← Insights

Compliance Guides

What does a dual-compliance system cost for EU companies?

Running EU rules next to UK, US or Swiss rules usually means paying for the same control twice. Where the money actually goes, and what one central system should save you.

Co-founder
· 7 min read
The Union Jack and the flag of the European Union flying from the same pole

Photo: Rocco Dipoppa / Unsplash

New to the topic? Start with What sovereign compliance actually means.

Bing now shows us which questions AI agents are answering using our insights articles as a source. The one at the top of the list in August and September 2026 was not about DORA or the AI Act, as had been the case until now. It was the cost of centralised dual-compliance systems for EU companies. That is a budget question, and I think it deserves a straight answer.

This is a topic we have been spending time on (I will get back to that in a moment), so here is my answer. Most of what dual compliance costs comes, in my opinion, from duplication, the same control tested, evidenced and audited twice by two teams who do not talk to each other. A central system removes most of that, but it cannot remove the parts where the regimes really differ, and anyone who tells you otherwise is selling you a spreadsheet with a login.

What dual compliance means in practice

Dual compliance is two regulatory regimes over the same business. For a European company it usually takes one of three forms.

  • EU and UK. Brexit left the UK with its own copy of GDPR and, for financial firms, its own operational resilience regime. UK firms had to be able to stay within their impact tolerances by 31 March 2025, and the UK critical third parties regime has applied since 1 January 2025. A bank with a London branch lives under both sets.
  • EU and US. A German group with a US listing carries SOX internal-control testing and, since 18 December 2023, the SEC rule on disclosing material cyber incidents. A group with US customers adds a growing patchwork of state privacy laws on top of GDPR.
  • EU and Switzerland. The revised Swiss Federal Act on Data Protection came into force on 1 September 2023. It is close to GDPR, though not identical, and Swiss financial firms add FINMA requirements on top.

When CFOs and company owners bring this up with me, they rarely name a single rule. They describe a feeling that they are paying for everything twice, and they are usually right.

One incident, four clocks

The clearest way to see the cost is to follow one incident through the rules. Picture a mid-sized German machine maker that sells connected machines across the EU and runs a sales subsidiary in the UK. Attackers get in through a flaw in the machines' remote-maintenance software and take customer data from both the German and the UK business.

RegimeWhat starts the clockFirst report dueTo whom
NIS2A significant incident at the companyEarly warning within 24 hours of becoming awareThe national CSIRT or competent authority
Cyber Resilience ActAn actively exploited vulnerability in the productEarly warning within 24 hours of becoming awareENISA's single reporting platform, addressed to the CSIRT of the country of main establishment
GDPRA breach of EU customers' personal dataWithout undue delay and, where feasible, within 72 hours, unless the breach is unlikely to put people at riskThe competent data protection authority
UK GDPRA breach of UK customers' personal dataThe same test: where feasible, within 72 hoursThe ICO

Machinery makers of that size fall under NIS2 as an important entity, and since 11 September 2026 the Cyber Resilience Act makes them report exploited flaws in their products too, including machines sold years ago. That gives two 24-hour clocks and two 72-hour clocks, each started by something different: the attack on the company, the flaw in the product, the EU data and the UK data. Every report goes to a different place. This part of dual compliance cannot be merged, and it should not be. What can be merged is everything underneath it: the incident process, the logging, the classification criteria, the people on call and the evidence that they did their job. Two programmes build all of that twice. One system builds it once and prints each report from it.

Where the money goes

No vendor can quote you a fair number without your scope, and I will not invent one here. What I can tell you is where the cost sits, because it is the same in each and every group I have looked at.

  • Duplicate control testing. The access review DORA expects is also evidence for the IT controls a SOX auditor tests and for UK resilience work. Run as two programmes, it gets tested twice, on two schedules, with two sets of screenshots.
  • Duplicate evidence. Evidence gathering is where the internal hours disappear. Your team answers the same question in two formats, for two auditors, a few weeks apart.
  • Two sets of advisers. A UK firm for the UK rules, a German firm for the EU rules, and nobody paid to reconcile them. The reconciling then lands on your own compliance officer.
  • Change tracking. Every regime moves on its own timetable. Two programmes means two people reading two sets of consultations, and a real chance that a change in one never reaches the other.

Two programmes or one system

Two separate programmesOne central system
ControlsTwo control sets that drift apart over timeOne control set, mapped to both regimes
EvidenceCollected twice, in two formatsCollected once, reused wherever it applies
Regulatory changeTracked per regime, often by different peopleTracked centrally, with the affected controls flagged
ReportingSeparate, per regimeStill separate, per regime, from shared data
Upfront costLow, because you extend what you already haveHigher, because the mapping has to be built
Running costGrows with every regime you addGrows mainly where the regimes differ

The central system costs more at the start, which is why many groups never make the move. The mapping between regimes is real work, and it needs a person who owns the gaps where the rules do not line up. After that first year, the second regime costs you only its differences, while a separate programme keeps costing you the whole regime.

How to price it before you buy

  1. List every regime and every entity. The cost follows scope, not headcount. If you are not sure what applies, start with which EU regulations apply to your company.
  2. Count the overlap. Ask how many of your current controls already serve both regimes. The higher that share, the more a central system saves.
  3. Ask who maintains the mapping. When the FCA or the EBA changes a rule, does the vendor update the link between the regimes, or does your team?
  4. Price the status quo honestly. Add the consultant days, the internal hours before each audit and the second audit itself. Our guide to what EU compliance software costs walks through the pricing models.
  5. Check where the records sit. A central system holds the most sensitive map of your group. For a European company, a platform that sends it outside EU jurisdiction brings a third-party risk of its own.

Why I care about this one

I know the mapping problem well, because it is the part of COMPLY.Reg we spent the most time on. In our own cross-walk, more than 2,000 regulatory requirements come down to about 250 actionable controls. That ratio is the whole business case for dual compliance, and it holds for EU companies facing the UK, the US or Switzerland alike. Each determination is reviewed by a person, and the data stays in the EU. If you want a number for your own group, tell us your regimes and entities and we will give you a real one.

Frequently asked questions

What is a dual-compliance system?
A way of meeting two regulatory regimes over the same business from one control set. Each control is defined, tested and evidenced once, then mapped to every requirement it satisfies in both regimes. Only the regime-specific parts, such as reporting deadlines and filings, stay separate.
What does dual compliance cost an EU company?
There is no list price. The cost depends on how many regimes and legal entities are in scope, how much the regimes overlap, and how often each one changes. The largest cost is usually duplication: running two programmes that test and evidence the same controls twice.
Is one central compliance system cheaper than two programmes?
Usually, because most of the work in the second regime overlaps with the first. The saving only holds if the system keeps a maintained mapping between the regimes and shows the gaps where they differ, such as incident reporting deadlines.
Which regimes do EU companies most often run side by side?
EU and UK rules since Brexit (UK GDPR and the UK operational resilience regime), EU and US rules for groups with a US listing or US customers (SOX and the SEC cyber disclosure rule), and EU and Swiss rules (the revised Swiss Federal Act on Data Protection, in force since 1 September 2023).

Sources