The Security Testing Market Is Changing. Here Is What Is Driving It.
If your business operates in financial services, supplies into a regulated sector, or sits in a government-adjacent supply chain, the security testing market is changing in ways that will affect your procurement decisions, your insurance coverage, and your ability to win and retain clients. This post explains what is driving that change and what it demands from the businesses navigating it.
The ICO fined Capita £14 million in 2025 following a cyber incident where security measures were found to have fallen below regulatory expectations. That figure is worth holding in mind as you read what follows.
For years, the market tolerated automated scanning dressed up as genuine security assessment. Cheap, fast, and easy to procure, it satisfied compliance requirements on paper while providing limited real assurance. That model is under pressure from multiple directions simultaneously, and the shift is structural rather than cyclical.
The regulatory picture is tightening
On the demand side, regulators, insurers, and procurement frameworks are raising what counts as acceptable evidence of security assurance.
Financial services has seen the most concentrated pressure. DORA, the EU's Digital Operational Resilience Act, establishes mandatory digital operational resilience requirements across EU-regulated financial entities and has been fully in force since January 2025. It includes formal penetration testing obligations, with the most significant entities required to conduct Threat-Led Penetration Testing, a structured, intelligence-driven red team exercise, at least once every three years. Smaller entities in scope still face annual penetration testing requirements as part of their broader resilience programme.
In the UK, FCA Policy Statement PS21/3 on operational resilience requires firms to demonstrate they can absorb and recover from disruptions to their important business services, with cyber resilience explicitly central to that framework. Full compliance was required by 31 March 2025, covering banks, building societies, insurers, and Enhanced scope SM&CR firms.
PCI DSS v4.0 has significantly tightened testing requirements for organisations handling payment card data, moving away from point-in-time compliance toward more continuous validation.
Public sector and defence supply chains are tightening separately. Procurement Policy Note 014, which came into force in February 2025, makes Cyber Essentials mandatory across central government contracts involving personal data, government employee data, or ICT systems. Since April 2025, Procurement Policy Note 01/25 has extended this to all public sector suppliers bidding on contracts over £5 million. The Defence Cyber Certification scheme, which came into force in December 2025, requires Cyber Essentials as the baseline across all four certification levels for MOD suppliers.
Healthcare operates under the Data Security and Protection Toolkit, which governs NHS suppliers and organisations handling patient data. NHS Supply Chain now requires Cyber Essentials Plus from suppliers handling NHS data or providing IT and digital services. For any organisation in the NHS supply chain, independent verification of security controls is no longer discretionary.
Across all sectors, UK GDPR and the Data Protection Act create a structural pressure that is easy to underestimate. The direction of travel from the ICO is clear: inadequate security measures are being treated as serious regulatory failures, not administrative oversights. For a business that has not invested in independent security testing, a regulatory finding is not just a financial penalty. It is reputational damage, potential loss of contracts, and in regulated sectors, a direct threat to operating licences.
The cyber insurance market is functioning as an informal regulator in parallel. Underwriters are tightening requirements around independent security testing, and organisations that cannot evidence a recent assessment from a certified provider are increasingly finding themselves facing higher premiums, coverage restrictions, or exclusions on cyber incidents. What was previously a preferred practice is becoming a condition of coverage.
The supply chain effect
Regulatory pressure does not stop at the directly regulated entity. It flows down through supply chains, and that is where a significant portion of businesses feel it most acutely.
A FinTech business supplying services to a bank is subject to that bank's supplier security requirements, which are themselves driven by FCA and DORA obligations. An MSP managing infrastructure for a regulated firm is increasingly being asked to demonstrate the security posture of the environments it manages. A SaaS company whose clients operate in financial services, healthcare, or the public sector will find that its clients' compliance obligations become its own procurement requirements. Enterprise procurement teams are pushing security requirements down to suppliers and subcontractors with increasing specificity, and independent penetration testing is one of the most common requirements they are adding.
For businesses that sit one step removed from direct regulation, the question is not whether this pressure will reach them. It is whether they are ready when it does.
Technology is reshaping what testing needs to look like
AI is accelerating both attack and defence simultaneously, and the evidence from 2025 makes that concrete rather than theoretical. Google's Threat Intelligence Group documented multiple nation-state hacking groups using AI to accelerate and scale cyberattack operations, including reconnaissance, malware development, and social engineering at a speed and scale that was not previously possible. Microsoft's Security Blog noted at RSAC 2026 that AI is now being used across every stage of the attack lifecycle, from infrastructure discovery and persona development through to payload generation and post-compromise automation. CrowdStrike's 2025 Threat Hunting Report found adversaries weaponising AI to scale operations with fewer human operators, with one documented campaign compromising over 320 organisations in a single year.
The consequence for security testing is direct. The threat has accelerated. A testing methodology that was adequate two years ago is measuring against an attacker profile that no longer exists. Automated scanning tools are optimised for known patterns. They do not adapt, they do not chain findings contextually, and they do not replicate the judgement of an adversary who is using AI to find the path of least resistance through a specific environment. Novel attack paths, business logic flaws, and environment-specific vulnerabilities require practitioner judgement to identify and contextualise, and that requirement is becoming more important as the offensive capability available to threat actors increases.
Sovereign capability is becoming a procurement question
Sovereign capability is emerging as a formal consideration rather than a soft preference. The UK Cyber Security and Resilience Bill, introduced to Parliament in November 2025 and expected to receive Royal Assent in 2026, represents the most significant reform to the UK's cyber security framework since the NIS Regulations in 2018. It extends security obligations to MSPs, data centres, and supply chains, and tightens requirements across Critical National Infrastructure sectors.
Under G-Cloud 15, Cyber Essentials is now a mandatory requirement for all public sector cloud suppliers. The GovAssure compliance regime, rolling out from the 2026-27 cycle, requires documented evidence including penetration test results as part of mandatory third-party audits. Self-assessment is no longer acceptable. For organisations operating in defence supply chains, regulated financial services, or public sector procurement, where data is processed, who owns the testing business, and what government-recognised certifications practitioners hold is becoming a hard question in tender processes. The days of a supplier self-declaring their security posture are ending.
Where the market is heading and what it demands
The compliance-driven, low-cost end of the market becomes more automated and more commoditised. The assurance-driven end becomes more regulated, more credentialised, and significantly harder to enter. Testing is moving from an annual event toward a programme aligned to development cycles and infrastructure change.
The window for businesses to get ahead of this is narrowing. Regulatory frameworks are already in force. Procurement requirements are already changing. The insurers, the auditors, and the enterprise procurement teams asking harder questions about security assurance are not a future problem. They are the present one.
What that environment demands from a testing partner is specific. Verified practitioner-level certification that holds up under regulatory scrutiny. UK sovereign capability that satisfies data residency and procurement requirements. A programme model that keeps pace with how environments actually change rather than producing a report once a year and starting from scratch the next time. And the ability to map findings to the regulatory frameworks that matter to the client's specific sector, whether that is DORA, FCA PS21/3, PCI DSS, or the government supply chain requirements now flowing down through Cyber Essentials.
Tarian Labs is built for the environment that is arriving. Our lead practitioner holds the CSTL-INF, recognised by NCSC and the UK Cyber Security Council as a mandatory requirement for Principal and Chartered status in security testing, alongside CREST CRT, OSCP, and OSEP qualifications. We are entirely UK-owned and operated, with all engagement data held onshore under UK jurisdiction. We continue to invest in adding to our credentials alongside the operational experience we have built across years of working in some of the UK's most demanding security environments, because in a market that is tightening around verified capability, standing still is not an option.
If you recognise your situation in this post and want to understand what it means for your security programme, the first step is a conversation. No commitment, no agenda. Just an honest discussion about where you stand and what would actually help.
Get in touch at info@tarianlabs.com or start the conversation at tarianlabs.com/contact.
Recognise your situation in this post?
Get in touch for a no-commitment conversation about your security programme. No hard sell, just an honest discussion about where you stand.