If your organisation operates in the EU, supplies customers there, or sits in the supply chain of businesses that do, the EU’s NIS2 Directive may already apply to you, even though it is not UK law. And with the UK’s own Cyber Security and Resilience Bill now in its final parliamentary stages, the two regimes are converging fast. This note explains where things stand in mid-2026 and what you should be doing about it.
What is NIS2?
NIS2 (Directive (EU) 2022/2555) is the EU’s flagship cyber security law. It replaced the original NIS Directive and sets minimum cyber security and incident reporting standards across 18 critical sectors, including energy, transport, health, water, digital infrastructure, managed IT services, food production and manufacturing.
The directive divides in-scope organisations into “essential” and “important” entities. As a rule of thumb, you are caught if you operate in a listed sector and have 50 or more employees or annual turnover above EUR 10 million, although some entities (such as DNS providers and trust service providers) are in scope regardless of size.
EU member states had until 17 October 2024 to transpose NIS2 into national law. Most missed that deadline, but the position has changed significantly since then, and the large majority of member states have now adopted NIS2 into their national laws, the European Commission has pursued infringement proceedings against the stragglers, and national regulators have moved from preparation into active enforcement. The grace period is over.
Does NIS2 apply to a UK organisation?
NIS2 does not apply in the UK directly. It reaches UK organisations in three main ways:
- You have an EU subsidiary or establishment operating in a covered sector. That entity must comply with the national NIS2 law of each member state in which it is established.
- You provide certain digital services into the EU without an establishment there, for example as a cloud, data centre, DNS or online marketplace provider. You may need to appoint an EU representative and will fall under the jurisdiction of the member state where that representative is based.
- You supply in-scope EU customers. NIS2 requires regulated entities to manage supply chain risk, so expect security questionnaires, contractual security clauses and audit rights to flow down to you even if you are not directly regulated.
The third route is the one most UK businesses underestimate. Even a modest UK supplier can find NIS2-style obligations arriving through its contracts with EU customers.
NIS2 clauses in your contracts: what to expect and how to respond
Article 21(2)(d) requires regulated entities to address the security of their supply chains, including the security-related aspects of their relationships with each direct supplier and service provider. In practice, the only tool a regulated customer has to discharge that duty is its contracts with you. That is why UK suppliers are now seeing NIS2 terms appear in new agreements, renewals and even mid-term variation requests.
The clauses tend to follow a familiar pattern. Expect requests for:
- Mandated security standards, often expressed by reference to ISO 27001, the customer’s own security schedule, or national frameworks in the customer’s member state.
- Incident notification obligations requiring you to tell the customer about security incidents within a fixed period, sometimes shorter than the 24 hours the customer itself has to give its regulator an early warning.
- Audit and inspection rights, including rights to security questionnaires, evidence of certifications, penetration test results and, in some cases, on-site audits.
- Flow-down obligations requiring you to impose equivalent terms on your own subcontractors.
- Cooperation duties, obliging you to assist with the customer’s regulatory reporting and any investigation by its competent authority.
- Enhanced termination rights and, increasingly, attempts to carve security failures out of liability caps.
None of this is inherently unreasonable; your customer is passing down obligations it cannot avoid. But there is a real difference between accepting proportionate terms and signing up to commitments you cannot operationally meet. A promise to notify within 12 hours that you are unsure whether your incident response process can is a breach of contract waiting to happen.
When these terms land on your desk, focus on the following:
- Match notification triggers and timescales to reality. Test what your team can actually detect, escalate and communicate out of hours before agreeing a deadline, and define “incident” tightly so that routine events do not trigger contractual reporting.
- Contain audit rights. Agree sensible limits on frequency, notice periods, confidentiality and who bears the cost, and offer certifications or independent assurance reports as the first line of evidence instead of open-ended access.
- Watch the liability position. Uncapped or specially carved-out liability for security failures shifts the customer’s regulatory risk onto you; resist it, or price it.
- Check your ability to flow down. Do not accept subcontractor obligations you cannot pass on under your existing supply contracts without renegotiation.
- Keep your answers consistent. Security questionnaire responses can be incorporated into the contract or relied on later; treat them with the same care as the contract itself.
Handled well, this is also a commercial opportunity. Suppliers who can evidence strong security and respond to NIS2 questionnaires quickly are easier to buy from, and some EU customers are already consolidating their supply base around them.
The core obligations
Risk management measures
Article 21 requires in-scope entities to take “appropriate and proportionate” measures across ten areas, including risk analysis, incident handling, business continuity and backups, supply chain security, vulnerability management, encryption, access control and cyber security training. If you already hold ISO 27001 certification you have a strong head start, but it does not cover everything; registration, reporting and some national add-ons sit outside it.
Incident reporting
Significant incidents must be reported to the national CSIRT or competent authority on a strict cascade: an early warning within 24 hours, a fuller incident report within 72 hours, and a final report within one month. If you also process personal data, this runs in parallel with your 72-hour UK GDPR or EU GDPR breach notification obligations; one incident can trigger several clocks at once.
Management accountability
Boards must approve the organisation’s cyber security risk measures, oversee their implementation and undertake training. Under Article 20, management bodies can be held personally liable for non-compliance, and several member states allow regulators to temporarily ban individuals from management roles. How that liability bites varies by country, which matters for directors’ and officers’ insurance if you operate across borders.
Penalties
Essential entities face fines of up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. For important entities the ceiling is EUR 7 million or 1.4%. Member states are free to set higher figures, and some have.
The UK position: the Cyber Security and Resilience Bill
The UK’s existing regime remains the Network and Information Systems Regulations 2018, which pre-date NIS2 and are widely seen as outdated. The Cyber Security and Resilience Bill, introduced in November 2025, will change that. It has completed its Commons stages, is now before the House of Lords, and is expected to receive Royal Assent later in 2026, with phased implementation likely to be running until 2028.
The Bill amends and expands the 2018 Regulations rather than replacing them, but the direction of travel is deliberate alignment with NIS2. Key features include:
- An expanded scope covering managed service providers, designated critical suppliers, larger data centres and load controllers.
- A 24-hour early warning and 72-hour full report for significant incidents, mirroring the NIS2 cascade, with reports going to both the sector regulator and the NCSC.
- A two-tier penalty regime of up to £10 million or 2% of global turnover for standard breaches, and up to £17 million or 4% for serious breaches, with daily penalties for continuing contraventions.
- New supply chain powers, allowing secondary legislation to impose contractual and assurance requirements on regulated entities’ suppliers.
For UK organisations with EU operations, this alignment is good news: a compliance programme built to NIS2 standards should carry most of the weight of the UK regime, and vice versa. Building one framework now, rather than two later, is likely to be much more efficient and cost effective.
What you should do now
- Map your exposure. Identify any EU establishments, EU-facing digital services and in-scope EU customers, then confirm which national NIS2 laws apply and whether you must register with a regulator.
- Check your reporting readiness. Test whether you could genuinely deliver an early warning within 24 hours of detecting a significant incident, including out of hours, and who would draft and approve it.
- Brief your board. Directors need to understand their personal accountability under NIS2 and the incoming UK regime, approve the risk management approach and complete appropriate training.
- Review supplier and customer contracts. Expect NIS2 security clauses from EU customers and prepare your own flow-down terms for critical suppliers.
- Align, do not duplicate. Design one cyber governance framework that satisfies NIS2, the incoming UK regime and your UK GDPR obligations together.
How we can help
Our data protection team can advise on NIS2 obligations, incident response planning, board training and supply chain contracting for organisations operating on both sides of the Channel. If you would like to discuss how the EU and UK regimes affect your business, please get in touch with Matthew Cole.