NIS2 Compliance Checklist for UK & EU Firms | SecurityHQ
NIS2 Compliance Checklist: What UK and EU Businesses Still Get Wrong
NIS2 has been in force for long enough that most in-scope organizations know the name. Only a few organizations have worked out what it actually requires of them, and a significant number have reached the wrong conclusion about whether it applies to their needs.
Two mistakes account for most of the gap. The first is reading the directive text and assuming that is the obligation.
NIS2 is a directive, so it binds organizations only through each member state’s own transposition law, and those laws differ on registration, deadlines, and penalties. The second is a UK assumption that Brexit settled the question. For a large number of UK businesses, it did not.
This checklist covers what NIS2 requires, who falls inside it, where the UK position actually sits, and the specific points where compliance programs are coming up short.
What Is the NIS2 Directive?
NIS2, formally Directive (EU) 2022/2555, sets a baseline for cybersecurity risk management and incident reporting across the sectors the EU treats as critical. It raises the required security measures, widens the range of organizations covered, and places accountability for compliance on management rather than on just the security function.
The practical shift is that NIS2 attaches consequences to governance failures. Management bodies must approve the risk-management measures, oversee their implementation, and undergo training. Member states can hold individual managers liable for infringements, and for essential entities, authorities can temporarily bar a person at chief executive or legal representative level from holding managerial responsibility.
NIS2 vs. the Original NIS Directive
NIS2 repealed and replaced the 2016 NIS Directive. The differences that matter in practice:
- Wider sector coverage: The original directive covered a narrow set of operators of essential services and a few digital service providers. NIS2 spans eleven sectors of high criticality and seven further critical sectors, adding areas such as waste management, chemicals, food, manufacturing, postal services, ICT service management, public administration, and space.
- Objective scope rules: Member states previously identified individual operators, which produced inconsistent coverage across the EU. NIS2 applies size and sector criteria directly, so organizations must assess their own scope rather than wait to be told.
- Prescribed minimum measures: The earlier regime described broad duties. NIS2 names ten specific categories of risk-management measures every in-scope entity must implement.
- A fixed reporting cascade: NIS2 replaces general notification duties with defined stages and deadlines.
- Management accountability and higher penalties: Personal liability for managers and turnover-based fines both arrive with NIS2.
- Explicit supply chain duties: Entities must address the security of their suppliers and service providers as part of their own compliance.
Who Counts as an “Essential” or “Important” Entity?
Scope generally starts with size. Medium-sized organizations, meaning roughly 50 or more staff or above €10 million in turnover, and large organizations, which haveroughly 250 or more staff or above €50 million in turnover, fall in scope when they operate in a listed sector. Certain entity types are in scope at any size, including DNS service providers, top-level domain registries, qualified trust service providers, and organizations that are the sole provider of a service critical to society.
From there, the classification splits:
- Essential entities: Large organizations in the high-criticality sectors, plus specific categories designated regardless of size. These face proactive supervision, meaning authorities can inspect and audit without waiting for evidence of a problem.
- Important entities: Medium organizations in the high-criticality sectors, and medium and large organizations in the other critical sectors. These face reactive supervision, meaning scrutiny follows an indication of non-compliance.
Here is the point programs most commonly get wrong: The security measures required of important entities are the same as those required of essential entities. Only the supervisory approach and the fine ceilings differ. Teams that read “important” as “lighter obligations” and scale their program accordingly have misread the directive, and they will be judged against the full Article 21 list whenever scrutiny arrives.
Does NIS2 Apply to UK Businesses?
NIS2 does not apply to the UK as a member state, and the UK did not adopt it. UK domestic obligations still run through the Network and Information Systems Regulations 2018.
That answer misleads if you stop there, because a UK-headquartered business can be pulled into NIS2 through three separate routes, and can face a comparable domestic regime regardless.
On the domestic side, the government introduced the Cyber Security and Resilience (Network and Information Systems) Bill to the House of Commons in November 2025. It has since passed second reading and Commons committee stage and moved to the Lords, with Royal Assent expected during 2026 and phased implementation running beyond that.
The Bill expands the 2018 Regulations to cover new categories including data centres, managed service providers, and designated critical suppliers, tightens incident reporting, and raises penalties substantially. UK firms treating NIS2 as somebody else’s problem should expect similar obligations domestically on a short horizon.
Cross-Border Scope After Brexit
Three routes bring UK organizations inside NIS2:
- An establishment in the EU: A subsidiary, branch, or office in a member state operating in a covered sector falls under that state’s transposition law directly. Group structure does not shield it.
- Offering certain digital services into the EU without an EU establishment: Providers of services such as DNS, cloud computing, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, and social networking platforms fall under EU jurisdiction when they serve EU users, and must designate a representative in a member state where they operate.
- Supply chain flow-down: This is the route that catches the most companies. NIS2 requires in-scope entities to manage supplier security, so EU customers push those requirements into contracts. A UK supplier outside NIS2 scope still ends up meeting NIS2-derived security terms, reporting timelines, and audit rights because its customer is obliged to impose them.
- For most UK businesses, the third route arrives first, and it arrives as a procurement conversation rather than a regulatory one. Treating it as a contract question for the legal team, rather than a security program question, is how organizations end up committing to obligations they cannot evidence.
Key NIS2 Compliance Deadlines
Two sets of dates matter, and conflating them causes real problems.
The first refers to the directive requiring member states to transpose NIS2 into national law by 17 October 2024. Only a handful met that date.
The European Commission opened infringement proceedings against 23 member states in November 2024, escalated to reasoned opinions against 19 of them in May 2025, and in July 2026 referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union, requesting financial sanctions in the form of a lump sum plus daily penalties until transposition is notified.
Two consequences follow for compliance teams:
- Your deadlines are national, not European: Registration windows, reporting channels, competent authorities, and penalty structures come from each member state’s law. An organization operating in six member states is managing six variants of the same directive, with different entry-into-force dates.
- A delayed transposition is not a reprieve: Waiting for a national law to appear before starting work leaves no time to build capability once it does, and the security measures themselves take quarters rather than weeks to stand up. Entities in late-transposing states have generally had interim guidance from their national authority in the meantime.
The incident reporting deadlines, covered below, are the ones that bite during an actual event.
The NIS2 Compliance Checklist
Work through the three areas below against your current program. Each item maps to an obligation an auditor or competent authority can ask you to evidence.
Risk Management Measures
Article 21 names ten categories of measures. Treat them as a control inventory and confirm you can produce documentation for each:
- Risk analysis and information system security policies: A documented, approved policy set with a current risk assessment behind it.
- Incident handling: Defined detection, triage, escalation, and response procedures with named owners.
- Business continuity and crisis management: Backup management, disaster recovery, and tested crisis procedures.
- Supply chain security: Security requirements for suppliers and service providers, applied and monitored.
- Secure acquisition, development, and maintenance: Vulnerability handling and disclosure processes covering systems you buy as well as systems you build.
- Effectiveness assessment: A method for testing whether the measures work, not only whether they exist.
- Cyber hygiene and training: Baseline practices and role-appropriate training, including for the management body.
- Cryptography and encryption: Documented policy on where and how each is applied.
- Human resources security, access control, and asset management: Joiner, mover, and leaver controls, least privilege, and a current asset inventory.
- Multi-factor authentication and secured communications: MFA or continuous authentication, plus secured voice, video, text, and emergency communications.
Two items trip programs up: Effectiveness assessment requires evidence of testing, so a control that has never been validated will not satisfy it. The training obligation reaches the board, which means management cannot delegate its way out of the requirement.
Organizations without a permanent security leader often meet the governance and accountability side through CISO as a Service, which supplies the documented ownership and board-level reporting the directive expects.
Incident Reporting Obligations
NIS2 sets a three-stage cascade for any significant incident, meaning one that causes or could cause severe operational disruption or financial loss to you, or considerable damage to others:
- Early warning within 24 hours: Submitted to your CSIRT or competent authority, indicating whether you suspect an unlawful or malicious act and whether cross-border impact is possible.
- Incident notification within 72 hours: An updated assessment covering severity, impact, and indicators of compromise.
- Final report within one month: A detailed account including root cause, mitigations applied, and any cross-border effect. Authorities can request interim status reports along the way.
You may also need to notify affected service recipients, and cross-border incidents can require parallel filings in every member state where the impact is material.
The 24-hour clock is where most organizations are exposed, because it starts when you become aware of the incident, not when you have confirmed and scoped it. Meeting it requires detection capable of identifying a significant incident within hours and an escalation path that reaches the person authorized to file at any hour of any day.
Organizations relying on business-hours monitoring will miss the deadline on a Friday night event. SecurityHQ addresses that gap through Managed Detection and Response, where analysts detect, investigate, and classify incidents around the clock and produce the severity and impact assessment the notification requires.
Practical steps to close the reporting gap:
- Define your significance threshold in advance: Agree now what qualifies, so the judgment is not made under pressure.
- Pre-build the submission: Hold templates and portal credentials for every relevant national authority.
- Name the filer and a deputy: Confirm who has authority to submit outside working hours.
- Rehearse against the clock: Run an exercise that ends in a completed 24-hour filing rather than a tabletop discussion.
Supply Chain Security Requirements
NIS2 makes supplier security your obligation, which means a supplier failure becomes your compliance failure. Questionnaires alone will not evidence this:
- Maintain a supplier inventory tied to criticality: Know which providers touch your essential services and which hold your data.
- Set security requirements in contracts: Include incident notification windows short enough to let you meet your own 24-hour obligation, plus audit and assurance rights.
- Assess in proportion to risk: Reserve deeper assurance for suppliers whose compromise would disrupt your critical services.
- Monitor continuously: Track third-party breaches and exposures rather than reassessing annually.
- Plan for supplier failure: Build continuity arrangements for concentrated or hard-to-replace dependencies.
Penalties for Non-Compliance
NIS2 sets minimum ceilings that member states must provide for, and national laws may go further:
- Essential entities: Fines of at least €10 million or at least 2% of total worldwide annual turnover, whichever is higher.
- Important entities: Fines of at least €7 million or at least 1.4% of total worldwide annual turnover, whichever is higher.
Financial penalties are not the whole exposure. Authorities can order specific remediation, publish details of an infringement, and for essential entities suspend a certification or authorisation and temporarily prohibit a named individual from exercising managerial functions.
National competent authorities have begun issuing fines and running structured audit programs, with early activity concentrated in energy, health, and digital infrastructure.
The reputational and personal dimensions tend to move boards faster than the fine ceilings do. A published infringement reaches customers and prospects, and a management ban reaches individuals directly.
Get an Honest Read on Your NIS2 Position
Most organizations do not need convincing that NIS2 matters. They need to know which national law binds them, which of the ten measure categories they can evidence today, and whether they could actually file inside 24 hours.
SecurityHQ works with security and compliance leaders across the UK and EU to close those gaps with 24/7 detection and response, supply chain and dark web monitoring, and board-level security governance. Talk with a security expert to review your scope and readiness against the requirements that apply to you.
Frequently Asked Questions
What is the NIS2 Directive and who does it apply to?
NIS2, Directive (EU) 2022/2555, sets cybersecurity risk-management and incident reporting requirements across sectors the EU treats as critical. It applies to medium and large organizations in those sectors, classified as either essential or important entities, and to certain provider types at any size. Obligations reach organizations through each member state’s national transposition law rather than through the directive directly.
What is the difference between NIS1 and NIS2?
NIS2 covers far more sectors, replaces state-by-state identification of operators with objective size and sector criteria, names ten specific categories of required security measures, sets a fixed 24-hour, 72-hour, and one-month reporting cascade, adds explicit supply chain duties, and introduces management liability alongside turnover-based fines.
Do UK businesses need to comply with NIS2 after Brexit?
NIS2 does not apply to the UK directly. A UK business still falls in scope if it has an EU establishment in a covered sector, or if it provides certain digital services into the EU, in which case it must appoint an EU representative. Many others meet NIS2-derived requirements contractually as suppliers to in-scope EU customers. Separately, the Cyber Security and Resilience Bill will raise UK domestic requirements to a comparable level.
What are the penalties for NIS2 non-compliance?
Member states must allow fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever figure is higher. Authorities can also mandate remediation, publish infringements, suspend authorisations, and temporarily prohibit senior individuals from managerial functions.
What are the key deadlines for NIS2 compliance?
Member states were required to transpose NIS2 by 17 October 2024, and most missed it, so your applicable dates come from national law. During an incident, the deadlines are fixed: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month.
Does NIS2 apply to companies outside the EU?
Yes, in defined circumstances. Providers of services including DNS, cloud computing, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, and social networking platforms fall under EU jurisdiction when they serve EU users, and must designate a representative in the EU. Non-EU organizations outside those categories are commonly reached instead through supplier requirements imposed by in-scope EU customers.