The NIS (Network and Information Systems) Regulations 2018 apply to two main groups: DSPs and OES (operators of essential services) in the UK.
DSPs provide a digital service in the UK and, for the purposes of the NIS Regulations, are either headquartered in the UK or have nominated a UK-based representative.
‘Micro and small enterprises’ – organisations that employ fewer than 50 people and have an annual turnover and/or a balance sheet total of less than €10 million (around £8.7 million) – are outside the Regulations’ scope.
DSPs have lighter security requirements than OES because of the lower risk they typically present to society as a whole if their service is disrupted. Their compliance with the Regulations is not actively monitored by their regulator, the ICO (Information Commissioner’s Office).