UK Cyber Security and Resilience Bill vs NIS2: What Dual Exposure Means for your organisation

   Sep 22, 2026 | Adam Fearn, Senior OT Architect, Radiflow
What OT Organisations with European Operations Need to Understand About the UK Cyber Security and Resilience Bill and EU NIS2

Two significant pieces of cyber security regulation are now either in force or advancing toward it on either side of the UK’s border with the EU. The EU’s NIS2 Directive has been in effect since October 2024, with member states required to have transposed it into national law. The UK’s Cyber Security and Resilience Bill cleared the House of Commons in June 2026, is now progressing through the Lords, and Royal Assent is expected later this year.

For organisations with operations, customers, or supply chain relationships on both sides, there are questions to be asked regarding which regulation applies. It’s likely to be both. The consideration is to look at where they align closely enough to address together, and where they diverge in ways that require separate attention. For OT-heavy organisations, some of those divergences matter more than others.

Where the two regimes agree

Both frameworks share the same underlying intent. To raise the baseline of cyber resilience across critical sectors and their supply chains, with mandatory incident reporting and meaningful enforcement consequences for organisations that fall short.

The reporting timelines are broadly aligned. Both regimes require an early warning notification within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours. Organisations already designing incident response processes for one regime can largely carry that structure across to the other, which is a practical advantage for those operating across both jurisdictions.

The emphasis on supply chain security is also shared. Both NIS2 and the UK Bill place explicit obligations on regulated organisations to manage the cyber risk presented by their suppliers, including through contractual requirements and due diligence processes. Organisations building supply chain risk management programmes for NIS2 compliance will find the UK Bill pointing in the same direction, even where the specific mechanisms differ.

The penalty scales are broadly comparable. Both regimes allow for turnover-based fines serious enough to demand board attention rather than being treated as the cost of doing business.

Where they differ, and why it matters for OT

The differences between the two regimes are meaningful, and some of them are particularly relevant for manufacturing and OT-heavy organisations.

The most significant is sectoral scope. NIS2 covers 18 sectors, including food, manufacturing, chemicals, and postal services. The UK Bill, as currently set out, takes a narrower approach. It expands the existing UK NIS framework to bring in managed service providers, data centres, and large load controllers, but manufacturing and food are not included as directly regulated sectors. A food manufacturer or industrial producer operating in both the UK and the EU may find themselves directly in scope of NIS2 for their continental operations while remaining outside the direct scope of the UK Bill, at least until secondary legislation expands the framework further.

The asymmetry of this is worth understanding carefully, because it doesn’t mean the UK Bill is irrelevant to manufacturers. The Bill’s supply chain provisions and Designated Critical Supplier mechanism can reach manufacturers indirectly, through their customers in regulated sectors. The point is that the route into scope may be different in each jurisdiction. That means direct regulation under NIS2, and indirect pressure through procurement and potential designation under the UK Bill.

The second significant difference is the supply chain mechanism itself. NIS2 imposes supply chain security obligations on in-scope organisations but doesn’t directly regulate their suppliers. The UK Bill goes further, giving regulators the power to formally designate specific suppliers as critical suppliers and bring them under direct statutory oversight. That’s a more targeted mechanism, but also a less predictable one, since designation decisions will be made by regulators rather than through a fixed sectoral list.

The third difference is in incident reporting process. The UK Bill requires dual notification. Reports go to both the relevant sector regulator and the National Cyber Security Centre. NIS2 routes reporting through the national CSIRT in each member state. Organisations with operations in multiple EU countries face the additional complexity of national implementation varying across member states. The UK’s model is more centralised, which simplifies the reporting path even as the dual-destination requirement adds a step.

A fourth difference is board-level accountability. NIS2 includes explicit obligations on the management body, requiring board-level involvement in cyber risk decisions and, in certain circumstances, exposure to personal liability for non-compliance. The UK Bill takes a less prescriptive approach on governance, reinforcing board-level expectations without imposing the same harmonised liability framework. For organisations subject to both regimes, NIS2’s governance requirements set the higher bar.

Finally, the technical standards differ. The UK Bill is expected to align with the NCSC’s Cyber Assessment Framework rather than international standards such as ISO 27001 or NIST CSF. NIS2 is less prescriptive on specific standards, allowing organisations to use recognised frameworks to demonstrate compliance. Organisations already certified to ISO 27001 will find that helps with NIS2 readiness, but UK-specific CAF alignment is an additional requirement that needs separate attention.

Securing a Global Chemicals Manufacturer

The practical position for manufacturers with dual exposure

For an OT-heavy organisation with operations or significant commercial relationships on both sides of the border, the practical position is that NIS2 is the regime most likely to apply directly, because of its broader sectoral scope. The UK Bill is the regime most likely to apply indirectly, through supply chain pressure from in-scope customers and the potential for supplier designation. Managing both simultaneously is not a duplication of effort, because the underlying work is the same in both directions – i.e. understanding what’s on your OT network, knowing your risk, maintaining current documentation, and being able to report an incident credibly and quickly.

The differences in process, governance, and reporting destination require specific attention for each regime. But the foundation, which is genuine, current visibility into the OT environment, is the same foundation that satisfies both. Organisations that build it once, and maintain it continuously, are in a considerably stronger position than those trying to satisfy two separate regimes from two separate snapshots.

Three questions worth asking to your team

Which of our operations, customer relationships, or supply chain positions puts us in scope of NIS2, the UK Bill, or both, and have we tested this assumption?

If we’re subject to both regimes, do we have a clear picture of where they align and where they require separate compliance action?

Do we have the OT visibility that would allow us to respond credibly to an incident reporting obligation under either framework, within the timelines both regimes require?

The answer to these questions will tell you more about your readiness than any compliance checklist. And it’s a better question to answer in a boardroom now, than in the aftermath of an incident later.

Building OT visibility and cyber risk management capability is the work Radiflow helps manufacturers and critical infrastructure operators do.

 

 

Additional Resources

Request Demo Contact Us