# GitLab Dedicated: Compliance for a new regulatory era

DevFeed: [GitLab Dedicated: Compliance for a new regulatory era](<https://devfeed.tech/articles/gitlab-dedicated-compliance-for-a-new-regulatory-era-20785.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/gitlab-dedicated-compliance/>)

Author: Aathira Nair

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Multitenancy](<https://devfeed.tech/topics/multitenancy.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [product](<https://devfeed.tech/tags/product.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

## AI overview

The article presents GitLab Dedicated as a fully isolated, single-tenant SaaS platform hosted and managed by GitLab in a preferred Amazon Web Services region. It explains how the service is intended to help European enterprises address compliance, data sovereignty, audit readiness, security, resilience, and operational responsibilities related to DORA, NIS2, and GDPR.

## Source excerpt

Enforcements such as NIS2 are no longer a future planning consideration. The European Union Agency for Cybersecurity's (ENISA) NIS360 report confirms that supervisory authorities are actively assessing cybersecurity maturity across critical sectors. The agency is moving from guidance and consultation into active oversight, scrutiny, and accountability. This is the regulatory environment European enterprises now operate in. Multi-tenant cloud platforms remove operational overhead but place source code and pipelines on shared infrastructure regulators now scrutinize. Self-managed solutions provide isolation but transfer responsibility for upgrade cycles, security patches, and disaster recovery (DR) tests to an already stretched platform team. Both deployment options leave gaps in risk management, data sovereignty, and furnishing audit evidence. In this article, you'll discover how GitLab Dedicated, a fully isolated, single-tenant SaaS solution deployed in your preferred Amazon Web Services (AWS) region and hosted and managed by GitLab, addresses these challenges and helps you keep pace with evolving compliance requirements. "NatWest Group is adopting GitLab Dedicated SaaS to enable our engineers to use a common cloud engineering platform; delivering new customer and colleague outcomes rapidly, frequently, and securely with high quality, automated testing, on-demand infrastructure, and straight-through deployment." -- Adam Leggett, Platform Lead for Engineering Platforms, NatWest Group Regulations are driving change In the European Union, key regulations are driving the need for a different platform approach. These regulations converge on a decision most enterprises made before they existed: a platform their developers build on. That decision now carries audit consequences it didn't before. Digital Operational Resilience Act (DORA), which came into force across EU financial services in January 2025, requires financial institutions to keep critical technology resilient,