[Home](/)/[Resources](/resources)/UK NIS Regulations

UKCybersecurityRegulation guide

# UK NIS Regulations — Network and Information Systems Security

The UK Network and Information Systems (NIS) Regulations 2018 implement the original EU NIS Directive in UK law post-Brexit, with amendments under the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 expanding scope. While primarily targeting operators of essential services and digital service providers, NIS creates supply chain obligations that affect hardware and IoT product suppliers to regulated sectors.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fuk-nis-regulations)

At a glance

Legislation

UK NIS Regulations 2018

Regulator

NCSC + sector competent authorities

Framework

NCSC CAF

Max OES penalty

£17M

Related regime

PSTI Act 2022

## Scope: OES, DSPs, and supply chain implications

Hardware manufacturers are rarely the primary target of UK NIS enforcement — but they are consistently in scope through the supply chains of organisations that are. Understanding who is directly regulated and how that flows to suppliers is the starting point for any NIS compliance assessment.

### Operators of Essential Services (OES)

OES are directly regulated under UK NIS. Covered sectors: energy (electricity generation, transmission, distribution; oil and gas), transport (air, rail, road, maritime), health (NHS trusts and equivalents), drinking water supply, and digital infrastructure (internet exchange points, DNS, TLD registries). OES must implement appropriate and proportionate security measures and report significant incidents.

### Digital Service Providers (DSPs)

DSPs — online marketplaces, online search engines, and cloud computing services with more than 50 employees or €10M turnover — have lighter-touch obligations. They must take appropriate security measures and report significant incidents to the ICO as competent authority for DSPs.

### Supply chain: obligations flowing to hardware suppliers

While hardware manufacturers are not directly regulated by UK NIS unless they operate essential services themselves, OES procurement requirements flow down contractually. An OES procuring connected hardware for its critical systems will impose CAF-aligned security requirements on the supplier. Demonstrating CAF alignment is increasingly a commercial prerequisite in regulated sector tenders.

### PSTI Act: separate regime for consumer IoT

The Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and its 2024 regulations create direct obligations for consumer IoT manufacturers (minimum security requirements, no default passwords, vulnerability disclosure policy, defined support periods). PSTI is distinct from NIS but overlaps in the cybersecurity controls required.

## CAF: the Cyber Assessment Framework

The NCSC Cyber Assessment Framework is the primary tool used by competent authorities to assess OES compliance. It comprises 14 security outcomes grouped into four top-level objectives. Hardware suppliers whose products are deployed in OES environments should understand which CAF indicators their products affect — and be prepared to provide evidence of alignment in procurement and audit processes.

01

Objective A — Managing security risk: governance structures, risk management processes, asset management, and supply chain security. Hardware suppliers must demonstrate they manage cyber risk in ways that protect the OES customer's critical systems.

02

Objective B — Protecting against cyber attack: service protection policies, identity and access management, data security, system security, resilient network architecture, and staff awareness. Hardware devices used in OES environments must meet these baseline controls.

03

Objective C — Detecting cyber security events: security monitoring, anomaly detection, and event discovery capability. Connected hardware deployed in critical infrastructure should support logging and monitoring integration.

04

Objective D — Minimising the impact of incidents: response and recovery planning, improvements from incidents, and communications. Suppliers should maintain incident response plans that cover devices deployed in OES environments.

## Incident reporting obligations

UK NIS imposes mandatory incident reporting on OES. While hardware suppliers are not direct reporters under the regulations, a security incident originating in or affecting a supplier's product will trigger OES reporting obligations. Suppliers should understand the reporting chain and their contractual obligations to support it.

### OES incident reporting obligations

OES must report significant incidents to their sector-specific competent authority: Ofgem for energy, the Civil Aviation Authority for air transport, the Department for Transport for rail and road, the Maritime and Coastguard Agency for maritime, DHSC for health, and the Drinking Water Inspectorate for water. The ICO is competent authority for DSPs.

### What constitutes a significant incident

An incident is significant if it has a substantial impact on the continuity of the essential service. Factors considered: number of users affected, duration of the incident, geographic spread, degree of disruption to the service, and the extent to which the incident affects economic and social activities. There is no single threshold — competent authorities apply judgement.

### 72-hour reporting window

OES must notify the competent authority without undue delay and in any event within 72 hours of becoming aware of a significant incident. Hardware suppliers whose devices are implicated in an OES incident may be required to provide technical information to support the notification. Downstream incident response obligations should be specified in supply contracts.

### Cross-border coordination post-Brexit

Before Brexit, cross-border incident coordination used EU NIS mechanisms via ENISA and the NIS Cooperation Group. Post-Brexit, UK OES report to NCSC (which acts as the UK CSIRT) and coordinate bilaterally with EU counterparts. Dual UK/EU operators must comply with both regimes independently — there is no mutual recognition of incident reports.

## UK NIS vs EU NIS2 divergence

Since Brexit, UK NIS and EU NIS2 have diverged materially. For hardware manufacturers selling into both markets, understanding the differences is essential — compliance with one does not imply compliance with the other.

### Scope differences: UK NIS vs EU NIS2

EU NIS2 (effective October 2024) significantly expands sector scope to include manufacturing, food, postal services, chemicals, and waste management. UK NIS has not yet expanded to these sectors. UK consultation on expansion to managed service providers (MSPs) is ongoing but not yet enacted. Hardware manufacturers selling only in the UK are not subject to NIS2 obligations.

### Threshold differences

EU NIS2 uses size-based thresholds (medium and large enterprises in covered sectors). UK NIS identifies specific OES by name through a separate designation process. The approaches differ: NIS2 captures more entities automatically; UK NIS requires positive designation. This creates different compliance obligations for the same organisation depending on jurisdiction.

### Penalty regimes

EU NIS2 penalties can reach €10M or 2% of global turnover for essential entities. UK NIS maximum fines are currently £17M for OES and £8.5M for DSPs — lower than NIS2 in most scenarios. The UK is reviewing penalty levels as part of its NIS reform consultation.

### Implications for dual UK/EU market suppliers

Suppliers selling into both markets must comply with PSTI (UK) and the EU Cyber Resilience Act (EU CRA, applicable from late 2027) independently, as well as supporting OES/NIS2-regulated customers in both markets. The control frameworks have significant overlap but are not identical — a unified security documentation approach is recommended.

## Frequently asked questions

### Are hardware manufacturers directly covered by UK NIS Regulations?

Not directly, unless the manufacturer itself operates an essential service or is a designated digital service provider. However, hardware manufacturers supplying connected devices to OES-regulated organisations face indirect obligations through procurement and contractual requirements. OES are required to manage supply chain security under CAF Objective A, meaning they impose security requirements on hardware suppliers as a condition of procurement. Demonstrating CAF-aligned security controls is increasingly necessary to win contracts in regulated sectors.

### How does UK NIS interact with the PSTI Act for IoT products?

UK NIS and the PSTI Act are separate regulatory regimes with different scope and enforcement mechanisms. PSTI directly regulates manufacturers, importers, and distributors of consumer connectable products sold in the UK — it is a product safety regulation with mandatory minimum security requirements (no universal default passwords, a published vulnerability disclosure policy, and transparency about the minimum security update period). UK NIS regulates operators of essential services and digital service providers. A connected product deployed in an OES environment must comply with both: PSTI for the product itself, and NIS supply chain requirements as specified by the OES customer.

### What is the NCSC CAF and do hardware suppliers need to comply with it?

The NCSC Cyber Assessment Framework (CAF) is a set of 14 security outcomes across four objectives used by competent authorities to assess OES compliance with UK NIS. Hardware suppliers are not directly assessed against the CAF by regulators. However, OES customers use the CAF as a procurement standard and may require suppliers to complete CAF-aligned self-assessments or provide evidence against specific CAF indicators. Hardware suppliers should familiarise themselves with CAF Objective B (protecting against attack) and CAF Objective A supply chain indicators as these directly reference product and supplier security.

### How has UK NIS diverged from EU NIS2 since Brexit?

EU NIS2 (transposed by EU member states from October 2024) substantially expanded the scope, thresholds, security requirements, and penalties of the original NIS Directive. The UK has not matched this expansion: UK NIS retains the original sector scope, designation-based OES identification, and lower penalty caps. Key divergences include: EU NIS2 covers manufacturing and food sectors (UK NIS does not); EU NIS2 uses automatic size-based thresholds (UK NIS uses named designation); EU NIS2 penalties are higher. UK hardware manufacturers supplying EU markets must comply with EU NIS2 customer requirements independently of UK NIS obligations.

**Disclaimer:** This page is an educational resource only and does not constitute legal advice. NIS compliance obligations depend on your organisation's specific role, sector, and the nature of products and services supplied. Consult qualified legal and cybersecurity advisers for your particular circumstances.

🇬🇧 UK roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇬🇧 UK compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $199](/courses/37-uk-cyber-security-resilience-bill-connected-devices)[Prefer to read? Get the book — $24.99](/books/37-uk-cyber-security-resilience-bill-connected-devices)

Related guides

*   [UK PSTI Security RequirementsComplete guide to UK PSTI Act: security requirements for connectable products, compliance obligations, statement of compliance,…](/guides/uk-psti-security)
*   [UK GDPR for Connected ProductsUK GDPR applies to any connected hardware product collecting or transmitting personal data about UK users.](/guides/uk-gdpr-connected-products)
*   [EU NIS2 Directive for HardwareNIS2 Directive (EU) 2022/2555 extends cybersecurity obligations to manufacturers of connected products and critical infrastruct…](/guides/eu-nis2-directive-hardware)
*   [UK OPSS Market SurveillanceComplete guide to OPSS (Office for Product Safety and Standards) market surveillance in Great Britain: enforcement powers, comp…](/guides/uk-opss-market-surveillance)