What is NIS2 and who does it apply to?
NIS2 is the EU’s updated Network and Information Security directive. It came into force across EU member states in October 2024 and sets out cybersecurity requirements for organisations operating in sectors the EU considers critical, including energy, transport, water, healthcare, and manufacturing.
The directive applies to organisations based in or operating in the EU, so if you’re a UK manufacturer without EU operations, you’re not directly in scope. But that doesn’t mean you can ignore it.
The supply chain obligation: what in-scope EU organisations must now do
We said above that the directive applies to organisations based in or operating in the EU, but UK companies can still be impacted. Because NIS2 doesn’t just require in-scope organisations to secure their own systems. It requires them to assess and manage the cybersecurity risks posed by their suppliers.
NIS2 includes specific provisions around supply chain security. In-scope organisations are expected to consider the risks that their suppliers and service providers might pose, and to factor those risks into how they manage their own cybersecurity. In practice, many are responding by introducing supplier security assessments, adding security requirements to contracts, or asking suppliers to complete questionnaires and provide evidence of their controls.
Why NIS2 can affect UK suppliers regardless of Brexit
Brexit means NIS2 isn’t UK law. The UK has its own regulatory trajectory, which we’ll cover in a separate article. But it doesn’t mean NIS2 has no bearing on your business.
If you supply components, materials, or services to an EU manufacturer or to a UK business that itself supplies into the EU, the businesses above you in the chain may be in scope. And if they’re in scope, they have an obligation to assess you.
The question isn’t whether NIS2 applies to you legally. It’s whether your customers are asking you to demonstrate that your security posture meets their requirements. For many UK manufacturers, that conversation is already starting.
It’s worth noting that this isn’t a new concept. Larger manufacturers have been applying supply chain security requirements informally for years. NIS2 formalises and extends that practice, and it gives it regulatory teeth for the organisations doing the asking.
What being asked to demonstrate compliance actually looks like
In practice, NIS2-driven supplier assessments tend to take one of a few forms.
Security questionnaires are the most common starting point. Your customer sends you a document asking about your security controls: how you manage access to your systems, how you handle software updates and patching, whether you have incident response procedures in place, and how you’d communicate a breach if one occurred.
Some customers go further and ask for evidence rather than just answers. That might mean sharing the results of a recent risk assessment, providing documentation of your security policies, or, in some cases, accepting a direct audit.
A smaller number of customers, particularly larger tier-one manufacturers and those in heavily regulated sectors, are beginning to include security requirements as formal contract terms. If you can’t demonstrate an adequate security posture, you may find yourself unable to renew a contract or qualify for new business.
The level of scrutiny varies. But the direction of travel is clear, and it’s moving toward greater expectation, not less.
How to ensure you can respond with confidence
The businesses that struggle most when these questions arrive are the ones who haven’t thought about it beforehand. Trying to pull together evidence of your security posture under time pressure, in response to a customer request, is a stressful and difficult position to be in.
The businesses that handle it well are the ones who know what’s in their environment, understand where their risks sit, and have a clear picture of what controls they have in place. They don’t need to scramble when a questionnaire lands, because they’ve already done the thinking.
Getting to that position doesn’t require a large security programme or a significant budget. It starts with a structured assessment of your OT environment: what assets you have, how they’re connected, who has access, and where the vulnerabilities are. From that foundation, you can build a prioritised action plan and, critically, a clear and credible answer to the questions your customers are likely to ask.
If you’d like to understand what that assessment involves and how it works in practice, our OT Security Risk Assessment page is a good starting point.
