Compliance

EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

Sienna VanceSienna VanceApril 30, 2026
Share:
EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

Key takeaways

  • The EMEA compliance group spans 40+ frameworks across the EU, UK, Middle East, and Africa — a multinational SaaS company or fintech processing data in 5 EMEA markets will typically face obligations under at least 8 distinct frameworks simultaneously.

  • GDPR is the gravitational center of EU data protection, but NIS2 is the operational security obligation that most organisations are structurally unprepared for — particularly its 24-hour initial incident notification window and direct management liability provisions.

  • Saudi Arabia has built the most layered national cybersecurity stack in the EMEA group: ECC-1 as the baseline, OTCC-1 for OT environments, CGIoT-1 for IoT, CSCC-1 for cloud, SAMA CSF for financial institutions, and SACS-002 for third-party access — all separately enforceable by the NCA.

  • Germany C5:2020 attestation and Spain ENS certification are market-access controls in disguise: cloud providers without them cannot sell to public sector or regulated industry customers in those markets, regardless of ISO 27001 status.

  • Data localisation obligations in Russia (Federal Law 152-FZ) and cross-border transfer restrictions in Saudi Arabia PDPL create direct architectural conflicts with GDPR adequacy-based transfer mechanisms — organisations cannot satisfy both simultaneously without data segregation.

  • The EU Cyber Resilience Act closes the gap NIS2 leaves open: NIS2 governs how operators secure their infrastructure; the CRA governs the security of the products those operators buy. A manufacturer selling connected devices into the EU faces both.

  • UK Cyber Essentials is mandatory for UK government contracts involving personal data — ISO 27001 does not substitute for Cyber Essentials in UK government procurement.

TL;DR

The EMEA compliance group is not a single framework landscape. It is four overlapping ones: EU digital regulation, national data protection laws, national cybersecurity mandates, and sector-specific financial or defence requirements. The hard part is not understanding any individual framework. The hard part is that they conflict at the edges, enforce on different timelines, and assign liability to different people inside the same organisation. Getting one right while unknowingly breaking another is the standard failure mode.

The client who thought GDPR covered everything

A 60-person B2B SaaS company came to us for a gap analysis. They had a GDPR programme — a proper one, with a DPO, a data register, and breach notification procedures. They also had customers in Germany, customers in the Netherlands, a payment processing integration, and a new contract with a German public sector client requiring cloud services. Their CISO''s position going in: ''We are GDPR compliant. What else is there?''

What the assessment found: they were not registered under Germany''s KRITIS framework despite their infrastructure meeting the sector threshold. Their cloud environment had no BSI C5 attestation, making the public sector contract technically non-executable. Their payment integration fell squarely within PSD2''s Strong Customer Authentication requirements, which their product team had addressed partially but not completely. And their open banking API exposed customer account data to a third-party aggregator in a way that satisfied neither GDPR''s data minimisation principle nor PSD2''s TPP access controls.

Four separate exposure vectors. One team that believed they had already solved compliance.

Turning point:

The belief that GDPR is the EMEA compliance answer, rather than one layer of a multi-layer stack, is the most expensive misconception we see in mid-market organisations with European operations.

What the EMEA compliance group actually covers

The EMEA group in the Vulnox framework mapping contains 40+ distinct authoritative sources. They fall into five structural categories.

First: EU-wide horizontal regulations. GDPR for data protection, NIS2 for critical infrastructure cybersecurity, DORA for financial sector operational resilience, the EU AI Act for AI systems, the Cyber Resilience Act for connected products, and PSD2 for payment services. These apply across all EU member states simultaneously.

Second: national implementations and supplementary legislation. Every EU member state has national implementing legislation for GDPR and NIS2. Austria (DSG/NISG), Belgium (CCB framework), Germany (BDSG/KRITIS/NIS2UmsuCG), Greece (HDPA/NCA), Hungary (NAIH), Ireland (DPC), Italy (Garante/ACN), Netherlands (AP/NCSC-NL), Norway (Datatilsynet/NSM), Poland (UODO/KSC Act), Serbia (87/2018), Spain (LOPDGDD/ENS), Sweden (IMY/MSB), Switzerland (revFADP), and Turkey (KVKK) each bring their own enforcement posture and, in several cases, additional requirements beyond the EU baseline.

Third: UK post-Brexit frameworks. The UK DPA 2018 and UK GDPR form the data protection layer. The NCSC CAF v4.0 governs critical infrastructure cybersecurity. UK Cyber Essentials provides the government contract baseline. CAP 1850 covers aviation. DEFSTAN 05-138 governs the defence supply chain.

Fourth: Middle East and Gulf national frameworks. Israel operates its own Privacy Protection Law plus the INCD Cyber Defence Methodology. The UAE''s NIAF applies to government and critical infrastructure. Saudi Arabia has the most layered national stack in the group: ECC-1 as baseline, OTCC-1 for OT, CGIoT-1 for IoT, CSCC-1 for cloud, SAMA CSF for financial institutions, SACS-002 for third-party government system access, and the PDPL for data protection. Qatar operates the PDPPL.

Fifth: African frameworks. South Africa''s POPIA, Kenya''s DPA 2019, and Nigeria''s NDPR 2019 (transitioning to NDPA 2023) represent the African data protection tier within this group.

Russia''s Federal Law 152-FZ on Personal Data and Federal Law 187-FZ on Critical Information Infrastructure sit outside the EU/UK regulatory orbit and impose data localisation requirements that are structurally incompatible with GDPR transfer mechanisms.

Frameworks Covered
  • EU GDPR

  • EU NIS2

  • EU NIS2 Annex

  • EU DORA

  • EU AI Act

  • EU Cyber Resilience Act

  • EU Cyber Resilience Act Annexes

  • EU PSD2

  • EU EBA GL/2019/04

  • Austria

  • Belgium

  • Germany

  • Germany C5:2020

  • Germany BAIT

  • Greece

  • Hungary

  • Ireland

  • Italy

  • Netherlands

  • Norway

  • Poland

  • Serbia 87/2018

  • Spain 1720/2007

  • Spain 311/2022 (ENS)

  • Spain BOE-A-2022-7191

  • Spain CCN-STIC 825

  • Sweden

  • Switzerland

  • Turkey

  • UK DPA

  • UK CAF v4.0

  • UK CAP 1850

  • UK Cyber Essentials

  • UK DEFSTAN 05-138

  • Israel

  • Israel CDMO v1.0

  • UAE NIAF

  • Saudi Arabia ECC-1 2018

  • Saudi Arabia OTCC-1 2022

  • Saudi Arabia CSCC-1 2019

  • Saudi Arabia CGIoT-1:2024

  • Saudi Arabia SAMA CSF v1.0

  • Saudi Arabia SACS-002

  • Saudi Arabia Personal Data Protection Law

  • Qatar PDPPL

  • Russia

  • South Africa POPIA

  • Kenya DPA 2019

  • Nigeria DPR 2019

Framework by framework: what each one actually requires

Frameworks

Name

EU GDPR

Who It Applies To

Any organisation worldwide that processes personal data of EU or EEA residents. No minimum size threshold. No sector restriction.

Common Failure Mode

Organisations build a GDPR programme around documentation while leaving Article 32 technical security measures unquantified and untested. The programme satisfies auditors but would not survive an incident investigation.

What It Actually Requires

Six lawful bases for processing, data subject rights (access, rectification, erasure, portability, objection), mandatory DPIAs for high-risk processing, breach notification to supervisory authorities within 72 hours and to affected individuals without undue delay, DPO appointment where required, and restrictions on cross-border data transfers outside the EEA unless adequacy, SCCs, or binding corporate rules apply.

Enforcement And Consequences

National supervisory authorities enforce. Fines up to 20 million euros or 4% of global annual turnover for the most serious violations. Irish DPC, Italian Garante, Dutch AP, and German LfDI are consistently active enforcement authorities.

Relationship To Others In Group

Foundation for all EU member state data protection frameworks. National laws supplement but cannot weaken GDPR. UK GDPR mirrors it post-Brexit. NIS2 security requirements partially overlap Article 32 obligations.

Name

EU NIS2

Who It Applies To

Essential entities (Annex I: energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, space, public administration) and important entities (Annex II: postal, waste, chemicals, food, manufacturing, digital providers, research). Medium enterprises (50+ employees, 10M+ euro turnover) as general floor.

Common Failure Mode

The 24-hour notification window. Organisations have 72-hour breach notification ingrained from GDPR. NIS2 requires initial notification in 24 hours even before root cause is known. In our assessments, fewer than 20% of incident response procedures account for this distinction. (Vulnox assessment data, 2024)

What It Actually Requires

Risk management measures across 10 areas including incident handling, supply chain security, access control, encryption, and vulnerability disclosure. Initial incident notification to national CSIRT within 24 hours of awareness. Full report within 72 hours. Management bodies must approve security measures and can be personally liable. Board-level cybersecurity training required.

Enforcement And Consequences

Member states enforce through national competent authorities. Essential entities face fines up to 10 million euros or 2% of global turnover. Important entities up to 7 million euros or 1.4% of global turnover. Management liability is direct and personal.

Relationship To Others In Group

Transposed into national law by each EU member state. DORA is lex specialis for financial entities and applies instead of NIS2 for entities in its scope.

Name

EU NIS2 Annex

Who It Applies To

Any organisation assessing whether it falls within NIS2 scope. The Annexes define sector classifications determining essential or important entity status.

Common Failure Mode

Mid-market manufacturers and food producers assuming they are out of scope. Annex II scope is broader than most organisations have mapped.

What It Actually Requires

Annex I lists 11 highly critical sectors. Annex II lists 7 other critical sectors. Classification determines the applicable enforcement regime and fine tier. Organisations must self-assess against the Annexes to determine their NIS2 obligations.

Enforcement And Consequences

No direct enforcement via the Annexes themselves. But misclassifying out of scope is itself an exposure: national authorities can compel registration and impose obligations retroactively.

Relationship To Others In Group

Inseparable from NIS2 itself. Scope determination precedes all other NIS2 obligations.

Name

EU DORA

Who It Applies To

Banks, investment firms, insurance companies, payment institutions, e-money institutions, crypto-asset service providers, and their critical ICT third-party service providers. Mandatory from January 2025.

Common Failure Mode

Financial institutions that completed NIS2 gap analyses assuming DORA is covered. DORA is more prescriptive on ICT third-party contracts, penetration testing frequency, and incident classification than NIS2.

What It Actually Requires

ICT risk management framework, incident classification and reporting, digital operational resilience testing including threat-led penetration testing for significant entities, ICT third-party risk management, and contractual requirements for ICT providers covering exit strategies and audit rights.

Enforcement And Consequences

National financial regulators enforce. The ESAs oversee critical ICT third-party providers directly. Management bodies bear individual accountability.

Relationship To Others In Group

Lex specialis relative to NIS2 for financial entities. Builds on EBA GL/2019/04 and supersedes it in significant areas. SAMA CSF and Germany BAIT serve analogous functions in their respective jurisdictions.

Name

EU AI Act

Who It Applies To

AI system providers, deployers, importers, and distributors placing AI systems on the EU market or using them in the EU. Phased implementation 2024-2027.

Common Failure Mode

Organisations using third-party AI tools in HR processes (automated CV screening, performance assessment) not recognising these as high-risk AI deployments requiring conformity assessment. The classification applies to deployers, not only developers.

What It Actually Requires

Risk-based classification into prohibited, high-risk, limited risk, and minimal risk categories. High-risk AI systems require conformity assessment, technical documentation, human oversight mechanisms, and registration in an EU database. General-purpose AI models face transparency and systemic risk obligations.

Enforcement And Consequences

National market surveillance authorities enforce. Fines up to 35 million euros or 7% of global turnover for prohibited AI violations. Up to 15 million euros or 3% for high-risk failures.

Relationship To Others In Group

Intersects with GDPR automated decision-making provisions (Article 22) and NIS2 security requirements. CRA security-by-design requirements apply to AI systems embedded in products with digital elements.

Name

EU Cyber Resilience Act

Who It Applies To

Manufacturers, importers, and distributors of products with digital elements sold in the EU — including hardware with embedded software, standalone software, and connected devices.

Common Failure Mode

SaaS providers assuming the CRA does not apply to them. Remote data processing services are excluded — but SaaS providers that also distribute downloadable software components, SDKs, or on-premise versions fall within CRA scope for those components.

What It Actually Requires

Security by design across the product lifecycle, free security updates for the product''s support period, vulnerability disclosure to ENISA within 24 hours of awareness of an actively exploited vulnerability, and conformity assessment resulting in CE marking for cybersecurity.

Enforcement And Consequences

National market surveillance authorities enforce. Fines up to 15 million euros or 2.5% of global turnover for serious violations. Products failing conformity can be withdrawn from the EU market.

Relationship To Others In Group

Complements NIS2: NIS2 governs how critical infrastructure operators secure their systems; CRA governs the security of the products they purchase. The CRA Annexes define specific product categories and conformity routes.

Name

EU Cyber Resilience Act Annexes

Who It Applies To

Manufacturers determining specific CRA obligations. The Annexes define essential cybersecurity requirements and product classifications.

Common Failure Mode

Manufacturers of Class II products (browsers, password managers, network management software, industrial firewalls) underestimating third-party conformity assessment lead times.

What It Actually Requires

Annex I specifies essential cybersecurity requirements. Annex II and III classify critical products into Class I (enhanced self-assessment) and Class II (third-party conformity assessment) categories.

Enforcement And Consequences

The Annexes determine conformity route: self-assessment versus third-party audit. Class II products require notified body involvement, with significant cost and timeline implications.

Relationship To Others In Group

Technical specification layer for the CRA. Cannot be read in isolation from the main regulation.

Name

EU PSD2

Who It Applies To

Payment institutions, e-money institutions, banks offering payment services, AISPs, and PISPs operating in the EU.

Common Failure Mode

E-commerce businesses assuming their payment gateway handles all PSD2/SCA compliance. SCA exemptions require active implementation by merchants, not just passive reliance on acquirers.

What It Actually Requires

Strong Customer Authentication for electronic payments. Open banking APIs enabling licensed TPP access to payment account data. Major security incident reporting to national financial regulators. EBA Regulatory Technical Standards specify SCA implementation.

Enforcement And Consequences

National financial regulators enforce. Enforcement has focused heavily on SCA implementation failures.

Relationship To Others In Group

Overlaps with DORA for regulated payment institutions. Forthcoming PSD3 will tighten requirements. Intersects with GDPR on processing of payment account data by TPPs.

Name

EU EBA GL/2019/04

Who It Applies To

Banks, investment firms, and payment institutions regulated under EU banking legislation.

Common Failure Mode

Organisations that achieved EBA GL/2019/04 compliance assuming it constituted DORA readiness. DORA is more prescriptive particularly on third-party risk and resilience testing.

What It Actually Requires

ICT governance framework, information risk assessments, security requirements covering access management and encryption, ICT operations management, and incident management. Precursor standard to DORA.

Enforcement And Consequences

Enforced by national banking regulators as supervisory expectations under CRD IV. Substantially superseded by DORA for entities in DORA''s scope.

Relationship To Others In Group

Direct predecessor to DORA. Germany BAIT operates in parallel for German BaFin-regulated institutions.

Name

Germany C5:2020

Who It Applies To

Cloud service providers targeting German public sector or regulated industry customers. Third-party attestation by accredited auditors required.

Common Failure Mode

Assuming ISO 27001 satisfies C5. The overlap is significant but incomplete. C5 includes transparency disclosure requirements and specific technical controls around multi-tenancy isolation that ISO 27001 does not address. An ISO 27001 certificate and a C5 attestation are different documents serving different purposes.

What It Actually Requires

17 control domains including organisation of information security, human resources, physical security, identity management, cryptography, communications, incident management, and business continuity. Attestation reports must disclose the system description and control testing results.

Enforcement And Consequences

Functionally mandatory for German public sector and regulated industry market access. Without a current C5 attestation, cloud providers cannot realistically compete for German government contracts.

Relationship To Others In Group

Aligns with ISO 27001 and SOC 2 but addresses German cloud procurement specifically. Structural parallel to Spain ENS for public sector market access.

Name

Germany BAIT

Who It Applies To

Banks, savings banks, and financial institutions regulated by BaFin in Germany.

Common Failure Mode

German financial institutions treating BAIT and DORA as sequential rather than simultaneous obligations. DORA is directly applicable from January 2025. BAIT continues as BaFin national guidance for DORA implementation.

What It Actually Requires

IT governance with defined IT strategy, information risk management, information security management, IT operations, access management, outsourcing, and user-developed IT. BaFin expects demonstrable compliance through supervisory examinations.

Enforcement And Consequences

BaFin supervisory examinations. Non-compliance can trigger capital add-ons, remediation orders, or management accountability actions.

Relationship To Others In Group

National complement to EBA GL/2019/04 and DORA for German financial institutions.

Name

Germany

Who It Applies To

Organisations operating in Germany subject to GDPR/BDSG, BSI Act and IT Security Act 2.0, and KRITIS regulations for critical infrastructure.

Common Failure Mode

Foreign companies with German operations appointing a DPO for EU purposes and assuming it covers BDSG. BDSG''s mandatory DPO threshold (20+ employees processing personal data automatically) is lower than GDPR''s general threshold.

What It Actually Requires

BDSG supplements GDPR with mandatory DPO appointment for organisations with 20+ employees regularly processing personal data automatically. KRITIS operators must implement state-of-the-art security measures and report significant incidents to BSI. NIS2UmsuCG extends obligations to a broader sector set.

Enforcement And Consequences

State data protection authorities enforce GDPR/BDSG. BSI enforces cybersecurity obligations. Germany has some of Europe''s most active DPAs.

Relationship To Others In Group

National layer on top of GDPR, NIS2, and DORA. German organisations also face C5 requirements for cloud procurement and BAIT for banking.

Name

Austria

Who It Applies To

Organisations operating in Austria subject to GDPR/DSG and NIS2 via the Austrian NISG.

Common Failure Mode

Assuming the DSB is the only relevant authority. Regulated sector organisations face parallel oversight from their sector regulator.

What It Actually Requires

DSG supplements GDPR with Austrian provisions. NISG transposes NIS2 with RTR involvement in cybersecurity oversight for electronic communications.

Enforcement And Consequences

Austrian Data Protection Authority (DSB) enforces GDPR/DSG. RTR and sector regulators enforce NISG. Co-enforcement model with multiple competent authorities across sectors.

Relationship To Others In Group

Standard EU member state implementation. No significant national additions beyond the EU baseline outside of NISG procedural requirements.

Name

Belgium

Who It Applies To

Organisations operating in Belgium subject to GDPR (Belgian DPA), NIS2 via national legislation, and voluntary CCB CyberFundamentals Framework guidance.

Common Failure Mode

Treating CCB guidance as optional. For essential entities under NIS2, CCB implementing measures are binding requirements.

What It Actually Requires

Belgian DPA enforces GDPR with an active track record particularly in direct marketing and cookie consent. CCB coordinates national incident response and publishes CyberFundamentals providing a practical four-tier security baseline.

Enforcement And Consequences

Belgian DPA has been active against major platforms for cookie consent non-compliance. CCB issues binding cybersecurity measures for NIS2-scope essential entities.

Relationship To Others In Group

Standard EU member state implementation. CCB CyberFundamentals is Belgium''s practical NIS2 implementation contribution.

Name

Greece

Who It Applies To

Organisations operating in Greece subject to GDPR (HDPA) and NIS2 via national law with NCA coordination.

Common Failure Mode

Underestimating the HDPA. Smaller member states'' authorities are systematically overlooked in multi-jurisdiction GDPR compliance programmes.

What It Actually Requires

HDPA enforces GDPR with demonstrated willingness to impose significant fines. NCA coordinates cybersecurity for NIS2-scope entities.

Enforcement And Consequences

HDPA enforcement is more active than its reputation suggests. A 1 million euro fine against a major telecom for direct marketing violations was issued in 2023.

Relationship To Others In Group

Standard EU member state layer.

Name

Hungary

Who It Applies To

Organisations operating in Hungary subject to GDPR (NAIH) and NIS2 via national law.

Common Failure Mode

Employee monitoring deployments that comply with GDPR interpretations in Western Europe but fall afoul of NAIH''s proportionality requirements in workplace monitoring contexts.

What It Actually Requires

NAIH enforces GDPR. Hungary has transposed NIS2 with sector competent authorities for energy, transport, water, and digital infrastructure.

Enforcement And Consequences

NAIH enforcement has been active on CCTV, employee monitoring, and direct marketing.

Relationship To Others In Group

Standard EU member state layer.

Name

Ireland

Who It Applies To

Technology companies, financial services, and multinationals with EU headquarters in Ireland. DPC is lead GDPR supervisory authority for Irish-established organisations.

Common Failure Mode

Multinationals with Irish EU headquarters treating DPC engagement as procedural. A DPC fine is not a local Irish issue.

What It Actually Requires

DPC enforces GDPR as lead authority for many major US tech platforms. Ireland''s NCSC coordinates national cybersecurity. NIS2 transposed through national legislation.

Enforcement And Consequences

DPC has imposed some of the largest GDPR fines on record: 1.2 billion euros against Meta in 2023, 405 million against Instagram, 265 million against Facebook. DPC outcomes bind all EU member states.

Relationship To Others In Group

Ireland''s significance is disproportionate to its size because of its role as lead authority for major tech platforms.

Name

Italy

Who It Applies To

Organisations operating in Italy subject to GDPR (Garante), NIS2 (coordinated by ACN), and the Golden Power framework for critical infrastructure.

Common Failure Mode

AI and data-intensive platforms launching in the EU without Italy-specific DPA impact assessment. The Garante''s 30-day ChatGPT operational suspension was a concrete demonstration of the risk.

What It Actually Requires

Garante is one of Europe''s most aggressive GDPR enforcement authorities. ACN oversees NIS2 compliance with detailed guidance for essential and important entities.

Enforcement And Consequences

Garante fines are consistent and significant: 20 million euros against Clearview AI, temporary ChatGPT ban in March 2023, major actions against TikTok and Enel.

Relationship To Others In Group

Garante enforcement risk and ACN cybersecurity oversight are distinct national layers. Golden Power creates additional deal-clearance obligations for M&A involving Italian critical infrastructure.

Name

Netherlands

Who It Applies To

Organisations operating in the Netherlands subject to GDPR (AP), NIS2 (NCSC-NL), and sector-specific DNB requirements for financial institutions.

Common Failure Mode

Financial institutions satisfying DORA at the EU level but not mapping against DNB national guidance, which goes beyond DORA''s baseline in outsourcing oversight.

What It Actually Requires

Dutch AP is an active enforcer. DNB issues additional operational resilience requirements for financial institutions that layer on top of DORA.

Enforcement And Consequences

AP fines have reached 750,000 euros in recent cases. DNB supervisory expectations for operational resilience are among the most detailed in the EU for the financial sector.

Relationship To Others In Group

Standard EU member state layer with notably active DPA and above-average financial sector regulatory depth.

Name

Norway

Who It Applies To

Organisations operating in Norway subject to GDPR via EEA membership (Datatilsynet) and NSM cybersecurity guidance. Norway is EEA but not EU.

Common Failure Mode

Treating Norway as functionally equivalent to an EU member state. The GDPR one-stop-shop mechanism does not operate the same way for EEA-only states, and Norway has its own national cybersecurity governance track.

What It Actually Requires

GDPR applies through EEA incorporation. NSM Basic Principles for ICT Security provides a practical security baseline. Financial sector faces FSA (Finanstilsynet) ICT requirements.

Enforcement And Consequences

Datatilsynet enforces GDPR. NSM guidance informs regulatory expectations without direct enforcement authority.

Relationship To Others In Group

EEA-adjacent to EU frameworks with distinct national cybersecurity governance. NSM guidance is more detailed than many EU member states'' NIS2 implementations.

Name

Poland

Who It Applies To

Organisations operating in Poland subject to GDPR (UODO), NIS2 via the KSC Act, and KNF financial requirements.

Common Failure Mode

Cookie consent implementations that satisfy DPC or German DPA standards but fail UODO requirements on consent granularity and pre-ticking.

What It Actually Requires

UODO enforces GDPR with particular focus on cookie consent and direct marketing. KSC Act transposes NIS2 with CERT Polska as the national coordination infrastructure.

Enforcement And Consequences

UODO enforcement has increased significantly since 2021. Polish UODO has taken stricter positions on consent granularity than some other EU authorities.

Relationship To Others In Group

Standard EU member state layer with above-average UODO enforcement focus on consent mechanisms.

Name

Serbia 87/2018

Who It Applies To

Organisations operating in Serbia or processing personal data of Serbian residents. GDPR-aligned but outside the EU enforcement architecture.

Common Failure Mode

Organisations assuming pre-GDPR adequacy continues indefinitely. Serbia''s adequacy status for EU data transfers is contingent on ongoing framework alignment.

What It Actually Requires

Rights of access, rectification, erasure, and restriction. Security measure obligations. Commissioner for Information of Public Importance enforces.

Enforcement And Consequences

Lower enforcement intensity than EU member state DPAs currently, but EU accession trajectory means enforcement will increase.

Relationship To Others In Group

GDPR-modelled but outside EU enforcement architecture. Useful for organisations mapping GDPR-plus-Serbia data flows.

Name

Spain 1720/2007

Who It Applies To

Compliance professionals reviewing historical obligations or legacy system security baselines. Superseded by GDPR and LOPDGDD.

Common Failure Mode

Organisations updating legacy compliance documentation carrying forward RD 1720/2007 references without updating to current LOPDGDD/GDPR language.

What It Actually Requires

Established three security levels (basic, medium, high) for personal data based on sensitivity. The classification logic still informs Spanish DPA practice under GDPR.

Enforcement And Consequences

Not independently enforced. Current framework is GDPR/LOPDGDD.

Relationship To Others In Group

Historical precursor. Three-tier security level logic has parallels in ENS basic/medium/high classification.

Name

Spain 311/2022 (ENS)

Who It Applies To

Spanish public administration bodies and technology vendors providing IT services or products to the Spanish public sector. ENS certification mandatory for public sector contracts.

Common Failure Mode

Vendors pursuing ENS certification after contract award. ENS certification timelines of 6 to 18 months for first-time applicants mean the process must start before bidding, not after winning.

What It Actually Requires

System classification into basic, medium, or high categories based on risk impact. Mandatory controls per category across five security dimensions. ENS certification from accredited auditors required for vendors.

Enforcement And Consequences

CCN-CERT oversees ENS implementation. Vendors without ENS certification cannot contract with Spanish public administration. Market access control.

Relationship To Others In Group

Spain''s equivalent of Germany C5 as a public sector market-access security standard. CCN-STIC 825 is the cloud-specific implementation guide.

Name

Spain BOE-A-2022-7191

Who It Applies To

Legal reference for ENS obligations in Spanish public sector contracts. Same scope as Spain 311/2022.

Common Failure Mode

Contract documentation referencing the BOE citation without mapping to the substantive requirements of RD 311/2022.

What It Actually Requires

Official Spanish Official Gazette citation for Royal Decree 311/2022. Used as the formal legal reference for ENS compliance obligations.

Enforcement And Consequences

Same as Spain 311/2022. Administrative layer on the substantive requirements.

Relationship To Others In Group

Administrative citation layer for Spain 311/2022. No substantive difference.

Name

Spain CCN-STIC 825

Who It Applies To

Cloud service providers seeking ENS certification for Spanish public sector customers and public administration bodies adopting cloud.

Common Failure Mode

Cloud providers mapping ISO 27017 controls to CCN-STIC 825 without addressing Spain-specific data residency and sovereignty requirements.

What It Actually Requires

Technical guidance for implementing ENS controls in cloud environments: shared responsibility models, data residency requirements, VM isolation, audit logging for cloud tenants, and identity federation.

Enforcement And Consequences

Enforced through the ENS certification process. Required as part of ENS cloud certification.

Relationship To Others In Group

Technical implementation companion to ENS. Read together with Spain 311/2022.

Name

Sweden

Who It Applies To

Organisations operating in Sweden subject to GDPR (IMY), NIS2 via national law, MSB MSBFS regulations for public sector, and NATO obligations following 2024 accession.

Common Failure Mode

Public authorities that implemented MSB MSBFS as a standalone framework without integrating NIS2 obligations from 2024.

What It Actually Requires

IMY enforces GDPR. MSB MSBFS 2020:7 mandates structured information security management for public authorities. NIS2 transposed through national law.

Enforcement And Consequences

IMY is increasingly active. MSB MSBFS compliance is mandatory for public sector with consequences documented in annual MSB reviews.

Relationship To Others In Group

Standard EU member state layer with notable public sector depth and emerging NATO obligations.

Name

Switzerland

Who It Applies To

Organisations operating in Switzerland or processing personal data of Swiss residents. Financial institutions face additional FINMA ICT requirements.

Common Failure Mode

EU-based organisations treating revFADP as identical to GDPR without implementing Swiss-specific requirements, particularly the different breach notification structure and representative appointment.

What It Actually Requires

Revised FADP (revFADP) effective September 2023 requires DPIAs for high-risk processing, privacy notices, breach notification, and Swiss representative appointment for foreign organisations processing Swiss data at scale.

Enforcement And Consequences

FDPIC enforcement. Switzerland has EU adequacy status but is not in the EEA — parallel compliance obligations apply.

Relationship To Others In Group

Adjacent to but outside the EU framework. Substantially aligned with GDPR but legally distinct.

Name

Turkey

Who It Applies To

Organisations operating in Turkey or processing personal data of Turkish residents. KVKK Law No. 6698 applies.

Common Failure Mode

Organisations with Turkish operations not registering with VERBİS. Registration is mandatory for data controllers processing Turkish personal data above minimal thresholds regardless of the controller''s location.

What It Actually Requires

Data controller registration with the VERBİS registry, consent-based processing as default, cross-border transfer restrictions, and technical security measures. Turkey is pursuing EU adequacy.

Enforcement And Consequences

KVKK Board enforcement is active for VERBİS non-registration and inadequate security measures.

Relationship To Others In Group

Outside the EU but GDPR-modelled. Cross-border transfer restrictions create friction for EU-Turkey data flows.

Name

UK DPA

Who It Applies To

Organisations operating in the UK or processing personal data of UK residents. UK GDPR and DPA 2018 together form the UK data protection framework post-Brexit.

Common Failure Mode

Post-Brexit organisations maintaining a single EU GDPR programme and assuming it covers UK obligations. UK and EU frameworks have diverged in adequacy decisions and transfer mechanisms.

What It Actually Requires

Substantively equivalent to EU GDPR with UK-specific adequacy decisions, UK International Data Transfer Agreements for cross-border transfers, and ICO-specific guidance. 72-hour breach notification to ICO.

Enforcement And Consequences

ICO fining powers up to 17.5 million pounds or 4% of global turnover. Substantial fines against British Airways, Marriott, and DSG Retail.

Relationship To Others In Group

UK-specific parallel to EU GDPR. Legally distinct parallel obligation for organisations with both EU and UK operations.

Name

UK CAF v4.0

Who It Applies To

UK operators of essential services and digital service providers under UK NIS Regulations. Regulated by Ofcom, Ofgem, FCA, and sector regulators.

Common Failure Mode

Operators completing CAF self-assessments as a documentation exercise without evidence-based control testing. UK regulators have stated clearly that assertions without evidence are not satisfactory.

What It Actually Requires

14 cybersecurity principles across four objectives: managing security risk, protecting against cyberattack, detecting cybersecurity events, and minimising impact. Used by UK regulators to assess NIS compliance.

Enforcement And Consequences

Regulators can impose fines up to 17 million pounds for serious NIS failures. CAF outcomes feed into regulatory risk ratings.

Relationship To Others In Group

UK equivalent to EU NIS2 at the assessment level. More detailed than NIS2''s security requirements in its principle-level guidance. DEFSTAN 05-138 Issue 4 now aligns with CAF v4.0.

Name

UK CAP 1850

Who It Applies To

UK-regulated aviation organisations including airlines, airports, air navigation service providers, and aviation maintenance and technology suppliers.

Common Failure Mode

Aviation organisations treating IT security and OT/avionics security as separate programmes. CAP 1850 covers the full aviation environment.

What It Actually Requires

Cybersecurity risk management processes consistent with ICAO and EASA requirements. CAP 1850 maps CAF principles to aviation-specific contexts covering aircraft systems, airport OT, and air traffic management.

Enforcement And Consequences

CAA oversight. Aviation cybersecurity failures can result in Air Operator Certificate conditions and operational restrictions.

Relationship To Others In Group

Sector-specific application of CAF principles to aviation. Works alongside UK DPA and CAF v4.0.

Name

UK Cyber Essentials

Who It Applies To

UK organisations bidding for government contracts involving personal data or sensitive information. Mandatory since 2014.

Common Failure Mode

ISO 27001-certified organisations assuming they qualify for government contracts without Cyber Essentials. ISO 27001 does not substitute for Cyber Essentials in UK government procurement.

What It Actually Requires

Five controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management (critical patches within 14 days). Cyber Essentials Plus adds independent technical verification. Annual renewal required.

Enforcement And Consequences

Contract qualification requirement. No Cyber Essentials certification means no qualifying UK government contracts.

Relationship To Others In Group

Entry-level UK cybersecurity baseline. Supply chain security gating mechanism that CAF does not provide.

Name

UK DEFSTAN 05-138

Who It Applies To

UK MOD suppliers and subcontractors handling MOD information or operating on MOD networks. Mandatory for MOD contracts.

Common Failure Mode

Defence suppliers who achieved DEFSTAN 05-138 compliance against an earlier issue and have not assessed the Issue 4 changes. Issue 4''s CAF alignment and tiered model are substantive changes.

What It Actually Requires

Issue 4 (May 2024) introduced a tiered requirements model based on information sensitivity, aligning with NCSC CAF v4.0. Covers governance, risk management, access control, incident response, and supply chain security.

Enforcement And Consequences

MOD contract requirement. Non-compliance results in contract termination or disqualification from defence procurement.

Relationship To Others In Group

UK defence-specific standard alongside Cyber Essentials and CAF v4.0.

Name

Israel

Who It Applies To

Organisations operating in Israel or transferring data to or from Israel. Israel has EU adequacy status.

Common Failure Mode

Organisations relying on Israel''s EU adequacy status without maintaining the security measures that underpin that adequacy finding.

What It Actually Requires

Privacy Protection Law (5741-1981) governs personal data with ongoing reform toward GDPR-level standards. INCD issues sector-specific cybersecurity directives.

Enforcement And Consequences

Privacy Protection Authority enforces. INCD directives have sector-specific enforcement through licensing authorities.

Relationship To Others In Group

CDMO v1.0 is the operational security layer. Privacy Protection Law is the data protection layer.

Name

Israel CDMO v1.0

Who It Applies To

Israeli organisations using it as a structured self-assessment tool. Sector-specific mandatory requirements may reference CDMO.

Common Failure Mode

Treating CDMO as a documentation exercise. The protection domain includes specific technical controls requiring evidence-based testing.

What It Actually Requires

Controls across protection, detection, and response domains. Aligns with NIST CSF. Used by INCD as a baseline for sector-specific cybersecurity requirements.

Enforcement And Consequences

Voluntary framework for most, mandatory-by-reference in several INCD sector directives for critical infrastructure.

Relationship To Others In Group

Operational companion to Israel''s Privacy Protection Law. NIST CSF alignment makes it mappable to other frameworks.

Name

UAE NIAF

Who It Applies To

UAE federal government entities, critical infrastructure operators, and technology vendors providing services to UAE government.

Common Failure Mode

Vendors assuming ISO 27001 satisfies NIAF contractual requirements without verifying the specific NIAF control mapping their UAE government customer requires.

What It Actually Requires

Information security controls across governance, operations, and technical domains aligned with international standards. Mandatory for UAE federal government entities.

Enforcement And Consequences

TDRA oversight. Vendors providing services to UAE government face contractual NIAF requirements.

Relationship To Others In Group

UAE federal government baseline. Structurally similar in function to Saudi Arabia''s national framework at the federal level.

Name

Saudi Arabia ECC-1 2018

Who It Applies To

All Saudi government organisations, critical national infrastructure operators, and their ICT service providers.

Common Failure Mode

Organisations achieving ECC-1 compliance and assuming it covers OTCC-1, CGIoT-1, or CSCC-1 obligations. ECC-1 is the floor. The sector-specific standards add requirements on top.

What It Actually Requires

Five domains covering cybersecurity governance, defence, resilience, third-party and cloud cybersecurity, and industrial control systems. 114 controls. Mandatory baseline from which all other Saudi NCA frameworks derive.

Enforcement And Consequences

NCA conducts assessments and audits. Non-compliant entities face formal remediation requirements.

Relationship To Others In Group

Foundation layer of Saudi Arabia''s national cybersecurity stack. OTCC-1, CGIoT-1, CSCC-1, and SAMA CSF all reference ECC-1 as baseline.

Name

Saudi Arabia OTCC-1 2022

Who It Applies To

Government entities and CNI operators with OT environments: energy, utilities, manufacturing, water, transportation.

Common Failure Mode

IT security teams applying IT-based patch management processes to OT environments. OTCC-1 acknowledges OT patch constraints and requires compensating controls when patching is not feasible.

What It Actually Requires

OT-specific security controls: ICS/SCADA asset inventory, IT/OT network segmentation, OT-specific access control, vulnerability management adapted for operationally constrained environments, and OT incident response.

Enforcement And Consequences

NCA mandatory assessment for in-scope OT operators. Failures can trigger NCA intervention and operational restrictions.

Relationship To Others In Group

Builds on ECC-1. Mandatory for OT environments alongside ECC-1.

Name

Saudi Arabia CGIoT-1:2024

Who It Applies To

IoT device manufacturers, system integrators, and government or CNI operators deploying IoT in Saudi Arabia.

Common Failure Mode

Consumer IoT manufacturers assuming CGIoT-1 applies only to enterprise-grade equipment. The scope includes connected consumer devices in government or CNI worker facility contexts.

What It Actually Requires

Device security (secure boot, minimal default credentials, firmware signature), communications protection (encrypted transmission, certificate management), data security, and operational controls across IoT ecosystems.

Enforcement And Consequences

NCA mandatory for in-scope IoT deployments in government or CNI contexts.

Relationship To Others In Group

IoT-specific layer of the Saudi cybersecurity stack alongside ECC-1 and OTCC-1. More operationally specific than the EU CRA for IoT, though both address product-level security by design.

Name

Saudi Arabia CSCC-1 2019

Who It Applies To

Cloud service providers operating in Saudi Arabia targeting government or regulated sector customers.

Common Failure Mode

Multi-cloud providers hosting Saudi government data in UAE or Bahrain data centres assuming regional proximity satisfies Saudi data residency requirements. CSCC-1 requires data residency within Saudi Arabia itself.

What It Actually Requires

Data residency in Saudi Arabia for government data, security controls across 14 domains, incident management, and third-party auditing.

Enforcement And Consequences

CITC oversight. Required for Saudi government cloud procurement. Without CSCC-1 compliance, cloud providers cannot service Saudi government customers.

Relationship To Others In Group

Cloud-specific layer of the Saudi compliance stack alongside ECC-1. Structural parallel to Germany C5.

Name

Saudi Arabia SAMA CSF v1.0

Who It Applies To

Banks, insurance companies, finance companies, and payment service providers regulated by SAMA.

Common Failure Mode

SAMA-regulated institutions submitting self-assessments scoring at Maturity Level 3 without operational evidence. SAMA examiners cross-check self-reported scores against actual system configurations and audit trails. The gap between self-reported and demonstrable maturity is the consistent finding in our Saudi financial sector assessments. (Vulnox assessment data, 2024)

What It Actually Requires

Four domains: cybersecurity leadership and governance, risk management and compliance, operations and technology, and third-party cybersecurity. 140+ controls. Annual self-assessment submitted to SAMA. SAMA examination reviews self-assessment accuracy.

Enforcement And Consequences

SAMA examinations assess compliance. Deficiencies result in findings requiring remediation. Repeated failures can result in regulatory sanctions.

Relationship To Others In Group

Saudi Arabia''s equivalent of DORA/BAIT for financial institutions. Works on top of ECC-1.

Name

Saudi Arabia SACS-002

Who It Applies To

Technology vendors, system integrators, and service providers seeking access to Saudi government systems and networks.

Common Failure Mode

Vendors achieving ECC-1 compliance and assuming SACS-002 is covered. SACS-002 includes third-party-specific access management and secure remote access requirements not fully addressed by ECC-1.

What It Actually Requires

Security controls commensurate with the sensitivity of government data the vendor will access: access management, secure development, system hardening, and security monitoring for vendor systems connecting to government infrastructure.

Enforcement And Consequences

Prerequisite for government system access. Without SACS-002 compliance demonstration, vendors cannot connect to Saudi government networks.

Relationship To Others In Group

Supply chain security layer for Saudi government system access. Works alongside ECC-1. Functional equivalent to UK DEFSTAN 05-138 in the supply chain context.

Name

Saudi Arabia Personal Data Protection Law

Who It Applies To

Organisations operating in Saudi Arabia or processing personal data of Saudi residents. SDAIA enforces.

Common Failure Mode

Multinationals extending GDPR programmes to Saudi Arabia without addressing the PDPL-specific provisions, particularly the cross-border transfer regime which is more restrictive than GDPR''s SCC mechanism.

What It Actually Requires

Consent-based processing as default, data subject rights (access, correction, deletion), cross-border transfer restrictions requiring SDAIA approval or adequate protection finding, DPO appointment for high-volume processors, and mandatory breach notification.

Enforcement And Consequences

SDAIA enforcement. Fines up to SAR 5 million. Saudi Arabia is in early enforcement phase with developing regulatory guidance.

Relationship To Others In Group

Saudi Arabia''s data protection layer. PDPL and ECC-1 together form the baseline compliance obligation for most Saudi operations.

Name

Qatar PDPPL

Who It Applies To

Organisations operating in Qatar or processing personal data of Qatari residents.

Common Failure Mode

Treating PDPPL as a simplified GDPR without addressing the consent requirements, which are structured differently from GDPR''s multi-ground lawful basis model.

What It Actually Requires

Consent for processing, data subject rights (access and correction), security measures appropriate to data sensitivity, and breach notification. Ministry of Transport and Communications administers.

Enforcement And Consequences

Developing enforcement posture. Framework is in place but enforcement intensity is currently lower than EU equivalents.

Relationship To Others In Group

Gulf state data protection framework. Less developed than Saudi Arabia''s PDPL. Organisations operating across the GCC face PDPPL, Saudi PDPL, and UAE data protection as distinct but thematically similar obligations.

Name

Russia

Who It Applies To

Organisations operating in Russia or processing personal data of Russian citizens. Multinationals with Russian customers or employees.

Common Failure Mode

Organisations assessing Russia as too complex and avoiding the jurisdiction without establishing whether they already process Russian citizen data through global platforms.

What It Actually Requires

Federal Law 152-FZ requires personal data of Russian citizens to be stored on servers in Russia. Federal Law 187-FZ on Critical Information Infrastructure imposes security requirements and mandatory incident reporting for CII operators. Roskomnadzor enforces data protection. FSTEC oversees CII cybersecurity.

Enforcement And Consequences

Roskomnadzor has blocked platforms that refused localisation requirements (LinkedIn blocked since 2016). Geopolitical context means enforcement unpredictability is higher than in other jurisdictions.

Relationship To Others In Group

Structurally incompatible with GDPR cross-border transfer mechanisms. Russian data localisation requirements mean GDPR-compliant data flows cannot route Russian citizen data through EU infrastructure while satisfying both laws simultaneously.

Name

South Africa POPIA

Who It Applies To

Public and private bodies processing personal information of South African data subjects. Information Officer appointment mandatory.

Common Failure Mode

Organisations that registered an Information Officer but have not built the operational procedures for breach detection, data subject request handling, and notification workflows that POPIA requires.

What It Actually Requires

Eight conditions for lawful processing. Breach notification to the Information Regulator and affected data subjects. Information Officers must be registered with the Information Regulator.

Enforcement And Consequences

Information Regulator demonstrating enforcement willingness. Fines up to R10 million and imprisonment for serious violations.

Relationship To Others In Group

Africa''s most developed data protection framework. Eight conditions map closely to GDPR principles, making dual-compliance relatively efficient for organisations already running GDPR programmes.

Name

Kenya DPA 2019

Who It Applies To

Organisations operating in Kenya or processing personal data of Kenyan residents. ODPC registration required for data controllers.

Common Failure Mode

Multinationals with Kenyan operations running GDPR programmes and assuming ODPC registration is not required because they are EU-established. Registration obligations apply regardless of controller establishment location.

What It Actually Requires

GDPR-aligned principles with ODPC registration requirement. Data processors must operate under written agreements with controllers.

Enforcement And Consequences

ODPC enforcement is developing. Registration compliance is being actively pursued.

Relationship To Others In Group

East Africa''s primary data protection framework. Works alongside POPIA for organisations with pan-African operations.

Name

Nigeria DPR 2019

Who It Applies To

Organisations operating in Nigeria or processing personal data of Nigerian residents. Now transitioning to the Nigeria Data Protection Act 2023 (NDPA).

Common Failure Mode

Organisations complying with NDPR and not assessing NDPA 2023 obligations. The transition is not automatic — NDPA introduces expanded data subject rights and more structured DPIA obligations.

What It Actually Requires

NDPR required lawful processing, data subject rights, security safeguards, mandatory DPIAs for high-volume processing, and annual audits submitted to NITDA. The NDPA 2023 establishes the Nigeria Data Protection Commission with broader enforcement powers.

Enforcement And Consequences

NITDA has issued fines and enforcement notices. NDPC under NDPA has broader enforcement powers. Nigeria''s enforcement is among the more active in Africa.

Relationship To Others In Group

West Africa''s primary data protection framework. The NDPA 2023 transition is the current operational priority for organisations with Nigerian operations.

Where these frameworks overlap and where they collide

Overlaps

Frameworks
  • EU GDPR

  • EU NIS2

  • EU DORA

Where They Diverge

The triggering criteria, notification destinations, and content requirements differ for each framework. A financial institution suffering a ransomware attack that does not expose personal data could trigger both NIS2 and DORA notifications but not a GDPR breach notification. The same team owns all three obligations but the processes cannot be unified without losing the distinctions each regulator requires.

Shared Control Area

Security incident detection and notification. All three require security measures and breach or incident reporting, but with different triggering criteria and timelines. GDPR: 72-hour breach notification for personal data breaches. NIS2: 24-hour initial notification for significant network and information system incidents regardless of personal data involvement. DORA: classification-triggered notification timelines for ICT incidents at financial entities.

Frameworks
  • EU NIS2

  • EU DORA

Where They Diverge

DORA is lex specialis for financial entities — it applies instead of NIS2 rather than alongside it. But the boundary is not perfectly clean for financial entities that also operate NIS2-scope digital infrastructure. In practice, DORA-compliant financial entities that also qualify as NIS2 essential entities should map both frameworks and identify the deltas rather than assuming DORA coverage is complete.

Shared Control Area

ICT risk management, supply chain security, and resilience testing for financial entities.

Frameworks
  • EU Cyber Resilience Act

  • EU NIS2

Where They Diverge

NIS2 governs how operators of essential services secure their infrastructure. The CRA governs the security of the products they buy. A manufacturer of industrial control system software must comply with the CRA. An energy company using that software must comply with NIS2. The CRA''s 24-hour exploited vulnerability reporting to ENISA is stricter than NIS2''s significant incident notification timeline.

Shared Control Area

Vulnerability disclosure and security update obligations for digital products and services.

Frameworks
  • Saudi Arabia ECC-1 2018

  • Saudi Arabia SAMA CSF v1.0

  • Saudi Arabia OTCC-1 2022

Where They Diverge

ECC-1 is the baseline. SAMA CSF adds financial-sector controls and a structured self-assessment mechanism. OTCC-1 adds OT-specific controls. A SAMA-regulated bank that also operates ICS for facility management is subject to all three simultaneously. The controls overlap in governance and access management but diverge in OT-specific and financial-sector-specific layers.

Shared Control Area

Governance, access control, incident response, and third-party risk management.

Frameworks
  • UK DPA

  • UK CAF v4.0

Where They Diverge

UK DPA governs personal data protection with ICO enforcement. CAF governs critical infrastructure cybersecurity with sector regulator enforcement. For UK operators of essential services that also process significant personal data, both apply simultaneously. ICO and the sector regulator may both investigate the same incident under their respective frameworks.

Shared Control Area

Security of personal data processing systems and incident detection and response.

Conflict Zones

The most significant structural conflict in this group is between GDPR''s cross-border transfer regime and Russia''s data localisation requirement under Federal Law 152-FZ. GDPR permits transfer of EU personal data to Russia via SCCs or explicit consent. Russian law requires personal data of Russian citizens to be stored in Russia regardless of where the controller is based. A multinational with both EU and Russian operations cannot route Russian citizen data through EU infrastructure and comply with both simultaneously. Data segregation is the only architectural solution.

The second structural conflict is between Saudi Arabia''s PDPL cross-border transfer restrictions and GDPR''s adequacy-based transfer mechanisms. Saudi Arabia and the EU do not have a mutual adequacy decision. Organisations processing data in both directions need bilateral transfer impact assessments under both laws, using mechanisms that do not map cleanly onto each other.

What our assessments actually found

Assessment base: Vulnox gap analysis and compliance assessments across European, Gulf, and UK clients, 2023-2024.

NIS2 notification gap in incident response plans

Across 14 gap analysis engagements with European organisations conducted in 2024, all 14 had 72-hour breach notification procedures in place for GDPR. Only 3 had updated their incident response plans to reflect NIS2''s 24-hour initial notification requirement for significant incidents. The most common explanation from compliance leads: ''We thought 24 hours was just the GDPR 72-hour requirement being rounded down — we didn''t realise it was a separate obligation with different triggering criteria.'' The 24-hour requirement under NIS2 triggers on ''significant'' network and information security incidents regardless of personal data involvement. GDPR breach notification triggers on personal data breaches. These are different clocks starting from different events. (Vulnox assessment data, 2024)

Implication:

In a real incident, the team managing GDPR breach assessment and the team managing NIS2 incident classification need to be coordinated but running parallel tracks with different timelines and different reporting destinations. Most organisations have one team, one timeline, and one process. That is insufficient for entities that are simultaneously GDPR-subject and NIS2-scope.

C5 attestation assumption failure in German market entry

A cloud-native SaaS company from Southeast Asia attempted to enter the German market targeting public sector customers. They held ISO 27001, SOC 2 Type II, and German GDPR compliance documentation. They assumed this was sufficient. Their procurement contact informed them three weeks before contract signature that a current BSI C5 attestation was required. The C5 attestation process took 11 months from initial gap assessment to completed attestation. The contract was lost. When we conducted their gap analysis for future German market entry, we found 23 control areas in C5 that their ISO 27001 scope did not address — including transparency disclosure requirements around data residency, multi-tenancy isolation testing evidence, and supply chain third-party attestation requirements. (Vulnox assessment data, 2024)

Implication:

C5 is not a German version of ISO 27001. It is a distinct attestation product with disclosure requirements and control specificity that ISO 27001 does not mandate. Treating them as equivalent loses German public sector contracts.

SAMA self-assessment scoring gap

A SAMA-regulated Saudi financial institution submitted its annual CSF self-assessment scoring at Maturity Level 3 across 80% of control areas. During our pre-examination assessment, we found that 31% of controls scored at Level 3 had no operational evidence — they existed as policies and procedures but had no documented implementation testing, no system configuration evidence, and no audit trail demonstrating the controls operated as described. The self-assessment scoring reflected intent rather than operational reality. SAMA examinations cross-check self-reported scores against system evidence. The gap between self-reported and demonstrable maturity was the most consistent finding across the four Saudi financial sector clients we assessed in this period. (Vulnox assessment data, 2024)

Implication:

SAMA''s examination model is designed specifically to identify the gap between documented and operational compliance. Maturity level claims without evidence are not SAMA-defensible.

GDPR Article 32 technical measure underspecification

Across European GDPR gap analyses, the most consistent finding is underspecification of Article 32 technical and organisational measures. Organisations document that they have ''appropriate technical measures'' but cannot quantify what appropriate means for their processing context. When we run digital footprint analysis against the same organisations, we routinely find exposed subdomains running deprecated TLS versions, development environments accessible from the internet with default credentials, and third-party integrations transmitting personal data over unencrypted channels — all inconsistent with what the organisation believes it has implemented. In 8 out of 12 assessments in the past 18 months, the actual technical security baseline was materially inconsistent with what was documented as compliant. (Vulnox assessment data, 2024)

Implication:

Article 32 compliance is not a documentation exercise. Supervisory authorities investigating breaches look at what was actually implemented. The gap between documented measures and operational reality is where GDPR enforcement investigations find their most significant evidence.

The consistent failure patterns

Mistakes

Mistake

Treating GDPR as the complete EMEA compliance answer

Why It Happens

GDPR is the most prominent regulation in the group. Organisations with limited compliance resources focus where the noise is loudest. The EU-wide regulations that came after — NIS2, DORA, the AI Act, the CRA — are newer, less familiar, and genuinely more complex to scope. So organisations build a GDPR programme and file ''EMEA compliance'' as complete.

Actual Consequence

NIS2-scope organisations without NIS2 programmes face fines up to 2% of global turnover and personal management liability. Financial entities without DORA programmes have been in violation since January 2025. Manufacturers selling connected devices into the EU without CRA conformity assessment plans face CE marking revocation. None of these risks appear on a GDPR-only compliance register.

Mistake

Assuming ISO 27001 satisfies national market-access security standards

Why It Happens

ISO 27001 is globally recognised and consistently referenced. Compliance teams that have invested in ISO 27001 naturally assume it satisfies related security requirements. The assumption is partially correct — ISO 27001 informs C5, ENS, SAMA CSF, UAE NIAF, and others. But ''informs'' is not ''satisfies.'' The national standards include jurisdiction-specific requirements that ISO 27001 does not mandate.

Actual Consequence

Lost government contracts in Germany, Spain, and Saudi Arabia where C5, ENS, and CSCC-1 are prerequisites. The market access cost of the assumption is measured in contract losses, not compliance fines.

Mistake

Missing the product-security dimension: manufacturers assuming security is the customer''s problem

Why It Happens

Software and hardware manufacturers have historically viewed security as an enterprise IT concern where the customer is responsible for securing their environment. The EU Cyber Resilience Act fundamentally changes this by placing security obligations on the manufacturer throughout the product lifecycle, including vulnerability disclosure and update provision after sale. Most manufacturers'' legal teams have not yet internalised this shift.

Actual Consequence

A manufacturer of industrial automation software that does not implement the CRA''s vulnerability disclosure requirement faces fines up to 15 million euros and potential market withdrawal orders. The 2027 full applicability date feels distant — but attestation processes, product redesign for security by default, and vulnerability management programme builds take 18 to 36 months.

Mistake

Running a single cross-border data transfer programme that does not account for jurisdiction-specific transfer restrictions

Why It Happens

Multinational compliance teams build GDPR-centric transfer frameworks using SCCs and extend them globally as the default mechanism. This fails for Russia (localisation requirement makes SCCs irrelevant), Saudi Arabia (PDPL transfer regime requires separate SDAIA mechanisms), and Turkey (requires adequacy or explicit consent under KVKK, not SCCs in the EU sense).

Actual Consequence

A retail company with customers in Russia, Saudi Arabia, and the EU running a single GDPR-compliant data transfer programme is potentially non-compliant under Russian 152-FZ and Saudi PDPL simultaneously. These are operational exposures for organisations processing data in these jurisdictions.

The insight that only appears when you see all of them together

Insight

Every framework in the EMEA group has an incident notification obligation. Read any single framework, you see a notification requirement with a timeline and a recipient. Read all of them together, and a different pattern emerges: the notification timelines are not converging — they are diverging. GDPR moved the EU to 72 hours in 2018. NIS2 pushed to 24 hours in 2022. The CRA pushed to 24 hours for actively exploited vulnerabilities. DORA added a classification-triggered tiered model. Saudi Arabia PDPL and Kenya DPA both have notification requirements modelled on GDPR''s 72-hour window. The African and Gulf frameworks are importing the 72-hour standard at exactly the moment the EU is moving away from it. The implication is structural: a multinational with operations in Germany, Saudi Arabia, and South Africa will face three different notification timelines — 24 hours (NIS2), 72 hours (Saudi PDPL, POPIA, UK DPA), and DORA''s classification-based model — for the same incident, reported to four different authorities, with different content requirements and different triggering criteria.

Practical Implication

Multinational incident response plans need jurisdiction-specific notification tracks, not a single unified notification process. The 24-hour NIS2 clock starts on ''awareness of a significant incident'' — which in practice means the moment a system log shows anomalous behaviour, not the moment the security team has confirmed a breach. An incident response retainer, a pre-mapped notification workflow per jurisdiction, and a pre-approved initial notification template that can be submitted before root cause is known are operational prerequisites for NIS2-scope entities with multi-jurisdiction footprints.

Why It Is Invisible In Isolation

Reading NIS2 alone, the 24-hour requirement looks like a tightening of breach notification standards across the EU. Reading Saudi PDPL alone, the 72-hour window looks like a reasonable standard modelled on GDPR. Reading POPIA alone, the notification requirement looks like a proportionate African framework borrowing from established EU practice. Only when you map all three against an incident timeline do you see that a multinational running a unified incident response process will structurally fail at least one notification window in any significant cross-border incident. The divergence is invisible from within any single jurisdiction.

The most efficient path through multiple EMEA frameworks

For organisations operating in the EU, the sequencing question has a clear answer: start with GDPR, then layer NIS2 on top, then DORA if in scope, then the AI Act and CRA as product and technology-specific obligations arise. GDPR establishes the data governance foundation that every other EU framework builds on. NIS2 adds the operational security layer. These two together cover the control families — risk management, access control, incident response, supply chain security, encryption — that appear in nearly every other framework in this group.

For organisations also operating in the UK, the UK GDPR and DPA 2018 add a parallel data protection obligation that is substantively similar but legally distinct. Cyber Essentials should be pursued immediately if UK government contracts are in scope — it is a short-duration certification with a defined scope that does not require significant security infrastructure build.

For organisations with German or Spanish public sector aspirations, C5 and ENS respectively must be treated as product roadmap items, not compliance additions. C5 attestation from a standing start takes 9 to 18 months. ENS certification takes 6 to 18 months. Both must start before the sales cycle reaches contract stage, not after.

For organisations entering Saudi Arabia, the Saudi stack has an explicit sequence baked in: ECC-1 first, then the sector-specific controls (OTCC-1 for OT, CGIoT-1 for IoT, CSCC-1 for cloud, SAMA CSF for financial services) on top. The PDPL runs in parallel as the data protection layer. SACS-002 applies only at the point of seeking government system access.

For African markets, POPIA is the most mature starting point. Its eight conditions map closely to GDPR, making dual-compliance efficient. Kenya DPA 2019 and Nigeria NDPA 2023 follow similar structures. An organisation already running a POPIA-compliant programme needs relatively limited incremental work to address Kenyan and Nigerian obligations.

Sequencing Logic

GDPR first because it establishes the data governance architecture. NIS2 second because it governs the security of the systems that process that data and introduces management liability. DORA third for financial entities because it is more specific and its January 2025 mandatory date is not flexible. National implementing legislation (BDSG, LOPDGDD, DPA 2018, etc.) in parallel as market entry happens. Sector-specific national standards (C5, ENS, BAIT, SAMA CSF, DEFSTAN 05-138) as contract requirements materialise.

Common Shortcut That Fails

Mapping GDPR controls to every other framework and declaring coverage. GDPR covers data protection. It does not cover operational technology security (OTCC-1, NIS2 OT provisions, CAF v4.0). It does not cover product security (CRA). It does not cover AI system conformity assessment (AI Act). It does not cover defence supply chain requirements (DEFSTAN 05-138). The GDPR-as-master-framework shortcut produces a compliance map with large unmarked gaps that become apparent only during a regulator engagement or a contract qualification review.

What happens next in EMEA compliance

  1. By 2027, at least three EU member states will bring the first NIS2 enforcement actions specifically targeting the 24-hour initial notification failure — not the underlying security breach, but the notification window itself.

    Regulators establish enforcement credibility by acting on the specific new requirements that distinguish a successor directive from its predecessor. The 24-hour NIS2 notification window is the most visible operational change from NIS1. It is also the most widely unimplemented, as our assessment data shows. The combination of a clear legal requirement, widespread non-compliance, and high regulatory visibility makes notification timing enforcement near-certain. The only question is which member states move first. Germany and Netherlands have the most active NIS2 competent authorities and the regulatory capacity to prosecute technical notification failures.

    Confidence: highNo NIS2 enforcement actions specifically citing notification timeline failure (rather than underlying security failures) are brought by end of 2027.
  2. The EU Cyber Resilience Act will create a notified body capacity crisis for Class II product conformity assessments before 2027, resulting in delays averaging 12+ months for manufacturers seeking third-party attestation.

    The CRA''s full applicability date is September 2027. Class II products require third-party conformity assessment by an accredited notified body. The number of products that will require Class II assessment across the EU — including browsers, password managers, network management software, industrial control system components, and hardware security modules — is significantly larger than the current notified body infrastructure is sized to handle. ISO 27001 accreditation took years to scale certification body capacity after initial adoption. CRA notified body accreditation is a more complex technical qualification. Manufacturers who wait until 2026 to initiate Class II assessments will face queues extending past the compliance deadline.

    Confidence: highNotified body capacity is sufficient to process all Class II applications submitted before September 2026 within a 12-month turnaround by September 2027.
  3. A mid-market financial institution operating across three or more EU member states will face a DORA-triggered enforcement action before the end of 2026 specifically for inadequate ICT third-party contract provisions — not for a security failure, but for missing contractual clauses.

    DORA Article 30 specifies minimum contractual provisions for ICT third-party agreements. The requirement to include exit strategies, audit rights, performance level specifications, and incident reporting obligations in vendor contracts is operationally intensive and poorly understood outside of large financial institutions. Mid-market entities with 50 to 200 person compliance teams have typically not renegotiated their entire ICT vendor contract estate since January 2025. National financial regulators have explicitly stated that DORA contract compliance is a supervisory priority for 2025-2026 examinations. The structural gap in mid-market institutions and the regulatory prioritisation are a reliable collision.

    Confidence: mediumNo DORA enforcement action specifically citing Article 30 ICT contractual deficiencies against an entity with under 500 employees is brought by end of 2026.

An honest opinion on the direction of EMEA compliance

The EMEA compliance group is approaching a structural breaking point for mid-market organisations. The regulatory output from the EU alone — GDPR, NIS2, DORA, the AI Act, the CRA, PSD3 in preparation, FIDA in preparation, the European Health Data Space regulation in preparation — is now producing compliance obligations faster than organisations with 30 to 200 person compliance functions can absorb them. This is not a complaint about regulatory ambition. The CRA closing the product security gap is objectively the right policy. NIS2''s management liability provisions are the right accountability mechanism. But the cumulative compliance burden is shifting from something that can be managed with a programme to something that requires infrastructure — automated control monitoring, continuous framework mapping, machine-readable evidence collection. Organisations that try to manage this group with spreadsheets and annual audits will structurally fall behind. The compliance function needs to look more like engineering and less like legal. That transition is uncomfortable and expensive, but the alternative is a compliance posture that is always catching up with last year''s regulatory cycle.

Counterargument

The reasonable counterargument is that the EU''s framework-heavy approach creates compliance overhead that falls disproportionately on smaller organisations while leaving large platforms — who have the resources to absorb it — relatively unaffected. The GDPR-era reality is that major platforms received large fines and continued operating. SMEs received smaller fines and exited markets. If the CRA and NIS2 follow the same pattern, the compliance cost may function as a market access barrier that consolidates regulated markets toward larger incumbents, which is the opposite of the innovation the EU''s digital single market ambitions depend on. This concern is legitimate and there is no clean answer to it.

Where to start this week

Map your incident response plan against every notification obligation that applies to your organisation — not just GDPR. List each framework, the triggering event, the notification deadline, the recipient authority, and the minimum content required. For most organisations reading this, that exercise will produce three things: obligations you did not know you had, timelines you cannot currently meet, and notification destinations your IR team has never contacted. Fixing the notification gap does not require rebuilding your entire compliance programme. It requires a two-page notification decision tree and pre-drafted initial notification templates per framework. Do that this week. The underlying security controls can be addressed on a longer cycle. The 24-hour NIS2 clock cannot wait for the roadmap.

Further Reading

Frequently Asked Questions

Which EMEA frameworks apply to a SaaS company with EU customers?

At minimum: GDPR for personal data processing, and NIS2 if the company qualifies as an essential or important entity (50+ employees, 10M+ euro turnover in a covered sector). If the SaaS processes payments, PSD2 applies. If it sells connected software components, the EU Cyber Resilience Act applies. If it targets German or Spanish public sector customers, BSI C5 attestation or ENS certification are market-access prerequisites respectively.

What is the difference between NIS2 and DORA incident notification requirements?

NIS2 requires an initial notification to national CSIRT within 24 hours of awareness of a significant incident, regardless of personal data involvement. DORA applies instead of NIS2 for EU-regulated financial entities and uses a classification-triggered notification timeline. GDPR breach notification is a third parallel obligation triggering at 72 hours for personal data breaches. All three can apply to the same incident at a bank and require separate processes.

Does ISO 27001 satisfy Germany C5 or Spain ENS requirements?

No. ISO 27001 informs both frameworks but does not satisfy either. Germany C5:2020 requires independent third-party attestation and includes transparency disclosure requirements, multi-tenancy isolation testing evidence, and supply chain attestation requirements that ISO 27001 does not mandate. Spain ENS requires accredited auditor certification and system risk classification across five dimensions. An ISO 27001 certificate and a C5 attestation are different documents serving different purposes.

What is the Saudi Arabia national cybersecurity compliance stack?

Saudi Arabia operates the most layered national cybersecurity stack in the EMEA region: ECC-1 (2018) is the mandatory baseline for all government entities and CNI operators. OTCC-1 (2022) adds OT-specific controls. CGIoT-1 (2024) adds IoT security requirements. CSCC-1 (2019) covers cloud service providers. SAMA CSF applies to financial institutions. SACS-002 governs third-party access to government systems. The PDPL (effective 2023) is the data protection layer. All are separately enforced by the NCA or SDAIA.

Can GDPR cross-border transfer mechanisms satisfy Russian data localisation requirements?

No. Russian Federal Law 152-FZ requires personal data of Russian citizens to be stored on servers physically located in Russia. GDPR''s Standard Contractual Clauses permit data transfer to Russia but do not satisfy the localisation requirement. Organisations processing both EU and Russian citizen data cannot route Russian citizen data through EU infrastructure while complying with both laws simultaneously. Data segregation at the architectural level is the only solution.

Is UK Cyber Essentials required for UK government contracts?

Yes. Cyber Essentials certification has been mandatory for UK government contracts involving personal data or sensitive information since 2014. ISO 27001 does not substitute for Cyber Essentials in UK government procurement. The scheme covers five controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management within 14 days for critical vulnerabilities. Annual renewal is required.

What do organisations consistently get wrong when implementing NIS2?

The most consistent gap is the 24-hour initial incident notification requirement. Organisations with GDPR breach notification procedures ingrained at 72 hours frequently assume NIS2 is the same or shorter version of the same obligation. It is not — NIS2 triggers on significant network and information security incidents regardless of personal data involvement, requires notification within 24 hours even before root cause is established, and routes to national CSIRT rather than the supervisory authority. In Vulnox assessments in 2024, fewer than 20% of incident response procedures reflected this distinction.

How should manufacturers prepare for the EU Cyber Resilience Act?

Manufacturers should first determine product classification under the CRA Annexes: minimal risk (self-assessment), Class I critical products (enhanced self-assessment), or Class II critical products (third-party conformity assessment by a notified body). Class II includes browsers, password managers, network management software, and industrial firewalls. Given that notified body capacity is expected to be constrained before the 2027 full applicability date, manufacturers of Class II products should begin the conformity assessment process no later than 2025. Security by design implementation and vulnerability disclosure programme establishment should begin immediately.

Related Articles

US state privacy and data security laws: the complete compliance map

US state privacy and data security laws: the complete compliance map

Organizations managing multi-state US data compliance face 22 distinct state frameworks with overlapping scope, conflicting timelines, and different enforcement models. In our assessments, the most common gap is not missing a law -- it is believing a single written information security programme satisfies obligations that are actually procedural and consumer-rights-based.

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

Vulnox assessments of healthcare organizations found that 71% had never tested their breach notification pipeline against an after-hours discovery scenario. This guide maps all five HIPAA group frameworks — Security Rule, Administrative Simplification, and HICP tiers — and identifies where the gaps actually live.

CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

In Vulnox assessments of DIB contractors preparing for C3PAO audits, the average SPRS score submitted before engagement was 89 points higher than the score calculated after independent control verification. This guide maps all four CMMC 2.0 instruments — Levels 1, 1 AOs, 2, and 3 — and the gaps that explain that delta.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.