Cyber Security
Regulation

Does NIS2 apply to UK organisations?

NIS2 is an EU directive, but plenty of UK organisations still fall within its reach. Here is who is affected, and how it sits alongside the UK’s own regime.

13 September 2026 7 min read Regulation

NIS2 is the European Union’s updated Network and Information Security directive. Because the UK has left the EU, a common assumption is that it simply does not apply here. For many organisations that is wrong, and the gap between that assumption and reality is where the risk sits.

NIS2 in one paragraph

NIS2 widens the scope of the original NIS directive, brings more sectors into scope, tightens incident reporting timescales, and puts personal accountability on senior management for cyber risk. It splits organisations into essential and important entities, with proportionate obligations for each. EU member states transpose it into national law, so the exact detail varies by country.

Why a UK organisation can still be caught

A UK-based organisation can fall within NIS2 in several ways: if it offers in-scope services within the EU, if it forms part of the supply chain to an EU essential or important entity, or if it has establishments in EU member states. Supply-chain security is an explicit theme of NIS2, so EU customers are increasingly flowing these expectations down to their suppliers by contract - regardless of where the supplier is based.

  • You provide in-scope services (for example digital infrastructure, managed services, or cloud) to customers inside the EU.
  • You are a supplier to an EU essential or important entity, and their NIS2 obligations reach you through the contract.
  • You have subsidiaries or establishments in one or more EU member states.

The UK’s own regime has not stood still

Even where NIS2 does not reach you, the UK has its own Network and Information Systems Regulations, and the government has set out plans to strengthen them through the Cyber Security and Resilience Bill - extending scope to more digital service providers and managed service providers, and sharpening incident reporting. In practice, organisations preparing for one regime are usually doing most of the work needed for the other.

What good preparation looks like

Whichever regime applies, the underlying expectations rhyme: understand your critical services and dependencies, manage supplier risk proportionately, put appropriate technical and organisational measures in place, and be able to detect and report incidents quickly. The NCSC Cyber Assessment Framework is a practical yardstick for all of this, even outside government.

  • Confirm whether NIS2, the UK NIS Regulations, or both actually apply to you - do not assume either way.
  • Map your critical services and the suppliers they depend on, and tier that supply chain by consequence.
  • Check your incident detection and reporting can meet the tightest timescale you are subject to.
  • Make senior ownership of cyber risk explicit, because both regimes increasingly expect it.

The most expensive way to discover NIS2 applies to you is to be told by an EU customer mid-procurement. A short scoping exercise now is far cheaper than a scramble later.

Written by the E2E Security Consulting team. This article is general guidance, not formal advice on your specific circumstances - for that, the useful first step is a short conversation.

More insights

Need this on your programme?

If the topic above is live for you right now, we can help you work through it - practically, and aligned to NCSC guidance.