Three regulations. One question: can you prove your controls work?
GDPR, NIS2, and DORA now converge on one demand: not whether you have security controls, but whether you can prove they work. Here is the evidence they require.
Three EU frameworks now converge on the same demand. GDPR, NIS2, and DORA arrived at different times, use different language, and carry different enforcement mechanisms. But strip away the regulatory scaffolding and the question underneath is identical: not whether you have security controls, but whether you can demonstrate that they work.
This is not a theoretical shift. It is already being enforced.
GDPR: the requirement nobody read
GDPR Article 32(1)(d) has been in force since May 2018. It requires “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing.” That sentence has been sitting in the regulation for eight years. For the first five of those years, enforcement attention went elsewhere — consent banners, data subject access requests, breach notifications. The effectiveness provisions were treated as furniture.
That is changing. In August 2023, Romania’s data protection authority ANSPDCP fined UiPath €70,000 under Articles 25 and 32. The decision reasoning addressed Art. 32(1)(d) explicitly, citing failure to maintain a testing and effectiveness process — using the article’s own statutory language. This was not a massive breach case. It was a regulator reading the text and asking: where is your evidence that you tested whether your controls work?
The British Airways decision from October 2020 went further. The UK Information Commissioner’s Office imposed a £20 million fine after a breach affecting 429,612 customers. Among the Art. 32 failures named in the decision: the absence of penetration testing. Not that testing was inadequate. That it was absent. The control existed on paper. Nobody had checked whether it functioned.
These are not edge cases. They are early indicators of how regulators intend to read Art. 32 going forward.
NIS2: the obligation stated twice, with personal consequences
The NIS2 Directive creates the effectiveness obligation in two places. Article 21(2)(f) is explicit: essential and important entities must implement “policies and procedures to assess the effectiveness of cybersecurity risk-management measures.” No ambiguity. No room for interpretation. You must have a way to assess whether your measures work, and you must be able to show the policies and procedures that govern that assessment.
Article 21(1) creates the obligation again, implicitly. It requires that cybersecurity risk-management measures be “proportionate” to the risks faced. But proportionality is a comparative claim. You cannot demonstrate that your measures are proportionate to the risk unless you have measured what those measures actually do. Proportionality without measurement is an assertion without evidence.
Then there is Article 20. Management bodies — boards, named officers, senior leadership — can be held personally liable for failures to comply with Art. 21. This is not organisational risk that can be absorbed by insurance or distributed across a legal entity. It is personal risk attached to named individuals. A board member who signs off on a compliance posture that cannot demonstrate effectiveness is personally exposed.
As of mid-2026, most EU member states have not yet completed transposition. The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for delays. But the directive’s requirements are established. Organisations waiting for national transposition to begin preparing are misreading the timeline.
DORA: effectiveness as a continuous obligation
DORA is the most recently applicable of the three — operative from January 2025 — and the most granular in how it distributes the effectiveness obligation across the organisation.
At board level, Article 5(1) requires a governance framework ensuring “effective and prudent management of ICT risk.” That framing places accountability at the top of the hierarchy from the start. At strategy level, Article 6(8)(f) requires the digital operational resilience strategy to be built on assessment of the effectiveness of preventive measures. At the operational level, Article 13(4) creates a continuous monitoring obligation — not an annual review, but ongoing tracking of whether the strategy is working. Post-incident, Articles 13(2) and (3) require organisations to determine whether “actions taken were effective” and to feed lessons back into the risk framework.
This is what distinguishes DORA from the other two frameworks. GDPR established the principle. NIS2 added personal stakes. DORA made it a continuous obligation running through every layer of the organisation, from the board resolution to the post-incident review. Effectiveness is not a state you reach — under DORA, it is something you must continuously demonstrate.
For significant financial entities, Article 26 mandates Threat-Led Penetration Testing at least every three years. The first deadline is January 2028. There is no enforcement record yet. But the obligation is live and the clock is running.
The pattern
Three frameworks. Three different legislative processes. Three different enforcement bodies. And all three arrived independently at the same conclusion: attestation is not evidence.
Saying you have a firewall is not the same as showing it blocks what it should block. Saying you train employees is not the same as demonstrating that their behaviour changed. Saying your incident response plan exists is not the same as proving it works under pressure.
The compliance conversation has shifted. For years, the question was: do you have controls in place? Now the question is: can you show what those controls actually do? Organisations that cannot answer that question with evidence — not assertions, not checklists, not annual audit reports — face compliance gaps across all three frameworks simultaneously.
The regulatory direction is clear. The only question is whether your evidence record is keeping pace.
The full argument, with regulatory references and enforcement precedents, is in the white paper: Measuring Security Control Effectiveness: From Attestation to Evidence.
Ready to see your employees' security behaviors?
Connect your Microsoft 365 and see months of behavioral data in 15 minutes. Free 30-day trial — no credit card, no sales call.
Start Free Trial