NIS2 compliance is now a commercial condition of selling into the European Union, and most UK businesses meet it for the first time as a clause in a customer’s procurement pack rather than as a letter from a regulator. The question arrives quietly: a long-standing German or Irish client sends a security schedule, an incident-reporting annex and a supplier assurance questionnaire, and asks you to sign by the end of the month.

Leaving the EU did not put UK companies outside this. NIS2 compliance reaches UK businesses along two separate routes, and the second one catches far more of them than the first. Some UK firms fall directly under the law because of what they sell and where they sell it. Many more are pulled into NIS2 compliance contractually, because their EU customers are obliged to manage the security of their own supply chains and have no way to do that except through you.

This guide sets out how Directive (EU) 2022/2555 works in practice for a UK supplier. It covers who is caught directly, how the supply chain clause pulls in everyone else, the ten security measures the directive actually names, the 24-hour and 72-hour reporting clocks, what your EU customers will ask you to evidence, the penalty ceilings, and a 90-day plan that gets you to a defensible position without rebuilding your entire IT security function.

If you have already been through a supplier assurance exercise, the shape will be familiar. Our guide to Cyber Essentials for suppliers covers the UK contractual equivalent, and the ISO 27001 readiness assessment checklist covers the management system most EU customers will ask about next.

What NIS2 Compliance Means for a UK Business

nis2 compliance uk businesses eu customers b interlocking puzzle blocks plinth

The law behind NIS2 compliance

NIS2 is Directive (EU) 2022/2555, which replaced the original 2016 network and information security directive. It entered into force in January 2023, and EU Member States were required to transpose it into national law by 17 October 2024. That last point matters more than it looks: a directive is not directly binding on companies. You never comply with NIS2 itself. You comply with the Belgian, German, Irish or Dutch law that implements it, and those national laws differ in detail, in penalty levels and in how aggressively they are enforced.

Why Brexit did not settle the question

The directive is territorial in application, not in nationality. It bites on services offered inside the Union, not on companies headquartered inside it. A UK managed service provider running infrastructure for a Dutch manufacturer is offering services within the EU regardless of where its own registered office sits. NIS2 compliance for UK businesses therefore turns on where your customers are and what you do for them, not on your incorporation.

Essential entities and important entities

The directive splits in-scope organisations into two tiers. Essential entities are large organisations in the highest-criticality sectors listed in Annex I: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space. Important entities are medium-sized organisations in those sectors plus organisations in Annex II sectors, which include postal and courier services, waste management, chemicals, food, several categories of manufacturing, digital providers and research organisations.

The size test that filters most SMEs out of direct scope

Direct scope generally starts at medium-sized enterprise: 50 or more staff, or annual turnover and balance sheet total above €10 million. Large enterprises — 250 or more staff, or turnover above €50 million and balance sheet above €43 million — sit in the essential tier when they operate in an Annex I sector. A 20-person UK software house selling to European customers is almost never directly in scope on size alone. That is exactly why so many of them assume NIS2 compliance is somebody else’s problem, and exactly why they are wrong.

The supervision difference between the two tiers

The distinction is not cosmetic. Essential entities face proactive supervision: regulators can inspect, audit and demand evidence without waiting for an incident. Important entities face reactive supervision, meaning the regulator acts when it has grounds to believe there has been a breach of duty. Both tiers carry identical NIS2 compliance obligations. Only the intensity of oversight and the penalty ceiling differ, which is why a supplier questionnaire looks much the same whichever tier your customer sits in.

TierWho lands hereSize thresholdSupervisionMaximum fine
Essential entityAnnex I sectors, large organisations250+ staff, or turnover above €50mProactive — audits and inspections without cause€10m or 2% of global turnover
Important entityAnnex II sectors, plus medium Annex I organisations50+ staff, or turnover above €10mReactive — on evidence of non-compliance€7m or 1.4% of global turnover
Out of direct scopeSmall UK suppliers, most SMEsBelow 50 staff and €10mNone from the regulatorNone — but contractual liability applies

When NIS2 Compliance Applies to You as a UK Supplier

nis2 compliance uk businesses eu customers c single hourglass on plinth

Route one: you are caught directly

A specific list of digital service categories is caught wherever the provider sits. Article 26 names DNS service providers, top-level domain name registries, domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking platforms. If your UK business is one of these and you offer services in the EU, direct NIS2 compliance is your obligation, not your customer’s.

The EU representative requirement almost nobody has done

This is the sharpest edge for UK firms. Where an organisation in that list is not established in the Union but offers services within it, the directive requires it to designate a representative established in a Member State where those services are offered. That representative becomes the point of contact for the regulator, and jurisdiction follows the representative’s location. Many UK managed service providers with European clients have never appointed one, which leaves them non-compliant on a structural point before any technical control is even assessed.

Registration obligations for the same categories

Those same digital categories were also required to submit registration information — legal name, sector, address, contact details, IP ranges and the Member States where they operate — so that national authorities and ENISA could build a registry of in-scope providers. If you are a UK cloud, data centre or managed security provider selling into the EU, that registration is part of NIS2 compliance and it is not something a customer can do for you.

Route two: the supply chain clause pulls you in anyway

Most UK businesses arrive at NIS2 compliance here. Article 21 requires in-scope entities to manage supply chain security, including the security-related aspects of the relationship with each direct supplier and service provider. The directive goes further and tells entities to take account of vulnerabilities specific to each supplier and the overall quality of that supplier’s products and security practices. Your EU customer cannot satisfy that duty by hoping. It satisfies it by pushing NIS2 compliance obligations into your contract.

A practical NIS2 compliance decision test

Run three questions. First: do you sell one of the named digital services into the EU? If yes, you are directly in scope and need an EU representative. Second: is any EU customer of yours a medium or large organisation in an Annex I or Annex II sector? If yes, expect contractual NIS2 compliance requirements. Third: does your service touch that customer’s network, data or operational continuity? If yes, you will be treated as a critical supplier and audited accordingly.

FactorDirect scopeIndirect (contractual) scope
What triggers itSector, size and services offered in the EUBeing a supplier to an in-scope EU entity
Source of the dutyNational law implementing the directiveYour customer contract and security schedule
Who enforces itThe Member State competent authorityYour customer, through audit and termination rights
Registration requiredYes, for the named digital categoriesNo
EU representative requiredYes, if not established in the UnionNo
Worst realistic outcomeRegulatory fine and management liabilityLosing the contract and the reference
How fast it arrivesOn registration or after an incidentAt the next contract renewal

NIS2 Compliance and the UK's Own Cyber Security Rules

nis2 compliance uk businesses eu customers d five stacked blank slabs plinth

The UK kept its own version of NIS1

The UK implemented the original directive as the Network and Information Systems Regulations 2018, and those 2018 Regulations remain in force. They cover operators of essential services and relevant digital service providers, with a penalty ceiling of £17 million. They were not updated when the EU moved to NIS2, which is how the two regimes drifted apart.

The Cyber Security and Resilience Bill closes some of the gap

The UK government has brought forward a Cyber Security and Resilience Bill to modernise the 2018 regime, extending it towards managed service providers and tightening incident reporting. It moves the UK closer to the EU position without replicating it. Our earlier analysis of the Cyber Security and Resilience Bill covers the detail. For a UK supplier with EU customers, the practical consequence is simple: you will end up meeting the stricter of the two, and today that is the EU one.

Running one control set, not two NIS2 compliance programmes

The sensible response is not two parallel programmes. Build one control set that satisfies the stricter requirement and map it to both regimes. In practice the delta between UK expectations and NIS2 compliance is narrow on technical controls and wide on governance, reporting speed and supply chain evidence. That is where your effort should go.

DimensionEU NIS2UK NIS Regulations 2018Cyber Security and Resilience Bill
InstrumentDirective (EU) 2022/2555SI 2018/506Bill before Parliament
Sectors covered18 sectors across two annexesFive essential sectors plus digital servicesWidening towards managed services
Supply chain dutyExplicit and named in Article 21Implicit within general dutiesStrengthened
First report due24 hours (early warning)72 hoursExpected to tighten
Management liabilityNamed personally in Article 20Not specifiedNot yet equivalent
Maximum penalty€10m or 2% of global turnover£17mTo be confirmed
Applies to a UK firm selling in the EUYes, directly or contractuallyOnly for UK operationsOnly for UK operations

The compliance calendar for a UK supplier does not stop at the directive. Two adjacent EU regimes land on overlapping timelines, and both reach UK companies through contracts.

EU cyber regulation milestones affecting UK suppliers (2023–2027)
NIS2 enters into force Jan 2023
Member State transposition deadline Oct 2024
DORA applies to EU financial entities Jan 2025
Cyber Resilience Act vulnerability reporting Sep 2026
Cyber Resilience Act main obligations Dec 2027

Where DORA takes over instead

If your EU customers are banks, insurers or investment firms, the operative regime is the Digital Operational Resilience Act rather than the directive. DORA has applied since January 2025 and imposes prescriptive contractual terms on ICT third-party providers, including exit strategies, audit rights and register-of-information entries. A UK software supplier to an EU bank will be handed DORA clauses, not NIS2 compliance clauses, and the two sets of obligations are similar in spirit but different in wording.

The Ten Security Measures Behind NIS2 Compliance

nis2 compliance uk businesses eu customers e magnifying lens on plinth

Article 21 lists ten categories of risk-management measure. They are deliberately outcome-based rather than prescriptive, which is why customers translate them into questionnaires. The list below is the whole obligation, and any credible NIS2 compliance programme is organised around it.

Risk analysis and information security policy

A documented risk assessment methodology, a completed assessment, and an approved information security policy that the risk assessment actually feeds. This is the foundation every subsequent NIS2 compliance measure hangs from, and the item most often produced retrospectively to satisfy an auditor.

Incident handling

Documented detection, triage, escalation and response, with defined severity levels and named owners. The reporting clocks discussed below are unachievable without this, so treat your incident response capability as the load-bearing control rather than the paperwork exercise.

Business continuity and crisis management

Backup management, disaster recovery and crisis management. The test that matters is a documented restore, performed on a schedule, with evidence of the outcome. A backup job that reports success and has never been restored is a finding, not a control.

Supply chain security

Security in the relationships with your own direct suppliers and service providers. UK businesses consistently underestimate this one: NIS2 compliance is transitive, so your subcontractors and your own cloud dependencies come into scope through you. This is where vendor management stops being an administrative function.

Secure acquisition, development and maintenance

Security across the lifecycle of network and information systems, including vulnerability handling and disclosure. If you build software for EU customers, expect questions about your secure development process, your dependency scanning and your published disclosure route.

Assessing effectiveness

Policies and procedures to assess whether the risk-management measures actually work. Effectiveness testing, not control existence, is the difference between a mature programme and a document set. Penetration testing and control assurance both sit here.

Cyber hygiene and training

Basic cyber hygiene practices and cybersecurity training across the organisation. Patching cadence, account hygiene, device standards and a training record that shows who was trained and when. The NCSC Cyber Essentials scheme maps closely to this measure and is the cheapest way for a UK supplier to evidence it.

Cryptography and encryption

Policies covering the use of cryptography, and encryption where appropriate. Auditors look for a stated position on data at rest, data in transit and key management rather than a blanket claim that everything is encrypted.

HR security, access control and asset management

Screening, joiners-movers-leavers processes, least-privilege access, privileged access review and a maintained asset inventory. The asset inventory is the item that quietly blocks everything else when it is missing.

Multi-factor authentication and secured communications

Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications. Note the last item: NIS2 compliance expects you to be able to run an incident when your primary systems are the incident.

Article 21 measureCovered by Cyber EssentialsCovered by ISO 27001Typical UK supplier gap
Risk analysis and security policyNoYesNo documented methodology
Incident handlingPartlyYesNo 24-hour notification path
Business continuity and backupsNoYesRestores never tested
Supply chain securityNoPartlySubcontractors unassessed
Secure development and vulnerability handlingPartlyPartlyNo disclosure policy
Effectiveness assessmentNoYesNo internal audit cycle
Cyber hygiene and trainingYesYesNo training records kept
Cryptography policyPartlyYesKey management undefined
HR security and access controlPartlyYesPrivileged access never reviewed
MFA and secured communicationsYesYesNo out-of-band comms plan

NIS2 Compliance Incident Reporting: 24 Hours, 72 Hours, One Month

nis2 compliance uk businesses eu customers f blank signpost three arrows plinth

The three-stage NIS2 compliance clock

Reporting is where NIS2 compliance is genuinely harder than what most UK suppliers are used to. For a significant incident, an in-scope entity must send an early warning within 24 hours of becoming aware of it, a fuller incident notification within 72 hours including an initial assessment and severity, and a final report within one month of that notification. Authorities can request an intermediate status update at any point in between.

What “significant” means

An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or is capable of affecting others by causing considerable material or non-material damage. Implementing rules add quantitative triggers for certain digital providers, including thresholds based on service unavailability and numbers of users affected.

The 24-hour early warning is not an investigation

The early warning is short by design. It states that an incident has occurred, whether it is suspected to be unlawful or malicious, and whether it could have cross-border impact. It does not require root cause, scope or remediation detail. Teams miss the deadline because they wait for certainty they were never asked for.

Where a UK supplier sits in this

You will usually not be the reporting entity. Your EU customer is, and its clock starts when it becomes aware. That means your contractual notification window will be shorter than the regulator’s — commonly 12 to 24 hours, sometimes as little as six — because the customer needs time to assess before its own 24-hour deadline expires. Read the notification clause before you sign it, not during an incident.

Reporting deadlines compared, in hours from awareness
Supplier notice to customer, typical contract 12h
NIS2 early warning 24h
NIS2 incident notification, and UK GDPR breach report 72h
NIS2 final report 720h (1 month)

Running two clocks at once

A single incident frequently triggers both the directive and data protection law. If personal data is involved, the UK GDPR 72-hour notification to the ICO runs in parallel with the customer’s NIS2 obligations, on a different trigger and to a different regulator. Build one incident process that satisfies the fastest clock and feeds every other one from the same evidence set, rather than maintaining separate procedures that diverge under pressure.

RegimeFirst deadlineSecond deadlineFinal reportReported to
EU NIS224 hours — early warning72 hours — notificationOne monthNational CSIRT or authority
UK GDPR72 hours — breach reportWithout undue delay to individualsOn requestICO
UK NIS Regulations 201872 hoursNot stagedOn requestCompetent authority
EU DORAInitial notification, hoursIntermediate reportFinal reportFinancial regulator
Customer contractOften 6–24 hoursAs specifiedPost-incident reviewYour customer

NIS2 Compliance Evidence Your EU Customers Will Demand

The security schedule

Expect a contract annex rather than a conversation. It will name the security measures you must maintain, the notification window, audit rights, subcontractor approval, and a right to terminate for persistent failure. This is how the directive’s supply chain duty becomes your legal obligation, and this contractual form of NIS2 compliance is enforceable long before any regulator takes an interest.

The questionnaire

Most EU customers run a standardised supplier assessment. The questions track Article 21 almost line by line: risk assessment, incident handling, continuity, subcontractors, secure development, testing, training, encryption, access control and authentication. Answering from a maintained evidence pack takes a day. Answering from scratch takes three weeks and produces inconsistencies that invite follow-up.

The NIS2 compliance evidence pack

Assemble it once and reuse it. A defensible NIS2 compliance evidence pack contains your information security policy, current risk assessment, incident response plan with contact tree, most recent restore test result, asset and supplier inventories, access review records, training records, penetration test summary, and any certification you hold. Keep it versioned and dated.

Audit and testing rights

Larger customers will reserve the right to audit your NIS2 compliance, or to accept an independent certification in place of an audit. Certification is almost always cheaper than hosting audits from a dozen customers. This is the strongest commercial argument for ISO 27001 in a UK supplier that sells into Europe, and it converts an ongoing cost into a fixed one.

Model supplier clause a UK business can expect to sign

“The Supplier shall implement and maintain technical and organisational measures appropriate to the risks presented, consistent with Article 21 of Directive (EU) 2022/2555 as implemented in the Customer’s jurisdiction, and shall not materially reduce those measures during the Term.”

“The Supplier shall notify the Customer without undue delay and in any event within twelve (12) hours of becoming aware of any incident affecting the Services, and shall provide such information as the Customer reasonably requires to meet its own regulatory reporting obligations.”

“The Supplier shall not appoint any subcontractor with access to Customer systems or data without prior written approval, and shall impose obligations on each subcontractor no less protective than those in this Schedule.”

Negotiate the notification window, not the standard

You will not win an argument about whether Article 21 applies. You can reasonably negotiate the notification window, the definition of an incident, the frequency of audits and the cap on liability. A blanket six-hour notification duty for any incident is a trap; a twelve-hour duty for incidents affecting the contracted service is achievable and defensible, and it still supports your customer’s own NIS2 compliance clock.

NIS2 Compliance Penalties, Liability and Personal Risk

The NIS2 compliance fines

Essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%. Those are ceilings set by the directive; Member States implement them in national law and may go further. For most UK suppliers these numbers matter as leverage on their customers rather than as a direct exposure.

Management accountability is personal

Article 20 requires management bodies to approve the cybersecurity risk-management measures, to oversee their implementation, and to undertake training. It also provides that management can be held liable for failures. This is the change that moves NIS2 compliance from the IT budget to the board agenda, and it is why your EU customer’s directors care about your security posture in a way they did not five years ago.

The consequence that actually arrives first

No UK SME supplier has been fined under a European implementation of the directive. Plenty have lost renewals. The realistic downside of weak NIS2 compliance is commercial: failing a supplier assessment, being placed on a remediation plan with a deadline, being excluded from a tender shortlist, or being replaced at renewal by a competitor who answered the questionnaire better. That happens quietly and it happens now.

Maximum penalty ceilings compared
NIS2 essential entity €10m or 2% of global turnover
NIS2 important entity €7m or 1.4%
UK NIS Regulations 2018 £17m
UK GDPR £17.5m or 4% of global turnover

A 90-Day NIS2 Compliance Programme for UK Suppliers

Days 1 to 30: establish scope and find the gaps

Confirm which route applies to you. List every EU customer, their sector and their approximate size, and flag any that sits in Annex I or Annex II. Separately, check whether you provide one of the named digital services, because that changes the exercise from contractual to regulatory. Then score yourself against the ten Article 21 measures honestly, using the evidence you could produce today rather than the controls you believe exist.

Days 31 to 60: close the gaps that block everything else

Three items unblock the rest of a NIS2 compliance programme and should be done first: a maintained asset and supplier inventory, multi-factor authentication everywhere it is missing, and a tested restore. After those, write the incident response plan with a real contact tree and defined severity levels, and fix privileged access review. Most UK suppliers can complete this phase with existing staff and no new tooling.

Days 61 to 90: produce evidence and rehearse

Assemble the evidence pack, run a tabletop exercise against the 24-hour and 72-hour clocks, and produce a one-page NIS2 compliance summary you can send with proposals. Review your standard contract terms so that notification windows and subcontractor obligations you have agreed with customers are ones you can actually meet. If certification is the goal, this is the point at which a readiness assessment is worth buying.

What to do beyond 90 days

Set the recurring cycle: annual risk assessment refresh, quarterly access review, quarterly restore test, annual tabletop, and a supplier reassessment cadence tied to criticality. NIS2 compliance is a maintained state, not a project with an end date, and customers audit the cadence as much as the controls. A managed IT services partner can carry the recurring elements if you do not have the internal capacity.

PhaseMain activityOutputTypical effortOwner
Days 1–30Scope determination and gap scoringScope statement and scored gap register4–8 daysOps or IT lead
Days 31–60Inventory, MFA, restore test, incident planWorking controls with evidence10–15 daysIT and supplier owners
Days 61–90Evidence pack and tabletop exerciseReusable assurance pack5–8 daysIT lead and directors
OngoingReviews, tests and supplier reassessmentDated recurring records2 days per quarterNamed control owner

NIS2 Compliance Mistakes UK Suppliers Keep Making

Assuming Brexit is a defence

It is not, and saying so in a questionnaire response damages credibility. The obligation follows the service into the Union. A UK business that answers “not applicable, we are outside the EU” is telling a procurement team that it has not read the directive.

Treating NIS2 compliance as an IT project

The heaviest gaps are governance, evidence and supply chain records, not firewalls. Programmes run purely by an IT team consistently deliver controls with no documentation, which fails an assessment just as completely as having no controls.

Forgetting the subcontractors

Your own suppliers inherit the obligation through you, because NIS2 compliance is transitive down the chain. If a third-party developer, an offshore support team or a niche SaaS tool touches customer systems, it belongs in your inventory and in your assessment. This is the single most common finding in a supplier audit.

Signing notification windows you cannot meet

A six-hour notification duty agreed in a hurry becomes a contractual breach on the first weekend incident. Check whether you have out-of-hours cover capable of meeting the clause before you agree to it.

Ignoring the EU representative requirement

If you provide one of the named digital services into the Union, appointing a representative is not optional and no amount of technical control substitutes for it. It is also the cheapest item on the list, which makes leaving it undone particularly hard to explain.

Rebuilding from scratch when you already hold certification

Cyber Essentials Plus and ISO 27001 cover a large proportion of Article 21. Map what you have before you buy anything. Our comparison of Cyber Essentials Plus and ISO 27001 sets out which one answers more of the questions an EU customer will ask.

NIS2 Compliance Questions Answered

Does NIS2 apply to UK companies after Brexit?

Yes, in two ways. UK providers of certain digital services that offer them within the EU are directly in scope and must appoint an EU representative. Every other UK supplier to an in-scope EU organisation is reached contractually through the directive’s supply chain requirements. Neither route depends on being established in the Union.

We are a 15-person business. Are we in scope?

Almost certainly not directly, because direct scope generally starts at 50 staff or €10 million turnover. You will still face NIS2 compliance obligations through customer contracts, and small suppliers are assessed as rigorously as large ones when they touch critical systems.

Which country’s rules apply to us?

The national law of the Member State where your customer is established, or where your EU representative sits if you are directly in scope. This is why NIS2 compliance answers should reference the directive rather than any single national implementation — the underlying obligations are common, the procedural detail is not.

Does Cyber Essentials satisfy NIS2 compliance?

No, but it evidences a meaningful part of the cyber hygiene, access control and authentication measures. It does not cover risk methodology, business continuity, supply chain security or effectiveness testing. Treat it as a component, not an answer.

How long does NIS2 compliance realistically take?

Ninety days to a defensible position if you already have basic controls and someone owns the work. Longer if your asset inventory does not exist, because almost everything else depends on it. Certification, if you choose that route, adds three to six months.

What happens if we simply do not respond?

Commercially, you are removed from the approved supplier list at renewal. The customer has its own regulator to satisfy and cannot carry an unassessed supplier indefinitely. That is a slower and more certain outcome than a fine.

Who should own NIS2 compliance internally?

One named person with authority over both IT and contracts, reporting to a director. Split ownership between an IT manager and a commercial manager is the most reliable way to produce a programme where each half assumes the other is handling evidence. Our compliance and cybersecurity teams work alongside that owner rather than replacing them.

References