Compliance

NIS2 Compliance for UK Businesses: What You Need to Know

The EU's NIS2 Directive came into force in October 2024, significantly expanding the scope of mandatory cybersecurity requirements for organisations operating in the EU. UK businesses that supply EU customers or operate in EU member states may face NIS2 obligations — even though the UK is not subject to EU law post-Brexit.

Overview

NIS2 is the EU's expanded cybersecurity directive, in force from October 2024. UK businesses supplying EU entities may face NIS2 obligations through their customers. The security controls NIS2 requires — risk management, access controls, incident response, supply chain security — align with NCSC guidance and. The UK government is reviewing equivalent UK legislation.

Learn about managed cybersecurity

What is NIS2 and why does it matter to UK firms?

The Network and Information Security Directive 2 (NIS2) is the EU's expanded framework of mandatory cybersecurity requirements. Adopted in December 2022 and required in national law by October 2024, it replaces the original 2016 NIS Directive and widens both the sectors covered and the obligations imposed.

Post-Brexit, EU law does not apply directly to UK entities. But NIS2's reach extends through supply chains, customer contracts and EU-based subsidiaries — so UK firms feel its effects indirectly. The threat backdrop is real on both sides of the Channel: 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and 85% of those breaches involved phishing (DSIT 2025) (Cyber Security Breaches Survey 2025, gov.uk). If you run managed cybersecurity controls already, you have a head start on NIS2's technical baseline.

When does NIS2 affect a UK business?

NIS2 reaches UK organisations in three ways: when they supply EU customers bound by the directive, when they operate subsidiaries inside an EU member state, and when they provide ICT or managed services to in-scope EU clients. In each case the requirement arrives through contracts and procurement, not through UK law.

  • Supplying EU customers — EU organisations must manage cybersecurity risk in their supply chains. UK suppliers will increasingly see NIS2-equivalent security clauses in procurement questionnaires, contracts and due-diligence checks. Suppliers that cannot demonstrate adequate controls risk losing the business.
  • Operating EU subsidiaries — A UK parent with subsidiaries in EU member states is directly subject to NIS2 through those entities, which must meet the local transposition's controls, reporting and governance rules.
  • MSPs and digital infrastructure — NIS2 names ICT service management, managed service providers and digital infrastructure explicitly. UK MSPs and cloud providers serving EU customers may inherit obligations through those relationships.

Who does NIS2 cover: sectors and scope?

NIS2 covers 18 sectors split into "essential" and "important" entities. Essential entities include energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration and space. Important entities include postal services, waste management, manufacturing, food production, digital providers, research and chemicals.

The expansion from the original directive is substantial. The 2016 NIS Directive covered only operators of essential services and digital service providers. NIS2 pulls in managed service providers, manufacturing, food production, waste management and postal services — categories previously outside EU cybersecurity regulation. For UK technology firms serving EU clients, the inclusion of ICT service management and cloud providers is the headline change.

What does NIS2 require organisations to do?

NIS2 imposes both technical and organisational measures. Organisations must run a documented risk-management process covering security policies, incident handling, business continuity, supply chain security, vulnerability handling, effectiveness testing and cryptography. The directive treats these as a minimum baseline, not a wish list.

The standout obligations are the reporting clock and personal accountability:

  • Incident reporting is far stricter than UK GDPR. An early warning to the national authority is due within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Those timelines only work if detection and escalation already exist — yet just 14% of UK businesses have a formal incident response plan (DSIT 2025).
  • Management accountability is explicit. Senior management can be held personally liable for failing to implement adequate measures, moving cybersecurity from a technical concern to a board-level governance duty.
  • Penalties are material: for essential entities, fines can reach up to 10 million euros or 2% of global annual turnover, whichever is higher, under Article 34 of the directive.

NIS2 vs UK GDPR: how do the reporting rules compare?

The reporting gap is the single most operationally demanding part of NIS2 for firms used to the UK GDPR regime. The table below sets the two side by side.

RequirementNIS2UK GDPR
Early warning to authorityWithin 24 hours of awarenessNot required
Initial/full notificationWithin 72 hoursWithin 72 hours to the ICO
Final reportWithin one monthNo fixed final-report deadline
Personal management liabilityYes — explicitLimited
Maximum financial penalty€10m or 2% global turnover£17.5m or 4% global turnover

Meeting a 24-hour clock needs detection and triage running around the clock. AMVIA's 24/7 security monitoring and incident response processes are built to surface and escalate significant incidents inside that window.

How does NIS2 map to UK security standards?

NIS2's technical controls align closely with established UK guidance. The NCSC's five technical controls — boundary firewalls, secure configuration, access control, malware protection and patch management — form a significant subset of NIS2's requirements, and the NCSC Cyber Assessment Framework (CAF) maps to its fuller governance, risk and resilience scope (National Cyber Security Centre).

Firms that hold a recognised baseline certification, keep documented incident procedures, run regular risk assessments and manage supplier security have already covered much of NIS2. The gap usually sits in governance: formal risk-management processes, board-level accountability and structured reporting. AMVIA holds Cyber Essentials Plus and applies Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC, plus vulnerability management and patching to close the technical side.

What practical steps prepare a UK business for NIS2?

For UK firms that must show NIS2-equivalent security to EU customers or through EU subsidiaries, a structured readiness path works best. It starts with scoping exposure and ends with formal governance.

  • Assess exposure — identify EU customers, EU subsidiaries and any contract clauses referencing NIS2 or equivalent standards.
  • Implement technical controls — ensure endpoint security, access management, patching and network protection are in place and monitored.
  • Establish incident response — document detection, escalation and reporting that can meet the 24-hour early-warning rule.
  • Address supply chain security — assess key technology suppliers' security posture and record the assessment.
  • Formalise governance — make cybersecurity a board agenda item with documented accountability for risk decisions.

This is the same groundwork that strengthens GDPR and cybersecurity compliance and complements continuous managed detection and response.

What is the UK regulatory outlook?

The UK government is reviewing its own NIS Regulations (2018) and is expected to update them to align with — though not copy — NIS2. The Cyber Security and Resilience Bill, announced in the 2024 King's Speech, is set to widen UK cybersecurity regulation and tighten incident reporting.

Regardless of the exact UK timeline, the measures NIS2 requires — risk management, access control, incident response and supply chain security — are simply good practice. The average cost of a data breach for UK organisations was £3.58 million in 2024 (IBM 2024), which makes the business case for acting now rather than waiting for a deadline. AMVIA supports NIS2 compliance by implementing the technical and organisational measures UK businesses need; call 0333 733 8050 to discuss your readiness.

Key Points

What UK businesses need to know about NIS2.

Expanded Scope

NIS2 covers 18 sectors including digital infrastructure, managed service providers, cloud computing, and supply chains — significantly broader than the original NIS Directive.

Stricter Security Requirements

NIS2 requires risk management processes, security policies, access control, supply chain security, incident response, and business continuity planning.

24-Hour Incident Reporting

Significant cyber incidents must be reported to relevant authorities within 24 hours — far stricter than the UK GDPR 72-hour ICO notification requirement.

Supply Chain Liability

NIS2 extends to supply chain security — organisations must assess and manage cybersecurity risks from their technology suppliers and service providers.

NIS2 Readiness Checklist

Assess whether EU customers may contractually require NIS2-equivalent security

Documented risk management process — identifying and prioritising cybersecurity risks

Incident response procedure — including 24-hour escalation path if required

Supply chain security assessment — evaluating key technology suppliers

Business continuity plan documented and tested

Frequently Asked Questions

Assess Your NIS2 Readiness

AMVIA helps UK businesses understand their NIS2 obligations and implement the technical and organisational controls that satisfy EU and upcoming UK regulatory requirements.