Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Back to the NIS2 overview
United Kingdom · NIS2 context

United Kingdom cybersecurity regime — and the NIS2 question for suppliers

The UK is not subject to NIS2 directly post-Brexit. The legal NIS-equivalent regime is the Network and Information Systems Regulations 2018, which applies to a narrower population than NIS2 — Operators of Essential Services (OES) in energy, transport, healthcare, water, and digital infrastructure, plus Relevant Digital Service Providers (RDSPs). The Cyber Security and Resilience Bill — before Parliament as of mid-2026, with Royal Assent expected late 2026 — updates those 2018 Regulations to broadly align with, but not identically to, NIS2 standards, notably extending scope to managed service providers and data centres; obligations phase in through secondary legislation after passage. The National Cyber Security Centre (NCSC) is the technical authority and CSIRT; the ICO and sector regulators are competent authorities for RDSPs and OES respectively.

For most UK organisations outside the OES/RDSP scope, the practical cybersecurity baseline is Cyber Essentials and Cyber Essentials Plus — NCSC-backed certification schemes (administered by IASME) that cover the five core technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. CE is required for many UK public-sector contracts and is increasingly the answer UK suppliers give when EU buyers ask for evidence of cybersecurity posture under their NIS2 supply-chain assessments. A UK supplier holding current CE Plus certification is a common, defensible — though not framework-equivalent — substitute for the NIS2 Article 21(2)(d) evidence an EU buyer is collecting.

National competent authority
NCSC — Cyber Essentials

Authoritative source for United Kingdom cybersecurity guidance — including the certification schemes UK suppliers commonly hold when EU NIS2 buyers ask for evidence of posture.

5.0 / Next step

United Kingdom-based supplier? Answering EU NIS2 buyers?

Two ways to find out fast — a five-minute supplier readiness check (covers what EU NIS2 buyers commonly ask for), or a practitioner-walked exposure picture if you also serve regulated buyers.

Detailed United Kingdom guide in development — get notified

We’re writing a longer practitioner guide on NIS2 in United Kingdom: thresholds, registration timelines, and what regulators are starting to ask suppliers for. Drop your email and we’ll send it when it lands.

We use your address only for this — no marketing list, no resale. By submitting, you agree we may email you about it, per our Privacy Policy.