2025 Cybersecurity Compliance Guide: UK and EU Regulatory Landscape
UK and EU cybersecurity regulations are evolving rapidly in 2025. This guide covers the key frameworks — NIS2, DORA, the UK Cyber Security and Resilience Bill and UK GDPR — explaining what each requires, which businesses are in scope and the practical steps needed to achieve compliance.
Matt Cannon
Managing Director
Why the Regulatory Landscape Is Changing
Cybersecurity regulation is no longer solely the concern of critical national infrastructure operators. The escalating frequency and severity of cyber incidents — including supply chain attacks, ransomware against healthcare and education, and state-sponsored intrusions — has driven legislators in both the UK and EU to expand mandatory cybersecurity requirements to a wider set of organisations.
For UK businesses, particularly those that trade with the EU, serve public sector clients or operate in regulated sectors, understanding which frameworks apply and what they require has become a board-level compliance matter, not just an IT concern.
UK GDPR and the Data Protection Act 2018
UK GDPR's Article 32 security requirement remains foundational for any organisation processing personal data. The requirement to implement appropriate technical and organisational measures — including encryption, access controls, incident detection and response — applies to virtually every UK business.
The ICO's enforcement activity in 2024–2025 has increasingly focused on inadequate security measures leading to breaches: organisations using shared passwords, lacking MFA, failing to patch known vulnerabilities or storing personal data on unencrypted devices. The average UK data breach cost reached £3.4 million in 2024, with regulatory penalties and reputational damage compounding recovery costs.
NIS2 (EU Network and Information Security Directive 2)
NIS2 replaced the original NIS Directive in EU member states, significantly expanding the scope of organisations subject to mandatory cybersecurity requirements. The scope expansion is notable: NIS2 now covers 18 sectors including manufacturing, food production, postal services and digital infrastructure, in addition to the original critical sectors.
Does NIS2 apply to UK businesses? UK-only businesses are not directly subject to NIS2. However, UK businesses that:
- Have EU-based subsidiaries or operations
- Supply services to EU organisations in scope of NIS2
- Are required by EU-based clients to comply with NIS2 requirements contractually
..may face practical NIS2 requirements through contractual flow-down. Understanding your supply chain position relative to NIS2 is worth assessing if you have material EU client or partner relationships.
NIS2 requirements include: governance accountability (board-level responsibility), risk management measures, supply chain security, incident reporting to competent authority within 24 hours (initial notification) and 72 hours (detailed report), and business continuity measures.
DORA (Digital Operational Resilience Act)
DORA is EU legislation that came into force in January 2025, applying to financial services entities and their ICT (information and communications technology) service providers operating in the EU. It establishes mandatory requirements for ICT risk management, incident reporting, digital resilience testing and third-party ICT provider oversight.
Impact for UK businesses: UK financial services firms and ICT providers that supply EU financial entities are subject to DORA's requirements through their EU client relationships. UK MSPs and IT service providers supplying EU banks, insurers or investment firms must ensure their services meet DORA's technical and contractual requirements.
UK Cyber Security and Resilience Bill
The UK government's Cyber Security and Resilience Bill, progressing through Parliament in 2025, is the UK's equivalent response to the expanded scope of NIS2. It extends mandatory cybersecurity requirements to a wider set of digital service providers and regulated sectors, introduces new incident reporting obligations and strengthens the NCSC's powers.
Key anticipated provisions include expanded sector coverage, mandatory incident reporting within defined timeframes, and new supply chain security requirements. UK businesses in digital services, managed services and regulated sectors should monitor the Bill's progress and begin preparing for its requirements — the compliance timeline following Royal Assent is likely to be 12–18 months.
Practical Compliance Roadmap for UK SMEs
For most UK SMEs, a practical compliance approach addresses the most impactful requirements first:
- UK GDPR Article 32 technical controls: MFA, encryption, patch management, access control review and incident detection — many of these overlap with.
- Incident response plan: Document a process for detecting, responding to and reporting cyber incidents — required under UK GDPR, NIS2 (for in-scope organisations) and anticipated under the Resilience Bill.
- Supply chain security review: Assess the security posture of your IT and software suppliers — required under NIS2 and anticipated under the Resilience Bill.
- Board engagement: Cybersecurity governance requires board-level accountability under NIS2 and the anticipated Resilience Bill. Board-level risk awareness and regular security reporting should be established.
Where Do You Stand on Cybersecurity Compliance?
AMVIA provides a compliance gap assessment covering UK GDPR and relevant sector regulations — giving you a clear picture of your current position and a prioritised remediation plan.
Frequently Asked Questions
UK-only businesses are not directly subject to NIS2. However, UK firms with EU subsidiaries, operations, or clients in NIS2-regulated sectors may face the requirements through contractual flow-down or by being a critical supplier to an in-scope EU entity. Assess your EU supply chain exposure and decide whether NIS2-equivalent controls are appropriate.
Both certifications verify the same five technical controls, but by different methods. Cyber Essentials is self-assessed via a questionnaire reviewed by a certification body. Cyber Essentials Plus adds independent technical testing — an assessor verifies the controls through vulnerability scans, configuration checks, and endpoint testing. Cyber Essentials Plus gives higher assurance and is required by some government procurement frameworks.
The Bill's final provisions remain subject to Parliament, but its stated objectives are to expand mandatory cybersecurity duties beyond the current NIS Regulations, introduce incident reporting within defined timeframes, extend requirements to digital and managed service providers, and strengthen supply chain security. Treat its anticipated requirements as a planning framework and monitor the Bill's progress.
DORA applies directly to EU financial entities and their third-party ICT providers. UK MSPs, cloud providers, or IT companies supplying EU financial firms may be classified as Critical ICT Third-Party Service Providers, subject to contractual and technical obligations including resilience testing, audit rights, and incident notification to their EU clients. If you serve EU finance, expect to evidence these controls.
Start with UK GDPR Article 32 fundamentals — MFA, encryption, patching, access control, and incident detection — because they satisfy several frameworks at once. Certify to Cyber Essentials to gain an audited baseline, document and test an incident response plan, then review your supply chain. This sequence covers the highest-impact obligations before sector-specific rules.
Related Reading
UK Cyber Security and Resilience Bill | Business Guide
A complete guide to what the UK Cyber Security and Resilience Bill means for businesses and how to prepare.
UK Cybersecurity Guide for SMEs | Practical Steps
Practical cybersecurity steps for UK SMEs that address the most common compliance requirements.
Data Protection & Privacy | UK GDPR Guide for Businesses
UK GDPR requirements in detail — the foundational data protection compliance framework for UK businesses.
Protect your business → Get Cybersecurity Assessment