Network and Information Systems Regulations 2018

United KingdomCritical Infrastructure2018
ByDecipherU Editorial

The UK NIS Regulations implement cybersecurity requirements for operators of essential services (OES) and relevant digital service providers (RDSPs). The regulations require appropriate security measures and incident notification to the relevant competent authority. The UK is updating these regulations to align with NIS2 principles through the Cyber Security and Resilience Bill.

Quick Reference

EnactedMay 10, 2018
Last AmendedCyber Security and Resilience Bill introduced 2024
Enforcement BodySector-specific competent authorities (Ofgem, Ofcom, etc.), NCSC provides technical guidance
PenaltiesUp to 17 million GBP for operators of essential services
Applicable ToOperators of essential services (energy, transport, health, water, digital infrastructure) and relevant digital service providers

Key Requirements

Regulation 10 (Duties of operators of essential services)

OES must take appropriate and proportionate technical and organizational measures to manage risks posed to the security of their network and information systems

Regulation 11 (Duty to report incidents)

OES must notify the competent authority of any incident having a significant impact on the continuity of the essential service

Regulation 12 (Duties of relevant digital service providers)

RDSPs must identify and take appropriate measures to manage risks, including incident handling, business continuity, and monitoring

How Does UK NIS Regulations Affect Cybersecurity Careers?

Cybersecurity professionals at UK essential services operators work under these regulations. The upcoming Cyber Security and Resilience Bill will expand requirements, creating new compliance roles. GRC analysts in UK critical infrastructure must track both current NIS Regulations and the proposed updates.

Cybersecurity Roles That Work With UK NIS Regulations

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of UK NIS Regulations at the official source: https://www.legislation.gov.uk/uksi/2018/506/contents/made

Frequently Asked Questions

The UK NIS Regulations implement cybersecurity requirements for operators of essential services (OES) and relevant digital service providers (RDSPs). The regulations require appropriate security measures and incident notification to the relevant competent authority. The UK is updating these regulations to align with NIS2 principles through the Cyber Security and Resilience Bill.

Cybersecurity professionals at UK essential services operators work under these regulations. The upcoming Cyber Security and Resilience Bill will expand requirements, creating new compliance roles. GRC analysts in UK critical infrastructure must track both current NIS Regulations and the proposed updates.

Up to 17 million GBP for operators of essential services

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?