Cybersecurity

2025 Cybersecurity Compliance Guide: UK and EU Regulatory Landscape

UK and EU cybersecurity regulations are evolving rapidly in 2025. This guide covers the key frameworks — NIS2, DORA, the UK Cyber Security and Resilience Bill and UK GDPR — explaining what each requires, which businesses are in scope and the practical steps needed to achieve compliance.

AT

AMVIA Team

Editorial

11 min read·Mar 2026

*The AMVIA Team · 11 min read · Reviewed June 2026*

Why is the cybersecurity regulatory landscape changing in 2025?

Regulation has widened from critical national infrastructure to ordinary businesses because the attack surface has widened with it. Supply chain compromises, ransomware against healthcare and education, and state-sponsored intrusion have pushed legislators in London and Brussels to make cyber resilience a legal duty, not a best-effort IT task.

For UK businesses that trade with the EU, serve the public sector, or operate in regulated industries, "which rules apply to us" is now a board question. The frameworks overlap in intent — govern risk, secure your supply chain, detect and report incidents — but differ in scope and teeth. The table below maps the four that matter, then each section goes deeper.

FrameworkWho is in scopeHeadline requirementTypical UK SME impact
UK GDPR Art. 32Any org processing personal dataAppropriate technical & organisational securityDirect — applies to almost everyone
NIS2 (EU)18 EU sectors + their suppliersGovernance, risk mgmt, incident reportingIndirect — via EU clients/contracts
DORA (EU)EU financial entities + ICT suppliersICT risk mgmt, resilience testingIndirect — if you serve EU finance
UK Cyber Security & Resilience BillDigital & managed service providersExpanded reporting & supply chain dutiesEmerging — prepare now

You can map your own exposure quickly with a structured review of your controls and supply chain — that is exactly what our managed cybersecurity services are built around.

What does UK GDPR Article 32 require?

UK GDPR Article 32 requires every organisation processing personal data to put in place "appropriate technical and organisational measures" — encryption, access control, multi-factor authentication, patching, and the ability to detect and respond to incidents. It is the one framework on this list that applies to virtually every UK business, whatever the sector or size.

The Information Commissioner's Office (ICO) has concentrated enforcement on the basics that fail: shared passwords, missing MFA, unpatched known vulnerabilities, and personal data on unencrypted devices. You can read the statutory duty directly on the ICO's security guidance. The average UK data breach cost reached £3.58 million in 2024 — a figure dominated by detection, recovery, and lost business rather than the regulator's fine.

Practical Article 32 controls for an SME:

  • MFA everywhere, starting with email and remote access — see our multi-factor authentication setup guidance.
  • Encryption of laptops, mobiles, and backups.
  • Patch management with a defined SLA for critical fixes.
  • Logging and detection so a breach is found in hours, not months.
  • A tested incident response plan, not a document nobody has opened.

These same controls underpin GDPR cybersecurity compliance and map cleanly onto Cyber Essentials — which is why we steer most SMEs to certify first and build from there.

Does NIS2 apply to UK businesses?

UK-only businesses are not directly subject to NIS2. The directive binds organisations established in EU member states. But UK firms feel it indirectly: if you have EU subsidiaries, supply services to in-scope EU organisations, or sign contracts that flow NIS2 obligations down to you, the requirements arrive through commercial pressure rather than UK law.

NIS2 replaced the original NIS Directive and widened coverage to 18 sectors — adding manufacturing, food production, postal services, and digital infrastructure to the original critical sectors. Its core duties are worth knowing because EU clients increasingly mirror them in supplier contracts:

  • Governance accountability — named board-level responsibility for cyber risk.
  • Risk management measures — documented, proportionate, and reviewed.
  • Supply chain security — you assess your suppliers, and your clients assess you.
  • Incident reporting to the competent authority within 24 hours for the initial notification and 72 hours for the detailed report (NIS2 Article 23).
  • Business continuity — backup, recovery, and crisis management.

If you hold material EU client or partner relationships, assess your position now. A focused NIS2 compliance review shows whether contractual flow-down already obliges you to meet these controls.

What is DORA and who does it affect?

The Digital Operational Resilience Act (DORA) is EU legislation that applied from January 2025. It sets mandatory rules for financial-services entities and their ICT suppliers operating in the EU, covering ICT risk management, incident reporting, digital resilience testing, and oversight of third-party technology providers.

For UK firms, DORA bites through client relationships. A UK MSP, cloud provider, or software company that supplies an EU bank, insurer, or investment firm can be designated a Critical ICT Third-Party Service Provider, inheriting contractual and technical obligations: resilience testing, audit rights, and incident notification to EU clients. If your customer list includes EU financial entities, treat DORA as a procurement requirement you will be asked to evidence, not a distant regulation.

What will the UK Cyber Security and Resilience Bill require?

The UK Cyber Security and Resilience Bill is the UK's answer to NIS2's expanded scope, progressing through Parliament during 2025. Its stated aims are to extend mandatory cybersecurity duties to more digital and managed service providers, introduce incident reporting within defined timeframes, and strengthen supply chain security and the NCSC's powers.

Final provisions depend on the parliamentary process, but the direction of travel is clear and the planning value is high. Anticipated provisions include expanded sector coverage, mandatory incident reporting, and new supplier-security duties. Following Royal Assent, a compliance window of roughly 12–18 months is likely. The government's NIS Regulations guidance collection is the best place to track expectations as the Bill matures.

Managed IT and digital service providers should treat the Bill's likely requirements as a live planning framework rather than waiting for the commencement date.

What is a practical compliance roadmap for UK SMEs?

Most UK SMEs should sequence compliance by impact, not by which regulation makes the most noise. Start with the controls that satisfy several frameworks at once — UK GDPR, NIS2, and the anticipated Resilience Bill all reward the same fundamentals — then layer sector-specific obligations on top.

1. UK GDPR Article 32 technical controls — MFA, encryption, patch management, and access reviews. Many of these overlap directly with Cyber Essentials controls, so certifying gives you an audited baseline. 2. Incident response plan — a documented, tested process for detecting, responding to, and reporting incidents. Required under UK GDPR and NIS2, and anticipated under the Resilience Bill. 3. Supply chain security review — assess the security posture of your IT and software suppliers. Central to NIS2 and the Resilience Bill alike. 4. Board engagement — named accountability and regular security reporting at board level.

A pragmatic certification path for SMEs is Cyber Essentials, then IASME Cyber Assurance where you need broader, governance-level evidence. The UK government's Cyber Essentials scheme sets out the five controls every business should hold. AMVIA itself holds Cyber Essentials Plus, and our engineers are Microsoft-certified — one accountable provider for the controls and the platform they run on.

Where Do You Stand on Cybersecurity Compliance?

AMVIA provides a compliance gap assessment covering UK GDPR and relevant sector regulations — giving you a clear picture of your current position and a prioritised remediation plan.

Frequently Asked Questions