Skip to main content
Back to Blog
Compliance 6 min read 10 March 2026

NIS2 in 2026: What UK Businesses Need to Know

The EU NIS2 Directive has reshaped cybersecurity obligations for organisations operating in or supplying to the EU. Here is a practical guide for UK companies.

What is NIS2 and does it apply to UK businesses?

The Network and Information Security Directive 2 (NIS2) entered into force across EU member states in October 2024. While the UK left the EU in 2020, UK businesses are affected in three key ways:

  • UK subsidiaries or branches of EU entities are directly subject to NIS2.
  • UK businesses supplying EU-regulated entities face NIS2 obligations through supply chain requirements (Article 21(2)(d)).
  • UK government alignment: The UK's updated NIS regulations are expected to substantially mirror NIS2 obligations for UK-registered entities.

Key obligations under NIS2 Article 21

NIS2 Article 21 requires organisations to implement "appropriate and proportionate technical and organisational measures" to manage cybersecurity risks. In practice, this means:

  • Risk analysis and information system security policies
  • Incident handling — including detection, response, and reporting
  • Business continuity — including backup management and disaster recovery
  • Supply chain security — assessing and managing third-party ICT risks
  • Access control and authentication — MFA, privileged access management
  • Vulnerability management — disclosure policies and patching programmes
  • Cybersecurity training — awareness training for all staff, targeted training for technical roles

Incident reporting timelines

NIS2 introduces strict reporting obligations for "significant incidents":

  • T+24 hours: Early warning to the relevant CSIRT (NCSC in the UK)
  • T+72 hours: Full incident notification with impact assessment
  • T+1 month: Final report with root cause, remediation measures, and cross-border impact

This is significantly shorter than the previous NIS1 regime and more closely aligned with UK GDPR Article 33's 72-hour personal data breach notification requirement.

What you should do now

If NIS2 applies to your organisation — or you expect it will apply through the UK equivalent — the priority actions are:

  1. Determine whether you are an "essential" or "important" entity (the distinction affects supervisory intensity but not the core obligations)
  2. Conduct a gap analysis against Article 21 requirements
  3. Establish or update your incident response procedures with NIS2-aligned reporting timelines
  4. Review your supply chain — identify critical ICT third parties and assess their security posture
  5. Ensure board-level accountability — NIS2 makes senior management personally liable for significant non-compliance

How SummitBridge can help

We offer a structured NIS2 Gap Analysis starting at £2,000, covering Article 21 control assessment, risk register creation, incident response plan, and a prioritised remediation roadmap. Our NIS2 compliance package includes board-level reporting and 2 follow-up review calls.

Need help with this?

Our team can help you assess where you stand and build a practical remediation plan. Free 30-minute consultation — no obligation.

Book a Free Consultation

Related Articles