Get a quote

The UK NIS Regulations
and EU NIS2 Directive

26 November 2025

Knowledge

ISO 27001

What are the NIS Regulations and NIS2 Directive?

Since Brexit, the UK and EU have enforced separate but related cyber security regimes for critical infrastructure and essential services.

In the UK, this is the NIS (Network and Information Systems) Regulations 2018.

In the EU, this is the NIS2 Directive, which introduces a broader scope and stricter requirements than the original NIS Directive (Directive on security of network and information systems), which the UK NIS Regulations were based on.

Many organisations, particularly those operating across both markets, need to understand and comply with both regimes.

Speak to an expert
Get in touch with one of our experts for more information about NIS compliance and the products and services we can offer to assist your compliance journey. Call us on +44 (0)333 800 7000, or request a call back.

What are the NIS Regulations?

The Network and Information Systems Regulations 2018 – often referred to simply as the ‘NIS Regulations’ – took effect on 10 May 2018.

They apply to:

*The Regulations do not apply to DSPs that are considered a ‘micro or small enterprise’ (organisations employing fewer than 50 people whose annual turnover and/or balance sheet total is less than €10 million (about £8.4 million)).

 

What is the EU NIS2 Directive?

The EU’s NIS2 Directive came into force on 2 January 2023. EU member states were required to transpose NIS2 into national law by 17 October 2024, with enforcement applying from 18 October 2024.

NIS2 significantly expands the original Directive’s scope and introduces more detailed, consistent security and reporting requirements across the EU, along with stronger supervision and enforcement powers for regulators.

NIS2 applies to:

  • Essential entities – including qualified trust service providers, top-level domain name registries, DNS service providers, medium-sized or larger public electronic communications network providers, and larger organisations in sectors of high criticality (such as energy, transport, health and digital infrastructure); and
  • Important entities – other medium-sized or larger organisations in NIS2’s listed sectors that don’t meet the essential entity criteria.

Does NIS2 apply to UK organisations?

NIS2 does not directly apply to organisations operating solely within the UK.

However, its scope is extraterritorial: UK organisations that provide services within the EU, operate EU-based infrastructure or form part of EU supply chains may still fall in scope, even without an EU presence.

Many other UK organisations also choose to align with NIS2 as best practice to meet client and partner expectations.

If your organisation falls in scope of NIS2 without being established in the EU, you may need to designate an EU representative.

 

Consequences for non-compliance

Under the UK NIS Regulations, non-compliant organisations may be fined up to £17 million. The relevant competent authority will assess the level of fine.

Under the EU NIS2 Directive, member states must apply fines of at least:

  • €10 million or 2% of global annual turnover (whichever is higher) for essential entities; and
  • €7 million or 1.4% of global annual turnover (whichever is higher) for important entities.

NIS2 also allows regulators to hold management personally liable for gross negligence following an incident, including – for essential entities – a temporary ban from holding management positions.

 

What are the requirements for in-scope organisations?

Under both regimes, in-scope organisations must:

  • Secure their network and information systems with technical and organisational measures appropriate to the risk;
  • Ensure service continuity by taking appropriate measures to prevent and minimise the impact of any incidents; and
  • Notify their regulator of any security incident that has a significant impact.

 

Incident reporting requirements

Under the UK NIS Regulations, organisations must report “significant” or “substantial” incidents to their competent authority without undue delay and, where feasible, no later than 72 hours after having become aware of them.

Competent authorities have been assigned on a sectoral basis, each with its own incident reporting thresholds.

OES must consider three factors when determining whether an incident is “significant”:

  1. The number of users affected by the disruption.
  2. The duration of the disruption.
  3. The size of the geographical area affected by the incident.

For DSPs, incidents have a “substantial” impact if they result in:

  • Service unavailability for more than 5 million user hours;
  • Loss of confidentiality, integrity, availability or authenticity of data accessed over networks or information systems affecting more than 100,000 users;
  • A risk to public safety, public security, or loss of life; or
  • Material damage to at least one user exceeding €1 million (about £843,000).

Under the EU NIS2 Directive, essential and important entities must report significant incidents in three stages:

  1. An early warning within 24 hours of becoming aware of the incident;
  2. A full incident notification within 72 hours; and
  3. A final report within one month of the incident notification.

 

Audits and the CAF (Cyber Assessment Framework)

In the UK, OES’ compliance with the NIS Regulations is monitored through audits conducted by the designated competent authorities.

The CAF, developed by the NCSC (National Cyber Security Centre), guides organisations to assess themselves against 14 security principles and outlines the acceptable security levels for organisations under the Regulations’ requirements.

DSPs are not audited but will be subject to investigations following any incident that may indicate non-compliance with the Regulations.

NIS2 representative service

If your organisation falls in the scope of the EU NIS2 Directive without being established in the EU, you may be required to designate an EU representative as your local point of contact for regulators.

GRC Solutions offers an EU NIS2 representative service for UK organisations operating in the EU.

 

Assess your compliance needs with a NIS Regulations gap analysis

Our NIS Regulations Gap Analysis is conducted by experts to highlight shortcomings in your overall security programme to help you prioritise objectives and establish a roadmap for achieving full NIS Regulations compliance. Kick-start your NIS Regulations compliance journey today.

 

How GRC Solutions can help you comply with the NIS Regulations

  • We can deliver everything you need for compliance, including consultancy, training and tools.
  • Our unique combination of technical expertise and solid track record in international management system standards means we can deliver a complete solution for NIS Regulations compliance and manage the project from start to finish.
  • We work with organisations in all industries and have managed hundreds of projects around the world.
  • We’re independent of vendors and certification bodies and encourage our clients to select the best fit for their needs and objectives.
  • We have multidisciplinary teams that can undertake rigorous penetration testing of your networks and systems, project managers to roll out compliance implementation projects, and executive expertise to brief your board and develop a suitable risk mitigation strategy.
  • We deliver practical advice and work according to your budget and business needs. No organisation or project is ever too big or small.
  • We offer clear and transparent pricing.