Skip to content
Compliance

The NIS2 Directive: What UK Businesses Need to Know in 2026

NIS2 guidance for UK businesses: determine entity, sector, size and jurisdiction, then separate EU national-law duties from contractual supply-chain requirements and UK legislation.

row of european union flags

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

The NIS2 Directive: What UK Businesses Need to Know in 2026

NIS2 is an EU directive implemented through national law. A UK business is not directly in scope merely because it has EU customers or suppliers. Start with the legal entity, sector, size, service role and jurisdiction, then distinguish direct obligations from contractual supply-chain requirements.

Section 02

Establish which entity and law apply

The European Commission’s NIS2 overview describes 18 sectors and a general medium/large entity rule, with exceptions. The directive distinguishes essential and important entities; sector alone does not determine classification in every case.

For each legal entity, record its establishments, services, size and group relationships. Confirm the applicable member-state implementation and regulator with a legal adviser. Certain service providers can fall under special jurisdiction or representative rules even without an EU establishment. Do not apply a blanket “all EU suppliers” rule.

Section 03

Direct duties versus customer requirements

An in-scope customer may require supplier assurance, security clauses or incident cooperation from a UK supplier. These contractual duties can matter commercially without making the supplier directly regulated under NIS2. Record the actual clause, scope, deadline and evidence required.

The UK has its own NIS Regulations and sector rules. Its Cyber Security and Resilience Bill is a separate legislative proposal, not UK transposition of NIS2. Do not infer generic FCA, PRA, NHS or Ofcom adoption of the directive, or a universal 2026 enforcement date. Verify current UK law and any commencement measures for the entity concerned.

Section 04

NIS2 addresses proportionate risk management, governance, incident handling, continuity, supply-chain security and access controls. Build an evidence register against the applicable national requirements, recording control owners, gaps, approvals and review dates.

Useful implementation choices can include maintained asset inventories, MFA, vulnerability management, logging, endpoint detection, tested backups and supplier monitoring. Real-time inventories, a named IDS/EDR product or an annual testing schedule are not universal requirements solely because they appear in this guide. Select controls and cadence according to risk and the applicable rules.

Section 05

Reporting, penalties and dates

Reporting stages, significant-incident triggers, recipients and sanctions must be checked against the applicable national law and entity classification. An initial warning is not the same as a full incident report, and NIS2 notifications are not interchangeable with GDPR personal-data breach duties. This guide does not establish a universal 24-hour full report, blanket notice to every affected individual or the same penalty ceiling for every entity.

The member-state transposition deadline was 17 October 2024. It does not create a universal 12-month risk-assessment grace period or 24-month compliance extension for businesses. Check national implementation, registration and reporting deadlines rather than relying on an invented UK FCA timetable.

Section 06

Practical preparation checklist

1. Identify the legal entities, services, sectors, size and jurisdictions.

2. Obtain a documented scope decision distinguishing direct legal duties and customer contracts.

3. Assign an accountable owner and map applicable obligations to controls and evidence.

4. Prioritise gaps by service impact and test incident and continuity arrangements.

5. Record reporting triggers, recipients, time limits, approval routes and out-of-hours cover.

6. Review changes in national law, entity scope and customer terms.

Section 07

How Fig Group can support the work

Discuss the required integrations, mappings and evidence with Fig Group before relying on a workflow. Risk registers, assigned actions, incident records and audit evidence can support the process when configured and maintained appropriately. A platform does not determine legal scope or guarantee compliance.

For any notification workflow, establish the jurisdiction, legal trigger, recipient, timing, authorised human approval and audit trail. Do not assume automatic regulatory submission is enabled or appropriate. Reuse evidence across frameworks only where it actually meets each requirement.

Start with the scope decision and the applicable national law. That gives the security team a defensible remediation plan and prevents contractual supplier requirements from being mistaken for direct statutory obligations.

The organisations best positioned to succeed are those that start their assessment and planning now.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group