Skip to main content

Does NIS2 apply to a UK company?

NIS2 is an EU directive. Whether it reaches a UK company turns on where you are established, what service you provide and how large you are. Where it does not apply to you directly, it can still arrive through your EU customers' contracts.

Has an EU customer sent you a NIS2 clause?

Do you have an establishment in the EU?

Do you provide cloud or managed services in the EU?

  • A free 45 minute diagnostic to establish whether NIS2 applies to you
  • If it does, a scope and gap assessment against your ISO 27001 management system
  • No NIS2 certificate sold, because none exists
  • Run by a senior practitioner, not a coordinator
Book the diagnosticBring the contract clause, the questionnaire or the customer email.Same-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

CISSP, ISO 27001 Lead Implementer and Lead Auditor, ISO 42001 Lead Implementer and Lead Auditor, PMP.

EU law, applied through national law

What NIS2 is

Directive (EU) 2022/2555, known as NIS2, sets cybersecurity risk-management and incident reporting duties for organisations in listed sectors. As a directive it does not apply on its own: each EU member state writes it into national law. Member states had until 17 October 2024 to adopt and publish those measures, and were to apply them from 18 October 2024 (Article 41).

Transposition has been uneven. On 7 May 2025 the European Commission sent reasoned opinions to 19 member states for failing to notify full transposition. For any organisation, the specific country's law decides the detail: who is in scope, who supervises and how incidents are reported.

EU law

Who is caught

Annex I, sectors of high criticality

Energy; transport; banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure; ICT service management (business-to-business); public administration; space.

Annex II, other critical sectors

Postal and courier services; waste management; chemicals; food; manufacturing; digital providers; research.

The size rule

NIS2 applies to organisations of a listed type that are medium-sized or larger under the EU definition in Commission Recommendation 2003/361/EC, and that provide their services or carry out their activities in the EU (Article 2(1)). A small enterprise, one with fewer than 50 staff and turnover or balance sheet total of no more than 10 million euros, is outside the size rule.

Caught regardless of size

Some organisations are in scope whatever their size, including providers of public electronic communications networks or services, trust service providers, top-level domain name registries, DNS service providers and domain name registration services, and organisations a member state identifies because, for example, they are the sole provider of an essential service in that state (Article 2(2) to (4)).

The answer for a UK company

Having EU customers does not by itself make a UK company a NIS2 entity. What decides it is whether you provide a service of a listed type in the EU and meet the size rule. An establishment in the EU can bring you into scope. So can providing a listed service in the EU, such as cloud computing, data centre, managed or managed security services where the size rule is met, or DNS services, which are caught regardless of size. That can include a UK SaaS company: the directive lists Software as a Service among the cloud computing service models (recital 33). A provider of those digital services that offers them in the EU without being established there must designate a representative in a member state where it offers them (Article 26(3)). Whether your product meets the definition turns on the specific national law.

EU law, reaching suppliers by contract

How it reaches UK suppliers

NIS2 requires organisations in scope to address supply chain security, including the security of their relationships with their direct suppliers and service providers (Article 21(2)(d)). That duty reaches suppliers as contract clauses, security questionnaires and incident notification terms. A UK supplier outside the directive can still be bound by those terms through its contract.

Guidance, not law

NIS2 and ISO 27001

ISO 27001 is a strong base for NIS2, and it is not the same thing. In June 2025 ENISA published technical implementation guidance for Commission Implementing Regulation (EU) 2024/2690, which sets out NIS2's technical requirements for digital infrastructure, ICT service management and digital provider organisations. It maps each requirement to standards including ISO/IEC 27001:2022, and ENISA states that the mapping should not be read as a measure of equivalence.

What ISO 27001 does not cover on its own

Management body responsibility

The management body must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements (Article 20).

Registration

Named digital provider types, including cloud computing and managed service providers, must submit registration information to the competent authority (Article 27).

Notification deadlines

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of that notification (Article 23(4)).

Read about ISO 27001
UK law in force, and a Bill before Parliament

The UK position

NIS2 is not UK law. In the UK, the Network and Information Systems Regulations 2018 still apply. The government's Cyber Security and Resilience Bill will update them, and the government's policy statement of 1 April 2025 says the Bill will align, where appropriate, with the approach taken in NIS2. As at 23 September 2026 the Bill is at report stage in the House of Lords and is not yet law.

Find out whether it applies to you

A free diagnostic establishes whether NIS2 applies to you directly, reaches you through a customer, or does not reach you at all. If it applies, the next step is a scope and gap assessment against your ISO 27001 management system.

Book the diagnostic

Frequently asked

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.