NIS2 compliance is now a commercial condition of selling into the European Union, and most UK businesses meet it for the first time as a clause in a customer’s procurement pack rather than as a letter from a regulator. The question arrives quietly: a long-standing German or Irish client sends a security schedule, an incident-reporting annex and a supplier assurance questionnaire, and asks you to sign by the end of the month.
Leaving the EU did not put UK companies outside this. NIS2 compliance reaches UK businesses along two separate routes, and the second one catches far more of them than the first. Some UK firms fall directly under the law because of what they sell and where they sell it. Many more are pulled into NIS2 compliance contractually, because their EU customers are obliged to manage the security of their own supply chains and have no way to do that except through you.
This guide sets out how Directive (EU) 2022/2555 works in practice for a UK supplier. It covers who is caught directly, how the supply chain clause pulls in everyone else, the ten security measures the directive actually names, the 24-hour and 72-hour reporting clocks, what your EU customers will ask you to evidence, the penalty ceilings, and a 90-day plan that gets you to a defensible position without rebuilding your entire IT security function.
If you have already been through a supplier assurance exercise, the shape will be familiar. Our guide to Cyber Essentials for suppliers covers the UK contractual equivalent, and the ISO 27001 readiness assessment checklist covers the management system most EU customers will ask about next.
Table of contents
- What NIS2 Compliance Means for a UK Business
- When NIS2 Compliance Applies to You as a UK Supplier
- NIS2 Compliance and the UK’s Own Cyber Security Rules
- The Ten Security Measures Behind NIS2 Compliance
- NIS2 Compliance Incident Reporting: 24 Hours, 72 Hours, One Month
- NIS2 Compliance Evidence Your EU Customers Will Demand
- NIS2 Compliance Penalties, Liability and Personal Risk
- A 90-Day NIS2 Compliance Programme for UK Suppliers
- NIS2 Compliance Mistakes UK Suppliers Keep Making
- NIS2 Compliance Questions Answered
- References
What NIS2 Compliance Means for a UK Business
The law behind NIS2 compliance
NIS2 is Directive (EU) 2022/2555, which replaced the original 2016 network and information security directive. It entered into force in January 2023, and EU Member States were required to transpose it into national law by 17 October 2024. That last point matters more than it looks: a directive is not directly binding on companies. You never comply with NIS2 itself. You comply with the Belgian, German, Irish or Dutch law that implements it, and those national laws differ in detail, in penalty levels and in how aggressively they are enforced.
Why Brexit did not settle the question
The directive is territorial in application, not in nationality. It bites on services offered inside the Union, not on companies headquartered inside it. A UK managed service provider running infrastructure for a Dutch manufacturer is offering services within the EU regardless of where its own registered office sits. NIS2 compliance for UK businesses therefore turns on where your customers are and what you do for them, not on your incorporation.
Essential entities and important entities
The directive splits in-scope organisations into two tiers. Essential entities are large organisations in the highest-criticality sectors listed in Annex I: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space. Important entities are medium-sized organisations in those sectors plus organisations in Annex II sectors, which include postal and courier services, waste management, chemicals, food, several categories of manufacturing, digital providers and research organisations.
The size test that filters most SMEs out of direct scope
Direct scope generally starts at medium-sized enterprise: 50 or more staff, or annual turnover and balance sheet total above €10 million. Large enterprises — 250 or more staff, or turnover above €50 million and balance sheet above €43 million — sit in the essential tier when they operate in an Annex I sector. A 20-person UK software house selling to European customers is almost never directly in scope on size alone. That is exactly why so many of them assume NIS2 compliance is somebody else’s problem, and exactly why they are wrong.
The supervision difference between the two tiers
The distinction is not cosmetic. Essential entities face proactive supervision: regulators can inspect, audit and demand evidence without waiting for an incident. Important entities face reactive supervision, meaning the regulator acts when it has grounds to believe there has been a breach of duty. Both tiers carry identical NIS2 compliance obligations. Only the intensity of oversight and the penalty ceiling differ, which is why a supplier questionnaire looks much the same whichever tier your customer sits in.
| Tier | Who lands here | Size threshold | Supervision | Maximum fine |
|---|---|---|---|---|
| Essential entity | Annex I sectors, large organisations | 250+ staff, or turnover above €50m | Proactive — audits and inspections without cause | €10m or 2% of global turnover |
| Important entity | Annex II sectors, plus medium Annex I organisations | 50+ staff, or turnover above €10m | Reactive — on evidence of non-compliance | €7m or 1.4% of global turnover |
| Out of direct scope | Small UK suppliers, most SMEs | Below 50 staff and €10m | None from the regulator | None — but contractual liability applies |
When NIS2 Compliance Applies to You as a UK Supplier
Route one: you are caught directly
A specific list of digital service categories is caught wherever the provider sits. Article 26 names DNS service providers, top-level domain name registries, domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking platforms. If your UK business is one of these and you offer services in the EU, direct NIS2 compliance is your obligation, not your customer’s.
The EU representative requirement almost nobody has done
This is the sharpest edge for UK firms. Where an organisation in that list is not established in the Union but offers services within it, the directive requires it to designate a representative established in a Member State where those services are offered. That representative becomes the point of contact for the regulator, and jurisdiction follows the representative’s location. Many UK managed service providers with European clients have never appointed one, which leaves them non-compliant on a structural point before any technical control is even assessed.
Registration obligations for the same categories
Those same digital categories were also required to submit registration information — legal name, sector, address, contact details, IP ranges and the Member States where they operate — so that national authorities and ENISA could build a registry of in-scope providers. If you are a UK cloud, data centre or managed security provider selling into the EU, that registration is part of NIS2 compliance and it is not something a customer can do for you.
Route two: the supply chain clause pulls you in anyway
Most UK businesses arrive at NIS2 compliance here. Article 21 requires in-scope entities to manage supply chain security, including the security-related aspects of the relationship with each direct supplier and service provider. The directive goes further and tells entities to take account of vulnerabilities specific to each supplier and the overall quality of that supplier’s products and security practices. Your EU customer cannot satisfy that duty by hoping. It satisfies it by pushing NIS2 compliance obligations into your contract.
A practical NIS2 compliance decision test
Run three questions. First: do you sell one of the named digital services into the EU? If yes, you are directly in scope and need an EU representative. Second: is any EU customer of yours a medium or large organisation in an Annex I or Annex II sector? If yes, expect contractual NIS2 compliance requirements. Third: does your service touch that customer’s network, data or operational continuity? If yes, you will be treated as a critical supplier and audited accordingly.
| Factor | Direct scope | Indirect (contractual) scope |
|---|---|---|
| What triggers it | Sector, size and services offered in the EU | Being a supplier to an in-scope EU entity |
| Source of the duty | National law implementing the directive | Your customer contract and security schedule |
| Who enforces it | The Member State competent authority | Your customer, through audit and termination rights |
| Registration required | Yes, for the named digital categories | No |
| EU representative required | Yes, if not established in the Union | No |
| Worst realistic outcome | Regulatory fine and management liability | Losing the contract and the reference |
| How fast it arrives | On registration or after an incident | At the next contract renewal |
NIS2 Compliance and the UK's Own Cyber Security Rules
The UK kept its own version of NIS1
The UK implemented the original directive as the Network and Information Systems Regulations 2018, and those 2018 Regulations remain in force. They cover operators of essential services and relevant digital service providers, with a penalty ceiling of £17 million. They were not updated when the EU moved to NIS2, which is how the two regimes drifted apart.
The Cyber Security and Resilience Bill closes some of the gap
The UK government has brought forward a Cyber Security and Resilience Bill to modernise the 2018 regime, extending it towards managed service providers and tightening incident reporting. It moves the UK closer to the EU position without replicating it. Our earlier analysis of the Cyber Security and Resilience Bill covers the detail. For a UK supplier with EU customers, the practical consequence is simple: you will end up meeting the stricter of the two, and today that is the EU one.
Running one control set, not two NIS2 compliance programmes
The sensible response is not two parallel programmes. Build one control set that satisfies the stricter requirement and map it to both regimes. In practice the delta between UK expectations and NIS2 compliance is narrow on technical controls and wide on governance, reporting speed and supply chain evidence. That is where your effort should go.
| Dimension | EU NIS2 | UK NIS Regulations 2018 | Cyber Security and Resilience Bill |
|---|---|---|---|
| Instrument | Directive (EU) 2022/2555 | SI 2018/506 | Bill before Parliament |
| Sectors covered | 18 sectors across two annexes | Five essential sectors plus digital services | Widening towards managed services |
| Supply chain duty | Explicit and named in Article 21 | Implicit within general duties | Strengthened |
| First report due | 24 hours (early warning) | 72 hours | Expected to tighten |
| Management liability | Named personally in Article 20 | Not specified | Not yet equivalent |
| Maximum penalty | €10m or 2% of global turnover | £17m | To be confirmed |
| Applies to a UK firm selling in the EU | Yes, directly or contractually | Only for UK operations | Only for UK operations |
The compliance calendar for a UK supplier does not stop at the directive. Two adjacent EU regimes land on overlapping timelines, and both reach UK companies through contracts.
Where DORA takes over instead
If your EU customers are banks, insurers or investment firms, the operative regime is the Digital Operational Resilience Act rather than the directive. DORA has applied since January 2025 and imposes prescriptive contractual terms on ICT third-party providers, including exit strategies, audit rights and register-of-information entries. A UK software supplier to an EU bank will be handed DORA clauses, not NIS2 compliance clauses, and the two sets of obligations are similar in spirit but different in wording.
The Ten Security Measures Behind NIS2 Compliance
Article 21 lists ten categories of risk-management measure. They are deliberately outcome-based rather than prescriptive, which is why customers translate them into questionnaires. The list below is the whole obligation, and any credible NIS2 compliance programme is organised around it.
Risk analysis and information security policy
A documented risk assessment methodology, a completed assessment, and an approved information security policy that the risk assessment actually feeds. This is the foundation every subsequent NIS2 compliance measure hangs from, and the item most often produced retrospectively to satisfy an auditor.
Incident handling
Documented detection, triage, escalation and response, with defined severity levels and named owners. The reporting clocks discussed below are unachievable without this, so treat your incident response capability as the load-bearing control rather than the paperwork exercise.
Business continuity and crisis management
Backup management, disaster recovery and crisis management. The test that matters is a documented restore, performed on a schedule, with evidence of the outcome. A backup job that reports success and has never been restored is a finding, not a control.
Supply chain security
Security in the relationships with your own direct suppliers and service providers. UK businesses consistently underestimate this one: NIS2 compliance is transitive, so your subcontractors and your own cloud dependencies come into scope through you. This is where vendor management stops being an administrative function.
Secure acquisition, development and maintenance
Security across the lifecycle of network and information systems, including vulnerability handling and disclosure. If you build software for EU customers, expect questions about your secure development process, your dependency scanning and your published disclosure route.
Assessing effectiveness
Policies and procedures to assess whether the risk-management measures actually work. Effectiveness testing, not control existence, is the difference between a mature programme and a document set. Penetration testing and control assurance both sit here.
Cyber hygiene and training
Basic cyber hygiene practices and cybersecurity training across the organisation. Patching cadence, account hygiene, device standards and a training record that shows who was trained and when. The NCSC Cyber Essentials scheme maps closely to this measure and is the cheapest way for a UK supplier to evidence it.
Cryptography and encryption
Policies covering the use of cryptography, and encryption where appropriate. Auditors look for a stated position on data at rest, data in transit and key management rather than a blanket claim that everything is encrypted.
HR security, access control and asset management
Screening, joiners-movers-leavers processes, least-privilege access, privileged access review and a maintained asset inventory. The asset inventory is the item that quietly blocks everything else when it is missing.
Multi-factor authentication and secured communications
Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications. Note the last item: NIS2 compliance expects you to be able to run an incident when your primary systems are the incident.
| Article 21 measure | Covered by Cyber Essentials | Covered by ISO 27001 | Typical UK supplier gap |
|---|---|---|---|
| Risk analysis and security policy | No | Yes | No documented methodology |
| Incident handling | Partly | Yes | No 24-hour notification path |
| Business continuity and backups | No | Yes | Restores never tested |
| Supply chain security | No | Partly | Subcontractors unassessed |
| Secure development and vulnerability handling | Partly | Partly | No disclosure policy |
| Effectiveness assessment | No | Yes | No internal audit cycle |
| Cyber hygiene and training | Yes | Yes | No training records kept |
| Cryptography policy | Partly | Yes | Key management undefined |
| HR security and access control | Partly | Yes | Privileged access never reviewed |
| MFA and secured communications | Yes | Yes | No out-of-band comms plan |
NIS2 Compliance Incident Reporting: 24 Hours, 72 Hours, One Month
The three-stage NIS2 compliance clock
Reporting is where NIS2 compliance is genuinely harder than what most UK suppliers are used to. For a significant incident, an in-scope entity must send an early warning within 24 hours of becoming aware of it, a fuller incident notification within 72 hours including an initial assessment and severity, and a final report within one month of that notification. Authorities can request an intermediate status update at any point in between.
What “significant” means
An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or is capable of affecting others by causing considerable material or non-material damage. Implementing rules add quantitative triggers for certain digital providers, including thresholds based on service unavailability and numbers of users affected.
The 24-hour early warning is not an investigation
The early warning is short by design. It states that an incident has occurred, whether it is suspected to be unlawful or malicious, and whether it could have cross-border impact. It does not require root cause, scope or remediation detail. Teams miss the deadline because they wait for certainty they were never asked for.
Where a UK supplier sits in this
You will usually not be the reporting entity. Your EU customer is, and its clock starts when it becomes aware. That means your contractual notification window will be shorter than the regulator’s — commonly 12 to 24 hours, sometimes as little as six — because the customer needs time to assess before its own 24-hour deadline expires. Read the notification clause before you sign it, not during an incident.
Running two clocks at once
A single incident frequently triggers both the directive and data protection law. If personal data is involved, the UK GDPR 72-hour notification to the ICO runs in parallel with the customer’s NIS2 obligations, on a different trigger and to a different regulator. Build one incident process that satisfies the fastest clock and feeds every other one from the same evidence set, rather than maintaining separate procedures that diverge under pressure.
| Regime | First deadline | Second deadline | Final report | Reported to |
|---|---|---|---|---|
| EU NIS2 | 24 hours — early warning | 72 hours — notification | One month | National CSIRT or authority |
| UK GDPR | 72 hours — breach report | Without undue delay to individuals | On request | ICO |
| UK NIS Regulations 2018 | 72 hours | Not staged | On request | Competent authority |
| EU DORA | Initial notification, hours | Intermediate report | Final report | Financial regulator |
| Customer contract | Often 6–24 hours | As specified | Post-incident review | Your customer |
NIS2 Compliance Evidence Your EU Customers Will Demand
The security schedule
Expect a contract annex rather than a conversation. It will name the security measures you must maintain, the notification window, audit rights, subcontractor approval, and a right to terminate for persistent failure. This is how the directive’s supply chain duty becomes your legal obligation, and this contractual form of NIS2 compliance is enforceable long before any regulator takes an interest.
The questionnaire
Most EU customers run a standardised supplier assessment. The questions track Article 21 almost line by line: risk assessment, incident handling, continuity, subcontractors, secure development, testing, training, encryption, access control and authentication. Answering from a maintained evidence pack takes a day. Answering from scratch takes three weeks and produces inconsistencies that invite follow-up.
The NIS2 compliance evidence pack
Assemble it once and reuse it. A defensible NIS2 compliance evidence pack contains your information security policy, current risk assessment, incident response plan with contact tree, most recent restore test result, asset and supplier inventories, access review records, training records, penetration test summary, and any certification you hold. Keep it versioned and dated.
Audit and testing rights
Larger customers will reserve the right to audit your NIS2 compliance, or to accept an independent certification in place of an audit. Certification is almost always cheaper than hosting audits from a dozen customers. This is the strongest commercial argument for ISO 27001 in a UK supplier that sells into Europe, and it converts an ongoing cost into a fixed one.
“The Supplier shall implement and maintain technical and organisational measures appropriate to the risks presented, consistent with Article 21 of Directive (EU) 2022/2555 as implemented in the Customer’s jurisdiction, and shall not materially reduce those measures during the Term.”
“The Supplier shall notify the Customer without undue delay and in any event within twelve (12) hours of becoming aware of any incident affecting the Services, and shall provide such information as the Customer reasonably requires to meet its own regulatory reporting obligations.”
“The Supplier shall not appoint any subcontractor with access to Customer systems or data without prior written approval, and shall impose obligations on each subcontractor no less protective than those in this Schedule.”
Negotiate the notification window, not the standard
You will not win an argument about whether Article 21 applies. You can reasonably negotiate the notification window, the definition of an incident, the frequency of audits and the cap on liability. A blanket six-hour notification duty for any incident is a trap; a twelve-hour duty for incidents affecting the contracted service is achievable and defensible, and it still supports your customer’s own NIS2 compliance clock.
NIS2 Compliance Penalties, Liability and Personal Risk
The NIS2 compliance fines
Essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%. Those are ceilings set by the directive; Member States implement them in national law and may go further. For most UK suppliers these numbers matter as leverage on their customers rather than as a direct exposure.
Management accountability is personal
Article 20 requires management bodies to approve the cybersecurity risk-management measures, to oversee their implementation, and to undertake training. It also provides that management can be held liable for failures. This is the change that moves NIS2 compliance from the IT budget to the board agenda, and it is why your EU customer’s directors care about your security posture in a way they did not five years ago.
The consequence that actually arrives first
No UK SME supplier has been fined under a European implementation of the directive. Plenty have lost renewals. The realistic downside of weak NIS2 compliance is commercial: failing a supplier assessment, being placed on a remediation plan with a deadline, being excluded from a tender shortlist, or being replaced at renewal by a competitor who answered the questionnaire better. That happens quietly and it happens now.
A 90-Day NIS2 Compliance Programme for UK Suppliers
Days 1 to 30: establish scope and find the gaps
Confirm which route applies to you. List every EU customer, their sector and their approximate size, and flag any that sits in Annex I or Annex II. Separately, check whether you provide one of the named digital services, because that changes the exercise from contractual to regulatory. Then score yourself against the ten Article 21 measures honestly, using the evidence you could produce today rather than the controls you believe exist.
Days 31 to 60: close the gaps that block everything else
Three items unblock the rest of a NIS2 compliance programme and should be done first: a maintained asset and supplier inventory, multi-factor authentication everywhere it is missing, and a tested restore. After those, write the incident response plan with a real contact tree and defined severity levels, and fix privileged access review. Most UK suppliers can complete this phase with existing staff and no new tooling.
Days 61 to 90: produce evidence and rehearse
Assemble the evidence pack, run a tabletop exercise against the 24-hour and 72-hour clocks, and produce a one-page NIS2 compliance summary you can send with proposals. Review your standard contract terms so that notification windows and subcontractor obligations you have agreed with customers are ones you can actually meet. If certification is the goal, this is the point at which a readiness assessment is worth buying.
What to do beyond 90 days
Set the recurring cycle: annual risk assessment refresh, quarterly access review, quarterly restore test, annual tabletop, and a supplier reassessment cadence tied to criticality. NIS2 compliance is a maintained state, not a project with an end date, and customers audit the cadence as much as the controls. A managed IT services partner can carry the recurring elements if you do not have the internal capacity.
| Phase | Main activity | Output | Typical effort | Owner |
|---|---|---|---|---|
| Days 1–30 | Scope determination and gap scoring | Scope statement and scored gap register | 4–8 days | Ops or IT lead |
| Days 31–60 | Inventory, MFA, restore test, incident plan | Working controls with evidence | 10–15 days | IT and supplier owners |
| Days 61–90 | Evidence pack and tabletop exercise | Reusable assurance pack | 5–8 days | IT lead and directors |
| Ongoing | Reviews, tests and supplier reassessment | Dated recurring records | 2 days per quarter | Named control owner |
NIS2 Compliance Mistakes UK Suppliers Keep Making
Assuming Brexit is a defence
It is not, and saying so in a questionnaire response damages credibility. The obligation follows the service into the Union. A UK business that answers “not applicable, we are outside the EU” is telling a procurement team that it has not read the directive.
Treating NIS2 compliance as an IT project
The heaviest gaps are governance, evidence and supply chain records, not firewalls. Programmes run purely by an IT team consistently deliver controls with no documentation, which fails an assessment just as completely as having no controls.
Forgetting the subcontractors
Your own suppliers inherit the obligation through you, because NIS2 compliance is transitive down the chain. If a third-party developer, an offshore support team or a niche SaaS tool touches customer systems, it belongs in your inventory and in your assessment. This is the single most common finding in a supplier audit.
Signing notification windows you cannot meet
A six-hour notification duty agreed in a hurry becomes a contractual breach on the first weekend incident. Check whether you have out-of-hours cover capable of meeting the clause before you agree to it.
Ignoring the EU representative requirement
If you provide one of the named digital services into the Union, appointing a representative is not optional and no amount of technical control substitutes for it. It is also the cheapest item on the list, which makes leaving it undone particularly hard to explain.
Rebuilding from scratch when you already hold certification
Cyber Essentials Plus and ISO 27001 cover a large proportion of Article 21. Map what you have before you buy anything. Our comparison of Cyber Essentials Plus and ISO 27001 sets out which one answers more of the questions an EU customer will ask.
NIS2 Compliance Questions Answered
Does NIS2 apply to UK companies after Brexit?
Yes, in two ways. UK providers of certain digital services that offer them within the EU are directly in scope and must appoint an EU representative. Every other UK supplier to an in-scope EU organisation is reached contractually through the directive’s supply chain requirements. Neither route depends on being established in the Union.
We are a 15-person business. Are we in scope?
Almost certainly not directly, because direct scope generally starts at 50 staff or €10 million turnover. You will still face NIS2 compliance obligations through customer contracts, and small suppliers are assessed as rigorously as large ones when they touch critical systems.
Which country’s rules apply to us?
The national law of the Member State where your customer is established, or where your EU representative sits if you are directly in scope. This is why NIS2 compliance answers should reference the directive rather than any single national implementation — the underlying obligations are common, the procedural detail is not.
Does Cyber Essentials satisfy NIS2 compliance?
No, but it evidences a meaningful part of the cyber hygiene, access control and authentication measures. It does not cover risk methodology, business continuity, supply chain security or effectiveness testing. Treat it as a component, not an answer.
How long does NIS2 compliance realistically take?
Ninety days to a defensible position if you already have basic controls and someone owns the work. Longer if your asset inventory does not exist, because almost everything else depends on it. Certification, if you choose that route, adds three to six months.
What happens if we simply do not respond?
Commercially, you are removed from the approved supplier list at renewal. The customer has its own regulator to satisfy and cannot carry an unassessed supplier indefinitely. That is a slower and more certain outcome than a fine.
Who should own NIS2 compliance internally?
One named person with authority over both IT and contracts, reporting to a director. Split ownership between an IT manager and a commercial manager is the most reliable way to produce a programme where each half assumes the other is handling evidence. Our compliance and cybersecurity teams work alongside that owner rather than replacing them.
References
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity
European Commission NIS2 Directive Policy Page
Commission Implementing Regulation (EU) 2024/2690
Regulation (EU) 2022/2554 on Digital Operational Resilience
Regulation (EU) 2024/2847 Cyber Resilience Act
The Network and Information Systems Regulations 2018
UK Cyber Security and Resilience Bill
NCSC Supply Chain Security Guidance