Compliance Guides
What does a dual-compliance system cost for EU companies?
Running EU rules next to UK, US or Swiss rules usually means paying for the same control twice. Where the money actually goes, and what one central system should save you.

Photo: Rocco Dipoppa / Unsplash
New to the topic? Start with What sovereign compliance actually means.
Bing now shows us which questions AI agents are answering using our insights articles as a source. The one at the top of the list in August and September 2026 was not about DORA or the AI Act, as had been the case until now. It was the cost of centralised dual-compliance systems for EU companies. That is a budget question, and I think it deserves a straight answer.
This is a topic we have been spending time on (I will get back to that in a moment), so here is my answer. Most of what dual compliance costs comes, in my opinion, from duplication, the same control tested, evidenced and audited twice by two teams who do not talk to each other. A central system removes most of that, but it cannot remove the parts where the regimes really differ, and anyone who tells you otherwise is selling you a spreadsheet with a login.
What dual compliance means in practice
Dual compliance is two regulatory regimes over the same business. For a European company it usually takes one of three forms.
- EU and UK. Brexit left the UK with its own copy of GDPR and, for financial firms, its own operational resilience regime. UK firms had to be able to stay within their impact tolerances by 31 March 2025, and the UK critical third parties regime has applied since 1 January 2025. A bank with a London branch lives under both sets.
- EU and US. A German group with a US listing carries SOX internal-control testing and, since 18 December 2023, the SEC rule on disclosing material cyber incidents. A group with US customers adds a growing patchwork of state privacy laws on top of GDPR.
- EU and Switzerland. The revised Swiss Federal Act on Data Protection came into force on 1 September 2023. It is close to GDPR, though not identical, and Swiss financial firms add FINMA requirements on top.
When CFOs and company owners bring this up with me, they rarely name a single rule. They describe a feeling that they are paying for everything twice, and they are usually right.
One incident, four clocks
The clearest way to see the cost is to follow one incident through the rules. Picture a mid-sized German machine maker that sells connected machines across the EU and runs a sales subsidiary in the UK. Attackers get in through a flaw in the machines' remote-maintenance software and take customer data from both the German and the UK business.
| Regime | What starts the clock | First report due | To whom |
|---|---|---|---|
| NIS2 | A significant incident at the company | Early warning within 24 hours of becoming aware | The national CSIRT or competent authority |
| Cyber Resilience Act | An actively exploited vulnerability in the product | Early warning within 24 hours of becoming aware | ENISA's single reporting platform, addressed to the CSIRT of the country of main establishment |
| GDPR | A breach of EU customers' personal data | Without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to put people at risk | The competent data protection authority |
| UK GDPR | A breach of UK customers' personal data | The same test: where feasible, within 72 hours | The ICO |
Machinery makers of that size fall under NIS2 as an important entity, and since 11 September 2026 the Cyber Resilience Act makes them report exploited flaws in their products too, including machines sold years ago. That gives two 24-hour clocks and two 72-hour clocks, each started by something different: the attack on the company, the flaw in the product, the EU data and the UK data. Every report goes to a different place. This part of dual compliance cannot be merged, and it should not be. What can be merged is everything underneath it: the incident process, the logging, the classification criteria, the people on call and the evidence that they did their job. Two programmes build all of that twice. One system builds it once and prints each report from it.
Where the money goes
No vendor can quote you a fair number without your scope, and I will not invent one here. What I can tell you is where the cost sits, because it is the same in each and every group I have looked at.
- Duplicate control testing. The access review DORA expects is also evidence for the IT controls a SOX auditor tests and for UK resilience work. Run as two programmes, it gets tested twice, on two schedules, with two sets of screenshots.
- Duplicate evidence. Evidence gathering is where the internal hours disappear. Your team answers the same question in two formats, for two auditors, a few weeks apart.
- Two sets of advisers. A UK firm for the UK rules, a German firm for the EU rules, and nobody paid to reconcile them. The reconciling then lands on your own compliance officer.
- Change tracking. Every regime moves on its own timetable. Two programmes means two people reading two sets of consultations, and a real chance that a change in one never reaches the other.
Two programmes or one system
| Two separate programmes | One central system | |
|---|---|---|
| Controls | Two control sets that drift apart over time | One control set, mapped to both regimes |
| Evidence | Collected twice, in two formats | Collected once, reused wherever it applies |
| Regulatory change | Tracked per regime, often by different people | Tracked centrally, with the affected controls flagged |
| Reporting | Separate, per regime | Still separate, per regime, from shared data |
| Upfront cost | Low, because you extend what you already have | Higher, because the mapping has to be built |
| Running cost | Grows with every regime you add | Grows mainly where the regimes differ |
The central system costs more at the start, which is why many groups never make the move. The mapping between regimes is real work, and it needs a person who owns the gaps where the rules do not line up. After that first year, the second regime costs you only its differences, while a separate programme keeps costing you the whole regime.
How to price it before you buy
- List every regime and every entity. The cost follows scope, not headcount. If you are not sure what applies, start with which EU regulations apply to your company.
- Count the overlap. Ask how many of your current controls already serve both regimes. The higher that share, the more a central system saves.
- Ask who maintains the mapping. When the FCA or the EBA changes a rule, does the vendor update the link between the regimes, or does your team?
- Price the status quo honestly. Add the consultant days, the internal hours before each audit and the second audit itself. Our guide to what EU compliance software costs walks through the pricing models.
- Check where the records sit. A central system holds the most sensitive map of your group. For a European company, a platform that sends it outside EU jurisdiction brings a third-party risk of its own.
Why I care about this one
I know the mapping problem well, because it is the part of COMPLY.Reg we spent the most time on. In our own cross-walk, more than 2,000 regulatory requirements come down to about 250 actionable controls. That ratio is the whole business case for dual compliance, and it holds for EU companies facing the UK, the US or Switzerland alike. Each determination is reviewed by a person, and the data stays in the EU. If you want a number for your own group, tell us your regimes and entities and we will give you a real one.
Frequently asked questions
- What is a dual-compliance system?
- A way of meeting two regulatory regimes over the same business from one control set. Each control is defined, tested and evidenced once, then mapped to every requirement it satisfies in both regimes. Only the regime-specific parts, such as reporting deadlines and filings, stay separate.
- What does dual compliance cost an EU company?
- There is no list price. The cost depends on how many regimes and legal entities are in scope, how much the regimes overlap, and how often each one changes. The largest cost is usually duplication: running two programmes that test and evidence the same controls twice.
- Is one central compliance system cheaper than two programmes?
- Usually, because most of the work in the second regime overlaps with the first. The saving only holds if the system keeps a maintained mapping between the regimes and shows the gaps where they differ, such as incident reporting deadlines.
- Which regimes do EU companies most often run side by side?
- EU and UK rules since Brexit (UK GDPR and the UK operational resilience regime), EU and US rules for groups with a US listing or US customers (SOX and the SEC cyber disclosure rule), and EU and Swiss rules (the revised Swiss Federal Act on Data Protection, in force since 1 September 2023).
Sources
- GDPR Article 33 - notification of a personal data breach
- DORA, Regulation (EU) 2022/2554
- NIS2, Directive (EU) 2022/2555, Article 23 (reporting obligations)
- Cyber Resilience Act, Regulation (EU) 2024/2847, Article 14 (reporting obligations)
- SEC, cybersecurity incident disclosure (Form 8-K Item 1.05)
- FCA PS21/3, building operational resilience