
NIS2 is an EU directive, but plenty of UK organisations still fall within its reach. Here is who is affected, and how it sits alongside the UK’s own regime.
NIS2 is the European Union’s updated Network and Information Security directive. Because the UK has left the EU, a common assumption is that it simply does not apply here. For many organisations that is wrong, and the gap between that assumption and reality is where the risk sits.
NIS2 widens the scope of the original NIS directive, brings more sectors into scope, tightens incident reporting timescales, and puts personal accountability on senior management for cyber risk. It splits organisations into essential and important entities, with proportionate obligations for each. EU member states transpose it into national law, so the exact detail varies by country.
A UK-based organisation can fall within NIS2 in several ways: if it offers in-scope services within the EU, if it forms part of the supply chain to an EU essential or important entity, or if it has establishments in EU member states. Supply-chain security is an explicit theme of NIS2, so EU customers are increasingly flowing these expectations down to their suppliers by contract - regardless of where the supplier is based.
Even where NIS2 does not reach you, the UK has its own Network and Information Systems Regulations, and the government has set out plans to strengthen them through the Cyber Security and Resilience Bill - extending scope to more digital service providers and managed service providers, and sharpening incident reporting. In practice, organisations preparing for one regime are usually doing most of the work needed for the other.
Whichever regime applies, the underlying expectations rhyme: understand your critical services and dependencies, manage supplier risk proportionately, put appropriate technical and organisational measures in place, and be able to detect and report incidents quickly. The NCSC Cyber Assessment Framework is a practical yardstick for all of this, even outside government.
The most expensive way to discover NIS2 applies to you is to be told by an EU customer mid-procurement. A short scoping exercise now is far cheaper than a scramble later.
Written by the E2E Security Consulting team. This article is general guidance, not formal advice on your specific circumstances - for that, the useful first step is a short conversation.