
NIS Regulations Compliance and Support Services

Turning regulatory pressure into operational confidence under the NIS Regulations
The Network and Information Systems Regulations 2018 – commonly known as the NIS Regulations – are the UK’s cyber security legislation for critical infrastructure and essential digital services. They set out requirements for OES (operators of essential services) and RDSPs (relevant digital service providers) operating in the UK.
What are the NIS Regulations compliance requirements?
The NIS Regulations set out security, governance and incident reporting obligations for organisations that keep the UK's essential services and digital infrastructure running. In-scope organisations must implement and maintain proportionate technical and organisational measures. These vary, depending on whether you are an OES or RDSP, and include:

Common NIS Regulations compliance challenges
- Uncertainty over whether they meet the OES or RDSP thresholds for their sector.
- Security measures that exist but are not mapped to the NCSC’s 14 principles.
- Incident response processes that do not meet the 72-hour reporting timeline.
- Limited supply chain oversight and third-party risk visibility.
- Insufficient audit evidence to satisfy a competent authority or the ICO.
Our approach: clear, structured and practical
We take a journey-based approach to NIS Regulations, meeting you where you are today and guiding you forward with confidence.
We help you confirm whether you are an OES, an RDSP, or out of scope, and what “good” looks like for your sector and competent authority.
We map your existing controls against the Regulations’ requirements to identify gaps, remediation priorities and implementation effort.
We support the design and implementation of proportionate controls, processes and documentation, integrated with existing frameworks such as ISO 27001 and ISO 22301.
We help you test incident response capabilities, validate controls and build the audit trail a competent authority or the ICO will expect to see.
NIS Regulations compliance is not a one-off exercise. We provide continued support to help you remain compliant and audit ready as your organisation and the threat landscape evolve.

How GRC Solutions supports NIS Regulations compliance
Our NIS Regulations services are designed to be modular and scalable, allowing you to focus on what matters most.
- NIS Regulations Representative Service
- NIS Regulations gap analysis for OES and RDSPs
- NIS Regulations Remediation Service
- CAF (Cyber Assessment Framework) readiness and self-assessment support
- Risk management and governance alignment
- Incident response planning and testing
- Supply chain and third-party risk management
- Business continuity and operational resilience
- ISO 27001 and ISO 22301 implementation and alignment
- Support with competent authority and ICO audits
If your organisation is in the scope of the EU’s NIS2 Directive, view our NIS2 compliance services.
The NIS Regulations as a foundation for resilience
NIS Regulations compliance FAQ
The NIS Regulations are the UK’s cyber security legislation for critical national infrastructure and digital services. They apply to OES (operators of essential services) in the energy, transport, health, water and digital infrastructure sectors, and to RDSPs (relevant digital service providers) providing online search engines, online marketplaces or cloud computing services, unless they qualify as a micro or small enterprise.
Cost varies depending on organisational size, sector, existing cyber security maturity and whether you are classed as an OES or an RDSP. Organisations that already operate ISO 27001 or ISO 22301 typically require less investment, while less mature environments may need more extensive support.
The EU’s NIS2 Directive does not directly apply to organisations operating solely within the UK. However, UK organisations that provide services in the EU, operate EU-based infrastructure or form part of EU supply chains may still fall in scope. See our NIS2 compliance services for more information.
In-scope organisations must secure their network and information systems with measures appropriate to the risk, ensure service continuity, and notify their regulator of any incident with a significant (OES) or substantial (RDSP) impact, generally within 72 hours of becoming aware of it.
Fines are set at four levels: up to £1 million for a contravention that could not cause an incident, up to £3.4 million where it could cause a reduction in service, up to £8.5 million where it could cause a disruption to service, and up to £17 million where it could cause an immediate threat to life or a significant adverse impact on the UK economy.
Preparation typically begins with a gap analysis, followed by improvements to risk management, incident response, supplier oversight and evidence management. A structured assessment helps prioritise action and accelerate readiness.
The CAF was developed by the NCSC to help competent authorities assess OES against 14 high-level security principles, grouped under four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. OES can also use the CAF for self-assessment.
ISO 27001 is an international standard for information security management systems, while the NIS Regulations are a legally binding UK regime. ISO 27001 provides a structured framework that supports NIS Regulations compliance, but it does not replace the underlying legal obligations.
Competent authorities and the ICO typically expect documented risk assessments, security policies, governance records, incident management procedures, supplier risk controls, staff training records and audit trails demonstrating that controls are effective, not just in place.
OES are subject to audits by their competent authority using the CAF. RDSPs are not routinely audited but may be investigated by the ICO following an incident. There is no standalone NIS Regulations certification scheme, though independent assessments and alignment with ISO 27001 can strengthen regulatory confidence.