Glossary · Related frameworks

NIS Regulations 2018

Definition

The Network and Information Systems Regulations 2018 (SI 2018/506) are the UK law that imposes cyber security and incident reporting duties on operators of essential services and relevant digital service providers. The Cyber Security and Resilience Bill amends these Regulations rather than replacing them, widening their scope and strengthening their enforcement.

What do the NIS Regulations 2018 require?

The Regulations implemented the EU NIS Directive (2016/1148) in UK law and stayed on the statute book after Brexit. They apply to two groups: operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers such as cloud computing services, online marketplaces and online search engines.

Each regulated organisation must take appropriate and proportionate measures to manage risks to its network and information systems, and must notify significant incidents. Enforcement sits with sector regulators, the designated competent authorities, and with the Information Commission for digital services.

What does the Cyber Security and Resilience Bill change?

The Bill widens the definition of "incident" to cover events capable of having an adverse effect, which is the basis of near-miss reporting. It also rewrites regulation 11 so that operators give an initial notification and a full incident report. Thresholds are mostly untouched: the Bill changes only the data centre and load control entries in Schedule 2.

Telecoms stays outside scope. Public electronic communications networks and services are excluded from essential service, digital service and managed service status. Most new duties will only bite once commencement regulations and secondary legislation are made, which is expected towards 2028.

NIS Regulations 2018 compared with the Regulations as amended by the Bill

AreaNIS Regulations 2018 todayAs amended by the Bill
Who is regulatedOperators of essential services and relevant digital service providersAdds data centres, managed service providers, large load controllers and designated critical suppliers
Incident definitionEvents with an actual adverse effectAlso events capable of having an adverse effect
Reporting deadlineWithout undue delay, no later than 72 hours24-hour initial notification and 72-hour full report, both from first awareness
Maximum penaltyTiered, with an overall cap of £17mThe greater of £10m and 2% of turnover, or the greater of £17m and 4%
Customer notificationNo general dutyDuty to tell likely affected customers in defined cases

Common misconceptions

Myth: The Bill repeals the NIS Regulations and starts again.

Reality: It amends them. Existing operators keep their current duties and regulators while the new provisions are phased in.

Myth: The maximum fine is capped at £17m.

Reality: The higher band is the greater of £17m and 4% of turnover, so for large undertakings the percentage sets the ceiling.

Where it appears in the Bill

  • Clause 1Defines "the NIS Regulations" as SI 2018/506.
  • Clause 15Widens the incident definition and substitutes regulation 11 (24-hour and 72-hour reporting).
  • Clause 21Substitutes the penalty provisions in regulation 18 with two bands.
  • Clause 40Report on the operation of the NIS Regulations at least every 5 years.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Are the NIS Regulations 2018 still in force?

Yes. The NIS Regulations 2018 apply today to operators of essential services and relevant digital service providers. The Cyber Security and Resilience Bill amends them rather than repealing them, and most of its changes will only take effect after Royal Assent, expected between late 2026 and spring 2027, and later commencement regulations.

Do I need to do anything under the NIS Regulations before the Bill passes?

If you are already an operator of essential services or a relevant digital service provider, your current duties continue unchanged, including security measures and incident notification. Organisations newly brought into scope, such as managed service providers and data centres, have no NIS duties until the relevant provisions commence, but preparing now shortens the gap.

What are the penalties under the amended NIS Regulations?

The Bill creates two bands in regulation 18. The standard maximum is the greater of £10m and 2% of turnover. The higher maximum, which covers security duty and incident notification failures, is the greater of £17m and 4% of turnover. For large undertakings the percentage figure sets the ceiling.

Related guidance

Official sources

More in Related frameworks

Full glossary