NIS2 in 2026: What UK CISOs with EU Operations Must Now Demonstrate | INFORMD Executive Briefing

NIS2 in 2026: What UK CISOs with EU Operations Must Now Demonstrate

NIS2 enforcement is now active across EU member states — and UK businesses that operate in or provide services to the EU are directly subject to its requirements, regardless of Brexit.

The EU’s Network and Information Security Directive 2 (NIS2) entered transposition enforcement from October 2024, with active regulatory scrutiny beginning in 2026 as national competent authorities across EU member states operationalise their oversight regimes. UK businesses are not exempt. Any UK company that provides services to entities in the EU in sectors covered by NIS2 — including financial services, digital infrastructure, transport, energy, manufacturing, health, and public administration — is required to comply with NIS2 in the member states where those services are provided. For many UK CISOs, this creates a parallel compliance obligation sitting alongside the UK’s own cyber security framework, with different notification timelines, different authority structures, and potentially different technical requirements.

According to CyberSmart’s 2026 NIS2 research, the majority of UK businesses that fall under NIS2 scope are not fully aware of their obligations. The fines for NIS2 non-compliance reach 10% of global annual turnover for essential entities — a penalty level comparable to GDPR. UK CISOs who have not assessed their NIS2 exposure are carrying unquantified regulatory and financial risk. Explore INFORMD’s cyber resilience and regulatory briefing library to understand the full regulatory landscape.

Which UK Businesses Are Caught by NIS2?

NIS2 applies to medium and large organisations in sixteen sectors designated as either “essential” or “important.” Essential entities — subject to the strictest oversight — include providers of energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure (cloud providers, data centres, CDNs, DNS services), and ICT service management. Important entities face lighter-touch oversight but still carry mandatory security and notification obligations. They include food production, manufacturing, postal services, waste management, chemicals, digital providers, and research organisations.

Size thresholds matter: NIS2 applies to medium enterprises (50+ employees, €10m+ turnover) and large enterprises (250+ employees, €50m+ turnover). Micro and small businesses are generally excluded — but there are exceptions for sole providers of critical services, and supply chain obligations under Article 21 mean that even smaller UK suppliers may face NIS2-derived security requirements if their large EU customers must ensure supply chain security.

UK CISOs should answer three scoping questions immediately. First, does the organisation provide digital or technology services into EU member states? Second, does the organisation operate branch offices, subsidiaries, or data centres in the EU? Third, does the organisation fall within a NIS2 sector by the nature of its products or services, even if its primary market is the UK? If the answer to any of these is yes, a formal NIS2 scoping assessment is required. Use INFORMD’s cyber regulatory scope assessment to structure the analysis.

Executive Action

  • Commission a formal NIS2 scoping assessment: map every EU market where the organisation provides services against the NIS2 sector classifications and size thresholds to determine whether compliance obligations apply.
  • Identify the relevant national competent authority in each EU member state where NIS2 obligations apply — different member states have different authorities (BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands) with different registration and reporting processes.
  • Review supply chain contracts with large EU customers: if those customers are NIS2 essential or important entities, they will impose contractual security requirements on you as part of their own Article 21 supply chain compliance.

What Security Measures Does NIS2 Article 21 Actually Require?

NIS2 Article 21 sets out the minimum cybersecurity risk management measures that essential and important entities must implement. These are not aspirational standards — they are legally mandated minimum requirements, and national competent authorities are assessing compliance against them in 2026. The ten required measures are: risk analysis and information system security policies; incident handling; business continuity and crisis management; supply chain security; security in network and information systems acquisition, development and maintenance; policies and procedures to assess the effectiveness of cybersecurity risk management; basic cyber hygiene practices and cybersecurity training; policies on the use of cryptography and, where appropriate, encryption; human resources security, access control policies, and asset management; and the use of multi-factor authentication or continuous authentication solutions.

For most UK CISOs with mature security programmes, many of these measures will already be in place. The compliance gap is usually in three areas. Supply chain security under NIS2 is more prescriptive than many organisations currently manage — requiring documented assessment of ICT suppliers and service providers against security criteria. Cryptography and encryption policies must be formally documented and evidenced, not just implemented informally. And the use of multi-factor authentication (MFA) must be organisation-wide and demonstrable, not just for privileged access.

Executive Action

  • Map your existing security controls against the ten NIS2 Article 21 requirements — identify gaps in formal documentation and policy coverage, even where technical controls are in place.
  • Conduct a supply chain security review of your top 20 ICT suppliers: do you have documented security assessments, contractual security requirements, and ongoing monitoring processes for each? NIS2 requires you to demonstrate this.
  • Verify that MFA is deployed organisation-wide across all systems and users, not just privileged accounts — NIS2 national competent authorities are specifically assessing MFA coverage in 2026 inspections.

What Are the NIS2 Incident Notification Requirements UK CISOs Must Build For?

NIS2 introduces a tiered mandatory notification timeline that is more demanding than the UK’s current NIS Regulations and creates parallel obligations to the UK’s own forthcoming mandatory reporting regime under the Cyber Security and Resilience Bill. Under NIS2 Article 23, organisations must provide an initial early warning to the relevant national competent authority within 24 hours of becoming aware of a significant incident — a much tighter window than the 72-hour GDPR data breach notification period. A full incident notification must follow within 72 hours, including an initial assessment of severity, impact, and indicators of compromise. A final incident report, including a root cause analysis, must be submitted within one month.

A “significant incident” under NIS2 is defined as one that causes or could cause severe disruption to the provision of services, or financial loss to the affected entity, or that affects other natural or legal persons by causing considerable material or non-material damage. This is a broad definition that could capture a wide range of cyber incidents beyond those that would typically trigger a GDPR notification.

UK CISOs must build incident detection, assessment, and notification infrastructure that can operate within a 24-hour window. This requires: 24/7 security monitoring with clear escalation to incident response; a pre-prepared incident assessment template that allows rapid severity evaluation; pre-drafted notification contacts and reporting templates for each relevant national competent authority; and a designated point of contact with sufficient authority to approve regulatory notifications without lengthy internal approval chains. Reference INFORMD’s CISO incident response and regulatory notification template to build this capability.

Executive Action

  • Review your incident response playbook against NIS2’s 24-hour early warning requirement — identify whether your current detection, escalation, and assessment capability can operate within this window, and invest to close gaps.
  • Prepare a pre-registration contact list for each EU national competent authority relevant to your operations — notification contacts, reporting portals, and template notification forms should be ready before an incident occurs.
  • Run a tabletop NIS2 notification exercise with your incident response team and legal counsel — test whether you can achieve the 24-hour early warning threshold under realistic incident conditions.

What Are the NIS2 Enforcement Consequences UK CISOs Must Understand?

NIS2 fines are structured differently from GDPR. For essential entities, the maximum administrative fine is at least €10 million or 2% of global annual turnover, whichever is higher, for security measure failures; and at least €10 million or 2% for notification failures. For the most serious breaches, fines can reach €10 million or 10% of global annual turnover. For important entities, the cap is €7 million or 1.4% of global turnover. These are minimums that member states can exceed — and some, including Germany and the Netherlands, are expected to impose fines at the upper end of available ranges.

Enforcement is not the only consequence. NIS2 introduces personal liability for senior management, requiring that management bodies of essential entities approve and oversee the implementation of cybersecurity risk management measures. Management body members can be held personally liable for negligent failures to implement required measures. This is a significant change from most UK frameworks, where personal liability for security failures has been limited. UK CISOs and the executives they report to should understand this exposure explicitly.

Ac

Similar Posts