If you sell to customers in the EU, you may be asked how you comply with NIS2, even though the UK never adopted it. This guide explains when it applies to UK businesses and when it doesn’t.
The NIS2 UK position is simple to state. NIS2 is EU law, so it doesn’t apply to UK businesses directly. But it can still affect them in two ways: through EU customers passing obligations down their supply chain, and directly if you sell certain digital or managed services into the EU.
NIS2 is Directive (EU) 2022/2555. It isn’t UK law, so it doesn’t bind UK companies. But a UK supplier to an EU essential or important entity takes on its requirements through contracts, and a UK managed service provider selling into the EU falls under a member state’s jurisdiction.
Does NIS2 Apply to UK Businesses?
Not as UK law. The UK left the EU before NIS2 was adopted and hasn’t adopted it since, so no UK regulator enforces it against a company that only operates in the UK. But UK businesses can still be affected, through a different route.
So the NIS2 UK answer is: not directly, but you shouldn’t ignore it. There are two routes, one through contracts and one direct, and Transputec sees both come up in client questionnaires.
Why Does the Distinction Matter So Much?
Because the two routes need different responses. A contractual obligation is agreed with your customer, backed by evidence and priced into the deal. A direct legal obligation involves a regulator, a representative in the EU, and fines based on worldwide turnover.
Getting it wrong either way costs money. If you assume it doesn’t apply, you could lose an EU tender. If you assume you’re directly regulated when you’re not, you spend money on obligations you don’t have. Working out your NIS2 UK position early is cheaper than either mistake.
Had a NIS2 Question From an EU Customer?
Transputec's managed SOC and cyber security services produce the access control, patching, incident response and monitoring evidence EU customers ask suppliers for. Talk to our team about the security work behind your answers.
Get a Strategic ConsultationWhat Is NIS2 and What Does It Replace?
The NIS2 Directive is the EU’s network and information security directive, formally Directive (EU) 2022/2555. It came into force in January 2023. Member states had until 17 October 2024 to put it into national law, and it replaced the original NIS Directive from 18 October 2024. It covers 18 sectors, far more than the original.
The main differences between NIS and NIS2 are scope and enforcement.
| NIS (2016/1148) | NIS2 (2022/2555) | |
|---|---|---|
| Sectors | Narrow, operators of essential services | 18 sectors, split into essential and important entities |
| Who decides scope | Member states identified individual operators | Size-based rules catch entities automatically |
| Supply chain | Barely addressed | Explicit duty to manage supplier risk |
| Reporting | Set nationally, inconsistent | 24 hours, 72 hours, one month, harmonised |
| Fines | Set nationally | Up to €10m or 2% of worldwide turnover |
| Accountability | Organisational | Management bodies carry responsibility |
The last row matters to boards, because management is now accountable.
Which UK Businesses Fall Directly Under NIS2?
A small group. Article 26 says an entity that isn’t established in the EU but offers services there “shall designate a representative in the Union”. The categories it names are DNS providers, TLD registries, cloud computing providers, data centre providers, content delivery networks, online marketplaces and search engines, and managed service providers and managed security service providers.
This is the one case where NIS2 UK exposure is direct. A UK MSP selling managed IT or managed security into the EU falls under the jurisdiction of the member state where its representative is based. If it doesn’t appoint a representative, the directive lets any member state where it provides services take legal action.
Transputec is in that category, so we follow this closely. Most UK businesses aren’t. For a manufacturer or a law firm selling into the EU, this route doesn’t apply.
What Are NIS2 Requirements for Suppliers?
This is the route that affects most other UK businesses, because it works through your EU customers. Article 21(2)(d) requires in-scope entities to manage “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”.
An EU essential or important entity can’t just trust you. It has to be able to show it manages supplier risk, so the requirement reaches you as a security questionnaire, a contract clause, an audit right or a request for certification. You aren’t being regulated. You’re being assessed by an organisation that is, and whose management is accountable for the answer. For most UK suppliers, NIS2 compliance is about providing evidence rather than getting certified, and NIS2 UK readiness means having that evidence ready before you’re asked.
In practice, that’s the same evidence as for other standards: access control, patching, incident response and monitoring you can report on. Our managed SOC services and cyber security services produce that evidence, and the same questions come up in cyber insurance requirements.
What Are the NIS2 Reporting Deadlines and Fines?
There are three deadlines, and they’re short. An in-scope entity must submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of that notification.
The fines below are minimum levels that member states must provide for:
- Essential entities: at least €10,000,000 or a maximum of at least 2% of total worldwide annual turnover, whichever is higher
- Important entities: at least €7,000,000 or a maximum of at least 1.4% of total worldwide annual turnover, whichever is higher
The fines are based on worldwide turnover, not EU turnover. For a UK group with a small European business, that’s the biggest risk.
What Is the UK Doing Instead of NIS2?
The UK is writing its own law. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025, had its second reading on 6 January 2026, went through committee in February 2026, and is now before the House of Lords. It updates the UK’s existing NIS Regulations 2018 instead of copying NIS2.
For many readers, the most important point is that the Bill brings medium and large managed service providers into scope. These are defined as organisations providing IT services, including IT helpdesks and cyber security services, because they have “unprecedented access to their customers’ systems”. The Information Commissioner will regulate MSPs. Reporting follows the EU pattern: initial notification within 24 hours and a fuller report within 72 hours. MSPs and data centres will also have to tell their customers.
So a NIS2 UK equivalent is coming, even though NIS2 itself isn’t. The UK and EU are moving in the same direction, and providers like Transputec are in scope. The government intends to consult on implementation during 2026, with the detail coming through secondary legislation.
Your NIS2 UK Readiness Checklist
Work through this list in order to work out your NIS2 UK position.
- Work out which route applies: do you sell in-scope services into the EU, or do you supply an EU entity that is in scope?
- If you sell managed IT, managed security, cloud or data centre services into the EU, take advice on whether you need a representative in the EU.
- Ask your EU customers whether they’re classed as essential or important entities. Their answer affects what they’ll ask of you.
- Check your incident response against the 24-hour, 72-hour and one-month deadlines, and test whether you could meet the first.
- Start collecting evidence now: access control, patching, monitoring reports and restore tests.
- Read the supplier clauses in your EU contracts before a questionnaire arrives.
- Follow the UK Bill. If you’re a medium or large MSP, it will regulate you in the UK.
- Don’t wait for the UK consultation to start the security work. You’ll need to do it either way.
Conclusion
On NIS2 UK applicability, the short answer is that NIS2 is EU law and doesn’t bind a UK business that only operates in the UK. But UK businesses aren’t fully protected from it, because supply chain duties are passed on through contracts and the directive names managed service providers directly. The UK’s own Bill is also heading in the same direction.
Transputec is in scope of the UK Bill as a managed service provider, and its category is named in the EU directive, so we’re preparing for this ourselves. We aren’t a law firm and this isn’t legal advice, so for a formal view on scope, speak to a lawyer. We do the security work behind the questionnaire through our managed IT services and cyber security services.
If an EU customer has asked you about NIS2, talk to us about the security work behind your answers.
FAQs
Does NIS2 Apply to UK Companies?
Not as UK law, because the UK hasn’t adopted it. UK companies can still be affected in two ways: as suppliers to EU entities that must manage supply chain security, and directly if they provide cloud, data centre, managed service or managed security services into the EU, where Article 26 requires a representative in the EU. The practical NIS2 UK step is to work out which route applies to you.
What Is the Difference Between NIS and NIS2?
NIS2 covers 18 sectors and uses size-based rules to decide who’s in scope. It adds a clear supply chain security duty, sets the same reporting deadlines everywhere (24 hours, 72 hours and one month), raises the maximum fines to at least 2% of worldwide turnover and makes management accountable. The original directive left most of this to member states.
What Are NIS2 Requirements for Suppliers?
Suppliers aren’t regulated directly, but in-scope EU customers must manage security in their relationships with direct suppliers and service providers. For suppliers, that means questionnaires, contract clauses, audit rights and requests for evidence on access control, patching, incident response and monitoring.
Is There a NIS2 UK Equivalent, or Will the UK Adopt NIS2?
No, the UK won’t adopt it. The UK is passing its own law, the Cyber Security and Resilience (Network and Information Systems) Bill, which updates the NIS Regulations 2018 and is currently before the House of Lords. It brings medium and large managed service providers into scope, including Transputec, with the Information Commissioner as regulator.
What Are the NIS2 Fines?
For essential entities, member states must provide for fines of at least €10 million or up to at least 2% of total worldwide annual turnover, whichever is higher. For important entities, the minimums are €7 million or 1.4%. The turnover figure is worldwide, not just EU revenue.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



