How the UK Cyber Security and Resilience Bill Extends to the Supply Chain

   Sep 14, 2026 | Adam Fearn, Senior OT Architect, Radiflow

Many organisations reading about the UK Cyber Security and Resilience Bill may assume it’s aimed at someone else. Energy companies. Water utilities. Transport operators. The obvious candidates for critical national infrastructure regulation.

The Bill, as currently drafted, is more ambitious than that. Through its supply chain provisions and the new Designated Critical Supplier mechanism, it has the potential to reach organisations that have never previously been in scope of any cyber regulation, including manufacturers and technology providers who don’t think of themselves as part of critical infrastructure at all. Understanding how far that reach extends is more useful than assuming the Bill doesn’t apply.

What the Bill does beyond its direct targets

The Bill directly regulates Operators of Essential Services, managed service providers, and data centre operators. That much is well understood. The less-discussed mechanism is what it does to the tier of organisations that supply them.

As currently set out, the Bill introduces a Designated Critical Supplier category. Regulators will have the power to designate specific suppliers, whose products or services are judged essential to maintaining the resilience of an essential service, as critical suppliers in their own right. Once designated, those suppliers face obligations equivalent to those of Operators of Essential Services. This means the same security standards, the same incident reporting requirements, and the same exposure to regulatory inspection and turnover-based penalties.

Regulated organisations will also be required to impose obligations on their suppliers contractually. An energy company or water utility subject to the Bill’s requirements is likely to pass those requirements downstream through procurement processes, asking suppliers to demonstrate security standards, respond to due diligence requests, and accept audit rights as a condition of doing business.

What this means for manufacturers in the supply chain

Manufacturing organisations that supply into regulated sectors need to think carefully about where they are positioned here. This may be an OT equipment vendor whose products are deployed in energy infrastructure, a component manufacturer whose parts go into water treatment systems, or a technology provider whose software runs on plant networks in regulated facilities. None of these organisations may be directly in scope of the Bill, but all of them are likely to find that their customers are, and that those customers now have statutory reasons to ask harder questions about their suppliers’ cyber position.

The practical effect is that the Bill creates two kinds of exposure for manufacturers. The first is formal designation as a critical supplier, which brings direct regulatory obligations. The second is commercial pressure from in-scope customers, which comes through contract renewals, procurement questionnaires, and due diligence processes. The second route will affect far more organisations than the first, and it will come faster, because customers don’t need to wait for a formal designation process before they start asking questions.

The OT dimension that makes this harder

For manufacturers specifically, the increased scrutiny of their supply chain has an OT dimension that IT-focused organisations don’t face in the same way. The products and systems that manufacturers supply into regulated sectors are often deeply embedded in operational environments, difficult to update, and connected to processes where availability and integrity matter in ways that don’t apply to standard IT services.

A customer asking whether a supplier’s technology introduces cyber risk into their OT environment is asking a question that requires the supplier to understand their own product’s security posture. This includes known vulnerabilities, network behaviour, update mechanisms, and what access the product requires to function. Many manufacturers have not historically needed to answer those questions in detail. The Bill’s supply chain provisions create an environment where those answers are increasingly expected, first commercially and potentially later through formal designation.

Knowing your own exposure before your customers ask

The organisations that will manage this transition well are the ones who understand their supply chain position before a customer’s procurement team asks them to demonstrate it. That means understanding which regulated sectors their products or services touch, what security posture those products present, and what they would need to show to satisfy a customer conducting supply chain due diligence under the Bill’s framework.

It also means understanding the risk in the other direction. Manufacturers are not only suppliers into regulated sectors, they are also buyers from their own supply chains, and those supply chains carry cyber risk into their own OT environments. Knowing what’s connected to your plant network, and what access your suppliers and technology vendors have to it, is the same question from the other side.

Building that visibility, both into your own OT environment and into the security posture of what you supply, is the work Radiflow helps manufacturers do, before the regulatory pressure lands.

Three questions worth asking to your team

Which regulated sectors do our products, technology, or services reach, directly or through an intermediary?

If a customer in one of those sectors asked us to demonstrate our cyber security posture today, what would we be able to show them?

Do we have sufficient visibility into our own OT environment to answer confidently, on behalf of a customer, what risk our products or systems introduce into theirs?

The answer to these questions will tell you more about your readiness than any compliance checklist. And it’s a better question to answer in a boardroom now, than in the aftermath of an incident later.

Building OT visibility and cyber risk management capability is the work Radiflow helps manufacturers and critical infrastructure operators do.

Additional Resources

Request Demo Contact Us