NIS2 and the suppliers you are now answerable for.
NIS2 is the EU directive that replaced the original NIS Directive and widened both who is regulated and what they must do. Its most under-read provision is Article 21(2)(d), which makes an entity responsible for the security of its direct suppliers and service providers. This page covers what NIS2 is, who falls in scope, what it requires, what it means for UK organisations, and the supply-chain obligations that turn a compliance exercise into a continuing operational commitment.
Last reviewed
What is NIS2?
NIS2 is Directive (EU) 2022/2555, adopted on 14 December 2022. It replaced the 2016 NIS Directive, whose weakness was inconsistency: member states interpreted scope so differently that the same kind of company could be regulated in one country and untouched in another.
NIS2 addresses that in four ways:
- Wider scope. More sectors, and a size-based rule that captures organisations automatically rather than leaving national regulators to nominate them.
- Named minimum measures. Article 21 sets out the risk-management measures entities must adopt, rather than requiring “appropriate” security in the abstract.
- Hard reporting deadlines. A 24-hour early warning, measured in hours rather than left to national discretion.
- Management accountability. Management bodies must approve and oversee the measures, and can be held personally liable.
It is a directive rather than a regulation, so it does not apply directly. Each member state transposes it into national law, and the transposition deadline was 17 October 2024. That is why NIS2 obligations differ in detail country by country while sharing a common floor — and why a group operating across several member states is dealing with several implementations of the same text.
NIS2 scope: who is actually covered
Scope is a function of three things: sector, size, and a set of exceptions.
NIS2 splits regulated organisations into essential entities (Annex I) and important entities (Annex II). Both must meet the same Article 21 requirements; what differs is supervision — essential entities face proactive supervision, important entities are supervised reactively, after evidence of a problem — and the level of fines.
Essential entities (Annex I)
Energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business to business), public administration and space.
Important entities (Annex II)
Postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, computer, electronic and optical products, machinery and equipment, motor vehicles and other transport equipment), digital providers such as online marketplaces, search engines and social networking platforms, and research organisations.
The size rule
In general the directive applies to medium-sized and larger organisations in those sectors — broadly 50 or more staff, or annual turnover and balance sheet total above €10 million. But size is not the whole test: certain entities are in scope regardless of headcount, including some providers of public electronic communications networks, trust service providers, DNS service providers and TLD name registries, and sole providers of a critical service in a member state.
The practical consequence is that “we are too small” is a conclusion to check rather than assume, and that the entity-by-entity analysis has to be done per member state where a group has legal entities in several.
Our NIS2 scope checker walks the Article 2 and Article 3 tests in four questions, including the size-independent cases and the essential-versus-important split.
NIS2 and the UK
NIS2 requirements the Article 21 measures
Article 21(2) names the minimum measures. They are deliberately baseline rather than exhaustive — a floor, not a ceiling.
- Risk analysis and information system security policiesDocumented policies, grounded in an actual assessment of risk.
- Incident handlingDetection, response and recovery processes, exercised rather than written.
- Business continuity and crisis managementBackup management, disaster recovery, and a crisis-management capability.
- Supply chain securitySecurity-related aspects of the relationship with each direct supplier and service provider. The obligation attaches to the relationship, not just to your own perimeter — see below.
- Security in acquisition, development and maintenanceIncluding vulnerability handling and disclosure across the systems you buy and build.
- Policies to assess effectivenessMeasuring whether the risk-management measures work, not merely that they exist.
- Cyber hygiene and security trainingBasic practice, applied consistently, including at management level.
- Cryptography and encryptionPolicies on the use of cryptography, and where appropriate encryption.
- Human resources security, access control and asset managementWho has access to what, on what basis, and what you own.
- Multi-factor authentication and secured communicationsMFA or continuous authentication, secured voice, video and text, and secured emergency communications.
Article 21(2)(d): the supply chain duty the expensive one
One line in the directive creates more sustained work than the other nine measures combined.
Article 21(2)(d) requires measures covering “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Article 21(3) sharpens it: entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of the products and cybersecurity practices of those suppliers.
Read carefully, that language does three things.
- It is per supplier, not portfolio-wide. “Each direct supplier” rules out a single generic policy applied uniformly. The assessment has to be specific enough to reflect what that supplier actually does for you.
- It covers practices, not just products. “Cybersecurity practices” is an assessment of how a supplier operates, which cannot be answered by a certificate alone.
- It is continuous by implication. A vulnerability is a live property. An annual questionnaire describes one day and says nothing about the 364 that follow.
This is where NIS2 programmes tend to stall. The measures that apply to your own estate are bounded — you know what you own. Supplier obligations scale with the number of suppliers, and for most in-scope organisations that is hundreds of relationships, each needing an assessment specific to it and a view that stays current between assessments. Doing that with a questionnaire cycle and a spreadsheet is where the headcount goes.
Incident reporting deadlines
Article 23 sets a staged timetable for significant incidents. The clock starts when you become aware of the incident, not when you finish investigating it.
| Stage | Deadline | What it must contain |
|---|---|---|
| Early warning | 24 hours | Notice that a significant incident has occurred, whether it may have been unlawful or malicious, and whether it could have cross-border impact. |
| Incident notification | 72 hours | An update on the early warning, with an initial assessment of severity, impact and indicators of compromise where available. |
| Final report | One month | A detailed description, the type of threat or root cause, mitigation applied, and any cross-border impact. |
Notification goes to the relevant national authority or CSIRT. A 24-hour early warning is short enough that it has to be a rehearsed process rather than a decision made under pressure — and if the incident originates at a supplier, you are dependent on that supplier telling you in time to meet a deadline that is yours, not theirs.
Penalties and management liability
Article 34 requires member states to provide for administrative fines up to at least these levels — whichever is higher, the amount or the percentage.
A NIS2 checklist start here
Not a compliance guarantee — a sequence that establishes whether you have a problem and how large it is.
- Determine scope, entity by entity and state by stateCheck each legal entity against the Annex I and Annex II sectors and the size thresholds, in each member state where it operates. Record the reasoning, not just the conclusion — you will be asked to justify it.
- Identify which national transposition appliesThe directive is the floor; the obligation that binds you is national law, and implementations differ in detail, deadlines and regulator.
- Gap-assess against the ten Article 21 measuresAssess what exists, what is documented, and what is evidenced. Those are three different states and only the third survives supervision.
- Build the direct-supplier registerList every direct supplier and service provider, what each one accesses or processes, and how critical it is to your service. Most organisations discover at this step that no single authoritative list exists.
- Assess each supplier specificallyPer-supplier, covering their vulnerabilities and cybersecurity practices — not one questionnaire sent to everyone. Prioritise by what the supplier can reach.
- Put the 24-hour reporting process in place and rehearse itIncluding how you learn about an incident that starts at a supplier, which is the path most likely to breach the deadline.
- Get management sign-off, in writingThe management body has to approve and oversee the measures. Minute it, because personal liability makes the record of who approved what a material document.
NIS2, answered.
Does NIS2 apply in the UK?
What is the difference between essential and important entities?
When did NIS2 come into force?
What does NIS2 require for supply chain security?
How quickly must an incident be reported under NIS2?
Is NIS2 the same as DORA?
Are small companies exempt from NIS2?
Where to go next.
Article 21(2)(d) says each direct supplier.
Book a 30-minute call and we will show you a per-supplier NIS2 evidence trail on your own vendors — assessed, scored and kept current between questionnaires.