2025 Cybersecurity Compliance Guide: UK and EU Regulatory Landscape
UK and EU cybersecurity regulations are evolving rapidly in 2025. This guide covers the key frameworks — NIS2, DORA, the UK Cyber Security and Resilience Bill and UK GDPR — explaining what each requires, which businesses are in scope and the practical steps needed to achieve compliance.
AMVIA Team
Editorial
*The AMVIA Team · 11 min read · Reviewed June 2026*
Why is the cybersecurity regulatory landscape changing in 2025?
Regulation has widened from critical national infrastructure to ordinary businesses because the attack surface has widened with it. Supply chain compromises, ransomware against healthcare and education, and state-sponsored intrusion have pushed legislators in London and Brussels to make cyber resilience a legal duty, not a best-effort IT task.
For UK businesses that trade with the EU, serve the public sector, or operate in regulated industries, "which rules apply to us" is now a board question. The frameworks overlap in intent — govern risk, secure your supply chain, detect and report incidents — but differ in scope and teeth. The table below maps the four that matter, then each section goes deeper.
| Framework | Who is in scope | Headline requirement | Typical UK SME impact |
|---|---|---|---|
| UK GDPR Art. 32 | Any org processing personal data | Appropriate technical & organisational security | Direct — applies to almost everyone |
| NIS2 (EU) | 18 EU sectors + their suppliers | Governance, risk mgmt, incident reporting | Indirect — via EU clients/contracts |
| DORA (EU) | EU financial entities + ICT suppliers | ICT risk mgmt, resilience testing | Indirect — if you serve EU finance |
| UK Cyber Security & Resilience Bill | Digital & managed service providers | Expanded reporting & supply chain duties | Emerging — prepare now |
You can map your own exposure quickly with a structured review of your controls and supply chain — that is exactly what our managed cybersecurity services are built around.
What does UK GDPR Article 32 require?
UK GDPR Article 32 requires every organisation processing personal data to put in place "appropriate technical and organisational measures" — encryption, access control, multi-factor authentication, patching, and the ability to detect and respond to incidents. It is the one framework on this list that applies to virtually every UK business, whatever the sector or size.
The Information Commissioner's Office (ICO) has concentrated enforcement on the basics that fail: shared passwords, missing MFA, unpatched known vulnerabilities, and personal data on unencrypted devices. You can read the statutory duty directly on the ICO's security guidance. The average UK data breach cost reached £3.58 million in 2024 — a figure dominated by detection, recovery, and lost business rather than the regulator's fine.
Practical Article 32 controls for an SME:
- MFA everywhere, starting with email and remote access — see our multi-factor authentication setup guidance.
- Encryption of laptops, mobiles, and backups.
- Patch management with a defined SLA for critical fixes.
- Logging and detection so a breach is found in hours, not months.
- A tested incident response plan, not a document nobody has opened.
These same controls underpin GDPR cybersecurity compliance and map cleanly onto Cyber Essentials — which is why we steer most SMEs to certify first and build from there.
Does NIS2 apply to UK businesses?
UK-only businesses are not directly subject to NIS2. The directive binds organisations established in EU member states. But UK firms feel it indirectly: if you have EU subsidiaries, supply services to in-scope EU organisations, or sign contracts that flow NIS2 obligations down to you, the requirements arrive through commercial pressure rather than UK law.
NIS2 replaced the original NIS Directive and widened coverage to 18 sectors — adding manufacturing, food production, postal services, and digital infrastructure to the original critical sectors. Its core duties are worth knowing because EU clients increasingly mirror them in supplier contracts:
- Governance accountability — named board-level responsibility for cyber risk.
- Risk management measures — documented, proportionate, and reviewed.
- Supply chain security — you assess your suppliers, and your clients assess you.
- Incident reporting to the competent authority within 24 hours for the initial notification and 72 hours for the detailed report (NIS2 Article 23).
- Business continuity — backup, recovery, and crisis management.
If you hold material EU client or partner relationships, assess your position now. A focused NIS2 compliance review shows whether contractual flow-down already obliges you to meet these controls.
What is DORA and who does it affect?
The Digital Operational Resilience Act (DORA) is EU legislation that applied from January 2025. It sets mandatory rules for financial-services entities and their ICT suppliers operating in the EU, covering ICT risk management, incident reporting, digital resilience testing, and oversight of third-party technology providers.
For UK firms, DORA bites through client relationships. A UK MSP, cloud provider, or software company that supplies an EU bank, insurer, or investment firm can be designated a Critical ICT Third-Party Service Provider, inheriting contractual and technical obligations: resilience testing, audit rights, and incident notification to EU clients. If your customer list includes EU financial entities, treat DORA as a procurement requirement you will be asked to evidence, not a distant regulation.
What will the UK Cyber Security and Resilience Bill require?
The UK Cyber Security and Resilience Bill is the UK's answer to NIS2's expanded scope, progressing through Parliament during 2025. Its stated aims are to extend mandatory cybersecurity duties to more digital and managed service providers, introduce incident reporting within defined timeframes, and strengthen supply chain security and the NCSC's powers.
Final provisions depend on the parliamentary process, but the direction of travel is clear and the planning value is high. Anticipated provisions include expanded sector coverage, mandatory incident reporting, and new supplier-security duties. Following Royal Assent, a compliance window of roughly 12–18 months is likely. The government's NIS Regulations guidance collection is the best place to track expectations as the Bill matures.
Managed IT and digital service providers should treat the Bill's likely requirements as a live planning framework rather than waiting for the commencement date.
What is a practical compliance roadmap for UK SMEs?
Most UK SMEs should sequence compliance by impact, not by which regulation makes the most noise. Start with the controls that satisfy several frameworks at once — UK GDPR, NIS2, and the anticipated Resilience Bill all reward the same fundamentals — then layer sector-specific obligations on top.
1. UK GDPR Article 32 technical controls — MFA, encryption, patch management, and access reviews. Many of these overlap directly with Cyber Essentials controls, so certifying gives you an audited baseline. 2. Incident response plan — a documented, tested process for detecting, responding to, and reporting incidents. Required under UK GDPR and NIS2, and anticipated under the Resilience Bill. 3. Supply chain security review — assess the security posture of your IT and software suppliers. Central to NIS2 and the Resilience Bill alike. 4. Board engagement — named accountability and regular security reporting at board level.
A pragmatic certification path for SMEs is Cyber Essentials, then IASME Cyber Assurance where you need broader, governance-level evidence. The UK government's Cyber Essentials scheme sets out the five controls every business should hold. AMVIA itself holds Cyber Essentials Plus, and our engineers are Microsoft-certified — one accountable provider for the controls and the platform they run on.
Where Do You Stand on Cybersecurity Compliance?
AMVIA provides a compliance gap assessment covering UK GDPR and relevant sector regulations — giving you a clear picture of your current position and a prioritised remediation plan.
Frequently Asked Questions
UK-only businesses are not directly subject to NIS2. However, UK firms with EU subsidiaries, operations, or clients in NIS2-regulated sectors may face the requirements through contractual flow-down or by being a critical supplier to an in-scope EU entity. Assess your EU supply chain exposure and decide whether NIS2-equivalent controls are appropriate.
Both certifications verify the same five technical controls, but by different methods. Cyber Essentials is self-assessed via a questionnaire reviewed by a certification body. Cyber Essentials Plus adds independent technical testing — an assessor verifies the controls through vulnerability scans, configuration checks, and endpoint testing. Cyber Essentials Plus gives higher assurance and is required by some government procurement frameworks.
The Bill's final provisions remain subject to Parliament, but its stated objectives are to expand mandatory cybersecurity duties beyond the current NIS Regulations, introduce incident reporting within defined timeframes, extend requirements to digital and managed service providers, and strengthen supply chain security. Treat its anticipated requirements as a planning framework and monitor the Bill's progress.
DORA applies directly to EU financial entities and their third-party ICT providers. UK MSPs, cloud providers, or IT companies supplying EU financial firms may be classified as Critical ICT Third-Party Service Providers, subject to contractual and technical obligations including resilience testing, audit rights, and incident notification to their EU clients. If you serve EU finance, expect to evidence these controls.
Start with UK GDPR Article 32 fundamentals — MFA, encryption, patching, access control, and incident detection — because they satisfy several frameworks at once. Certify to Cyber Essentials to gain an audited baseline, document and test an incident response plan, then review your supply chain. This sequence covers the highest-impact obligations before sector-specific rules.
Related Reading
UK Cyber Security and Resilience Bill | Business Guide
A complete guide to what the UK Cyber Security and Resilience Bill means for businesses and how to prepare.
UK Cybersecurity Guide for SMEs | Practical Steps
Practical cybersecurity steps for UK SMEs that address the most common compliance requirements.
Data Protection & Privacy | UK GDPR Guide for Businesses
UK GDPR requirements in detail — the foundational data protection compliance framework for UK businesses.
Protect your business → Get Cybersecurity Assessment