NIS2 COMPLIANCE

NIS2 compliance for UK businesses caught in EU supply chains

You sell into Europe, a German or Irish customer has just sent you a NIS2 questionnaire, and nobody in the building is sure whether the directive applies to a UK company at all. It does, through your customers, and this page tells you exactly what is now expected of you and how to evidence it.

Book a conversation

What is NIS2 compliance?

NIS2 compliance means meeting the cybersecurity risk management and incident reporting obligations set out in EU Directive 2022/2555, the second Network and Information Security Directive, which replaced the original 2016 NIS Directive. It raises the baseline of security expected from organisations operating in sectors the EU considers essential or important, widens the range of sectors in scope, makes senior management personally accountable for cyber risk, and introduces strict deadlines for reporting significant incidents. Member states were required to write NIS2 into national law, so the practical rules you face come from the legislation of whichever EU country regulates you or your customer.

Does NIS2 apply to UK businesses?

NIS2 is EU law, so it does not regulate UK companies directly the way the UK NIS Regulations do. The reason UK firms keep encountering it is the supply chain. The directive obliges in-scope EU organisations to manage the security risk in their suppliers and service providers, which means your European customers are now required to assess you, contract for specific security controls, and in some cases audit your environment. A UK managed service provider, software vendor, logistics firm or data processor selling into a German manufacturer or a Dutch hospital will be pulled into NIS2 through contract clauses, even though the directive never names you. If you ignore the questionnaire, you risk being designed out of the contract. Working out where you sit, and what a defensible answer looks like, is a core part of the cyber security consulting we provide.

Who falls in scope

NIS2 sorts in-scope organisations into essential and important entities, with essential entities facing tighter supervision. The sectors are far broader than under the first directive and now cover energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, public administration, space, postal and courier services, waste management, manufacture of chemicals and certain critical products, food production, and digital providers such as cloud, data centre and managed service firms. Size matters too: the directive generally captures medium and large organisations, those with at least fifty staff or above a defined turnover threshold, though some entity types are in scope regardless of size because of their criticality.

  • EU entities operating in the essential and important sectors named above
  • Their suppliers and service providers, including UK firms, through supply chain security obligations
  • Digital infrastructure and managed service providers, often regardless of headcount
  • Group companies where an EU subsidiary brings the wider business into customer assessments

The core obligations

NIS2 sets a baseline of risk management measures rather than a tick box checklist. In-scope organisations must take appropriate and proportionate technical, operational and organisational steps to manage the risks to their networks and systems. In practice that means policies on risk analysis and information security, incident handling, business continuity and crisis management, supply chain security, security in acquiring and maintaining systems, vulnerability handling and disclosure, testing and auditing of controls, basic cyber hygiene and training, cryptography, access control and asset management, and multi factor or continuous authentication where appropriate. The reporting regime is strict: a significant incident triggers an early warning to the relevant authority within twenty four hours, a fuller notification within seventy two hours, and a final report within one month. Embedding a workable incident response plan is what turns those deadlines from a panic into a process.

Board accountability under NIS2

One of the sharpest changes in NIS2 is that it puts cyber risk on the board’s desk and keeps it there. Management bodies must approve the organisation’s cybersecurity risk management measures, oversee their implementation, and undergo training so they can identify risks and assess the practices in their own business. Where the rules are breached, member states can hold senior managers personally accountable, and the directive allows for management to be temporarily barred from their roles in serious cases. This is not something a board can delegate to IT and forget. It is a governance responsibility, which is why we built the board cyber governance work to give directors the language and the evidence they need. The cost of getting it wrong is real: the IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and regulators have shown they will act, with the ICO fining British Airways GBP 20 million in 2020 and Interserve GBP 4.4 million in 2022.

How to get compliant, and how this differs from the UK NIS Regulations

It helps to be clear that NIS2 and the UK NIS Regulations are two separate regimes. The UK retained its own NIS Regulations after leaving the EU and has been consulting on updating them, but they remain a distinct piece of law with their own scope, competent authorities and reporting thresholds. NIS2 is the EU successor directive. A UK business can therefore face the UK regime directly and the EU regime indirectly through its European customers at the same time, and the two do not perfectly overlap. The practical route to compliance is the same in either case: establish what you are being asked to meet, map your current controls against it, fix the gaps in priority order, and produce evidence a customer or auditor will accept.

  • Confirm your exposure: which customers, which member state laws, which entity category
  • Run a gap assessment against the NIS2 risk management measures and your customers’ clauses
  • Prioritise remediation by risk, not by what is easiest to close
  • Stand up incident reporting that can hit the twenty four hour and seventy two hour deadlines
  • Brief the board so accountability is owned, recorded and defensible

If you need that expertise without a permanent hire, our CISO as a service and virtual CISO options give you a senior security leader who can own the programme, while a fractional CIO and CISO or interim CIO and CISO engagement suits firms that need the change driven hard over a fixed period. You can see how we structure fees on the pricing page.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Leading technology and security across multi site, private equity backed and dealership businesses means Daniel has built the supply chain controls, incident processes and board level reporting that NIS2 now demands, and can translate the directive into a plan your customers and your directors will both accept.

Frequently asked questions

Does NIS2 apply to my UK company?

Not directly, because NIS2 is EU law. It reaches UK firms through the supply chain: your in-scope EU customers are required to manage supplier security, so they pass NIS2 obligations to you through contracts, questionnaires and audits.

How is NIS2 different from the UK NIS Regulations?

They are separate regimes. The UK kept its own NIS Regulations after Brexit and has been consulting on reform, while NIS2 is the EU’s updated directive. A UK business can face the UK rules directly and NIS2 indirectly through EU customers at once.

What are the NIS2 incident reporting deadlines?

For a significant incident you give an early warning within twenty four hours, a fuller notification within seventy two hours, and a final report within one month. You need a tested process to hit those, not just a policy on a shelf.

Is the board really accountable under NIS2?

Yes. Management must approve and oversee the security measures and be trained on cyber risk. Member states can hold senior managers personally accountable for breaches, and in serious cases bar them from their management roles.

What is the fastest way to start?

Establish your exposure, run a gap assessment against the NIS2 measures and your customers’ clauses, then remediate in priority order. A virtual or interim CISO can own this end to end so it does not stall.

NEXT STEP

Find out whether your board can defend its cyber position

If a NIS2 questionnaire has landed and you are not sure your directors could answer for the controls behind it, start with the Board Cyber Governance check. It shows where the accountability gaps sit before a customer or regulator finds them, and we can talk through what closing them looks like.

Board Cyber Governance check Book a conversation