ISMS Copilot
NIS Regulations 2018

NIS Regulations 2018 Copilot

Understand your obligations under the UK NIS Regulations 2018

What the NIS Regulations 2018 Copilot Can Do

Understand OES security duties under Reg. 10 and the CAF or sector-specific profile your authority uses

Identify which competent authority applies to your sector under Sch. 1

Map your incident-reporting obligations as required by Reg. 11

Navigate the threshold requirements for essential services in Sch. 2

Interpret RDSP duties and registration requirements under Regs. 12-14A

Track enforcement and penalty provisions across Regs. 15-20A

About NIS Regulations 2018 Copilot

The NIS Regulations 2018 (SI 2018/506) impose security and incident-reporting duties on Operators of Essential Services and Relevant Digital Service Providers across critical sectors. ISMS Copilot helps you navigate the regulatory structure, competent authority landscape, and NCSC CAF alignment requirements.

Cross-framework mappings

Working across NIS Regulations 2018 and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

What are the NIS Regulations 2018?

The Network and Information Systems Regulations 2018 (SI 2018/506) impose legal duties on Operators of Essential Services across 10 designated subsectors and on Relevant Digital Service Providers to implement appropriate security measures and notify significant incidents to their competent authority.

How does the NIS Regulations 2018 Copilot help?

Copilot helps you understand how Reg. 10 security duties relate to the NCSC Cyber Assessment Framework or a sector-specific profile where your competent authority requires one, identify your authority under Sch. 1, and interpret incident-notification requirements under Reg. 11.

What is the relationship between the NIS Regulations and the NCSC CAF?

Reg. 10 requires OES to take appropriate and proportionate security measures but does not define what 'appropriate' means in technical terms. Competent authorities commonly use the NCSC Cyber Assessment Framework, or a sector-specific profile, when assessing that duty; the extent of required CAF use is set by each sector's regulator.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.