ciso.diy
UK Cyber Security & Resilience Act Kit preview
Compliance UK Cyber Security and Resilience ActCAF v4.0MSPNIS2

UK Cyber Security & Resilience Act Kit

MSPs are in scope, and it is twenty-four hours to notify. The CAF-aligned kit for the UK Bill — scope test, CAF v4.0 crosswalk, 24/72-hour notice templates, the MSP customer-notice duty, designated-supplier readiness, and the map to NIS2 and DORA.

What this actually gives you

  • MSPs are in scope directly, not through their customers — and the clock is 24 hours to an initial notification with a fuller report at 72.
  • The CAF is statutory here: 39 contributing outcomes across objectives A–D, mapped to ISO 27001, NIST CSF 2.0 and NIS2 Article 21, with Objective C (detect) scored separately because that is where most organisations are thinnest.
  • One incident, three regimes, nine deadlines — the clock overlay computes all of them from a single awareness time.
  • Built on HL Bill 32 as passed by the Commons on 16 June 2026. Everything provisional is marked "verify final", and the post-Assent edition is free to everyone who has bought it.
  • Not the EU Cyber Resilience Act — different regime, different regulator. That one is about products placed on the EU market; this is about services operated in the UK.

Managed service providers are in scope, and most of them do not know it yet. The UK's Cyber Security and Resilience Bill brings MSPs in directly rather than through their customers, and the reporting clock is 24 hours to an initial notification with a fuller report at 72. If you run infrastructure for other people, this is the regime that reaches you.

Bill-stage on purpose, and honest about it. This is built on HL Bill 32 as passed by the Commons on 16 June 2026, with Lords Committee from 1 September. Every section reference, threshold and duty is marked "verify final" until Royal Assent and the secondary legislation that follows. The post-Assent edition is free to everyone who has bought it — the point of buying now is that the CAF work and the runbook do not change when the section numbers do.

The CAF is the assessment, and it is statutory here. File 02 works all 39 contributing outcomes across objectives A to D with their "achieved" descriptions, mapped to ISO 27001, NIST CSF 2.0 and NIS2 Article 21, so the evidence you already hold is reused rather than regathered. It scores readiness, scores Objective C (detect) separately because that is where most organisations are thinnest, and returns a posture verdict.

One incident, three regimes, nine deadlines. If you are also in NIS2 or DORA scope, the reporting-clock overlay in file 06 computes all nine deadlines from a single awareness time. That is the only way to sequence them without missing one, and it is the part that cannot be improvised at 3 a.m.

What you get

01 Scope Test (XLSX) — ten questions returning your category (relevant MSP, data centre, operator of essential services or RDSP, load controller, or critical-supplier candidate), your regulator, and your registration, reporting, customer-notice and penalty exposure, with the obligations mapped.

02 CAF v4.0 Crosswalk (XLSX) — the 39 contributing outcomes with status and evidence against ISO 27001, NIST CSF 2.0 and NIS2 Article 21, a readiness percentage, an Objective C score and a posture verdict.

03 24/72-Hour Notice Templates & Runbook (DOCX) — the awareness rule that starts the clock, the clock log, a pre-drafted initial notification, the full-report structure, updates, the near-miss format, the regulator and NCSC contact sheet, and how all of it interacts with UK GDPR, NIS2, DORA, your contracts and your insurer.

04 MSP Customer-Notice Pack (DOCX) — the tests for who counts as "affected", the MSA clauses that should already be in your contracts, initial, update, closure and not-affected templates, the on-the-day sequence, the evidence pack and the customer-notice register. This duty is the one MSPs most often discover mid-incident.

05 Designated Critical Supplier Duties (DOCX) — the candidate test, how designation works, what it obliges, pre-designation readiness, a response template and how directions are handled.

06 Dual-Compliance Map (XLSX) — 14 topics compared across UK, NIS2 and DORA with build-once guidance, plus the nine-deadline clock overlay.

07 Practitioner Guide (PDF) — where the Bill stands, scope and the two indirect routes in, the regulators, the statutory CAF, the reporting regime, the MSP customer duty, data centres, designated suppliers, penalties, dual compliance, the timeline, a ninety-day plan, failure patterns and an FAQ.

ukcsr01.json — categories, thresholds, duties, clocks and penalties, machine-readable, every value flagged as pending.

Not the EU Cyber Resilience Act. Different regime, different regulator, different obligations — that one is about products you place on the EU market and lives in the EU Cyber Resilience Act Workbook. This one is about services you operate in the UK. Organisations doing both need both, and they do not substitute.

Pairs with the DORA & NIS2 Readiness Workbook for the EU side of the same estate, I've Been Breached for the incident itself, the Executive Tabletop Kit for the 24-hour drill, and the TPRM Program Kit and Vendor Risk Operations Kit for the supply-chain duties.

A practitioner's toolset, not legal advice. Section references and thresholds are provisional until Royal Assent — have counsel confirm anything you rely on, and re-download when the post-Assent edition lands.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-04
Pages 7