NIS2 Directive · UK NIS Regulations

Network security compliance — know which regulations apply to you

UK businesses are subject to the UK NIS Regulations 2018. If you have EU operations or serve EU customers in covered sectors, EU NIS2 applies too — and it raised the bar significantly. Fortify maps your posture against both frameworks and tracks the work to close gaps.

Free assessment · No account required

Which regulations apply to you

UK NIS Regulations or EU NIS2 — or both

Post-Brexit, UK businesses and EU businesses operate under different but related frameworks. UK-only businesses are subject to the UK NIS Regulations 2018. EU NIS2 applies if you have EU operations — and it introduced direct management liability with significantly expanded scope.

UK NIS Regulations

UK-only businesses

UK businesses operating solely within the UK are subject to the Network and Information Systems (NIS) Regulations 2018 — not EU NIS2. The UK government is currently consulting on an updated UK framework.

EU NIS2 — in scope

Essential entities (EU operations)

Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space.

EU NIS2 — in scope

Important entities (EU operations)

Postal and courier services, waste management, manufacture of certain products, food production, chemicals, digital providers, and research organisations.

EU NIS2 — likely in scope

UK organisations with EU operations

UK businesses serving EU customers or operating in sectors covered by NIS2 must meet NIS2 requirements for those EU operations — regardless of Brexit.

Indirect pressure

Supply chain of in-scope entities

Even if you are not directly in scope, your customers may be. NIS2 requires essential and important entities to manage supply chain security — your posture becomes their compliance problem.

NIS2 applies to medium-sized organisations (50+ employees or €10M+ turnover) and large organisations in covered sectors. Some sectors have no size threshold. Always verify your specific classification with legal counsel.

Key requirements

What NIS2 actually requires you to do

NIS2 mandates specific technical and organisational measures, with strict timelines for incident reporting and direct board-level accountability.

Art. 21

Risk management measures

  • Policies on risk analysis and information system security
  • Incident handling procedures
  • Business continuity and crisis management
  • Supply chain security
  • Security in network and information systems acquisition
  • Policies and procedures for cryptography and encryption
  • Human resources security and access control
Art. 23

Incident reporting

  • 24-hour early warning to national authority for significant incidents
  • 72-hour incident notification with initial assessment
  • 1-month final report with root cause and remediation
  • Intermediate progress report for ongoing incidents
Art. 26

Proportionality

  • Measures proportionate to risk, size, and impact
  • Differences between essential and important entities in supervisory regime
  • Cost-benefit of security measures considered
How Fortify helps

From posture check to evidence-backed compliance

NIS2 requires organisations to be able to demonstrate compliance — not just claim it. Fortify gives you the evidence trail.

01

Free posture assessment

The Digital Resilience assessment covers the core technical and organisational measures NIS2 requires under Article 21. You get a scored readiness summary in 10 minutes.

02

Gap tracking in the portal

Assessment findings populate your risk register and action plan. Each gap is tracked with status, owner, due date, and evidence — not buried in a PDF.

03

Incident management module

Log incidents with timestamps, impact classification, and response actions. Generate the structured reports NIS2 requires for national authority notification.

04

Supply chain risk management

Send vendor security questionnaires, score responses, and maintain a register of your critical suppliers — covering NIS2's supply chain security requirement.

Fortify Portal

Manage your NIS2 programme in one place

Risk register, incident log, vendor questionnaires, and evidence vault — all the components NIS2 expects you to have, tracked and evidenced in a single portal.

  • ✓Risk register mapped to NIS2 Article 21 measures
  • ✓Incident log with NIS2-compliant reporting timelines (24h / 72h / 30d)
  • ✓Vendor security questionnaires for supply chain due diligence
  • ✓Policy management with version control and sign-off tracking
  • ✓Evidence vault — attach documents against every control
  • ✓Quarterly posture reports for management review

Know where your network security posture stands — in 10 minutes

The free Digital Resilience assessment maps your current controls against NIS2 Article 21 requirements and UK NIS Regulations. No forms, no account needed.