NIS2, DORA and CRA in 2026: The Softprom Compliance Checklist for Central and Eastern Europe

NIS2, DORA and CRA in 2026: The Softprom Compliance Checklist for Central and Eastern Europe

NIS2, DORA and the Cyber Resilience Act reach full force in 2026, and companies across Central and Eastern Europe face three deadlines at once: on 17 October the NIS2 grace window closes for late-transposing states (only around 16 of 27 EU countries had completed transposition by early 2026), mandatory vulnerability reporting under the CRA starts on 11 September 2026, and the financial sector is already undergoing its first DORA supervisory audits. The biggest change is not the fines — it is the addressee: NIS2 places responsibility for cyber risk directly on the company's management body. Softprom — a value-added IT distributor since 1999, operating in 33 countries across Central and Eastern Europe, the Caucasus, and Central Asia — has mapped seven regulatory requirements to solutions from its portfolio of 120+ vendors.

NIS2 is the EU directive on the security of network and information systems: it expands the list of critical sectors to 18, introduces 24-hour incident reporting and makes management bodies personally accountable for cyber risk decisions.

Seven Requirements — Seven Solutions

Regulatory requirement / what it means in practice Solution from the Softprom portfolio

Risk management and compliance (NIS2 Art. 20/21, DORA)
An evidence base for the audit, not folders of policies

Vanta (compliance automation, 35+ frameworks)

Resilience testing (DORA TLPT, NIS2)
Continuous validation of defences, not an annual pentest

Cymulate (continuous exposure validation)

Privileged access control
Who accessed what, when and why

Segura (PAM, Gartner-recognised vendor)

Network access policies (NIS2 Art. 21(2)(i)/(j))
Zero Trust instead of "the internal network is trusted"

Belden macmon, Google BeyondCorp, Portnox (NAC + ZTNA)

Vulnerability handling (CRA from 11.09.2026)
Patching within SLAs, not "when we get to it"

Automox (automated patch management)

Incident reporting within 24 hours
Seeing the incident before the day runs out

Google SecOps (SIEM + SOAR), Logsign, NetWitness, NXLog (log collection)

Training for management and staff (NIS2 Art. 20.2)
The board learns too, not just IT

CybeReady (adaptive security awareness programmes)

Why "Personal Liability" Is Not a Metaphor

NIS2 explicitly requires management bodies to approve cyber risk management measures and holds them accountable for failures — up to a temporary ban on holding executive positions in critical sectors. The first national precedents are already in motion: Belgium passed its first NIS2 enforcement deadline in April 2026.

What to Do Before October

  1. Determine whether your company falls under NIS2: 18 sectors, threshold of 50 employees or €10 million turnover.
  2. Run a gap analysis against Article 21 — Softprom provides pre-sales consulting and a demo lab free of charge.
  3. Close the gaps with the solutions above — 30+ certified Softprom engineers support pilots across the region.

FAQ

Companies in 18 sectors with 50+ employees or €10M+ turnover in all EU countries; providers of critical services regardless of size.

The obligations arrive as soon as transposition happens — October 2026 effectively closes the window. Prepare now.

DORA is a directly applicable regulation for the financial sector, in force since 17.01.2025; NIS2 is a directive for 18 sectors applied through national laws.

Vulnerability and incident reporting — from 11 September 2026; the full regime — from December 2027.

With a gap analysis against NIS2 Article 21: Softprom runs it with partners across Central and Eastern Europe free of charge.