NIS2 in 2026: What UK Businesses Need to Know
The EU NIS2 Directive has reshaped cybersecurity obligations for organisations operating in or supplying to the EU. Here is a practical guide for UK companies.
What is NIS2 and does it apply to UK businesses?
The Network and Information Security Directive 2 (NIS2) entered into force across EU member states in October 2024. While the UK left the EU in 2020, UK businesses are affected in three key ways:
- UK subsidiaries or branches of EU entities are directly subject to NIS2.
- UK businesses supplying EU-regulated entities face NIS2 obligations through supply chain requirements (Article 21(2)(d)).
- UK government alignment: The UK's updated NIS regulations are expected to substantially mirror NIS2 obligations for UK-registered entities.
Key obligations under NIS2 Article 21
NIS2 Article 21 requires organisations to implement "appropriate and proportionate technical and organisational measures" to manage cybersecurity risks. In practice, this means:
- Risk analysis and information system security policies
- Incident handling — including detection, response, and reporting
- Business continuity — including backup management and disaster recovery
- Supply chain security — assessing and managing third-party ICT risks
- Access control and authentication — MFA, privileged access management
- Vulnerability management — disclosure policies and patching programmes
- Cybersecurity training — awareness training for all staff, targeted training for technical roles
Incident reporting timelines
NIS2 introduces strict reporting obligations for "significant incidents":
- T+24 hours: Early warning to the relevant CSIRT (NCSC in the UK)
- T+72 hours: Full incident notification with impact assessment
- T+1 month: Final report with root cause, remediation measures, and cross-border impact
This is significantly shorter than the previous NIS1 regime and more closely aligned with UK GDPR Article 33's 72-hour personal data breach notification requirement.
What you should do now
If NIS2 applies to your organisation — or you expect it will apply through the UK equivalent — the priority actions are:
- Determine whether you are an "essential" or "important" entity (the distinction affects supervisory intensity but not the core obligations)
- Conduct a gap analysis against Article 21 requirements
- Establish or update your incident response procedures with NIS2-aligned reporting timelines
- Review your supply chain — identify critical ICT third parties and assess their security posture
- Ensure board-level accountability — NIS2 makes senior management personally liable for significant non-compliance
How SummitBridge can help
We offer a structured NIS2 Gap Analysis starting at £2,000, covering Article 21 control assessment, risk register creation, incident response plan, and a prioritised remediation roadmap. Our NIS2 compliance package includes board-level reporting and 2 follow-up review calls.
Need help with this?
Our team can help you assess where you stand and build a practical remediation plan. Free 30-minute consultation — no obligation.
Book a Free Consultation