
The Regulatory Picture
Provable time is now a regulatory expectation
MiFID II / RTS 25. Firms engaged in trading must synchronise business clocks to UTC within defined tolerances and maintain traceability. If your time source is GNSS — and by default, it is — then interference with GNSS is interference with your compliance evidence.
DORA. The EU's Digital Operational Resilience Act requires financial entities, and the ICT providers serving them, to identify, manage and test ICT risk. UK organisations are in scope where they serve EU financial entities. Timing infrastructure that transactions, logs and audit trails depend on sits inside that perimeter, and “we assumed the satellite signal” is not a risk treatment.
NIS and the Cyber Security and Resilience Bill. The UK's resilience regime for essential and digital services continues to expand, with data infrastructure designated Critical National Infrastructure in 2024. The direction of travel is unambiguous: dependencies on external signals require identification, mitigation and evidence.
Aviation and beyond. EASA and EUROCONTROL's 2026 joint Action Plan, and EASA's repeatedly revised Safety Information Bulletin, define who must act and by when across European aviation. The regulatory pattern set there — monitor, report, harden, prove — is the template other sectors should expect.
What “in scope” means practically
Regulators do not ask whether you have GNSS exposure. They ask whether you can demonstrate you have identified it, tested it, and can operate through its failure. That demonstration is a document set: test findings, traceability audit, remediation architecture. Producing that set is precisely what a structured testing engagement is for.
Check which obligations apply to you →The assessment flags them automatically.