NIS2 and DORA in 2026: What it means for your project management tool
NIS2 has been in force since 2023, but it is the national laws of 2025 that made it real, and across much of the EU the deadline for the security measures actually be working falls during 2026. What to do to be NIS-ready? Keep on reading?

Table of contents
What is the NIS2 Directive?
The NIS2 timeline
What NIS2 actually requires
Where DORA fits in
Project management tool in scope
Easy8 Private WorkOps Platform: NIS2-ready deployment
TL;DR
NIS2 applies across all 27 member states, but it bites through national law, and most of those laws landed in 2025 with phase-ins that run out during 2026. Article 21(2)(d) makes your suppliers your problem, which is how a project management platform ends up inside the scope of a cybersecurity directive. No software can make you NIS2 compliant, but deployment control, access control and audit evidence decide how hard it is to prove you are.
What is the NIS2 Directive?
NIS2 is Directive (EU) 2022/2555, the EU cybersecurity law for critical and important sectors. It covers 18 sectors, applies to essential and important entities in all 27 member states, and sets minimum risk-management measures, a strict incident-reporting cascade and personal accountability for company management.
Because it is a directive rather than a regulation, it does not bind your organisation directly. Each member state transposes it into national law, so your obligations, your registration duty and your deadlines come from the country where your entity operates, not from Brussels. That is also why NIS2 is a 2026 story rather than a 2024 one.
The NIS2 timeline
How a 2024 deadline became a 2026 obligation:
| Date | What happened |
|---|---|
| 16 January 2023 | NIS2 entered into force |
| 17 October 2024 | Deadline for all 27 member states to transpose NIS2 into national law. Most missed it |
| 17 January 2025 | DORA becomes applicable to the EU financial sector |
| Through 2025 | The bulk of national transposition laws enter into force, each with its own registration and implementation clock |
| 19 November 2025 | Commission publishes the Digital Omnibus Package, a first wave of technical adjustments to NIS2 |
| 6 December 2025 | The German implementation act enters into force, with no transition period at all |
| 20 January 2026 | Commission proposes targeted amendments to NIS2 as part of a wider cybersecurity package |
| Through 2026 | In many member states the transition period to have the security measures in place expires |
| 8 July 2026 | Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice of the EU |
| 15 August 2026 | The Dutch NIS2 law enters into force |
Every country sets its own clock. You self-identify, register with your national authority, and then get a transition period to put the measures in place, which runs from nothing at all in Germany to about a year elsewhere, and that is what pushes the real deadline into late 2026.
What NIS2 actually requires
There are three articles that carry most of the operational weight.
Article 21 sets ten minimum areas your security measures have to cover:
- Risk analysis and security policies
- Incident handling
- Business continuity
- Supply chain security
- Secure acquisition, development and maintenance
- Checking the measures actually work
- Cyber hygiene and training
- Cryptography and encryption
- Staff security, access control and asset management
- Multi-factor authentication and secured communications
Article 20 puts the management body on the hook. It approves the measures, oversees them, can be held liable, and must follow cybersecurity training. "Our IT team handles that" is no longer an answer a board can give.
Article 23 sets the reporting cascade for a significant incident: an early warning within 24 hours, an incident notification with an initial impact assessment within 72 hours, and a final report within one month. The clock starts when you become aware of the incident, not when it began. Reports go to the national CSIRT or competent authority, which differs in every member state.
On penalties, Article 34 sets floors rather than ceilings, and they apply specifically to breaches of the risk-management or reporting obligations in Articles 21 and 23: a maximum of at least 10 million euro or at least 2% of total worldwide annual turnover for essential entities, and at least 7 million euro or 1.4% for important entities, whichever is higher.
Member states are free to set their ceilings higher, and several have, so the number that applies to you is the one in your national law.
Where DORA fits in
DORA (Digital Operational Resilience Act), Regulation (EU) 2022/2554, is the financial sector's version. It has applied since 17 January 2025 and, being a regulation, binds directly and identically in every member state.
What matters for software procurement is its third-party chapter. Financial entities must list every ICT provider contract in a Register of Information, write mandatory terms on audit rights, data access, subcontracting and exit into those contracts, and test their exit plans.
Banks, insurers, payment institutions and investment firms are usually in scope for both regimes, and the controls overlap heavily.
Project management tool in scope
Article 21( 2)(d) makes supplier security your obligation, and software vendors get caught as suppliers to in-scope customers who push the requirements down the contract.
A project management platform matters because of what sits inside it:
- delivery plans
- engineering documentation
- supplier records
- incident tickets
- access rights.
Article 21 makes that an asset requiring access control, and Article 23 can turn its timestamps into evidence.
There is no NIS2 certification, and no vendor can sell you compliance. The obligation is yours. Software only makes it easier to prove.
So ask any project management vendor for:
- Deployment options, including on-premises and isolated environments, not just a regional cloud
- The legal entity and jurisdiction of the operating company and its hosting providers
- ISO 27001 certification status and scope
- A current subprocessor list, with notification of changes
- Role-based access control, granular permissions and audit logging
- Incident notification terms in the contract, with a defined timeframe
- Backup, recovery and business continuity commitments
- Data export and exit terms, which DORA makes mandatory for financial entities
Easy8 Private WorkOps Platform: NIS2-ready deployment
Easy8 is a Private WorkOps Platform built for organisations that cannot treat where their work data lives as a detail.
It runs on European cloud infrastructure, in a Private Cloud or EU Sovereign Cloud, fully on-premises, or in an air-gapped environment, so the jurisdiction question has an answer you choose rather than inherit. That comes with ISO 27001 certification, GDPR compliance, role-based permissions across projects and portfolios, and audit trails on the work itself.
Still mapping your exposure? Start with the comparison of EU project management tools or the on-premises and air-gapped shortlist.
Try Easy8 for free, contact us and we will walk through the deployment and documentation your assessment requires.
Frequently asked questions
What is NIS2 audit?
A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.
What is NIS2 audit?
A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.
What is NIS2 in cyber security?
NIS2 is the EU's main cybersecurity law. It requires medium and large organisations in critical sectors to manage cyber risks, report significant incidents and make management accountable for security. It replaced the original NIS Directive, with member states required to transpose it by 17 October 2024.
What is NIS2 in cyber security?
NIS2 is the EU's main cybersecurity law. It requires medium and large organisations in critical sectors to manage cyber risks, report significant incidents and make management accountable for security. It replaced the original NIS Directive, with member states required to transpose it by 17 October 2024.
What is NIS2 and DORA?
NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.



