Glossary · Related frameworks

NIS2 Directive

Definition

The NIS2 Directive (EU) 2022/2555 is the European Union law setting cyber security and incident reporting duties for essential and important entities across 18 sectors. It replaced the original NIS Directive and does not apply in the UK, but it binds UK organisations that provide in-scope services within EU member states.

Does NIS2 apply to UK organisations?

Not in the UK itself. After Brexit the UK kept the NIS Regulations 2018, based on the first NIS Directive, and never adopted NIS2. NIS2 does apply to a UK-headquartered group’s EU subsidiaries, and to UK providers offering in-scope services in the EU.

Some digital providers without an EU establishment, such as cloud and data centre providers, must designate a representative in a member state. This mirrors the UK’s own UK representative rule for non-UK digital service providers.

How does NIS2 compare with the Cyber Security and Resilience Bill?

NIS2 uses a size-cap rule. Medium and large entities in listed sectors are generally in scope, split into essential and important entities. The UK keeps sector thresholds in Schedule 2 and exempts micro and small enterprises from digital and managed service provider status.

Both regimes bring managed service providers into scope and focus on supply chains. The UK adds a power to designate individual critical suppliers, and a separate Part 4 power for national security directions, which NIS2 does not mirror directly.

The Cyber Security and Resilience Bill compared with NIS2

AreaCyber Security and Resilience BillNIS2 Directive
JurisdictionUnited KingdomEU member states, via national law
Scope modelSector thresholds plus named additions (data centres, managed services, load controllers, critical suppliers)18 sectors, size-cap rule, essential and important entities
Incident reporting24-hour initial notification and 72-hour full report, both from first awareness24-hour early warning, 72-hour notification, final report within one month
Maximum finesGreater of £10m and 2%, or greater of £17m and 4% of turnoverAt least €10m or 2% (essential), at least €7m or 1.4% (important), whichever is higher
TelecomsExcludedIn scope

Common misconceptions

Myth: The Cyber Security and Resilience Bill is the UK version of NIS2.

Reality: It is a separate UK reform that amends the 2018 Regulations. It borrows some NIS2 ideas but has its own scope, reporting rules and penalties.

Myth: NIS2 compliance covers the UK too.

Reality: UK duties are set by UK law and enforced by UK regulators. Controls can be shared, but reporting and registration duties must be met separately.

Where it appears in the Bill

  • Clause 1The Bill amends the UK NIS Regulations 2018, not EU law.
  • Clause 15UK incident reporting: 24-hour initial and 72-hour full notification.
  • Clause 21UK penalty bands in new regulation 18.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Do UK companies have to comply with NIS2?

Only for their activities in the EU. A UK company with an EU subsidiary in a covered sector, or a UK provider offering in-scope digital services to EU customers, can be subject to NIS2 through member state law. Purely domestic UK operations fall under the NIS Regulations 2018, as amended by the Cyber Security and Resilience Bill.

Are incident reporting deadlines the same under NIS2 and the UK Bill?

They are similar but not identical. Both require a first report within 24 hours and a fuller report within 72 hours. NIS2 adds a final report within one month. Under the UK Bill both deadlines run from first awareness, and the report goes to the UK regulator and NCSC, not an EU authority.

Which has higher fines, NIS2 or the UK Bill?

The UK higher band, the greater of £17m and 4% of turnover, exceeds the NIS2 minimum maxima of €10m or 2% for essential entities. NIS2 figures are floors, though, and member states can set higher penalties. The UK also has a standard band, the greater of £10m and 2%, for lesser failures.

Related guidance

Official sources

More in Related frameworks

Full glossary