Foundry4

Cybersecurity 7 min read

NIS2 reaches British companies that never opted in

NIS2 is not UK law and never will be. Three separate routes still pull British organisations into it, and only one of them involves a regulator writing to you.

NIS2 is a European directive. It is not part of the law of the United Kingdom, no British regulator enforces it, and no Act of Parliament will implement it. Every sentence in that paragraph is true, and together they are why British compliance functions keep getting this wrong.

A directive does not bind companies directly even inside the Union. It binds member states to legislate, and the obligations that eventually land on a business are the national statute, not the directive. Article 41 of the directive required member states to adopt and publish the necessary measures by 17 October 2024 and to apply them from 18 October 2024. Where a member state was late, the operative law for an organisation in that country was whatever preceded it. This matters for a UK reader in a specific way: if you are trying to work out what a customer or subsidiary in Ireland, Germany or the Netherlands has to do, the answer is in that country’s implementing legislation and not in the directive text, and the two are not always the same shape.

We were not able to reach the Commission’s transposition tracker from this desk, so this piece does not state how many member states have completed the process or which are subject to infringement proceedings. Anyone who needs that answer should take it from the Commission’s own register rather than from a summary, including this one.

Three routes in, and only one of them is obvious

Route one: you are established in a member state

Article 2(1) applies the directive to entities of a type listed in Annexes I or II which qualify as medium-sized enterprises under the EU’s standard size Recommendation, or exceed those ceilings, and which provide their services or carry out their activities within the Union. Article 26(1) then says such entities fall under the jurisdiction of the member state in which they are established.

A UK group with a German operating subsidiary in a listed sector is not a UK problem with a European footnote. That subsidiary is a German regulated entity, supervised by a German authority, under German law. The group’s UK head office is where the risk decisions are usually taken and it has no standing in that regime at all.

Route two: you provide certain digital services into the Union without being there

This is the route that surprises people, and it is narrow but real. Article 26(1)(b) lists a specific set of provider types whose jurisdiction follows their main establishment in the Union rather than any place of business: DNS service providers, top-level domain registries, domain name registration services, cloud computing providers, data centre service providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms.

Article 26(3) then deals with such an entity that is not established in the Union but offers services within it. It must designate a representative in the Union, established in one of the member states where the services are offered, and it is then treated as falling under that member state’s jurisdiction. If it does not designate one, the sanction is not that it escapes: any member state in which it provides services may take legal action against it for infringement.

So a British managed service provider, managed security service provider, cloud provider or data centre operator selling into the EU is inside the regime by operation of the directive itself, whatever its compliance function has been told about Brexit. A British manufacturer, bank, hospital or logistics firm with no EU establishment and no listing in that digital set is not. That distinction is the single most useful thing on this page and it is routinely blurred by advisers who benefit from the blur.

Route three: your customer’s obligations become your contract

This is how NIS2 reaches most British organisations, and it never involves a regulator at all.

Article 21(2)(d) requires essential and important entities to take measures covering supply chain security, including the security aspects of the relationship between the entity and its direct suppliers or service providers. Article 21(3) goes further: when deciding what those measures should be, entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of the products and cyber security practices of those suppliers, including their secure development procedures.

A European customer discharging that duty does it the only way it can, through procurement. The obligation arrives at a British supplier as a questionnaire, a set of contractual warranties, an audit right and a notification clause. It is not enforceable against you by anybody in Brussels. It is enforceable against you by your customer, which in commercial terms is worse, because a contractual remedy does not require a regulator to prioritise your case.

What compliance actually consists of

For anyone genuinely in scope through route one or two, four things drive the work.

Governance is personal. Article 20 requires member states to ensure that management bodies approve the risk-management measures, oversee their implementation, and can be held liable for the entity’s infringements. It also requires members of management bodies to undergo training. That is a materially different proposition from a regime enforced only against the corporate entity, and it changes who has to read the papers.

The measures list is prescriptive but unsurprising. Article 21(2) sets a floor of ten items: risk analysis and information system security policies, incident handling, business continuity including backup management and crisis management, supply chain security, security in acquisition, development and maintenance including vulnerability handling and disclosure, policies to assess whether the measures work, basic cyber hygiene and training, cryptography policy, human resources security and access control and asset management, and the use of multi-factor or continuous authentication and secured communications where appropriate. An organisation already assessed against the NCSC’s Cyber Assessment Framework will recognise almost all of it.

Reporting is fast and staged. An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours updating that warning with an initial severity and impact assessment and any indicators of compromise, and a final report within one month. The 24-hour step is deliberately thin, and the directive’s recitals are explicit that reporting must not divert resources from actually handling the incident.

And the penalties are set as floors, not ceilings. Article 34 requires member states to provide administrative fines of a maximum of at least €10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher, and at least €7 million or 1.4% for important entities.

What Britain has instead

The Network and Information Systems Regulations 2018 remain in force and remain the only cross-sector cyber security legislation in the UK. Regulation 18 sets three penalty bands: up to £1 million for a contravention the enforcement authority determines is not material, up to £8.5 million for a material contravention, and up to £17 million where the contravention has or could have created a significant risk to or impact on the service provided by an operator of essential services or a relevant digital service provider.

The replacement is the Cyber Security and Resilience Bill, introduced on 12 November 2025, with the government’s supporting documents published the same day and factsheets following on 30 June 2026. The government’s policy statement says the proposals reflect lessons from the European Union’s implementation of NIS2, and, on reporting specifically, that the requirements are intended to be similar to and no more onerous than the equivalent NIS2 obligations. The two-stage structure it describes, notification within 24 hours followed by a report within 72, is the same shape as Article 23.

That convergence is the practical answer for a UK organisation with European exposure. Two regimes designed to a common template, arriving a few years apart, do not justify two control sets. They justify one, built to the stricter of the two thresholds, with two reporting routes wired to the same detection.

There is an awkward asymmetry in the timing, though, and it is worth naming. A British managed service provider selling into the European Union has been within reach of Article 26(3) since the directive applied. The same firm will not be regulated at home until the Cyber Security and Resilience Bill completes its passage and its secondary legislation follows. For a subset of British companies, the first cyber security regulator to take an interest in them will be a European one, in a country where they have no office, reached through a representative they had to appoint. That is not a hypothetical compliance risk. It is a registration obligation: Article 27 required the member states to have entities in those digital categories submit their details, including the address and contact details of any Article 26(3) representative, by 17 January 2025, for a registry maintained by ENISA.

The organisational failure this exposes

Compliance functions are usually organised by jurisdiction, which means somebody owns UK regulation and somebody owns EU regulation and the boundary between them is assumed to be the boundary of the business. Route three does not respect that boundary. It arrives through the sales team, as a clause in a renewal, and it lands on whoever owns the contract rather than on whoever owns cyber compliance.

The tell is simple and any general counsel can check it in an afternoon. Ask how many of your European contracts now carry a supplier security schedule with an incident notification deadline shorter than your own internal escalation time. If nobody knows, that is the answer.

Wider coverage of the incoming British regime sits under cybersecurity. The supplier-borne compromise pattern that drove both statutes is set out in what happens when a vendor is the one that gets breached.

Sources

  1. Directive (EU) 2022/2555 (NIS2), consolidated text on EUR-Lex, CELEX 32022L2555 eur-lex.europa.eu
  2. The Network and Information Systems Regulations 2018, regulation 18 (penalties) legislation.gov.uk
  3. DSIT, Cyber Security and Resilience Bill policy statement, 9 April 2025 gov.uk
  4. DSIT, Cyber Security and Resilience Bill collection gov.uk