
The EU directive strengthening cyber security obligations for essential and important entities, replacing the original NIS Directive.
NIS2 is European Union legislation — Directive (EU) 2022/2555 — that strengthens and widens cyber security obligations across the EU. It replaced the original Network and Information Systems Directive, broadening the sectors in scope and tightening what organisations must do.
The United Kingdom is not subject to NIS2. The UK retains its own NIS Regulations 2018, with reform proposed through the Cyber Security and Resilience Bill.
UK organisations still encounter NIS2 in practice, either because they operate within the EU or because they supply entities that fall within its scope.
A UK organisation with EU operations may be directly in scope, depending on the sector it operates in and where it provides services.
More often the effect is indirect. Because NIS2 requires in-scope EU entities to manage supply chain risk, their UK suppliers receive the contractual clauses and assurance questions that this obligation generates — even though those suppliers are not themselves regulated under NIS2.
The UK’s NIS Regulations 2018 cover similar ground for operators of essential services and relevant digital service providers, and the NCSC Cyber Assessment Framework is used as the assessment tool in several UK sectors.
The proposed Cyber Security and Resilience Bill is intended to update the UK regime. Organisations operating on both sides should expect broadly comparable expectations, applied through different legal instruments and regulators.