- Status
- In Force
- Penalty ceiling
- Prosecution 1 of 19 obligations carry a fine up to £17,500,000. 18 have no criminal penalty — flagged in the list below.
Does it bind you?
Business-side roles with duties under this instrument.
Plus 9 duties on the regulator, Crown ministers and public bodies — folded into the section list below.
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Any Person — also bound by 2340 other Acts
Operator — also bound by 746 other Acts
What it requires
Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
Introduction
0 of 1 section shown1 other section in this Part — procedural and definitional
The National Framework
5 of 6 sections shownOther duties (1) — Crown / regulator
- Regulators must provide guidance and maintain lists of essential servicesStatutory regulator
Other duties (1) — Crown / regulator
- GCHQ (SPOC) must cooperate with enforcement authoritiesStatutory regulator
Other duties (1) — Crown / regulator
- GCHQ (as CSIRT) must monitor and support UK businesses against cyber incidentsStatutory regulator
Other duties (1) — Crown / regulator
- Enforcement authorities may share your information with other bodiesStatutory regulator
Other duties (1) — Crown / regulator
- Northern Ireland Departments and regulators may share NIS informationCrown / Minister / Government department
1 other section in this Part — procedural and definitional
Operators of essential services
4 of 5 sections shown- Nominate a UK representative for essential servicesAny Person
- Notify the competent authority if you are an operator of essential servicesAny Person
- Manage and secure network systems for essential servicesAny Person
- Notify your regulator of significant service disruptionsAny Person
1 other section in this Part — procedural and definitional
Digital Services
3 of 4 sections shown- Secure network systems and notify the ICO of substantial incidentsOperator
Fine up to £17,500,000
- Appoint a UK representative for overseas digital servicesOperator
- Register your business as a relevant digital service provider (RDSP)Any Person
1 other section in this Part — procedural and definitional
Enforcement and penalties
5 of 9 sections shown- Respond to formal Information Notices from regulatorsAny Person
- Comply with enforcement notices regarding digital and network securityAny Person
Other duties (1) — Crown / regulator
- Tribunal must hear appeals against regulator decisions under NIS RegulationsTribunal / Court
Other duties (1) — Crown / regulator
- Tribunal must determine appeals against NIS enforcement or designationTribunal / Court
Other duties (1) — Crown / regulator
- Regulators may start court proceedings to enforce NIS complianceStatutory regulator
4 other sections in this Part — procedural and definitional
Miscellaneous
2 of 5 sections shownOther duties (1) — Crown / regulator
- Regulators must pay penalty proceeds into government fundsStatutory regulator
3 other sections in this Part — procedural and definitional
Schedules
0 of 11 shown11 other schedules
Help complying
Guvnor’s practical routes through this instrument.
Respond to a data breach
Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting …
Data breach 72-hour checklist
Emergency checklist when you discover a personal data breach. Covers immediate containment, the 72-hour ICO notification rule, when to notify affected individuals, …
Respond to a cyber attack
Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data …
Cyber security fundamentals
A structured learning path for business owners new to cyber security. Understand the threat landscape, implement the five essential controls, prepare for …
Cyber security quick wins
Five practical security improvements any business can implement today without technical expertise. Covers passwords, updates, backups, phishing awareness, and access control.
Grow your construction business
Scale your construction business - win public contracts, build your workforce, achieve accreditations, and manage subcontractors at scale
NIS Regulations: compliance for operators of essential services
How to comply with the Network and Information Systems (NIS) Regulations 2018 as an operator of essential services. Covers OES designation, the …
Network and Information Systems (NIS) Regulations
The NIS Regulations 2018 (as amended in 2022) require operators of essential services and relevant digital service providers to implement appropriate security …
12 more guides that reference this instrument
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.