Cyber security law
Does NIS2 apply to UK companies? What it asks, and how it reaches suppliers
NIS2 is European Union law, not UK law. It still lands on UK desks, most often in a customer's contract.
Checked against the published sources on 2 October 2026.
The short answer
Not as UK law. NIS2 can apply directly to a UK company that provides covered services in the EU or has an establishment there. It reaches many more through their customers, because organisations covered by NIS2 must manage the security of their supply chain and pass requirements down in contracts and questionnaires.
- What it is
- An EU Directive on cyber security
- Transposition deadline
- 17 October 2024
- Sectors covered
- Eighteen
- Incident early warning
- Within 24 hours of becoming aware
What it asks of a covered organisation
Article 21 lists ten risk management measures as a minimum, and Article 20 makes the management body approve and oversee them. Members of the management body are required to follow training, and can be held liable for infringements.
Essential entities face fines of at least 10 million euros or 2 per cent of worldwide turnover, whichever is higher. For important entities the figures are 7 million euros or 1.4 per cent.
The reporting clock
Article 23 requires a significant incident to be reported in stages: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the notification. The clock starts when the organisation becomes aware, not when the investigation is finished.
If you are a supplier
A small UK supplier is probably not covered directly. If its customer is, the contract may require specific security measures and prompt notice of incidents, and that obligation is real even though it comes from the contract and not from the Directive.
This page explains what the rule says. It is not legal, regulatory, clinical or financial advice on your own position. Rules change, so read the sources listed beside it, and tell us at hello@wajd.co.uk if something here is out of date.
Learn it properly, free
This guide is the summary. The course teaches it in full, with a video conversation, worked scenarios and a knowledge check after each module. Every module is free to read with no account. A certificate, if you want one once you pass, is £9.
Cyber and AI regulation · 2.5 CPD hours
NIS2 and UK cyber resilience law: what your business has to do
Questions people ask
Does NIS2 apply to UK companies?
Not as UK law. It can apply to a UK company that provides covered services in the EU or has an establishment there, and it reaches many more through their customers' contracts.
Does NIS2 require directors to be trained?
Yes. Article 20 says members of the management bodies of essential and important entities are required to follow training.
How fast must an incident be reported under NIS2?
An early warning within 24 hours of becoming aware, a notification within 72 hours and a final report within one month of the notification.
We are a small supplier. Do we have to comply?
Probably not directly, since NIS2 mainly covers medium and large organisations in listed sectors. Your covered customers may still require measures of you by contract.