A procurement questionnaire arrives from a customer in Dublin. It asks how you comply with a directive the UK never adopted, and it wants an answer before the contract renews. Nobody in the building has heard of it.
The NIS2 UK position is this. NIS2 is EU law, so it does not apply to UK businesses directly. It still reaches a great many of them, in two ways: through EU customers passing obligations down their supply chain, and directly if you sell certain digital or managed services into the EU.
NIS2 is Directive (EU) 2022/2555. It does not bind UK companies as UK law. But a UK supplier to an EU essential or important entity inherits its requirements by contract, and a UK managed service provider selling into the EU falls under a member state’s jurisdiction outright.
Does NIS2 Apply to UK Businesses?
Not as domestic law. The UK left the EU before NIS2 was adopted and has not transposed it, so no UK regulator enforces it against a UK company operating only in the UK. That is where most articles stop, and it is where they mislead. The exposure is real, it just arrives by a different route.
That is the NIS2 UK question in one line: not directly, but not safely ignored either. Two routes, to be precise. One contractual, one direct, and Transputec sees both arrive in client questionnaires.
Why Does the Distinction Matter So Much?
Because the two routes need completely different responses. A contractual obligation is negotiated, evidenced and priced into the deal. A direct legal obligation involves a regulator, a representative inside the EU, and fines calculated on worldwide turnover.
Getting this wrong in either direction is expensive. Assume it does not apply and you fail an EU tender. Assume you are directly regulated when you are not and you spend money answering to nobody. Establishing your NIS2 UK position early costs far less than either mistake.
Had a NIS2 Question From an EU Customer?
Send it to the Transputec team and we will tell you which route applies to you, contractual or direct, and what evidence you actually need. No obligation.
Get a Strategic ConsultationWhat Is NIS2 and What Does It Replace?
The NIS2 Directive is the EU’s network and information security directive, formally Directive (EU) 2022/2555. It came into force in January 2023, member states had until 17 October 2024 to write it into national law, and it repealed the original NIS Directive from 18 October 2024. It covers 18 sectors, up from a much narrower original list.
The difference between NIS and NIS2 is mostly scope and teeth.
| NIS (2016/1148) | NIS2 (2022/2555) | |
|---|---|---|
| Sectors | Narrow, operators of essential services | 18 sectors, split into essential and important entities |
| Who decides scope | Member states identified individual operators | Size-based rules catch entities automatically |
| Supply chain | Barely addressed | Explicit duty to manage supplier risk |
| Reporting | Set nationally, inconsistent | 24 hours, 72 hours, one month, harmonised |
| Fines | Set nationally | Up to €10m or 2% of worldwide turnover |
| Accountability | Organisational | Management bodies carry responsibility |
That last row is why boards started paying attention.
Which UK Businesses Fall Directly Under NIS2?
A narrow but important group. Article 26 says an entity not established in the Union that offers services within the Union “shall designate a representative in the Union”, and it names the categories caught: DNS providers, TLD registries, cloud computing providers, data centre providers, content delivery networks, online marketplaces and search engines, and, named explicitly, managed service providers and managed security service providers.
That is the one case where NIS2 UK exposure is direct rather than inherited. If a UK MSP sells managed IT or managed security into the EU, it does not merely inherit obligations from a customer. It falls under the jurisdiction of the member state where its representative is established. Where no representative is designated, the directive allows any member state in which the entity provides services to take legal action.
Transputec sits in exactly that category, which is why we track this rather than treating it as somebody else’s regulation. Most UK businesses do not, and the honest answer for a manufacturer or a law firm selling into the EU is that this route does not catch you.
What Are NIS2 Requirements for Suppliers?
This is the route that catches almost everyone else. Article 21(2)(d) requires in-scope entities to manage “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”.
An EU essential or important entity cannot satisfy that by trusting you. It has to evidence it. So the requirement arrives as a security questionnaire, a contract clause, an audit right, or a demand for certification. You are not being regulated. You are being assessed by somebody who is, and who is personally accountable for the answer. For most UK suppliers, NIS2 compliance is therefore something you evidence rather than something you certify, and NIS2 UK readiness means having those answers ready before you are asked.
In practice that means the same evidence base as everything else in this space: access control, patching cadence, incident response, and monitoring you can produce reports from. Our managed SOC services and cyber security services exist to make that evidence real rather than asserted, and the same questions turn up in cyber insurance requirements.
What Are the NIS2 Reporting Deadlines and Fines?
Three deadlines, and they are tight. An in-scope entity must submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of that notification.
The penalties are set as floors that member states must at least provide for:
- Essential entities: at least €10,000,000 or a maximum of at least 2% of total worldwide annual turnover, whichever is higher
- Important entities: at least €7,000,000 or a maximum of at least 1.4% of total worldwide annual turnover, whichever is higher
Worldwide turnover, not EU turnover. For a UK group with a small European arm, that distinction is the whole risk.
What Is the UK Doing Instead of NIS2?
Building its own. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025, had its second reading on 6 January 2026, went through committee in February 2026, and is now before the House of Lords. It reforms the UK’s existing NIS Regulations 2018 rather than copying NIS2.
The detail that matters most to anyone reading this: the Bill brings medium and large managed service providers into scope, defined as organisations providing IT services including IT helpdesks and cyber security services, on the reasoning that they have “unprecedented access to their customers’ systems”. The Information Commissioner is named as the regulator for MSPs. Reporting mirrors the EU pattern: initial notification within 24 hours, a fuller report within 72 hours. MSPs and data centres will also have to tell their customers.
There is, in other words, a NIS2 UK equivalent coming, just not NIS2 itself. The direction of travel is the same on both sides of the Channel, and providers like Transputec are squarely inside it. Government has said it intends to consult on implementation during 2026, with the substance arriving through secondary legislation.
Your NIS2 UK Readiness Checklist
Work through this in order. It is the fastest route to a defensible NIS2 UK position.
- Work out which route applies: do you sell in-scope services into the EU, or do you supply an EU entity that is in scope?
- If you sell managed IT, managed security, cloud or data centre services into the EU, take advice on whether you need a representative in the Union.
- Ask your EU customers directly whether they classify as essential or important. Their answer sets your obligations.
- Map your incident response against 24 hours, 72 hours and one month, and test whether you could actually meet the first one.
- Collect the evidence base now: access control, patch cadence, monitoring reports, restore tests.
- Read the supplier clauses in your EU contracts before the questionnaire arrives, not after.
- Track the UK Bill, because if you are a medium or large MSP it will regulate you domestically.
- Do not wait for the UK consultation to start the estate work. It is the same work either way.
Conclusion
The short answer on NIS2 UK applicability is that this is EU law and it does not bind a purely domestic UK business. The useful answer is that the UK is not insulated, because supply chain duties travel down contracts and the directive names managed service providers directly. Meanwhile the UK’s own Bill is heading for the same place from a different direction.
Transputec is in scope of the UK Bill as a managed service provider, and named in the EU directive’s category list, so we are preparing for this rather than commenting on it from the outside. We are not a law firm and this is not legal advice: for a formal scope determination, take proper counsel. What we do is the work underneath the questionnaire, through our managed IT services and cyber security services.
If an EU customer has sent you something you cannot answer, send it to us and we will tell you what it is really asking for.
FAQs
Does NIS2 Apply to UK Companies?
Not as domestic law, because the UK has not transposed it. UK companies are still affected two ways: as suppliers to EU entities that must manage supply chain security, and directly if they provide cloud, data centre, managed service or managed security services into the EU, where Article 26 requires a representative in the Union. The practical NIS2 UK answer is to work out which of those two routes catches you.
What Is the Difference Between NIS and NIS2?
NIS2 widens scope to 18 sectors with automatic size-based criteria, adds an explicit supply chain security duty, harmonises reporting at 24 hours, 72 hours and one month, raises fines to as much as 2% of worldwide turnover, and makes management bodies accountable. The original directive left most of this to member states.
What Are NIS2 Requirements for Suppliers?
Suppliers are not directly regulated, but in-scope EU customers must manage security in their relationships with direct suppliers and service providers. That reaches suppliers as questionnaires, contract clauses, audit rights and evidence requests covering access control, patching, incident response and monitoring.
Is There a NIS2 UK Equivalent, or Will the UK Adopt NIS2?
No, the UK will not adopt it. The UK is legislating separately through the Cyber Security and Resilience (Network and Information Systems) Bill, which updates the NIS Regulations 2018 and is currently before the House of Lords. It brings medium and large managed service providers into scope, Transputec among them, with the Information Commissioner as regulator.
What Are the NIS2 Fines?
For essential entities, member states must provide for fines of at least €10 million or up to at least 2% of total worldwide annual turnover, whichever is higher. For important entities the floors are €7 million or 1.4%. The turnover measure is worldwide, not limited to EU revenue.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



