# NIS2 and UK cyber resilience law: what your business has to do

*Who NIS2 really catches, what it asks of managers, the 24 hour clock, and the UK Bill that is coming.*

## Production summary

- Modules to record: 3
- Total script: 1369 words, about 9 minutes of finished audio
- Voices: Emma (host) and George (practice educator)
- Level: Directors, owners, managers and team leaders in any sector. No technical background needed

## Accreditation wording that must appear in the description

- **The CPD Certification Service** (planned): Application scheduled.
- **Directive (EU) 2022/2555 (NIS2)** (aligned): Written against the published Directive. Our own summary, which is not legal advice and carries no endorsement from any EU body. National laws implementing the Directive differ in detail.
- **Cyber Security and Resilience (Network and Information Systems) Bill** (aligned): Written against the Bill and the government's published factsheets as at October 2026, when the Bill had not received Royal Assent. Our own summary, with no endorsement from the government implied.

> Do not upgrade any of these words in a description or a thumbnail. Aligned is not accredited, and planned is not approved.


---

## NIS2: who it catches, and what it asks of managers

**Runtime** about 3 minutes. **Words** 490. **Starts at** 00:00 in the full course recording.

### Learning outcomes to state on camera

- Explain why NIS2 is not UK law and how it still reaches UK firms
- Say which sectors and sizes of organisation are covered
- Distinguish essential from important entities and the fines for each
- State what Article 20 asks of management bodies
- List the ten measures in Article 21

### Script


`[CUE 1]` *A map with the EU shaded and the UK outside it, with two arrows reaching a UK firm: a service sold into the EU and a customer's contract*

**EMMA**  [00:00]
George, I keep being told NIS2 has landed and we all have to comply. We're a UK business. Do we?

**GEORGE**  [00:08]
Not as UK law, and that's the first thing to get straight before anyone spends money. NIS2 is an EU Directive. The UK left before it was made. So it doesn't apply here the way it applies in Germany.

**EMMA**  [00:23]
So I can ignore it.

**GEORGE**  [00:25]
No, and here's why. It reaches UK firms in two ways. Directly, if you provide a covered service inside the EU or have an establishment there. And indirectly, which is far more common, because a covered customer has to manage the security of its supply chain. They write that into your contract.


`[CUE 2]` *Eighteen sectors in two groups with a size threshold marker at fifty staff or ten million euros*

**EMMA**  [00:46]
That'll be the questionnaire we got from our Dutch customer.

**GEORGE**  [00:50]
Exactly that. So two questions first. Do we provide a covered service in the EU? And do any customers have to comply and pass it down?

**EMMA**  [01:00]
Who does it cover over there?

**GEORGE**  [01:03]
Eighteen sectors. The high criticality ones include energy, transport, banking, health, water, digital infrastructure and managed IT services. The others include post and couriers, waste, chemicals, food, and manufacturing of things like medical devices, electronics, machinery and vehicles.


`[CUE 3]` *Essential and important entities side by side with their maximum fines*

**EMMA**  [01:18]
Every business in those sectors?

**GEORGE**  [01:20]
Generally medium and large ones. Broadly, fifty or more staff or more than ten million euros of turnover. Some kinds of provider are covered whatever their size. And because it's a Directive, each country's version differs in detail.

**EMMA**  [01:35]
I've heard essential and important. What's the difference?

**GEORGE**  [01:38]
Two classes. Similar duties, closer supervision for essential. And different maximum fines. At least ten million euros or two per cent of worldwide turnover for essential entities. At least seven million or 1.4 per cent for important ones. Whichever is higher.


`[CUE 4]` *A boardroom table with three labels: approve, oversee, answer for it, and a training record*

**EMMA**  [01:55]
Those are data protection sized numbers.

**GEORGE**  [01:57]
They are, and that's deliberate. But the part that really changes things is Article 20. Management bodies must approve the security measures, oversee them, and can be held liable for infringements.

**EMMA**  [02:10]
So the board can't just say that's an IT matter.

**GEORGE**  [02:14]
Not any more. And the same Article says members of management bodies are required to follow training. Staff should be offered similar training regularly.


`[CUE 5]` *Ten numbered measures as a checklist, each with policy, owner, in place and last checked boxes*

**EMMA**  [02:23]
Required. For directors.

**GEORGE**  [02:24]
Required. So keep a record of who was trained, in what, and when. A training duty you can't evidence is treated as one you didn't meet.

**EMMA**  [02:35]
And what do they actually have to have in place?

**GEORGE**  [02:39]
Article 21 lists ten measures as a minimum. Risk and security policies. Incident handling. Business continuity with backups. Supply chain security. Secure development and vulnerability handling. Checking the measures work. Cyber hygiene and training. Cryptography. Access control and asset management. And multi-factor authentication with secure communications.

**EMMA**  [02:57]
That's a lot to hold.

**GEORGE**  [02:59]
So don't hold it, check it. For each of the ten ask four things. Is there a written policy? A named owner? Something actually in place? And a date it was last checked? Four yeses per line is a defensible position.

### Sources for the on screen credit

- Directive (EU) 2022/2555 (NIS2), Articles 20, 21 and 34, EUR-Lex
- NIS2 Directive: securing network and information systems, European Commission
- Cyber Assessment Framework, National Cyber Security Centre (UK)

---

## Incidents, suppliers and the 24 hour clock

**Runtime** about 3 minutes. **Words** 448. **Starts at** 03:16 in the full course recording.

### Learning outcomes to state on camera

- State the three stages of NIS2 incident reporting and their deadlines
- Explain what makes an incident significant
- Describe what a first hour looks like when something goes wrong
- Explain why NIS2 customers send security questionnaires to suppliers
- Answer a supplier questionnaire honestly and usefully

### Script


`[CUE 1]` *A timeline with three markers at 24 hours, 72 hours and one month, starting from the moment of becoming aware*

**EMMA**  [03:16]
George, the bit that worries people is the 24 hours. Report an incident in a day? We'd still be working out what happened.

**GEORGE**  [03:25]
And nobody expects you to have worked it out. NIS2 Article 23 has three stages. An early warning within 24 hours of becoming aware. A fuller incident notification within 72 hours. And a final report within one month.

**EMMA**  [03:40]
What goes in the early warning?

**GEORGE**  [03:42]
Very little. That it happened, whether it looks malicious, and whether it could affect other countries. It's deliberately light. They don't want the full story in a day. They want to be told.


`[CUE 2]` *An incident that was contained, with the words capable of causing highlighted*

**EMMA**  [03:56]
And when does the clock start?

**GEORGE**  [03:58]
When the organisation becomes aware. Not when the investigation finishes. That's the point people miss.

**EMMA**  [04:04]
Does every little thing count?

**GEORGE**  [04:06]
No, it has to be significant. Severe operational disruption or financial loss, or considerable damage to other people. But the wording is caused or capable of causing. Something you contained can still be reportable.


`[CUE 3]` *A first hour checklist: note the time, contain, tell the decision owner, tell customers, keep a log*

**EMMA**  [04:20]
So if in doubt?

**GEORGE**  [04:21]
Make the early warning and correct it later. That's the safer course.

**EMMA**  [04:26]
Realistically, who notices first? It's not going to be me.

**GEORGE**  [04:30]
No, and it's almost never the security lead. It's whoever is at the screen. So they need one thing. Who to tell, at any hour, without fear of blame.


`[CUE 4]` *A covered customer passing requirements down a chain of suppliers*

**EMMA**  [04:42]
And then?

**GEORGE**  [04:42]
In order. Write down the time you became aware, because every deadline runs from it. Contain what you can without destroying evidence. Tell the person who owns the decision to report. Tell affected customers. And keep a log of what was known and decided, and when.

**EMMA**  [05:01]
Why customers so early?

**GEORGE**  [05:02]
Because your contract probably requires it, and their own clock may have started. Which brings us to the questionnaire you got.


`[CUE 5]` *A questionnaire with honest answers: a no with a date, and three boxes customers check first*

**EMMA**  [05:11]
Yes. Why are they asking me forty questions?

**GEORGE**  [05:14]
Supply chain security is one of the ten measures. A covered organisation has to consider each direct supplier's vulnerabilities and practices. So they ask, and they write it into the contract. Security measures, a right to audit, and a duty to tell them about incidents fast.

**EMMA**  [05:32]
I'm tempted to tick yes to everything.

**GEORGE**  [05:35]
Don't. A no with a date beside it is more useful to them than a yes that turns out to be untrue. And an untrue answer in a contract is a liability of a different kind.

**EMMA**  [05:50]
What do they check first?

**GEORGE**  [05:52]
Three things. Multi-factor authentication. Backups you've actually tested. And staff training. Only tick those if you can show them.

**EMMA**  [05:59]
And one practical test?

**GEORGE**  [06:01]
Ask a member of staff at random. If your screen showed a ransom note at two in the morning on a Sunday, who would you ring? If they can't answer, the deadline is already lost.

### Sources for the on screen credit

- Directive (EU) 2022/2555 (NIS2), Articles 21 and 23, EUR-Lex
- NIS2 Directive: securing network and information systems, European Commission
- Incident management guidance, National Cyber Security Centre (UK)

---

## The UK Cyber Security and Resilience Bill, and what to do now

**Runtime** about 3 minutes. **Words** 431. **Starts at** 06:15 in the full course recording.

### Learning outcomes to state on camera

- State the Bill's status and why it is not yet law
- Say who the Bill would bring into scope
- State the Bill's incident reporting timeline and who is told
- Explain what will be decided later in secondary legislation
- Set out five steps worth taking now under either regime

### Script


`[CUE 1]` *A parliamentary timeline from November 2025 to report stage on 26 October 2026, with Royal Assent still ahead*

**EMMA**  [06:15]
George, so NIS2 is the EU's. What has the UK actually done?

**GEORGE**  [06:20]
It has a Bill, and it isn't law yet. That's the headline. The UK already has the Network and Information Systems Regulations from 2018. The Cyber Security and Resilience Bill amends and widens them.

**EMMA**  [06:33]
How far has it got?

**GEORGE**  [06:35]
Introduced in November 2025. Through the Commons in June 2026. Lords second reading in July, committee stage finished in September, report stage scheduled for 26 October 2026. Royal Assent has been expected late in 2026 or in spring 2027.


`[CUE 2]` *Four groups joining the regime: managed service providers, data centres, load controllers, designated critical suppliers*

**EMMA**  [06:51]
So today, what applies?

**GEORGE**  [06:52]
The 2018 Regulations as they stand. Until the Bill passes and the regulations under it are made. Check the current position before you rely on anything I'm about to say.

**EMMA**  [07:04]
Fair. Who would it bring in?

**GEORGE**  [07:07]
Four groups, according to the government's factsheets. Medium and large managed service providers, the firms that run IT for other organisations. Data centres above set thresholds. Large load controllers, which manage power for things like vehicle chargers. And designated critical suppliers.


`[CUE 3]` *A supplier outside regulation failing and a hospital's appointments being postponed*

**EMMA**  [07:23]
Designated by whom?

**GEORGE**  [07:24]
By regulators. If a supplier's failure would disrupt an essential service, they could be designated and brought under duties.

**EMMA**  [07:32]
Why that power?

**GEORGE**  [07:33]
June 2024. An attack on a pathology supplier to the NHS led to more than eleven thousand postponed appointments and procedures. The supplier wasn't itself regulated. That's the gap.


`[CUE 4]` *A 24 hour and 72 hour clock with the regulator and the National Cyber Security Centre both receiving the report*

**EMMA**  [07:45]
And reporting? Is it the same 24 hours as Europe?

**GEORGE**  [07:49]
Similar shape. An initial notification within 24 hours and a full report within 72, to the regulator, with the National Cyber Security Centre told at the same time. More incidents become reportable, including ones capable of significant impact, like ransomware.

**EMMA**  [08:05]
What about customers?

**GEORGE**  [08:06]
Managed service providers, digital service providers and data centres would have to tell customers likely to be affected.


`[CUE 5]` *Five numbered steps on a single card headed do this now*

**EMMA**  [08:13]
And the fines?

**GEORGE**  [08:14]
Maximum penalties go up, to align with things like data protection law. Regulators can recover their costs. And the Secretary of State can set priorities and give directions for national security. I won't quote figures, because a lot is left to secondary legislation, including what counts as significant.

**EMMA**  [08:34]
So what do I do while Parliament finishes?

**GEORGE**  [08:37]
Five things, and none needs the Bill to pass. Work out where you stand. Brief the people who run the business and record it. Check your critical suppliers and your incident clauses. Write down who decides and who reports, and test it out of hours.

**EMMA**  [08:55]
And the fifth?

**GEORGE**  [08:56]
Fix the three basics. Multi-factor authentication, backups you've tested, and staff training. They've been the advice for years, and they're what every one of these regimes checks first.

### Sources for the on screen credit

- Cyber Security and Resilience (Network and Information Systems) Bill factsheets: summary of the Bill, GOV.UK
- Cyber Security and Resilience (Network and Information Systems) Bill factsheets: incident reporting, GOV.UK
- Cyber Security and Resilience (Network and Information Systems) Bill: stages, UK Parliament
- The Network and Information Systems Regulations 2018, legislation.gov.uk

---

*Copyright WAJD Group. Built by WAJD AI.*