UK Statutory Instrument 2018 United Kingdom

Network and Information Systems Regulations 2018

At a glance

Enforced by

ICO, Ofgem, Ofcom, Ofwat, UREGNI

What's here

18 compliance obligations, 17 practical guides across 3 topics · 11 journeys

Penalty landscape

1 of 18 obligations carry a fine up to £17,500,000. 17 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Any Person 7
  • Operator 2

Plus 9 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Mentioned in related content

1 guides

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Any Person also bound by 749 other Acts (top 5 shown)
Operators also bound by 125 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

Part 1 — Introduction

Browse 1 other section in this Part — procedural / definitional / commencement

Part 2 — The National Framework

Part 3 — Operators of essential services

s.nomination by an oes of a person to act on its beh

Nomination by an OES of a person to act on its behalf in the United Kingdom

  • Nominate a UK representative for essential services Any Person
Browse 2 other sections in this Part — procedural / definitional / commencement

Part 4 — Digital Services

s.representatives of digital service providers estab

Representatives of digital service providers established outside the United Kingdom

  • Appoint a UK representative for overseas digital services Operator
Browse 1 other section in this Part — procedural / definitional / commencement

Part 5 — Enforcement and penalties

s.appeal by an oes or rdsp to the first-tier tribuna

Appeal by an OES or RDSP to the First-tier Tribunal

Other duties (1) — Crown / regulator
  • Tribunal must hear appeals against regulator decisions under NIS Regulations Tribunal / Court
s.decision of the first-tier tribunal

Decision of the First-tier Tribunal

Other duties (1) — Crown / regulator
  • Tribunal must determine appeals against NIS enforcement or designation Tribunal / Court
s.enforcement by civil proceedings

Enforcement by civil proceedings

Other duties (1) — Crown / regulator
  • Regulators may start court proceedings to enforce NIS compliance Statutory regulator
Browse 4 other sections in this Part — procedural / definitional / commencement

Part 6 — Miscellaneous

s.021

Fees

  • Pay costs incurred by the enforcement authority Any Person
s.022

Proceeds of penalties

Other duties (1) — Crown / regulator
  • Regulators must pay penalty proceeds into government funds Statutory regulator
Browse 3 other sections in this Part — procedural / definitional / commencement

Schedules

Browse 1 other Schedule — structural / supplementary

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

ICO

Primary

Information Commissioner's Office

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. …

Office of Gas and Electricity Markets

Regulates gas and electricity markets in Great Britain. Issues licences for generation, transmission, distribution, and supply. Protects consumers and promotes competition. Also …

Office of Communications

Regulates telecoms, TV, radio, video-on-demand, postal services, and online safety. Issues licences for telecoms providers, manages spectrum. Now enforces Online Safety Act …

Water Services Regulation Authority

Economic regulator for the water and sewerage sectors in England and Wales. Sets price limits, monitors service quality, and enforces environmental duties. …

Utility Regulator (Northern Ireland)

Regulates electricity, gas, and water industries in Northern Ireland. Protects consumers, promotes competition, and ensures adequate utility supply.

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.