NIS2 and the UK
NIS2 vs the UK Cyber Security and Resilience Bill
NIS2 is the EU's cyber security directive. The UK has its own equivalent in the making. Here is how the two compare, and why the UK Bill, not NIS2, is the law to watch if you operate here.
Last reviewed 14 July 2026 · all sources linked in the text
The short answer
Does NIS2 apply in the UK?
Not directly. Since leaving the EU, the UK is no longer bound by EU directives, so the NIS2 directive does not automatically apply to UK organisations. The UK's equivalent is the Cyber Security and Resilience Bill, the government's planned law to strengthen the cyber resilience of essential and digital services. It is widely described as the UK's NIS2 equivalent and it updates and expands the Network and Information Systems Regulations 2018. So the position for a UK business asking about NIS2 is straightforward: watch the UK Bill, and treat NIS2 as the useful reference point it is modelled on, not as a law that binds you at home.
There is an important exception, covered further down: if you also operate in the EU, NIS2 can still reach you directly through the national laws of the member states you work in.
| Dimension | EU NIS2 directive | UK Cyber Security and Resilience Bill |
|---|---|---|
| Legal status | A directive of the European Union, adopted and in force across the EU. As a directive it takes effect through each member state's own national transposing law. | A Bill before the UK Parliament, announced in the King's Speech in July 2024 with a policy statement published on gov.uk. It has not yet received Royal Assent and is not yet law. |
| Who it covers | Essential entities and important entities across named sectors such as energy, transport, banking, health and digital infrastructure, generally sized above medium enterprise thresholds. | Expected to use an essential entities and important entities style categorisation and to bring more organisations into scope, including managed service providers. The exact in scope definitions are set by the Bill and by secondary legislation to follow. |
| Core obligations | Risk management measures, governance and management accountability, supply chain security and structured incident handling for in scope entities. | Expected to strengthen security duties, incident management and supply chain requirements, building on and expanding the Network and Information Systems Regulations 2018. |
| Incident reporting | A multi stage duty: an early warning, followed by a fuller incident notification, and then a final report, on defined timescales set out in the directive. | Expected to strengthen incident reporting duties. The exact thresholds, recipients and timescales are set by the Bill and by secondary legislation. |
| Enforcement and regulators | National competent authorities and national cyber incident response teams in each member state, with powers to supervise and to impose significant administrative fines. | The existing NIS regime is overseen by sector regulators as competent authorities. The Bill is expected to give regulators stronger oversight and enforcement powers. |
| Current status | Adopted and in force across the EU, with member states applying it through their own national laws. | Announced in 2024, policy statement published, progressing through the legislative process. There are no statutory duties or deadlines yet. |
EU NIS2 details describe the directive as adopted. UK details follow the government's published policy statement and are expected positions rather than settled law, because the Bill is still progressing and much of the detail lands in secondary legislation. Sources: the gov.uk policy statement for the Bill, NCSC guidance, and the NIS Regulations 2018 the Bill amends.
The EU law
What NIS2 is
NIS2 is the European Union's directive on network and information security, the successor to the original 2016 NIS directive. It raises cyber security requirements for organisations across the EU, widens the sectors and entities in scope, tightens incident reporting and puts accountability on senior management. It is in force across the EU and applies through each member state's own national transposing law rather than as a single rulebook applied centrally.
For a UK reader, NIS2 matters mainly as the model the UK is measuring itself against. When people search for nis2 uk or nis 2 uk, what they usually want is the UK equivalent, and that is the Cyber Security and Resilience Bill.
Post Brexit
Why the NIS2 directive does not directly bind the UK
EU directives take effect through the national law of member states. Because the UK is no longer a member state, the NIS2 directive was never transposed into UK law and does not apply to UK organisations of its own force. The UK's domestic cyber regime remains the Network and Information Systems Regulations 2018, and the Cyber Security and Resilience Bill is the vehicle chosen to update and expand it.
This is the crux of the common does nis2 apply to uk question. The accurate answer is no, not directly, but the direction of travel is clearly towards a comparable UK standard.
Mirrors and differences
How the UK Bill mirrors and differs from NIS2
The Cyber Security and Resilience Bill is the UK's nis2 uk equivalent, and it borrows the shape of NIS2 while remaining a distinct UK law.
Where it mirrors NIS2
- A broader set of organisations in scope, including managed service providers, rather than a narrow list.
- An essential entities and important entities style split, echoing the NIS2 categorisation.
- Stronger incident reporting and a firmer focus on supply chain security.
- Stronger powers for regulators to supervise and enforce.
Where it differs
- It is UK law built on the NIS Regulations 2018, not a transposition of an EU directive.
- Its exact sectors, definitions and thresholds are set by the Bill and by UK secondary legislation, so they will not match NIS2 line for line.
- Oversight sits with UK regulators, not EU national competent authorities.
- It is not yet in force, so there are no UK duties or deadlines to meet today.
The plain English detail of what the UK Bill will require sits on the what the Bill is page, and the direction it takes on scope is unpacked in who is in scope.
The scope model
Essential entities and important entities
NIS2 sorts in scope organisations into two categories, and the UK Bill is expected to use a similar split. It is worth understanding, because it is likely to shape how the UK decides who carries the heaviest duties.
Broadly, essential entities are the organisations whose disruption would have the most serious effect, in sectors such as energy, transport, health, water and digital infrastructure. Important entities are a wider group whose role is significant but a step below, and they typically face a lighter supervisory regime than essential entities.
Essential entities
The organisations most critical to national and economic life. Expected to face the fullest duties and the closest, most proactive supervision.
Important entities
A broader group carrying significant, though less critical, roles. Expected to face comparable core duties with lighter touch, more reactive oversight. This is often where managed service providers land.
CyPro is itself an in scope managed service provider, so we are preparing for this alongside the organisations we work with, not watching from the sidelines.
Whether you are likely to be treated as essential or important, and how managed service providers are caught, is the subject of who is in scope.
Do not stop reading at Brexit
UK organisations operating in the EU may still face NIS2 directly
Saying NIS2 does not bind the UK is only half the picture. If your business provides in scope services inside the EU, or has establishments in member states, you can be caught by NIS2 directly through those countries' national laws, whatever the UK does at home. Many UK organisations therefore end up managing two related regimes: NIS2 in the EU markets they operate in, and the Cyber Security and Resilience Bill once it takes effect in the UK.
The practical upside is that the two are close cousins. Building strong cyber governance, incident reporting and supply chain controls once tends to serve both, which is why understanding the comparison early is worth the effort.
Work out where you stand
NIS2, the UK Bill, or both?
If you are trying to tell which regime reaches your business and how to prepare early, book a discovery call and get a straight read on your exposure. No obligation.