WAJD Learning

Cyber and AI regulation · Directors, owners, managers and team leaders in any sector. No technical background needed

NIS2 and UK cyber resilience law: what your business has to do

Who NIS2 really catches, what it asks of managers, the 24 hour clock, and the UK Bill that is coming.

  • 3modules
  • 2.5CPD hours
  • 150guided minutes
  • Freeto study

Start the course, free Create a free account to save progress

About this course

NIS2 is the European Union's cyber security law for essential and important services. It is not UK law. It still matters to UK businesses in two ways: directly, if you provide covered services in the EU, and indirectly, because the organisations it covers must manage the security of their suppliers, and they pass that on in contracts and questionnaires.

The UK is legislating too. The Cyber Security and Resilience (Network and Information Systems) Bill will widen the UK's existing rules to managed service providers, data centres and designated critical suppliers, and tighten incident reporting to 24 and 72 hours. In October 2026 it is still before Parliament and is not yet law.

This course tells a manager what each regime asks, in plain language and from the published text, what is in force and what is not, and what is worth doing now whichever side of the line you turn out to be on. NIS2 requires management bodies to be trained; this is knowledge that supports that, not legal advice on your own position.

What you will be able to do

  • Explain why NIS2 is not UK law and the two ways it still reaches a UK business
  • Say which sectors and sizes of organisation NIS2 covers, and the two classes of entity
  • State what Article 20 asks of management bodies, including training and liability
  • List the ten risk management measures in Article 21
  • State the three stage incident reporting timeline in Article 23
  • Answer a customer's NIS2 supplier questionnaire honestly and usefully
  • Describe what the UK Cyber Security and Resilience Bill would change and its status
  • Set out the steps worth taking now under either regime

Modules

  1. 1 NIS2: who it catches, and what it asks of managers 50 min study · 3 min script · 5 question knowledge check
  2. 2 Incidents, suppliers and the 24 hour clock 50 min study · 3 min script · 5 question knowledge check
  3. 3 The UK Cyber Security and Resilience Bill, and what to do now 50 min study · 3 min script · 5 question knowledge check

Assessment and certificate

Knowledge check after each module and a final assessment at 80 per cent, with unlimited attempts.

A digital certificate, issued the moment you have passed and paid, showing 2.5 CPD hours with a verification code. It evidences knowledge of NIS2 and the UK Bill as published. It is not a regulated qualification, it is not legal advice, and it does not certify that any organisation complies with either regime.

Questions

Does NIS2 apply to UK companies?

Not as UK law. NIS2 is an EU Directive and the UK is outside it. It can apply to a UK company that provides covered services in the EU or has an establishment there, and it reaches many more through their customers, because organisations covered by NIS2 must manage supply chain security and pass requirements on to suppliers.

Is the UK Cyber Security and Resilience Bill law yet?

Not at the time of writing in October 2026. It was introduced in November 2025, passed the House of Commons in June 2026 and is in the House of Lords, with report stage scheduled for 26 October 2026. Royal Assent has been expected in late 2026 or spring 2027, and much of the detail will follow in secondary legislation.

Does NIS2 really require directors to be trained?

Yes. Article 20 says members of the management bodies of essential and important entities are required to follow training, and that entities should be encouraged to offer similar training to employees regularly. It also says management bodies approve the risk management measures, oversee them, and can be held liable for infringements.

We are a small supplier. Do we have to comply with NIS2?

Probably not directly, since NIS2 mainly covers medium and large organisations in listed sectors. But if your customer is covered, their contract may require specific security measures of you, and that obligation is real even though it comes from the contract and not from the Directive.