an audit in itself: it is where you keep the record that an audit would ask to see.

Built for medium and large MSPs who meet or are approaching the Bill’s Relevant MSP thresholds, and for MSPs whose enterprise or public-sector clients already ask for security evidence as part of due diligence. If you’re a sole trader or micro-MSP with no client asking for this yet, STREAM Cloud is likely more than you need today; the STREAM Editions Quiz will tell you either way in about two minutes.

Who this is for

The compelled buyer and the person who signs off the budget usually aren’t the same person here, and they’re looking for different things on this page.

Head of Compliance / Head of Information Security (or the vCISO at a smaller MSP)

The compelled buyer: responsible for showing the security measures are actually in place.

Managed Security Services / Service Delivery Lead

Builds the assurance evidence enterprise clients ask for, without it eating delivery time.

Client Delivery Director / Account Leadership

Needs a ready answer when a client’s procurement or security team runs due diligence.

Managing Director / Owner

The economic buyer at most medium-sized MSPs, weighing readiness cost against the £17 million / 4% turnover exposure and what the board will ask.

Risk and Governance Lead (larger MSPs)

Needs one register spanning the Bill alongside ISO 27001, client contracts and any framework-specific obligations.

A typical readiness path

There is no named MSP case study to share here yet; this is how the work typically runs.

1

Scope. Confirm whether you meet the Bill’s Relevant MSP thresholds and which services and clients are in scope.

2

Baseline. Record current security measures against the framework you’re assessed on, and see the gaps as a structured list.

3

Close the gaps. Assign an owner and a target date to each gap, and track status through to close.

4

Evidence. Hold the resulting record as your audit trail, ready for a regulator or a client’s due diligence request.

5

Maintain. Review on a set cycle so the register doesn’t go stale between audits.

When STREAM Classic may be needed

STREAM Cloud is built to fit most MSPs newly in scope of the Bill. STREAM Classic may be the better starting point if you need:

  • Configurable automations
  • APIs
  • Quantitative analysis
  • Enterprise-scale cyber GRC
  • Messaging and alerting
  • Advanced modelling
  • Complex data sets
  • You provide services into defence or other primes who themselves need Classic-grade evidence depth from their supply chain
Compare STREAM Cloud and Classic →

STREAM Cloud for MSPs: FAQs

Common questions about STREAM Cloud, the UK Cyber Security and Resilience Bill, and Relevant Managed Service Provider status.