UK Statutory Instrument SI 2018 United Kingdom

Network and Information Systems Regulations 2018

These Regulations implement Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the Union (OJ No L194, 19.7.2016, p1).

Enforced by
ICO, Ofgem, Ofcom, Ofwat, UREGNI
Status
In Force
Penalty ceiling
Prosecution 1 of 19 obligations carry a fine up to £17,500,000. 18 have no criminal penalty — flagged in the list below.

Does it bind you?

Business-side roles with duties under this instrument.

Any Person8 Operator2

Plus 9 duties on the regulator, Crown ministers and public bodies — folded into the section list below.

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Any Person — also bound by 2340 other Acts
Operator — also bound by 746 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

Part 1

Introduction

0 of 1 section shown
1 other section in this Part — procedural and definitional
Part 2

The National Framework

5 of 6 sections shown
s.003 Designation of national competent authorities (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Regulators must provide guidance and maintain lists of essential servicesStatutory regulator
s.004 Designation of the single point of contact (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • GCHQ (SPOC) must cooperate with enforcement authoritiesStatutory regulator
s.005 Designation of computer security incident response team (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • GCHQ (as CSIRT) must monitor and support UK businesses against cyber incidentsStatutory regulator
s.006 Information sharing – enforcement authorities (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Enforcement authorities may share your information with other bodiesStatutory regulator
s.007 Information sharing – Northern Ireland (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Northern Ireland Departments and regulators may share NIS informationCrown / Minister / Government department
1 other section in this Part — procedural and definitional
s.002 The NIS national strategy
Part 3

Operators of essential services

4 of 5 sections shown
s.008 Nomination by an OES of a person to act on its behalf in the United Kingdom Regulated
  • Nominate a UK representative for essential servicesAny Person
s.008 Identification of operators of essential services (opens in a new tab) Regulated
  • Notify the competent authority if you are an operator of essential servicesAny Person
s.010 The security duties of operators of essential services (opens in a new tab) Regulated
  • Manage and secure network systems for essential servicesAny Person
s.011 The duty to notify incidents (opens in a new tab) Regulated
  • Notify your regulator of significant service disruptionsAny Person
1 other section in this Part — procedural and definitional
Part 4

Digital Services

3 of 4 sections shown
s.012 Relevant digital service providers (opens in a new tab) Prosecution
  • Secure network systems and notify the ICO of substantial incidentsOperator

Fine up to £17,500,000

s.014 Representatives of digital service providers established outside the United Kingdom Regulated
  • Appoint a UK representative for overseas digital servicesOperator
s.014 Registration with the Information Commissioner (opens in a new tab) Regulated
  • Register your business as a relevant digital service provider (RDSP)Any Person
1 other section in this Part — procedural and definitional
Part 5

Enforcement and penalties

5 of 9 sections shown
s.015 Information notices (opens in a new tab) Regulated
  • Respond to formal Information Notices from regulatorsAny Person
s.017 Enforcement notices for breach of duties (opens in a new tab) Regulated
  • Comply with enforcement notices regarding digital and network securityAny Person
s.019 Appeal by an OES or RDSP to the First-tier Tribunal Regulated
Other duties (1) — Crown / regulator
  • Tribunal must hear appeals against regulator decisions under NIS RegulationsTribunal / Court
s.019 Decision of the First-tier Tribunal Regulated
Other duties (1) — Crown / regulator
  • Tribunal must determine appeals against NIS enforcement or designationTribunal / Court
s.reg.a20 Enforcement by civil proceedings Regulated
Other duties (1) — Crown / regulator
  • Regulators may start court proceedings to enforce NIS complianceStatutory regulator
4 other sections in this Part — procedural and definitional
Part 6

Miscellaneous

2 of 5 sections shown
s.021 Fees (opens in a new tab) Regulated
  • Pay costs incurred by the enforcement authorityAny Person
s.022 Proceeds of penalties (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Regulators must pay penalty proceeds into government fundsStatutory regulator
3 other sections in this Part — procedural and definitional
Schedules

Schedules

0 of 11 shown
11 other schedules
s.sch002 The electricity subsector
s.sch002 The digital infrastructure subsector
s.sch002 The oil subsector
s.sch002 The gas subsector
s.sch002 The air transport subsector
s.sch002 The water transport subsector
s.sch002 The rail transport subsector
s.sch002 The road transport subsector
s.sch002 The healthcare subsector
s.sch002 The drinking water supply and distribution subsector

Help complying

Guvnor’s practical routes through this instrument.

Respond to a data breach

Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting …

Data breach 72-hour checklist

Emergency checklist when you discover a personal data breach. Covers immediate containment, the 72-hour ICO notification rule, when to notify affected individuals, …

Respond to a cyber attack

Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data …

Cyber security fundamentals

A structured learning path for business owners new to cyber security. Understand the threat landscape, implement the five essential controls, prepare for …

Cyber security quick wins

Five practical security improvements any business can implement today without technical expertise. Covers passwords, updates, backups, phishing awareness, and access control.

Grow your construction business

Scale your construction business - win public contracts, build your workforce, achieve accreditations, and manage subcontractors at scale

NIS Regulations: compliance for operators of essential services

How to comply with the Network and Information Systems (NIS) Regulations 2018 as an operator of essential services. Covers OES designation, the …

Network and Information Systems (NIS) Regulations

The NIS Regulations 2018 (as amended in 2022) require operators of essential services and relevant digital service providers to implement appropriate security …

12 more guides that reference this instrument

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.