Blog/Regulation
RegulationSeptember 2026

NIS2 and UK SMEs: building the plan, not just reading the regulation

NIS2 is an EU directive, but UK businesses selling into the EU — or supplying an in-scope EU entity — can still inherit its obligations. The harder part isn't understanding the regulation, it's turning it into an evidenced security programme.

NIS2 gets discussed as if it were purely an EU problem. For a lot of UK businesses it isn't — if you sell into the EU, operate an EU subsidiary, or supply a company that falls in scope, obligations can reach you indirectly through contracts and due diligence, even if you're never directly regulated under it yourself.

Reading the regulation isn't the hard part

The text of NIS2 is publicly available and, as these things go, reasonably readable. The harder problem for most SMEs is deciding what to actually build first — the regulation describes outcomes (risk management, incident reporting, supply chain security) without handing you an implementation order.

A baseline, not a checklist

Treating NIS2 as a document to produce once and file away is the most common mistake we see. The organisations that hold up well under scrutiny — whether that's a regulator, an auditor, or an enterprise customer's due diligence team — are the ones with a living roadmap: a baseline of where they actually stand, gaps prioritised by risk, and a visible trail of what's been fixed and when.

Where most plans stall

Teams that treat NIS2 as a one-off document exercise rarely have anything to show six months later. A roadmap with owners, dates, and a review cadence is what actually holds up under scrutiny — a policy document on its own doesn't.

  • Baseline your current posture against the relevant control areas before writing anything down
  • Prioritise gaps by risk and likely impact, not by whichever control is easiest to fix first
  • Set a 30/60/90-day plan with a named owner and a review point — not just a list of intentions

This is exactly the gap a structured resilience roadmap closes — baselining your posture, ranking what matters most, and giving you a plan you can actually evidence later.

Read the full guide

How to build a cyber resilience roadmap

Baseline your posture in 10 minutes

Fortify's free Digital Resilience Assessment gives you a scored baseline across the areas NIS2 and similar frameworks care about — the starting point for any roadmap.