PayMetric Labs
UK · Compliance & GRC11 min read21 August 2026

DORA, the EU AI Act, and UK Compliance Salaries 2026: Who's Actually in Scope

By PayMetric Labs Research Desk

DORA doesn't directly bind UK-only entities, and there's no UK AI Act, so what's actually driving UK compliance hiring? The FCA/PRA's own Operational Resilience regime, EU AI Act exposure via market impact rather than domicile, and DORA reaching in through EU subsidiaries and Critical Third-Party Provider designations. See the 2026 GRC, SOC, pentest, architect, and CISO salary benchmarks, and which regulation actually applies to which UK employer.

The UK isn't in DORA's jurisdiction, but the hiring wave arrived anyway

Most compliance-salary content treats DORA as a straightforward driver of UK cybersecurity hiring the same way it is in Dublin or Frankfurt. That's not quite right, and the actual picture is more interesting. DORA is an EU regulation; the UK itself isn't a DORA jurisdiction. But UK financial groups with EU-authorised subsidiaries or branches carry a genuinely DORA-obligated entity inside the group, and UK-based ICT providers can be individually designated Critical Third-Party Providers by EU regulators regardless of Brexit, in November 2025 the European Supervisory Authorities designated 19 such providers, several UK-headquartered.

The bigger, more immediate driver of UK compliance hiring in 2026 is homegrown: the FCA and PRA's own Operational Resilience regime, whose 3-year transition period ended 31 March 2025. Every UK bank, building society, insurer, and payment provider is now expected to demonstrate it can stay within impact tolerance for its most important business services, and that's the deadline actually filling GRC, security architecture, and CISO roles across London's financial cluster right now.

GRC and cybersecurity salary benchmarks: UK 2026

Median gross annual salary in £K · permanent roles

RoleMedianRange
GRC / Compliance Analyst£58K£45K – £75K
SOC Analyst (Tier 1 / Tier 2)£53K£45K – £65K
Penetration Tester / Ethical Hacker£75K£62K – £90K
Security Architect / GRC Lead£110K£95K – £130K
CISO (Chief Information Security Officer)£150K£130K – £250K+

GRC / Compliance Analyst

£58K£45K – £75K

Owns the day-to-day documentation and evidence-gathering behind a firm's compliance posture: control testing, policy reviews, audit responses, and regulatory return preparation. This is the entry point into the compliance track, and demand has widened well beyond financial services since NIS2-adjacent sector expansion and the FCA's operational resilience regime pulled more mid-market firms into scope.

Certifications that move compensation

ISO 27001 Lead ImplementerCompTIA Security+PRINCE2

SOC Analyst (Tier 1 / Tier 2)

£53K£45K – £65K

Monitors, triages, and investigates security alerts across a firm's estate. UK SOC roles concentrated in financial services, defence, and critical infrastructure pay consistently above the general market, and senior SOC contractors bill £450-£650/day, a rate ceiling that has pulled permanent SOC salaries up alongside it as firms compete to retain talent rather than lose it to contracting.

Certifications that move compensation

CompTIA Security+SC-200 (Microsoft Sentinel)GCIH

Penetration Tester / Ethical Hacker

£75K£62K – £90K

Offensive security testing against systems, applications, and networks, increasingly a contractual requirement rather than a discretionary exercise once a firm falls under the FCA's operational resilience rules or a client's third-party risk questionnaire. OSCP-certified testers are the most consistently rewarded profile in this tier, and cloud-specific offensive skills (AWS, Azure environment testing) carry a further premium.

Certifications that move compensation

OSCPCEHCREST CRT

Security Architect / GRC Lead

£110K£95K – £130K

Designs enterprise-level controls: zero-trust architecture, identity and access frameworks, cloud security posture, and the regulatory compliance programmes (FCA operational resilience, third-party ICT risk, AI governance) that sit behind a firm's board reporting. Architects who can translate technical risk into board-level language are the single most sought-after profile in London's financial and fintech cluster right now.

Certifications that move compensation

CISSPCISMSABSA

CISO (Chief Information Security Officer)

£150K£130K – £250K+

Board-facing ownership of security strategy, incident response, regulatory relationships, and security culture. SME CISOs typically land £90K-£130K; enterprise CISOs at FTSE 100-scale firms routinely clear £150K-£160K, with total packages (bonus, LTIPs) reaching £250K+ at the largest regulated institutions. Operational resilience accountability has moved CISO hiring from a discretionary executive decision to a regulatory necessity at any firm holding FCA/PRA-regulated permissions.

Certifications that move compensation

CISSPCISMCRISC

What do these salaries look like after UK tax?

All benchmarks above are gross. After Income Tax and National Insurance, a £110K Security Architect package takes home roughly £70,000 to £72,500 per year outside Scotland (Scottish rates differ, see our Scotland vs England tax guide). Use our UK take-home calculator to model your specific number, including pension contributions and student loan repayments.

Three regulatory drivers, three different reaches into the UK

Understanding which of these actually applies to a given UK employer, directly, indirectly, or not at all, explains why compliance hiring has surged in some corners of the UK market and barely moved in others.

DORA (Digital Operational Resilience Act): indirect UK reach

DORA became fully applicable across the EU on 17 January 2025, with no remaining transition deadline. It binds financial entities authorised in an EU member state and the ICT third-party providers those entities depend on. A UK-only entity with no EU authorisation has no direct DORA obligation, but DORA follows the entity, not the group, so a UK banking group with an EU-authorised subsidiary or branch has a genuinely obligated entity inside it regardless of where the parent sits.

The other route in: Critical ICT Third-Party Provider (CTPP) designation. The European Supervisory Authorities can designate any ICT provider, cloud, data, infrastructure, as critical if enough EU financial entities depend on it, triggering direct ESA oversight. In November 2025 the ESAs designated 19 such providers, several UK-headquartered. Either route creates real DORA-adjacent hiring demand inside UK organisations, just not the blanket, jurisdiction-wide demand DORA creates for an EU-based firm.

FCA/PRA Operational Resilience (PS21/3): the real UK driver

This is the UK's own domestic equivalent of DORA's philosophy, built independently rather than transposed from the EU rulebook. Firms had a 3-year transition period to identify their important business services, set impact tolerances for severe-but-plausible disruption, and get board sign-off on their resilience plans. That transition ended 31 March 2025, and the FCA and PRA now expect full compliance from every UK bank, building society, insurer, and payment provider.

This is the deadline actually behind most of the GRC, security architecture, and CISO hiring surge in UK financial services in 2026, bigger and more immediate than DORA's own UK footprint, and worth knowing by name if you're interviewing for a compliance-adjacent role at a UK-regulated firm.

EU AI Act: extraterritorial by market impact, not domicile

The UK has no domestic AI statute, no AI bill before Parliament, and no dedicated AI regulator as of 2026, its approach is deliberately light-touch: existing regulators applying general principles sector by sector, plus regulatory sandboxes, rather than a single horizontal law with its own audit regime. But the EU AI Act's test for applicability is EU market impact, not corporate domicile: if a UK company's AI system is used by, or produces outputs affecting, people in EU member states, the Act's obligations can apply regardless of Brexit.

In practice, that means most UK AI-adjacent businesses serving EU customers need EU AI Act risk-tiering and documentation capability even without a UK law requiring it, a genuinely unusual compliance position, and one driving early AI-governance hiring in UK companies with real EU exposure well ahead of any domestic requirement.

Which certifications are actually moving UK compliance and security salaries?

Not every credential carries equal weight in the UK market. These are the certifications that consistently correlate with a real salary premium rather than just marking a checkbox on a job spec:

CertificationBest forSalary impact
CISSPSecurity Architect / CISO track+£8K – £15K
OSCPPenetration testing roles+£5K – £12K
CISMGRC and security management+£6K – £10K
ISO 27001 Lead ImplementerGRC / compliance analyst roles+£3K – £6K
CRISCRisk and compliance leadership+£5K – £9K
SC-200Azure / Microsoft Sentinel SOC roles+£2K – £5K

To benchmark your current profile against the broader UK market, compare against the State of Tech Salaries Mid 2026 report and the cloud security salary breakdown.

Stay current

UK salary benchmarks shift every April

When HMRC confirms new rates, we update every benchmark on this page. Get an email the day we publish. No lag, no waiting.

No spam. Unsubscribe any time. GDPR-compliant.

Frequently asked questions

1

Does DORA actually apply to UK companies, since it's an EU regulation?

Not automatically, and this is the detail most compliance-salary content gets wrong. DORA's applicability follows the entity, not the corporate group, so a UK-headquartered financial group has no direct DORA obligation on its UK entity alone, only entities actually authorised or registered in an EU member state fall in scope. But a UK banking group with an EU-authorised subsidiary or branch has a genuinely DORA-obligated entity inside the group regardless of where the parent is domiciled, and any UK-based ICT provider (cloud, data, infrastructure) can be individually designated a Critical ICT Third-Party Provider by the European Supervisory Authorities if EU financial entities depend on it, in November 2025 the ESAs designated 19 such providers, several UK-headquartered. Both routes pull real UK hiring demand toward DORA-adjacent skills without the UK itself being a DORA jurisdiction.

2

If DORA doesn't directly bind most UK firms, what's actually driving UK compliance hiring?

The FCA and PRA's own Operational Resilience regime (PS21/3), the UK's domestic equivalent of DORA's philosophy, if not its exact rulebook. Firms had a 3-year transition period to identify their important business services, set impact tolerances for severe-but-plausible disruption scenarios, and get board sign-off, and that transition period ended on 31 March 2025. All UK banks, building societies, insurers, and payment providers are now expected to be fully compliant, which is the real, immediate driver behind most of the GRC, security architecture, and CISO hiring in UK financial services in 2026, distinct from and larger than DORA's own UK footprint.

3

Does the EU AI Act apply to UK AI companies?

It can, and the test that matters is EU market impact, not UK domicile. The UK is not bound by the EU AI Act as domestic law, but if a UK company's AI system is used by, or produces outputs affecting, individuals in EU member states, the Act's obligations likely apply regardless of where the company is headquartered. Any UK AI-adjacent business serving EU customers, which is most of them, needs to track EU AI Act risk-tiering and documentation requirements even without a UK statute compelling it.

4

What is the UK's own approach to AI regulation, if there's no UK AI Act?

A deliberately lighter touch: sector-led regulation, regulatory sandboxes, and existing regulators (the ICO, FCA, and others) applying general principles case by case, rather than a single horizontal statute with its own audit regime the way the EU AI Act works. As of 2026 there's no UK AI bill before Parliament and no dedicated UK AI regulator. Whether this proves sufficient is a genuinely open debate, supporters argue it keeps the UK attractive for AI investment and talent, critics argue voluntary, regulator-by-regulator guidance leaves real accountability gaps. Either way, it means UK compliance hiring for AI-specific risk is currently driven more by EU market exposure and individual regulators' expectations than by a single domestic law.

5

Which certifications actually move UK GRC and security salaries?

CISSP is the closest thing to a baseline requirement for senior and management-level roles, adding roughly £8,000-£15,000 and appearing in the large majority of senior UK cybersecurity job postings. OSCP adds £5,000-£12,000 specifically for penetration testing roles and is the most consistently rewarded credential in that tier. CISM carries similar weight to CISSP for GRC and security-management tracks. Certifications without a hands-on technical or governance track record behind them (a standalone CEH with no offensive-security experience, for instance) carry meaningfully smaller premiums than the headline CISSP/OSCP numbers.

6

Is GRC/compliance a stable specialism to move into, or is it exposed to the same hiring slowdowns as other tech roles?

It's one of the more resilient corners of UK tech hiring right now. Security and compliance roles are increasingly treated as non-discretionary, tied to a specific regulatory deadline (the FCA's operational resilience transition, ongoing DORA-adjacent exposure for firms with EU entities, evolving AI governance expectations) rather than a general headcount budget that gets cut first in a slowdown. That doesn't make every GRC role recession-proof, but the roles tied directly to a live regulatory obligation have held up noticeably better than discretionary product engineering hiring through 2026.

7

How does UK compliance and cybersecurity pay compare to Ireland?

Ireland pays roughly 10-15% more in gross terms for equivalent roles, reflecting Dublin's hyperscaler concentration and cost-of-living-driven package inflation, our Ireland cybersecurity salary guide covers those figures directly. The regulatory driver differs too: Ireland's DORA exposure is direct and immediate (Irish-authorised financial entities are squarely in scope), while the UK's compliance hiring wave is driven mostly by its own domestic Operational Resilience regime plus indirect DORA/AI Act exposure through EU-facing entities and customers, a genuinely different compliance landscape behind similar-looking salary bands.