Cyber security and data protection compliance in the United Kingdom
In the United Kingdom, cyber security and data protection duties come from several sources rather than one law. The NCSC's Cyber Assessment Framework is the common assessment method for regulated and public-sector organisations; Cyber Essentials is the most widely demanded certification, asked for by government, defence and a growing number of supply chains; the FCA, the PRA and the Bank of England run their own operational resilience regime for financial services; and the UK GDPR, amended by the Data (Use and Access) Act 2025, binds every organisation that processes personal data. This page sets out which applies to whom and from when, from the primary sources.
- Frameworks listed4
- Issuing bodies4
- Framework pages4
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in United Kingdom
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
NCSC Cyber Assessment Framework (CAF) v4.0
Operators of essential services and relevant digital service providers under the NIS Regulations 2018, central government critical systems through GovAssure, councils in England through MHCLG's CAF for local government, and NHS bodies through the CAF-aligned DSPT. Guidance, binding through the bodies that adopt it
Open the framework page →Cyber Essentials and Cyber Essentials Plus (v3.3)
Voluntary in law; required for many central government contracts under PPN 014, at every level of MOD Defence Cyber Certification, and by Cyber Resilience Pledge signatories across their supply chains. v3.3 applies to assessment accounts created from 27 April 2026
Open the framework page →Operational resilience (FCA SYSC 15A, PRA SS1/21 and SS2/21) and the Critical Third Parties regime
Banks, building societies, PRA-designated investment firms, insurers, enhanced scope SM&CR firms, recognised investment exchanges, and payment and e-money institutions; designated critical third parties since 13 July 2026. Incident and third-party reporting under PS26/2 from 18 March 2027
Open the framework page →UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and PECR
Every controller and processor of personal data in the UK; PECR for electronic marketing, cookies and communications providers. The Information Commission replaced the Information Commissioner on 30 September 2026
Open the framework page →Which cyber security and data protection rules apply in the United Kingdom?
It depends on the sector and on who the customer is. Operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers (online marketplaces, online search engines and cloud computing services), are regulated under the NIS Regulations 2018 by the competent authority for their sector, and NCSC says the CAF is now used by nearly all UK cyber regulators. Central government assures its critical systems against the CAF through GovAssure, councils in England use MHCLG's CAF for local government, and NHS bodies submit the Data Security and Protection Toolkit, whose 2026-27 version is aligned to CAF v4.0.
Cyber Essentials is the baseline most often asked for in contracts, from central government under PPN 014 to the MOD's Defence Cyber Certification. Banks, insurers, payment firms and other regulated financial firms add the FCA and PRA operational resilience rules, and every organisation that processes personal data is bound by the UK GDPR and the Data Protection Act 2018, with PECR for marketing and cookies. A group can sit under several at once, which is why GRCLens runs them on one control model with ISO/IEC 27001 and the rest of the library, so a control evidenced once counts wherever it applies.
What is the NCSC Cyber Assessment Framework?
The CAF is the National Cyber Security Centre's outcome-based method for assessing how well an organisation manages cyber risk to its essential functions. Version 4.0, released on 4 August 2025, has 4 objectives, 14 principles and 41 contributing outcomes, each judged Achieved, Partially achieved or Not achieved against indicators of good practice. Regulators and schemes set a profile, the minimum result expected per outcome: GovAssure assigns a Basic or Enhanced profile to each government system, and Ofgem uses Basic and Enhanced profiles for downstream gas and electricity.
In GovAssure the assessment runs through WebCAF: a self-assessment at stage 3, an independent assurance review at stage 4 and a targeted improvement plan at stage 5. Under the NIS Regulations an operator of essential services notifies its competent authority of an incident with a significant impact on its essential service without undue delay and within 72 hours of becoming aware of it. GRCLens carries all 373 indicators of good practice, 225 in Achieved columns and 148 in Partially achieved columns, and scores each outcome against the profile selected.
What changed in Cyber Essentials in 2026?
Version 3.3 of the requirements, answered through IASME's Danzell question set, applies to assessment accounts created from 27 April 2026. Missing multi-factor authentication on any cloud service that offers it is now an automatic fail, and so is failing to install high-risk or critical updates within 14 days. Cloud services cannot be excluded from scope, every in-scope legal entity is listed on the certificate, the board-level declaration covers ongoing compliance, and a second failed Cyber Essentials Plus update-management test revokes the Cyber Essentials certificate.
Issuance is at a record: 61,430 certificates were awarded between July 2025 and June 2026, 46,245 Cyber Essentials and 15,185 Cyber Essentials Plus. Certificates last 12 months, and a CE+ audit must be completed within three months of the Cyber Essentials certificate. GRCLens carries 115 requirements in 8 domains, 18 of them automatic-fail checks, together with the CE+ test cases. It prepares the submission; certificates are issued through IASME's licensed certification bodies.
What do the FCA and PRA require on operational resilience?
Firms in scope of FCA SYSC 15A and the PRA's Operational Resilience Part identify their important business services, set an impact tolerance for each, map the people, processes, technology, facilities, information and third parties that deliver them, test against severe but plausible scenarios and keep a self-assessment approved by the board. Since 31 March 2025 they have had to be able to remain within their impact tolerances. PRA SS2/21 and FCA SYSC 8 govern outsourcing and third-party risk.
Two changes are reshaping the third-party side. HM Treasury's first critical third parties (Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited) were designated with effect from 13 July 2026 and are overseen by the Bank of England, the PRA and the FCA. From 18 March 2027, FCA PS26/2 and PRA PS7/26 require operational incidents to be reported on one form, with the initial report expected within 24 hours of a threshold being met (4 hours for payment service providers), and material third-party arrangements to be notified in advance and listed in a register submitted every year.
What changed in UK data protection in 2025 and 2026?
The Data (Use and Access) Act 2025 amended the UK GDPR, the Data Protection Act 2018 and PECR in phases. Most data-protection changes commenced on 5 February 2026, among them recognised legitimate interests, Articles 22A to 22D on automated decision-making, new DSAR time limits, cookie exemptions and PECR enforcement at UK GDPR levels. The duty to handle data-protection complaints applied from 19 June 2026, and on 30 September 2026 the Information Commission, a body corporate with a board, replaced the Information Commissioner; it is still branded ICO.
A personal data breach is still notified without undue delay and, where feasible, within 72 hours. Maximum fines are £17.5 million or 4% of worldwide turnover at the higher tier and £8.7 million or 2% at the standard tier. Enforcement is active: the ICO fined Capita £14 million in October 2025 for a 2023 breach affecting 6.6 million people, and received 17,431 personal data breach reports in 2025/26, 40% more than in 2024/25.
Is the Cyber Security and Resilience Bill law yet?
Not as of October 2026. The Bill amends the NIS Regulations 2018; it passed the Commons on 16 June 2026, and its Lords Report stage was provisionally scheduled for 26 October 2026. It would bring data centres (regulated by Ofcom) and managed service providers that are not small or micro enterprises (regulated by the Information Commission) into scope, widen reporting to incidents with the potential for significant impact, require an initial notification within 24 hours and a full report within 72, and raise maximum fines to the greater of £17 million or 4% of worldwide turnover. Most substantive duties will follow in secondary legislation, and NCSC says the CAF will evolve to match.
How GRCLens runs the UK frameworks together
Each framework is assessed per group or per legal entity and rolls up into a group view with a heat map across 15 risk areas: the CAF with 373 indicators of good practice across 41 contributing outcomes, Cyber Essentials with 115 requirements including 18 automatic-fail checks, operational resilience with 218 requirements in 11 domains, and UK data protection with 178 requirements in 10 domains. Each has four stakeholder dashboards: board and management, CISO and risk (the DPO for UK GDPR), operations, and third party and supply chain.
Connectors for incident records, backup and restore, vulnerability and patch, identity and MFA, the third-party register, resilience testing, training and log monitoring validate the answers alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. Gaps flow into a multi-owner assurance register and a remediation and risk treatment plan, key risk indicators trace to the requirements they measure, Baseerah writes the executive summary on a self-hosted language model, and reports export as Word and PDF.
Cyber compliance in United Kingdom: common questions
Is the NCSC CAF mandatory in the UK?
Not in itself. The CAF is NCSC guidance that becomes binding through the bodies that adopt it: the NIS competent authorities for operators of essential services, GovAssure for central government's critical systems, MHCLG for councils in England, and NHS England through the CAF-aligned Data Security and Protection Toolkit.
Is Cyber Essentials mandatory?
Not in law, but often by contract. PPN 014 requires it, or independently verified equivalent controls, for central government contracts that handle personal data, OFFICIAL ICT systems or day-to-day government business; the MOD's Defence Cyber Certification requires it at every level and Cyber Essentials Plus at Levels 2 and 3; and Cyber Resilience Pledge signatories commit to requiring it across their supply chains on a risk basis.
Who supervises operational resilience for UK financial firms?
The FCA for every firm in SYSC 15A scope, and the PRA for banks, building societies, PRA-designated investment firms and insurers, so dual-regulated firms answer to both and set impact tolerances against both regulators' objectives. Critical third parties designated by HM Treasury are overseen jointly by the Bank of England, the PRA and the FCA.
Who regulates UK GDPR?
The Information Commission, which replaced the Information Commissioner on 30 September 2026 under the Data (Use and Access) Act 2025. It is a body corporate with a board and is still branded ICO. A personal data breach is reported to it without undue delay and, where feasible, within 72 hours.
Has the Cyber Security and Resilience Bill become law?
Not as of October 2026. It passed the Commons on 16 June 2026, and its Lords Report stage was provisionally scheduled for 26 October 2026. It would bring data centres and managed service providers into regulation, require an initial incident notification within 24 hours and a full report within 72, and raise maximum fines to the greater of £17 million or 4% of worldwide turnover, with most duties following in secondary legislation.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.
- NCSC, Cyber Assessment Framework collection (v4.0)
- NCSC, CAF changelog (v3.2 to v4.0)
- The Network and Information Systems Regulations 2018 (SI 2018/506), regulation 11
- UK Government Security, GovAssure
- NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3
- IASME, Important update: changes to Cyber Essentials for April 2026
- Cabinet Office, PPN 014: Cyber Essentials Scheme (17 Feb 2025)
- DSIT / DCMS, Cyber Essentials management information (updated 16 Sep 2026)
- FCA Handbook, SYSC 15A Operational resilience
- FCA PS26/2 Operational incident and third party reporting (18 Mar 2026)
- Bank of England, UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury (10 Jul 2026)
- Data (Use and Access) Act 2025
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
- ICO, ICO governance changes confirmed for 30 September 2026
- ICO, Capita fined £14m for data breach affecting over 6m people (Oct 2025)
- UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill: stages

Run United Kingdom's frameworks on one platform
See GRCLens with your own frameworks loaded. Need hands-on help? UK cyber security and data protection services from Security Solution Consultants.