NIS2, DORA and CRA in 2026: The Softprom Compliance Checklist for Central and Eastern Europe
NIS2, DORA and the Cyber Resilience Act reach full force in 2026, and companies across Central and Eastern Europe face three deadlines at once: on 17 October the NIS2 grace window closes for late-transposing states (only around 16 of 27 EU countries had completed transposition by early 2026), mandatory vulnerability reporting under the CRA starts on 11 September 2026, and the financial sector is already undergoing its first DORA supervisory audits. The biggest change is not the fines — it is the addressee: NIS2 places responsibility for cyber risk directly on the company's management body. Softprom — a value-added IT distributor since 1999, operating in 33 countries across Central and Eastern Europe, the Caucasus, and Central Asia — has mapped seven regulatory requirements to solutions from its portfolio of 120+ vendors.
NIS2 is the EU directive on the security of network and information systems: it expands the list of critical sectors to 18, introduces 24-hour incident reporting and makes management bodies personally accountable for cyber risk decisions.
Seven Requirements — Seven Solutions
| Regulatory requirement / what it means in practice | Solution from the Softprom portfolio |
|---|---|
|
Risk management and compliance (NIS2 Art. 20/21, DORA) |
Vanta (compliance automation, 35+ frameworks) |
|
Resilience testing (DORA TLPT, NIS2) |
Cymulate (continuous exposure validation) |
|
Privileged access control |
Segura (PAM, Gartner-recognised vendor) |
|
Network access policies (NIS2 Art. 21(2)(i)/(j)) |
Belden macmon, Google BeyondCorp, Portnox (NAC + ZTNA) |
|
Vulnerability handling (CRA from 11.09.2026) |
Automox (automated patch management) |
|
Incident reporting within 24 hours |
Google SecOps (SIEM + SOAR), Logsign, NetWitness, NXLog (log collection) |
|
Training for management and staff (NIS2 Art. 20.2) |
CybeReady (adaptive security awareness programmes) |
Why "Personal Liability" Is Not a Metaphor
NIS2 explicitly requires management bodies to approve cyber risk management measures and holds them accountable for failures — up to a temporary ban on holding executive positions in critical sectors. The first national precedents are already in motion: Belgium passed its first NIS2 enforcement deadline in April 2026.
What to Do Before October
- Determine whether your company falls under NIS2: 18 sectors, threshold of 50 employees or €10 million turnover.
- Run a gap analysis against Article 21 — Softprom provides pre-sales consulting and a demo lab free of charge.
- Close the gaps with the solutions above — 30+ certified Softprom engineers support pilots across the region.
FAQ
Companies in 18 sectors with 50+ employees or €10M+ turnover in all EU countries; providers of critical services regardless of size.
The obligations arrive as soon as transposition happens — October 2026 effectively closes the window. Prepare now.
DORA is a directly applicable regulation for the financial sector, in force since 17.01.2025; NIS2 is a directive for 18 sectors applied through national laws.
Vulnerability and incident reporting — from 11 September 2026; the full regime — from December 2027.
With a gap analysis against NIS2 Article 21: Softprom runs it with partners across Central and Eastern Europe free of charge.
As a value-added IT distributor since 1999, Softprom supports partners across Central and Eastern Europe with pre-sales expertise, a demo lab and 30+ certified engineers. Request a NIS2 gap analysis for your organisation today.