UK businesses are subject to the UK NIS Regulations 2018. If you have EU operations or serve EU customers in covered sectors, EU NIS2 applies too — and it raised the bar significantly. Fortify maps your posture against both frameworks and tracks the work to close gaps.
Free assessment · No account required
Post-Brexit, UK businesses and EU businesses operate under different but related frameworks. UK-only businesses are subject to the UK NIS Regulations 2018. EU NIS2 applies if you have EU operations — and it introduced direct management liability with significantly expanded scope.
UK businesses operating solely within the UK are subject to the Network and Information Systems (NIS) Regulations 2018 — not EU NIS2. The UK government is currently consulting on an updated UK framework.
Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space.
Postal and courier services, waste management, manufacture of certain products, food production, chemicals, digital providers, and research organisations.
UK businesses serving EU customers or operating in sectors covered by NIS2 must meet NIS2 requirements for those EU operations — regardless of Brexit.
Even if you are not directly in scope, your customers may be. NIS2 requires essential and important entities to manage supply chain security — your posture becomes their compliance problem.
NIS2 applies to medium-sized organisations (50+ employees or €10M+ turnover) and large organisations in covered sectors. Some sectors have no size threshold. Always verify your specific classification with legal counsel.
NIS2 mandates specific technical and organisational measures, with strict timelines for incident reporting and direct board-level accountability.
NIS2 requires organisations to be able to demonstrate compliance — not just claim it. Fortify gives you the evidence trail.
Free posture assessment
The Digital Resilience assessment covers the core technical and organisational measures NIS2 requires under Article 21. You get a scored readiness summary in 10 minutes.
Gap tracking in the portal
Assessment findings populate your risk register and action plan. Each gap is tracked with status, owner, due date, and evidence — not buried in a PDF.
Incident management module
Log incidents with timestamps, impact classification, and response actions. Generate the structured reports NIS2 requires for national authority notification.
Supply chain risk management
Send vendor security questionnaires, score responses, and maintain a register of your critical suppliers — covering NIS2's supply chain security requirement.
Risk register, incident log, vendor questionnaires, and evidence vault — all the components NIS2 expects you to have, tracked and evidenced in a single portal.
The free Digital Resilience assessment maps your current controls against NIS2 Article 21 requirements and UK NIS Regulations. No forms, no account needed.