Cyber Security
Cyber Security Glossary

NIS2 Directive

The EU directive strengthening cyber security obligations for essential and important entities, replacing the original NIS Directive.

What it is
EU legislation — Directive (EU) 2022/2555
Applies to
Essential and important entities operating in the EU
Does it apply in the UK?
No — the UK has its own NIS Regulations 2018
Notable change
Management accountability and 24-hour early incident warning

NIS2 is European Union legislation — Directive (EU) 2022/2555 — that strengthens and widens cyber security obligations across the EU. It replaced the original Network and Information Systems Directive, broadening the sectors in scope and tightening what organisations must do.

The United Kingdom is not subject to NIS2. The UK retains its own NIS Regulations 2018, with reform proposed through the Cyber Security and Resilience Bill.

UK organisations still encounter NIS2 in practice, either because they operate within the EU or because they supply entities that fall within its scope.

What changed from the original NIS Directive

  1. Wider scopeMore sectors are covered, and size-based criteria bring far more organisations into scope than the original directive did.
  2. Essential and important entitiesA two-tier classification applies, with both tiers meeting the requirements but facing different levels of supervision.
  3. Management accountabilitySenior management can be held responsible for compliance failures, moving cyber risk firmly onto the board agenda.
  4. Faster incident reportingAn early warning is required within 24 hours of becoming aware of a significant incident, followed by fuller notification.
  5. Supply chain securityIn-scope entities must address security in their supplier relationships, which pushes obligations outwards to their suppliers.

Why it matters to UK organisations

A UK organisation with EU operations may be directly in scope, depending on the sector it operates in and where it provides services.

More often the effect is indirect. Because NIS2 requires in-scope EU entities to manage supply chain risk, their UK suppliers receive the contractual clauses and assurance questions that this obligation generates — even though those suppliers are not themselves regulated under NIS2.

How it compares to the UK regime

The UK’s NIS Regulations 2018 cover similar ground for operators of essential services and relevant digital service providers, and the NCSC Cyber Assessment Framework is used as the assessment tool in several UK sectors.

The proposed Cyber Security and Resilience Bill is intended to update the UK regime. Organisations operating on both sides should expect broadly comparable expectations, applied through different legal instruments and regulators.

NIS2 Directive, answered

Does NIS2 apply in the UK?
No. The UK is outside the EU and not bound by NIS2. The UK has its own NIS Regulations 2018, with reform proposed through the Cyber Security and Resilience Bill. UK organisations may still be affected through EU operations or EU customers.
What is the difference between essential and important entities?
Both must meet the security and reporting requirements, but essential entities face more active, proactive supervision, whereas important entities are generally supervised after the fact.
How does NIS2 affect suppliers who are not in scope?
In-scope entities must address supply chain security, so obligations flow down through contracts and assurance questions to suppliers who are not themselves regulated under the directive.
What is the 24-hour reporting requirement?
In-scope entities must submit an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification and a final report within defined timescales.

Related terms

Authoritative sources

How we help

We help organisations work out what regulatory obligations actually mean for them, and build the evidence needed to answer their customers’ questions.