NIS 2 came into force across the EU on 17th October 2024. A lot has changed since then.
The UK is no longer sitting this one out. A new UK law modelled closely on NIS 2 is now working its way through Parliament, and it will bring many more UK businesses into scope.
Whether you operate in the UK, supply customers in the EU, or simply want to stay ahead of emerging regulation, here’s what NIS 2 and the new Cyber Security & Resilience Bill mean for your organisation, and the key cyber security metrics you should be tracking.
Table of Contents
A quick recap: What is NIS 2?
The NIS 2 Directive is a legislative act that aims to enhance the cybersecurity capability of EU member states.
NIS 2 is the EU’s update to its original Network and Information Security (NIS) Directive. The NIS Directive dates back to 2016 and, in practice, didn’t land consistently across member states. NIS 2 tightens things up and casts a much wider net.
It expands coverage from 7 sectors to 18, bringing in medium- to large-sized organisations in sectors like telecoms, digital infrastructure, and managed IT services alongside the usual suspects of energy, transport, health and finance. Any mid-sized organisation with 50+ employees and either €10m+ turnover or a €10m+ balance sheet is included in the scope of NIS 2. For large organisations, it rises to 250+ employees and €50m+ turnover (or a €43m+ balance sheet).
The penalties are real. Essential entities can be fined up to €10m or 2% of global annual turnover, whichever is higher, and management teams can be held personally accountable for negligence following a security incident.
If you’re a UK business providing services into the EU, NIS 2 already applies to you, and enforcement is genuinely picking up. As of January 2026, 23 of the 27 EU member states have fully implemented NIS 2 into national law, with others, including France, Spain and Ireland, still finishing the job through 2026. If you’re not based in the EU but offer services there, you’re still expected to appoint an EU representative and meet the same obligations as an EU entity.
Is the UK implementing its own version of NIS 2?
The UK government previously said it wouldn’t be implementing NIS 2, but has since introduced a new cyber security bill to bring major changes to the UK’s outdated security legislation.
The Cyber Security and Resilience Bill was introduced to the House of Commons on 12th November 2025. It’s the UK’s own answer to NIS 2: not a copy-paste of the EU directive, but a Bill built to align closely with it while reflecting some distinctly UK priorities. It completed its committee stage in the House of Commons by early March 2026, and Royal Assent is expected in late 2026, with phased implementation likely running through to 2028.
What does it actually do? It amends and expands the existing NIS Regulations 2018 rather than replacing them outright. Key changes include:
- Wider scope: The Bill introduces new categories of regulated entity, including data centres above certain capacity thresholds, load controllers, critical suppliers that provide essential services to regulated organisations and, notably, managed service providers, which puts much of the MSP world more directly in scope than before.
- Bigger penalties: A standard maximum of £10m or 2% of global turnover, and a higher tier of £17m or 4% of worldwide turnover for the most serious breaches, whichever figure is higher in each case.
- Faster, more structured reporting: A two-stage process with an initial notification to the regulator within 24 hours of a significant incident, followed by a full report within 72 hours, with parallel reporting to the National Cyber Security Centre.
- Aligning with CAF: Organisations in scope are expected to have their security obligations rooted in the NCSC’s Cyber Assessment Framework (CAF), moving it from a voluntary good-practice framework to a legal requirement. The CAF is built around four objectives, such as managing security risk, protecting against cyberattack, detecting cybersecurity events, and minimising the impact of incidents.
If you operate in a regulated sector, or you supply into one, the direction of travel is clear even before the Bill receives Royal Assent. The reporting timelines, the scope categories and the fines regime are already drafted. Waiting for the final vote before you start preparing is, frankly, the most expensive way to approach this.
How do you stay compliant with NIS 2?
NIS 2 stipulates a number of key areas where organisations must be compliant.
- Duty of care. You must carry out a risk assessment. Based on this risk assessment you should take measures to guarantee business continuity as much as possible and protect the information used.
- Duty to report. Where incidents might disrupt the provision of essential services, you have the duty to report incidents to the supervising authority within 24 hours. Whether an incident is subject to the duty to report depends on several factors such as the number affected, the duration of the disruption, and the potential financial losses.
- Supervision. Organisations in some sectors covered by the NIS2 directive will be under supervision. The supervisory body will look at compliance with the obligations of the directive, such as the duty of care and the duty to report.
To ensure compliance with these areas, it’s imperative for board-level reporting to encompass a comprehensive set of strategic key performance indicators (KPIs). Organisations that are more mature in their compliance structure may also look at Key Risk Indicators (KRIs).
These metrics serve as essential tools to assess risk and provide evidence to the board about the organisation’s compliance, as well as carry out assurance of critical third-party suppliers.
Examples of useful KPIs
On the KPI side, metrics that can support demonstration of NIS 2 compliance include:
- Number of security incidents. Measure the number of security incidents and breaches that have occurred within a specific period. Fewer incidents over time is the clearest signal that your security investment is working.
- Patch management compliance. What percentage of critical vulnerabilities are you patching, and how fast? It’s a clear indicator of proactive security maintenance and compliance.
- Employee training completion rate. Track the percentage of employees who have completed mandatory cybersecurity training. A high completion rate indicates a culture of security awareness and compliance with training requirements.
- Third-Party threat assessment. How many of your critical vendors have actually been assessed for cyber risk? Ensure vendors comply with your supply chain security requirements.
- Incident response time. How long does it take you to detect, respond to, and resolve an incident once it happens? A lower incident response time indicates efficient incident management processes.
Getting ready for NIS 2 & Cyber Security & Resilience Bill
If you started your NIS 2 work back in 2024, you’ve likely made real progress against several of these already. That’s not wasted effort. But it’s worth running back through the list rather than assuming a project signed off in 2024 still covers what matters in 2026.
Whether you’re bracing for the UK’s Cyber Security and Resilience Bill, or already caught up with NIS 2, or simply trying to keep up your security posture, get in touch with us for a Security Exposure Review to work out where you actually stand, what’s missing, and what a realistic roadmap looks like.


