NIS2 and UK Suppliers: What Changes When Your Client Is in the EU

NIS2 does not apply to a UK company directly, and it will still land on your desk if you supply an in-scope European organisation. The directive made supply chain security an explicit obligation for the entities it covers, so those entities push requirements down their contracts. Member states had until 17 October 2024 to bring it into national law, and the questionnaires started arriving shortly afterwards.
Who NIS2 actually covers
NIS2 applies to medium and large organisations in sectors the directive lists as essential or important, which is a far wider net than the original NIS regulations. Energy, transport, banking, health, drinking water and digital infrastructure sit in the first group. The second adds postal services, waste management, chemicals, food production, manufacturing of medical devices and digital providers. If your customer runs a factory in Ireland or a logistics operation in the Netherlands, they are likely to be in scope even if they never thought of themselves as a technology business. ENISA has published technical implementation guidance for the digital sector, which is the clearest description of what the security measures mean in practice.
How it reaches a UK supplier
The pressure arrives through Article 21, which requires in-scope entities to manage security risks in their supply chains and in their relationships with direct suppliers. In commercial terms that means your customer must be able to show their regulator that they assessed you. What arrives is usually a questionnaire, a request for evidence of testing, and a contract amendment covering incident notification timescales. The reporting clock matters here: an entity has 24 hours to send an early warning about a significant incident and 72 hours to follow with a fuller notification, so any contract you sign will pass a shorter deadline to you.
“Suppliers keep telling me NIS2 is not their problem because they are outside the EU. Then a customer sends a questionnaire with a renewal date attached, and suddenly it is a sales problem rather than a compliance one. Get your evidence in order while you can choose the timing, because doing it under contract pressure costs more and looks worse.”
William Fieldhouse, Director, Aardwolf Security Ltd

The evidence buyers ask for
You should expect to hand over documents rather than assurances. The common requests are a current penetration test report or an executive summary of one, a patching policy with deadlines, an incident response plan naming who calls whom, and proof of multi-factor authentication across remote access. Certification helps but rarely satisfies on its own, because NIS2 asks about your risk management rather than a control checklist. Where a customer asks for testing evidence and you have none, ask for a penetration testing quoteearly enough that the report exists before the contract review, since retesting after remediation adds several weeks to the timeline.
Getting ahead of the questionnaire
Treat the first questionnaire as the template for every one that follows. Build a small evidence pack and keep it current: scope of your last test with dates, a remediation summary showing what was fixed and when, your business continuity arrangements, and a named security contact who answers within a working day. Review it quarterly. When you compare the best penetration testing companies for this kind of work, ask whether the report is written to be shared with a customer, because a document full of raw scanner output is not something you will want to send to a buyer.
Frequently asked questions about NIS2 and UK firms
These questions come up as soon as an EU customer raises the subject.
Will the UK adopt something similar?
The government has signalled its own reform of network and information systems rules, and the direction of travel matches NIS2. Preparing for a customer’s requirements now leaves you in a reasonable position either way.
Does an ISO 27001 certificate satisfy NIS2?
It helps and it does not settle the matter. Certification demonstrates a management system. Customers still ask for technical evidence about your own environment, particularly testing results and patching performance.





