Does NIS2 apply to a UK company?
NIS2 is an EU directive. Whether it reaches a UK company turns on where you are established, what service you provide and how large you are. Where it does not apply to you directly, it can still arrive through your EU customers' contracts.
Has an EU customer sent you a NIS2 clause?
Do you have an establishment in the EU?
Do you provide cloud or managed services in the EU?
- A free 45 minute diagnostic to establish whether NIS2 applies to you
- If it does, a scope and gap assessment against your ISO 27001 management system
- No NIS2 certificate sold, because none exists
- Run by a senior practitioner, not a coordinator
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
CISSP, ISO 27001 Lead Implementer and Lead Auditor, ISO 42001 Lead Implementer and Lead Auditor, PMP.
What NIS2 is
Directive (EU) 2022/2555, known as NIS2, sets cybersecurity risk-management and incident reporting duties for organisations in listed sectors. As a directive it does not apply on its own: each EU member state writes it into national law. Member states had until 17 October 2024 to adopt and publish those measures, and were to apply them from 18 October 2024 (Article 41).
Transposition has been uneven. On 7 May 2025 the European Commission sent reasoned opinions to 19 member states for failing to notify full transposition. For any organisation, the specific country's law decides the detail: who is in scope, who supervises and how incidents are reported.
Who is caught
Annex I, sectors of high criticality
Energy; transport; banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure; ICT service management (business-to-business); public administration; space.
Annex II, other critical sectors
Postal and courier services; waste management; chemicals; food; manufacturing; digital providers; research.
The size rule
NIS2 applies to organisations of a listed type that are medium-sized or larger under the EU definition in Commission Recommendation 2003/361/EC, and that provide their services or carry out their activities in the EU (Article 2(1)). A small enterprise, one with fewer than 50 staff and turnover or balance sheet total of no more than 10 million euros, is outside the size rule.
Caught regardless of size
Some organisations are in scope whatever their size, including providers of public electronic communications networks or services, trust service providers, top-level domain name registries, DNS service providers and domain name registration services, and organisations a member state identifies because, for example, they are the sole provider of an essential service in that state (Article 2(2) to (4)).
The answer for a UK company
Having EU customers does not by itself make a UK company a NIS2 entity. What decides it is whether you provide a service of a listed type in the EU and meet the size rule. An establishment in the EU can bring you into scope. So can providing a listed service in the EU, such as cloud computing, data centre, managed or managed security services where the size rule is met, or DNS services, which are caught regardless of size. That can include a UK SaaS company: the directive lists Software as a Service among the cloud computing service models (recital 33). A provider of those digital services that offers them in the EU without being established there must designate a representative in a member state where it offers them (Article 26(3)). Whether your product meets the definition turns on the specific national law.
How it reaches UK suppliers
NIS2 requires organisations in scope to address supply chain security, including the security of their relationships with their direct suppliers and service providers (Article 21(2)(d)). That duty reaches suppliers as contract clauses, security questionnaires and incident notification terms. A UK supplier outside the directive can still be bound by those terms through its contract.
NIS2 and ISO 27001
ISO 27001 is a strong base for NIS2, and it is not the same thing. In June 2025 ENISA published technical implementation guidance for Commission Implementing Regulation (EU) 2024/2690, which sets out NIS2's technical requirements for digital infrastructure, ICT service management and digital provider organisations. It maps each requirement to standards including ISO/IEC 27001:2022, and ENISA states that the mapping should not be read as a measure of equivalence.
What ISO 27001 does not cover on its own
Management body responsibility
The management body must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements (Article 20).
Registration
Named digital provider types, including cloud computing and managed service providers, must submit registration information to the competent authority (Article 27).
Notification deadlines
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of that notification (Article 23(4)).
The UK position
NIS2 is not UK law. In the UK, the Network and Information Systems Regulations 2018 still apply. The government's Cyber Security and Resilience Bill will update them, and the government's policy statement of 1 April 2025 says the Bill will align, where appropriate, with the approach taken in NIS2. As at 23 September 2026 the Bill is at report stage in the House of Lords and is not yet law.
Find out whether it applies to you
A free diagnostic establishes whether NIS2 applies to you directly, reaches you through a customer, or does not reach you at all. If it applies, the next step is a scope and gap assessment against your ISO 27001 management system.
Book the diagnosticFrequently asked
Sources
- Directive (EU) 2022/2555 (NIS2), EUR-Lex
- Commission Recommendation 2003/361/EC, EUR-Lex
- NIS2 transposition, European Commission
- NIS2 Technical Implementation Guidance, ENISA, June 2025
- Cyber Security and Resilience Bill: policy statement, GOV.UK, 1 April 2025
- Cyber Security and Resilience (Network and Information Systems) Bill, UK Parliament
Information, not legal advice. Last checked 23 September 2026.
