WAJD Learning

Module 1 of 3 · 50 minutes

NIS2: who it catches, and what it asks of managers

By the end of this module you will be able to

  • Explain why NIS2 is not UK law and how it still reaches UK firms
  • Say which sectors and sizes of organisation are covered
  • Distinguish essential from important entities and the fines for each
  • State what Article 20 asks of management bodies
  • List the ten measures in Article 21

Work through it

1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.

Watch: Emma and George talk it through

4 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.

Emma George, I keep being told NIS2 has landed and we all have to comply. We're a UK business. Do we?

George Not as UK law, and that's the first thing to get straight before anyone spends money. NIS2 is an EU Directive. The UK left before it was made. So it doesn't apply here the way it applies in Germany.

Emma So I can ignore it.

George No, and here's why. It reaches UK firms in two ways. Directly, if you provide a covered service inside the EU or have an establishment there. And indirectly, which is far more common, because a covered customer has to manage the security of its supply chain. They write that into your contract.

Emma That'll be the questionnaire we got from our Dutch customer.

George Exactly that. So two questions first. Do we provide a covered service in the EU? And do any customers have to comply and pass it down?

Emma Who does it cover over there?

George Eighteen sectors. The high criticality ones include energy, transport, banking, health, water, digital infrastructure and managed IT services. The others include post and couriers, waste, chemicals, food, and manufacturing of things like medical devices, electronics, machinery and vehicles.

Emma Every business in those sectors?

George Generally medium and large ones. Broadly, fifty or more staff or more than ten million euros of turnover. Some kinds of provider are covered whatever their size. And because it's a Directive, each country's version differs in detail.

Emma I've heard essential and important. What's the difference?

George Two classes. Similar duties, closer supervision for essential. And different maximum fines. At least ten million euros or two per cent of worldwide turnover for essential entities. At least seven million or 1.4 per cent for important ones. Whichever is higher.

Emma Those are data protection sized numbers.

George They are, and that's deliberate. But the part that really changes things is Article 20. Management bodies must approve the security measures, oversee them, and can be held liable for infringements.

Emma So the board can't just say that's an IT matter.

George Not any more. And the same Article says members of management bodies are required to follow training. Staff should be offered similar training regularly.

Emma Required. For directors.

George Required. So keep a record of who was trained, in what, and when. A training duty you can't evidence is treated as one you didn't meet.

Emma And what do they actually have to have in place?

George Article 21 lists ten measures as a minimum. Risk and security policies. Incident handling. Business continuity with backups. Supply chain security. Secure development and vulnerability handling. Checking the measures work. Cyber hygiene and training. Cryptography. Access control and asset management. And multi-factor authentication with secure communications.

Emma That's a lot to hold.

George So don't hold it, check it. For each of the ten ask four things. Is there a written policy? A named owner? Something actually in place? And a date it was last checked? Four yeses per line is a defensible position.

The written material

What NIS2 is, and what it is not

NIS2 is Directive (EU) 2022/2555, the European Union's law on the security of network and information systems. Member states were meant to turn it into national law by 17 October 2024. Most missed that date, the Commission began enforcement action, and by the middle of 2026 a few had still not finished. Because it is a Directive, the detail differs from country to country.

The United Kingdom left the EU before NIS2 was made, so NIS2 is not UK law. A UK business is reached in two ways. Directly, if it provides covered services in the EU or has an establishment there. Indirectly, far more often, because a covered customer must manage the security of its supply chain and writes that into contracts.

Who is covered

NIS2 covers eighteen sectors. The sectors of high criticality include energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, managed ICT services, public administration and space. The other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing of certain products such as medical devices, electronics, machinery and vehicles, digital providers and research.

As a general rule it applies to medium and large organisations in those sectors: broadly, fifty or more staff or more than ten million euros of turnover. Some kinds of provider are covered whatever their size.

Covered organisations are either essential or important. The duties are similar. Supervision is closer for essential entities, and the maximum fines differ: at least ten million euros or two per cent of worldwide annual turnover for essential entities, and at least seven million euros or 1.4 per cent for important ones, whichever is higher.

Article 20: it lands on management

Article 20 is the part that changes the conversation. Management bodies must approve the cyber security risk management measures, oversee their implementation, and can be held liable for infringements. Security can no longer be delegated downwards and forgotten.

The same Article says members of management bodies are required to follow training, and that organisations should be encouraged to offer similar training to employees on a regular basis, so that they can identify risks and assess risk management practices and their effect on the services provided.

Article 21: ten measures

Article 21 requires appropriate and proportionate technical, operational and organisational measures, based on an approach that covers all hazards. It lists ten that must be included at a minimum. Read them as a checklist of things a manager should be able to point to, each with an owner.

  • Policies on risk analysis and information system security
  • Incident handling
  • Business continuity: backups, disaster recovery and crisis management
  • Supply chain security, including suppliers and service providers
  • Security in acquiring, developing and maintaining systems, including handling vulnerabilities
  • Policies and procedures to assess whether the measures are working
  • Basic cyber hygiene practices and cyber security training
  • Policies on cryptography and, where appropriate, encryption
  • Human resources security, access control and asset management
  • Multi-factor authentication, secured communications and emergency communications

Knowledge check

The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.

Create a free account Sign in

The learning itself stays free and open. You are reading all of it right now without an account.