The Network and Information Systems Regulations 2018 (SI 2018/506) come into force today, implementing the EU NIS Directive in the UK.
Who is covered? Operators of essential services in the energy, transport, health, drinking water and digital infrastructure sectors that meet the threshold criteria, and relevant digital service providers (online marketplaces, online search engines and cloud computing services).
Key obligations
- Take appropriate and proportionate technical and organisational measures to manage security risks.
- Notify significant incidents to the relevant competent authority within 72 hours.
- Cooperate with regulators, who will use the NCSC Cyber Assessment Framework to assess compliance.
Penalties can reach £17 million. The ICO regulates digital service providers. Suppliers to in-scope operators should expect security requirements to flow down through contracts.
Source: Network and Information Systems Regulations 2018 (legislation.gov.uk)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.