FreeFind your cybersecurity gaps with a free GAPZe assessmentStart now

Cybersecurity

NIS2 Implementation: A Practical Guide for UK and EU Firms

Isometric illustration of a red shield on a platform surrounded by a ring of twelve stars, with connected infrastructure blocks, in Anvay's red and stone colours

NIS2 implementation means putting the cybersecurity risk-management, governance and incident-reporting duties of Directive (EU) 2022/2555 into practice in every EU country where you operate. The practical next step is simple: confirm whether you are an essential or important entity, run a gap assessment against Article 21, then fix the gaps that would stop you reporting a significant incident within 24 hours.

TL;DR

  • Confirm scope first: check your sector against Annexes I and II, your size, and which national law applies. Allow one to three weeks with legal input.
  • Article 21 sets ten minimum risk-management areas. Map each one to an owner and to evidence you can show a supervisor.
  • Build the reporting chain now: early warning within 24 hours, incident notification within 72 hours, final report within one month.
  • The management body must approve the measures, oversee them and complete training. Book board training in the first quarter of the programme.
  • UK organisations are not bound by NIS2 itself, but may be caught if they provide in-scope services in the EU.

What is NIS2 and why does NIS2 implementation matter?

NIS2 is the EU’s second Network and Information Security Directive. It replaced the original NIS Directive and widens both the range of sectors covered and the obligations placed on organisations. Because it is a directive rather than a regulation, it works through national law: Member States had to adopt and publish their transposing measures by 17 October 2024 and apply them from 18 October 2024.

Not every country met that deadline. The European Commission has taken infringement action against Member States that did not notify full transposition, so the national rules, registration portals and supervisory authorities you deal with depend on where you operate. Check the current position in each country on the Commission’s transposition tracker before you plan. The Commission has also proposed targeted amendments to simplify parts of the regime, so keep an eye on whether and when those are adopted.

NIS2 matters because it turns cybersecurity into a governance duty with named accountability, fixed reporting deadlines and significant fines. Even organisations outside its scope feel it through supply chains, as in-scope customers push security requirements down to their suppliers.

This article is general guidance, not legal advice. Whether NIS2 applies to you, and how, depends on the facts and on national law, so take legal advice on your specific position.

Who must comply? NIS2 essential and important entities

NIS2 applies to public or private entities of a type listed in Annex I (sectors of high criticality, such as energy, transport, banking, health, drinking water, digital infrastructure and ICT service management) or Annex II (other critical sectors, such as postal services, waste management, manufacturing of certain products, food, digital providers and research) that provide services or carry out activities in the EU.

The size-cap rule is the starting point: as a general rule, the Directive applies to entities that are at least medium-sized under the EU definition of SMEs. There are important exceptions. Some entities are in scope regardless of size, including providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers, domain name registration services, entities that are the sole provider of an essential service in a Member State, and entities identified as critical under the Critical Entities Resilience Directive. Member States can also designate other entities.

In-scope organisations fall into two groups:

  • Essential entities are, broadly, large organisations in Annex I sectors plus certain entities named in the Directive regardless of size. They face proactive supervision, including inspections and audits.
  • Important entities are other in-scope organisations in Annex I or II. Supervision is mainly after the event, triggered by evidence or an indication of non-compliance.

Both groups have the same core duties under Articles 20, 21 and 23. The difference lies in how closely they are supervised and in the maximum fines.

Does NIS2 apply to UK businesses?

The UK is not bound by NIS2. It left the EU before the Directive was adopted, and the UK continues to rely on its own Network and Information Systems Regulations 2018, overseen by sector regulators and supported by the NCSC’s Cyber Assessment Framework.

NIS2 UK businesses still need to think about it in three situations:

  1. You provide in-scope services in the EU. If you operate through an EU subsidiary or establishment, that entity may be in scope under the national law where it is established.
  2. You are a digital provider without an EU establishment. Certain providers, including cloud computing, data centre, managed service and managed security service providers, DNS providers, online marketplaces, search engines and social networking platforms, that offer services in the EU without being established there must designate a representative in the EU.
  3. Your EU customers are in scope. Article 21 requires them to manage supply chain security, so expect security questionnaires, contract clauses and audit rights.

The UK is also reforming its own regime. The Cyber Security and Resilience Bill was introduced to Parliament in November 2025 to update and extend the NIS Regulations 2018, including to more digital and managed service providers. Check its current status before you plan, because the final requirements and commencement dates depend on its passage and on secondary legislation.

What does NIS2 Article 21 require?

Article 21 requires essential and important entities to take “appropriate and proportionate” technical, operational and organisational measures, based on an all-hazards approach. Proportionality takes account of your exposure to risk, your size, and the likelihood and severity of incidents. The Directive then lists ten areas that the measures must cover as a minimum. For certain digital infrastructure and digital service providers, Commission Implementing Regulation (EU) 2024/2690 sets out more detailed technical and methodological requirements.

The ten NIS2 Article 21 risk-management measures with example evidence
Article 21(2)MeasureExample evidence
(a)Policies on risk analysis and information system securityApproved security policy, risk methodology, current risk register with owners
(b)Incident handlingIncident response plan, severity criteria, incident log, post-incident reviews
(c)Business continuity, backup management, disaster recovery and crisis managementBCP and DR plans, backup restore test results, crisis team contact list
(d)Supply chain securitySupplier inventory with criticality ratings, security clauses, supplier assessments
(e)Security in acquisition, development and maintenance, including vulnerability handling and disclosureSecure development standard, patching SLAs and metrics, vulnerability disclosure policy
(f)Policies and procedures to assess the effectiveness of measuresInternal audit plan, control testing results, security KPIs reported to the board
(g)Basic cyber hygiene practices and cybersecurity trainingHardening baselines, training completion records, phishing exercise results
(h)Cryptography and, where appropriate, encryptionCryptography policy, key management procedure, encryption coverage records
(i)Human resources security, access control and asset managementJoiner-mover-leaver process, access reviews, asset inventory
(j)Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communicationsMFA coverage report, approved communication tools, out-of-band emergency channel

Article 21 also says that an entity that finds it does not comply must take the necessary corrective measures without undue delay. In other words, a known gap with no remediation plan is itself a problem.

How does NIS2 incident reporting work?

Article 23 requires entities to notify their national CSIRT or competent authority of any significant incident: one that has caused, or could cause, severe operational disruption or financial loss, or considerable material or non-material damage to others. The deadlines run from when you become aware of the significant incident:

  1. Early warning within 24 hours, indicating whether the incident is suspected to be caused by unlawful or malicious acts or could have a cross-border impact.
  2. Incident notification within 72 hours, updating the early warning with an initial assessment of severity and impact and, where available, indicators of compromise.
  3. Intermediate reports on request from the CSIRT or authority.
  4. Final report within one month of the incident notification, covering a detailed description, the likely root cause, mitigation measures and any cross-border impact. If the incident is still ongoing, you provide a progress report then and a final report within one month of handling it.

Where appropriate, you must also tell the recipients of your services about significant incidents likely to affect them. The tight timings mean the decision on “is this significant?” has to be made quickly, by people who know the criteria and have authority to report.

What do management bodies have to do under Article 20?

Article 20 makes cybersecurity a leadership duty. Management bodies of essential and important entities must approve the Article 21 measures, oversee their implementation and can be held liable for infringements. Members of the management body must also follow training so that they can identify risks and assess cybersecurity risk-management practices, and entities are encouraged to offer similar training to employees regularly.

In practice, that means board papers that show decisions rather than just updates: approved risk appetite, approved policies, funded remediation and recorded challenge. Supervisors will look for that trail.

NIS2 checklist: step-by-step implementation

Use this NIS2 checklist as the backbone of your programme:

  1. Confirm applicability. Check Annex I and II sector definitions, your size (including linked and partner enterprises) and the size-cap exceptions. Record the decision and the reasoning.
  2. Identify jurisdictions. List each Member State where you are established or provide services, the applicable national law and whether registration is required.
  3. Appoint an accountable owner and agree the management body’s role in approval and oversight.
  4. Run a gap assessment against Article 21, rating each of the ten areas and capturing existing evidence.
  5. Prioritise remediation by risk and by supervisory exposure, with owners, dates and budget.
  6. Define significant-incident criteria and the decision path, and set up reporting templates and contacts for each authority.
  7. Rehearse the reporting timeline with a tabletop exercise that tests the 24-hour and 72-hour steps.
  8. Assess critical suppliers and update contracts with security and notification clauses.
  9. Train the management body and record attendance and content.
  10. Build an evidence library and an effectiveness review cycle so the programme stays current.

How long does NIS2 implementation take?

Scoping usually takes one to three weeks, and a gap assessment typically four to eight weeks depending on the number of entities and countries. Remediation is the long tail: organisations with a mature ISMS often close the main gaps in three to six months, while those starting from a low base should plan for nine to eighteen months.

The main effort drivers are:

  • the number of Member States and national laws involved;
  • whether you are an essential entity facing proactive supervision;
  • the maturity of existing frameworks such as ISO/IEC 27001 or NIST CSF;
  • the size and criticality of your supplier base;
  • the state of asset inventories, logging and detection, which drive your ability to report on time.

Supervision and penalties set the stakes. Where they infringe Article 21 or 23, essential entities face maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the figures are at least EUR 7 million or 1.4%. National laws set the final amounts and may add other measures, including binding instructions and, for essential entities, temporary bans on individuals exercising managerial functions.

Common NIS2 compliance mistakes

  • Assuming you are out of scope because of size, without checking the exceptions or national designations.
  • Treating it as an IT project. Article 20 puts accountability on the management body, so it needs board ownership.
  • Writing policies without evidence. Supervisors ask what you do, not just what you say.
  • Untested reporting. A plan that has never been rehearsed rarely meets a 24-hour deadline.
  • Ignoring suppliers. Article 21(2)(d) expects you to consider the security practices of direct suppliers. Our guide to third-party risk management covers how to do that in proportion.
  • Planning against one country’s rules when you operate in several.

How Anvay approaches NIS2 implementation

NIS2 is an expert-led assessment with Anvay. We work in four steps:

  1. Confirm applicability and scope – sectors, size, exceptions, entities and countries, recorded with clear reasoning for your legal advisers to confirm.
  2. Gap assessment against Article 21 – each of the ten areas rated, with evidence gaps and risks identified.
  3. Remediate and set up reporting – a prioritised plan, significant-incident criteria and a working 24-hour, 72-hour and one-month reporting process.
  4. Train leaders and keep evidence – management body training, board reporting and an evidence library that stays current.

If you want a quick starting view, the free GAPZe assessment’s live ISO/IEC 27001:2022 and NIST CSF 2.0 packs can show where your existing controls overlap with Article 21. GAPZe gives an indicative readiness screening based on your own answers; it is not a certification, an audit opinion or a NIS2 compliance determination.

Anvay's four-step NIS2 approach: 1. Confirm applicability and scope; 2. Gap assessment against Article 21; 3. Remediate and set up reporting; 4. Train leaders and keep evidence
Anvay’s four-step approach to NIS2 implementation, from scope to sustained evidence.

One practical takeaway for NIS2 implementation

If you do only one thing this month, run a 90-minute tabletop exercise on a realistic incident and time how long it takes to decide whether it is significant and who sends the early warning. That single test exposes gaps in scope, criteria, ownership, logging and supplier contacts faster than any document review, and it gives your board something concrete to act on.

— Achal, Anvay

Anvay services for NIS2 compliance

Start with the free GAPZe assessment to see how your current controls compare with ISO/IEC 27001 or NIST CSF 2.0, then talk to us about an expert-led NIS2 assessment through our compliance and assurance service. Our GRC and risk work helps set up ownership, risk registers and board reporting, and our tabletop exercises rehearse the 24-hour and 72-hour reporting steps with your leadership team. For supplier obligations, see our guide to third-party risk management, and for framework overlap, NIST CSF vs ISO 27001. Ready to begin? Book your free GAPZe assessment and 30-minute call.

FAQ

What is the first step in NIS2 implementation?

Confirm whether you are in scope. Check your sector against Annexes I and II of the Directive, your size under the EU SME definition, and the exceptions that bring some entities into scope regardless of size. Then identify which national laws apply. Record the decision, because everything else, including supervision and fines, depends on it.

What are the NIS2 incident reporting deadlines?

For a significant incident, you must send an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month of the notification. Authorities can also request intermediate reports. If the incident is still ongoing at one month, you send a progress report and a final report later.

Does NIS2 apply to UK businesses?

The UK is not bound by NIS2, and UK organisations follow the NIS Regulations 2018 and any reforms from the Cyber Security and Resilience Bill. However, UK businesses can be caught if they provide in-scope services in the EU, through an EU establishment or as certain digital providers that must appoint an EU representative. In-scope EU customers will also pass requirements to UK suppliers.

What is the difference between essential and important entities under NIS2?

Both must meet the same Article 21 risk-management and Article 23 reporting duties. Essential entities, broadly larger organisations in Annex I sectors plus certain named entities, face proactive supervision and maximum fines of at least EUR 10 million or 2% of worldwide turnover. Important entities face mainly after-the-event supervision and maximum fines of at least EUR 7 million or 1.4%.

Can ISO 27001 certification prove NIS2 compliance?

Not on its own. ISO/IEC 27001 provides a strong management system and covers much of Article 21, but NIS2 adds specific duties such as fixed incident reporting deadlines, management body training and supply chain expectations set by national law. Use your ISMS as the foundation and map it to the ten Article 21 areas to find the remaining gaps.

Sources

Primary references and standards: this article draws on the text of the NIS2 Directive, its implementing regulation, European Commission guidance and UK government and NCSC material, as checked in October 2026.

Back to all insights

Make your next step clearer.

Tell us what you are working on or where you feel unsure. We will talk it through with you and suggest practical support that fits.

Discuss your requirements