NIS2 for UK Companies: You Are Not in the EU, but You May Be in Scope
NIS2 is an EU directive, and the UK is not in the EU, so a surprising number of UK boards have filed it under somebody else's problem. For many companies that is correct. For a significant minority, it is expensively wrong. Here is how the directive actually reaches UK businesses, and what to do about it.
What NIS2 is
NIS2 is the EU's updated network and information security directive. It widens the original NIS rules to many more sectors, including manufacturing, digital providers, food, waste and postal services alongside the classic energy, transport, health, water and digital infrastructure sectors, and it hardens the obligations: risk management measures, incident reporting on tight timescales, supply chain security, and personal accountability for management bodies, backed by substantial fines. Each EU member state transposes it into national law, so the detail varies by country, but the shape is consistent.
Three ways it reaches a UK company
- You operate in the EU. If you provide in-scope services within a member state, through a subsidiary, branch or direct offering, you can be regulated there directly, whatever your headquarters address says. Digital providers offering services into the EU can also be caught and may need an EU representative.
- Your customers are in scope. This is the most common route. NIS2 makes regulated entities responsible for the security of their supply chains, so EU customers are pushing NIS2-shaped requirements into contracts and vendor assessments. You will not receive a letter from a regulator; you will receive a security questionnaire from your biggest client, and the commercial consequence of failing it is the same.
- Your group is in scope. UK subsidiaries of EU parents, and vice versa, frequently inherit group-wide NIS2 programmes and reporting lines.
What the obligations look like in practice
Strip away the directive language and NIS2 asks for things a well-run security programme already does: risk analysis and security policies, incident handling with rapid reporting, business continuity and crisis management, supply chain security, secure development and vulnerability handling, testing of your measures, cryptography and access control, and training for management, who are personally accountable for oversight. If that list sounds familiar, it should: it maps closely onto ISO 27001 with business continuity depth behind it.
The sensible UK response
First, establish scope honestly: an afternoon's structured analysis of your EU footprint, sectors and customer base settles whether NIS2 is a direct obligation, a contractual one, or genuinely not your problem. Second, if it reaches you by either route, resist the temptation to build a bespoke NIS2 programme. Implement or extend an ISO 27001 management system, with incident response and continuity given real weight, and map its controls to the NIS2 measures and to each customer questionnaire once. One system, evidenced many ways, is the difference between compliance as a project and compliance as a permanent tax.
And a word on the home front: the UK is pursuing its own strengthening of cyber legislation for essential services, so the direction of travel is the same on both sides of the Channel. Work done now is not wasted either way.
Cybercontrols helps UK companies scope NIS2 exposure and build the management system that answers it, alongside ISO 27001, DORA and the rest of the alphabet. A free 30-minute scoping call will tell you which side of the line you sit on.
