›Does NIS2 apply to UK companies?
Only in narrow circumstances, and this is the point most summaries get wrong. NIS2 anchors jurisdiction to establishment. A UK organisation with no EU establishment is reached directly only if it falls in one of the nine digital categories in Article 26(1)(b), which include cloud, data centre, CDN, managed service, managed security, DNS, TLD registry, domain registration and online platform providers. Those must appoint an EU representative. For everyone else the exposure is contractual: your EU customers must manage supply-chain security under Article 21, and they push that down in contracts.
›What is the difference between an essential and an important entity?
Supervision and penalties. Essential entities face comprehensive supervision both before and after the fact, including random checks, regular audits and powers to suspend authorisation or ban a chief executive from management functions, with a penalty ceiling of at least EUR 10 million or 2% of worldwide turnover, whichever is higher. Important entities face lighter, after-the-fact supervision triggered by evidence of non-compliance, and a ceiling of at least EUR 7 million or 1.4%. Incident reporting deadlines are identical for both.
›Can size alone make my organisation an essential entity?
Only if you are in an Annex I sector of high criticality. Size cannot elevate an Annex II entity: a manufacturer with ten thousand employees is an important entity, not an essential one. Getting this backwards is the single most common error in published scope tools. Separately, qualified trust service providers, TLD name registries and DNS service providers are essential irrespective of size.
›Has the UK Cyber Security and Resilience Bill become law?
No. As at 3 August 2026 it is in the House of Lords and has not received Royal Assent, with Lords committee stage due to begin on 1 September 2026. Its scope can still change. The Bill also contains no commencement date for its substantive provisions: they come into force on a day the Secretary of State appoints by regulations, and the government has said only that it intends to consult on implementation during 2026. Any specific date quoted elsewhere is commentary rather than law.
›How does the UK Bill differ from NIS2 on incident reporting?
The UK Bill runs a two-stage clock: an initial notification within 24 hours and a full notification within 72 hours, with an express duty to notify affected customers. NIS2 adds stages after that: an intermediate report if the authority requests one, and a final report within one month of the 72-hour notification, plus a progress report where the incident is still running. The UK therefore front-loads more substance into 72 hours and requires nothing afterwards.
›Is this legal advice?
No. It is an indicative assessment from the answers you give, and scope decisions turn on facts this tool does not ask about. NIS2 in particular is a Directive, so what binds you is your Member State's transposing law, which varies in thresholds and sector scoping. Every regime links its primary source so you can check the position, and anything consequential warrants proper advice.