Definition · External Attack Surface Management
What is NIS2?
NIS2 is Directive (EU) 2022/2555, which replaces the original NIS Directive of 2016. As a directive it does not apply directly: each EU member state transposes it into national law, with a transposition deadline of 17 October 2024, so the precise obligations, thresholds and penalties an organisation faces are set by the national implementation rather than by the directive text alone.
Who it covers and what it requires
NIS2 widens the sectors in scope compared with the original directive and splits in-scope organisations into essential and important entities, with lighter-touch supervision for the latter. Core duties include risk-based technical and organisational measures, supply-chain security, incident handling, and management-body accountability for compliance. Incident reporting is staged: an early warning to the national authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report later.
The UK position — a common source of confusion
The UK is not covered by NIS2. Having left the EU before the directive was adopted, the UK continues to operate its own regime: the Network and Information Systems Regulations 2018, which transposed the original NIS Directive and have since been amended domestically. The UK government has set out plans to update that regime through separate legislation, but NIS2 itself does not apply to UK entities by virtue of being UK entities.
UK organisations can still be affected. A UK business that provides in-scope services inside the EU may fall under a member state’s NIS2 law and be required to designate a representative in the EU, and any UK supplier to an in-scope EU entity may be pulled in through that entity’s supply-chain security obligations — typically as contract terms, security questionnaires and evidence requests rather than direct regulation.
Where external exposure fits
Both regimes are outcome-focused, and both expect an organisation to understand and manage the risk in its own infrastructure. Internet-facing assets are where that is easiest to demonstrate and hardest to hide: an accurate inventory, monitored exposure, and evidence that known CVEs on reachable services are remediated to a timescale.
Related concepts
See GDPR Article 32 for the separate data-protection security duty, and ISO 27001, which many organisations use as the management framework behind either regime. See also external attack surface management and attack surface reduction.