NIS2

NIS2 compliance support for UK organisations with EU operations or EU customers. Gap analysis, incident reporting readiness and supply chain evidence.

Service Details

NIS2 compliance matters to you if you operate in the EU or sell to organisations that do, and Falx gives you a clear answer on whether it applies, then the controls and evidence to meet it. The Network and Information Security Directive (NIS2) is EU law that sets cyber security, incident reporting and supply chain duties for organisations in 18 critical sectors.

We check your scope, assess you against the ten risk management measures, fix the gaps that carry regulatory risk and get your team ready for the 24-hour reporting clock. The work sits within our governance services, alongside the other frameworks you may already be working towards.

INFO

NIS2 is not UK law. UK organisations are caught through EU operations, EU-facing digital services, or EU customers that must secure their supply chain.


Who NIS2 applies to

NIS2 covers 18 sectors split across two annexes. Medium-sized and larger organisations in these sectors are in scope, and some, such as DNS providers and top-level domain registries, are in scope whatever their size.

Highly critical sectors

  • Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space
  • Large organisations here are usually essential entities, with proactive supervision
  • Fines of up to 10 million euros or 2% of worldwide turnover

Other critical sectors

  • Postal and courier, waste management, chemicals, food, manufacturing, digital providers, research
  • Organisations here, and medium-sized ones in the highly critical sectors, are usually important entities
  • Fines of up to 7 million euros or 1.4% of worldwide turnover

Does NIS2 apply to UK organisations?

NIS2 reaches UK organisations in three ways. If you have operations in an EU member state in a covered sector, that country’s NIS2 law applies to them. If you provide certain digital services into the EU, such as managed services, managed security, cloud or data centre services, you may need to name a representative in the EU and meet the rules directly.

The most common route is the supply chain. EU customers in scope must manage the security risk of their suppliers, so they will ask you for evidence of your controls, incident processes and contract terms.

At home, the Network and Information Systems Regulations 2018 still apply to UK operators of essential services and certain digital service providers. The Cyber Security and Resilience Bill proposes to update that regime. Much of the same work, such as risk management, incident reporting and supplier security, supports both.

How size decides your category

  • Large: 250 or more staff, or annual turnover above 50 million euros and a balance sheet above 43 million euros.
  • Medium: 50 or more staff, or annual turnover and balance sheet both above 10 million euros.

Large organisations in the highly critical sectors are usually essential entities. Most others in scope are important entities. Each member state applies its own law, so check the rules in the countries where you operate.


What NIS2 requires

The duties fall into three areas. Each one needs to be working and evidenced, not just written down.

  1. Risk management measures — Article 21 sets ten areas: risk analysis and security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, testing whether your controls work, basic cyber hygiene and training, cryptography and encryption, staff security with access control and asset management, and multi-factor authentication with secure communications.
  2. Incident reporting — For a significant incident, you send an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month.
  3. Management accountability — Your management body must approve and oversee the security measures, take part in training, and can be held liable for failures.

NIS2 replaced the original NIS Directive of 2016. It widened the sectors covered, added the supply chain duties and management liability, and tightened the reporting timeline.


Make your business NIS2 compliant

If NIS2 applies to you, incident reporting, supplier security and board accountability all need to be live and evidenced. If it reaches you through a customer, you need answers ready before the security questionnaire arrives.

Our consultants assess where you stand against all ten risk management measures, close the gaps that carry regulatory risk, and prepare your team for the 24-hour reporting clock.

Three colleagues working at laptops in a bright open-plan office

How we help you meet NIS2

From scope check to evidence your regulator or customer will accept:

Scope and Gap Analysis

We confirm whether and how NIS2 applies, then assess you against the ten risk management measures and rank the gaps by risk.

Remediation

We close the gaps in policy, process and technology, from access control and encryption to backups and vulnerability handling.

Incident Reporting Readiness

Clear criteria for significant incidents, named owners and a tested process to meet the 24-hour, 72-hour and one-month deadlines.

Supply Chain and Evidence

Supplier risk reviews, contract terms and an evidence pack your board, regulator or EU customers can rely on.

Testing and ongoing work come from our wider services. Risk management keeps your risk register current, security posture reviews and penetration testing show whether controls work, and identity and access covers multi-factor authentication and access control. Our compliance support team keeps the evidence up to date.


NIS2 overlaps with other regimes, so one set of controls can serve several. Financial firms in the EU should look at DORA, which takes precedence over NIS2 for financial entities, and FCA requirements at home. ISO 27001, the NIST framework and CIS Controls give you a structure for the risk measures, while Cyber Essentials covers basic hygiene and GDPR shares the breach reporting mindset. Card payments bring in PCI-DSS.

Our NIS2 vs NIST vs CIS vs DORA comparison maps the main regimes side by side. For the wider picture, see our end-to-end compliance programme and the sector pages for financial services, insurance and manufacturing.


Frequently asked questions

Find out where NIS2 leaves you

Tell us where you operate and who your EU customers are. You get a straight answer on whether NIS2 applies, and a prioritised list of what to fix if it does.