Data Center interior, ISG Provider Lens Agentic AI Services Report October 2025 | DXC Technology

In its latest assessment of European Cybersecurity Governance, Risk, and Compliance (GRC) In its latest assessment of European Cybersecurity Governance, Risk, and Compliance (GRC) Consulting and Professional Services Vendors, IDC MarketScape notes, “Regulators are also raising the bar for scrutiny and accountability. The formal designation of certain technology providers as critical ICT third parties under DORA is a signal of how deeply regulatory oversight now reaches into the technology supply chain. For senior executives and board members, the days when cyber risk was a technical exercise are long gone; cyber risk is now firmly a governance responsibility with financial and legal implications.”  

In response to the increasingly intense scrutiny of how organizations are managing cyber risk, enterprises and other organizations must come to conclusions about whether they want to build and run their GRC capability, have a service provider build it and run it themselves, or have a service provider do both, according to the IDC MarketScape. 



Source
: "IDC MarketScape: European Cybersecurity Governance, Risk, and Compliance Consulting and Professional Services 2026 Vendor Assessment," by David Clemente, July 2026, Doc. #EUR154110926e

IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of ICT suppliers in a given market. The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. The Capabilities score measures vendor product, go-to-market and business execution in the short-term. The Strategy score measures alignment of vendor strategies with customer requirements in a 3-5-year timeframe. Vendor market share is represented by the size of the circles. Vendor year-over-year growth rate relative to the given market is indicated by a plus, neutral or minus next to the vendor name.

According to the report, “Global and European providers, spanning large professional services firms, major IT services companies, and specialist consultancies, are investing heavily in GRC capability, proprietary tooling, and AI-enabled delivery to meet growing client demand. Vendors are competing on the depth of their regulatory coverage, the sophistication of their risk quantification capabilities, and increasingly, their ability to demonstrate sovereignty-aligned delivery (however defined) for clients with data residency and security independence requirements.” 

Under today’s demanding conditions, we believe DXC proves itself to be a strong contender, as one of the top three service providers in the Major Players category. The IDC MarketScape recognized DXC’s strengths in:

  • Comprehensive, structured GRC delivery model: DXC's seven-offering portfolio spans the full GRC life cycle, from assessment and governance through to remediation. DXC supports continuous program management rather than point-in-time engagements.
  • Proprietary maturity methodology with defined outputs: The CMR's Cyber Reference Architecture, CMMI-based maturity scale, and multi-framework alignment provide a structured, repeatable basis for client assessments and improved roadmaps.
  • Strong client retention and satisfaction metrics: Independently reported retention rates and satisfaction scores, alongside a long average client relationship duration, reflect a stable European client base across regulated industries.

AI enters the picture, too, with the IDC MarketScape pointing out that innovations are being developed through LabX, DXC’s internal AI incubator, and all these innovations will be validated in our own operations first. “Innovation is developed through LabX, DXC's internal AI incubation function, targeting production-ready solutions within 90 days and validated in DXC's own operations first.”

We have more than 1,500 security professionals and over 500 GRC engagements, supported by more than 3,600 security certifications, and our European delivery centers span the UK, France, Italy, Germany, the Netherlands, Belgium, Bulgaria, Finland and Iberia. 

The IDC MarketScape recommends considering DXC when:

  • Integrating GRC with broader managed IT services
  • Developing or maturing incident response governance
  • Running a scalable, multi-framework compliance program

Recognition as a Major Player by IDC validates what we strive for every day: combining deep cybersecurity expertise, governance excellence and client commitment to make organizations more resilient. Proud to be part of DXC and the people who make this achievement possible.

Ramsés Gallego

DXC Chief Technologist, Cybersecurity