October Is the Deadline: A NIS2 Board-Liability Checklist Every In-Scope IT Provider Needs Now

October Is the Deadline: A NIS2 Board-Liability Checklist Every In-Scope IT Provider Needs Now

NIS2 makes company directors personally accountable for cybersecurity, not just their IT teams. Here's what UK SME boards and their IT advisors must do before the October 2026 enforcement window closes.

Tony Brown
By Tony Brown ·

A managed service provider in Manchester lost a contract last year because their client's parent company in Germany asked a single question their board couldn't answer: "Can you demonstrate that your management team has approved and oversees your cybersecurity risk measures?" Nobody could. The contract went elsewhere. That question is coming to a lot more UK businesses, and the reason is a piece of EU law called NIS2.

If you run or advise an SME that trades with the EU, supplies EU customers, or sits in a supply chain that reaches across the Channel, this affects you directly. And the part that should keep directors awake isn't the organisational box-ticking. It's the personal accountability. NIS2 puts named individuals on the hook.

A group of directors in a boardroom reviewing documents on a laptop, representing board-level accountability for cybersecurity

Why UK businesses can't wave this away

The Network and Information Systems Directive 2 (NIS2) is EU legislation, so the obvious reaction from a Nottingham boardroom is "we're not in the EU any more, move on." That's a mistake.

NIS2 applies to entities that operate in the EU or provide services into it, regardless of where they're headquartered. A UK software firm selling to Dutch councils, a logistics business with a distribution arm in Ireland, or a managed IT provider whose clients include EU subsidiaries can all find themselves in scope. Even if you're not directly caught, your EU customers are, and they're contractually obliged to police their supply chains. That means they'll push the requirements down to you whether you like it or not.

Member states were meant to have NIS2 written into national law by October 2024. Enforcement has been ramping up unevenly since, and the practical squeeze — audits, contract clauses, insurer questions — is landing on businesses through 2025 and into 2026. If you've been treating the October window as a distant problem, it isn't one any more.

The bit that changes the conversation: Article 20

Most cybersecurity regulation talks about what the organisation must do. NIS2 does that too, but Article 20 goes further. It makes the management body — directors, in plain terms — personally responsible in two specific ways.

First, management bodies must approve the cybersecurity risk-management measures the entity takes. Not delegate them, not rubber-stamp a slide, but approve them as a formal act of governance.

Second, they must oversee the implementation of those measures. This is ongoing. You can't approve a policy in March and forget it exists by June.

And there's a third element that turns this from paperwork into a real obligation: members of the management body are required to undergo training so they can identify risks and assess cybersecurity practices. The law expects directors to be competent enough to challenge what they're told, not just nod along to the IT report.

Member states can hold these individuals personally liable for breaches. In some implementations that includes temporary bans from holding management positions. This is the shift. Cybersecurity stops being something the board hears about and becomes something the board answers for.

For an IT provider, that reframes your role. You're no longer just keeping systems patched. You're the person who has to give directors evidence they can stand behind — because if it goes wrong, they're the ones facing the consequences.

The 24-72-30 reporting cascade

The other immediately actionable part of NIS2 is the incident reporting timeline. It runs in three stages, and every in-scope business needs it written down and rehearsed before anything goes wrong.

Within 24 hours of becoming aware of a significant incident, you must submit an early warning to the relevant national authority. This is a heads-up, not a full report — enough to say something serious is happening and whether it looks like it might be malicious or cross-border.

Within 72 hours, you provide an incident notification. This updates the early warning with an initial assessment: severity, impact, and any indicators of compromise you've found.

Within one month (30 days) of the notification, you submit a final report covering a detailed description of the incident, its root cause, the mitigation applied, and any cross-border impact.

The reason this matters so much to SMEs is that 24 hours is nothing. If your first response to a ransomware hit is to work out who to phone, you've already blown the clock. The reporting obligation forces you to have a decision-maker, a contact route, and a rough playbook ready in advance. Most businesses don't.

The board-liability checklist

Here's what a director or their IT advisor should be able to answer with a straight yes. If any of these is a no, that's your priority list.

1. Have we confirmed whether we're in scope — or in a customer's scope? Map your EU trade and your supply-chain position. Don't assume you're out just because you're UK-based.

2. Has the management body formally approved our cybersecurity risk-management measures? There should be a dated board minute recording this. Approval by implication doesn't count.

3. Is there a documented oversight mechanism? A standing cybersecurity item on the board agenda, a quarterly report against agreed measures, and named responsibility. Oversight you can't evidence is oversight you didn't do.

4. Have directors had cybersecurity training? Even a short, recorded session that covers the organisation's specific risks and the questions a director should be asking. Keep the certificate.

5. Do we have the ten baseline measures in place? NIS2 Article 21 spells out the minimum: risk analysis and security policies, incident handling, business continuity and backups, supply-chain security, secure procurement and development, policies to assess effectiveness, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Each one needs an owner and evidence.

6. Is the 24-72-30 reporting process written down? Who declares an incident significant, who contacts the authority, where the templates live, and who signs off the final report.

7. Have we tested it? A tabletop exercise where someone plays out a breach and the team works to the clock. The first time you run the process should not be during a real attack.

8. Are our suppliers covered? Your own third parties can be your weakest link. Contracts should require them to meet equivalent standards and to notify you fast when something goes wrong.

What IT providers should do this quarter

If you advise SMEs, you have a commercial opening as well as a duty of care. Your clients' boards need someone to translate Article 20 into practical governance, and few of them will do it alone.

Start by scoping who among your clients trades with or supplies the EU. Bring the board-liability angle to those directors directly — not the IT manager. The message that lands is "this is now your personal responsibility, and here's how we help you discharge it." Then build the evidence trail: approved measures, oversight cadence, training records, a tested reporting playbook.

The businesses that treat NIS2 as a governance project rather than an IT chore will pass audits, keep contracts, and answer that awkward question from the German parent company without breaking stride. The ones that don't will find out the hard way that the deadline was real.

If you're not sure where your clients — or your own business — sit against this, get the scoping done now. October has a habit of arriving faster than you expect.

Request a no obligation callback