en
Language
  • en
  • cs
  • hu
  • de
  • fr
  • es
  • br
  • ru
  • kr
  • jp
AI translation
  • it
  • pl
  • tr

NIS2 and DORA in 2026: What it means for your project management tool

9/16/2026
5 minutes

NIS2 has been in force since 2023, but it is the national laws of 2025 that made it real, and across much of the EU the deadline for the security measures actually be working falls during 2026. What to do to be NIS-ready? Keep on reading?

Table of contents

What is the NIS2 Directive?
The NIS2 timeline
What NIS2 actually requires
Where DORA fits in
Project management tool in scope
Easy8 Private WorkOps Platform: NIS2-ready deployment

TL;DR

NIS2 applies across all 27 member states, but it bites through national law, and most of those laws landed in 2025 with phase-ins that run out during 2026. Article 21(2)(d) makes your suppliers your problem, which is how a project management platform ends up inside the scope of a cybersecurity directive. No software can make you NIS2 compliant, but deployment control, access control and audit evidence decide how hard it is to prove you are.


What is the NIS2 Directive?

NIS2 is Directive (EU) 2022/2555, the EU cybersecurity law for critical and important sectors. It covers 18 sectors, applies to essential and important entities in all 27 member states, and sets minimum risk-management measures, a strict incident-reporting cascade and personal accountability for company management.

Because it is a directive rather than a regulation, it does not bind your organisation directly. Each member state transposes it into national law, so your obligations, your registration duty and your deadlines come from the country where your entity operates, not from Brussels. That is also why NIS2 is a 2026 story rather than a 2024 one.


The NIS2 timeline

How a 2024 deadline became a 2026 obligation:

DateWhat happened
16 January 2023NIS2 entered into force
17 October 2024Deadline for all 27 member states to transpose NIS2 into national law. Most missed it
17 January 2025DORA becomes applicable to the EU financial sector
Through 2025The bulk of national transposition laws enter into force, each with its own registration and implementation clock
19 November 2025Commission publishes the Digital Omnibus Package, a first wave of technical adjustments to NIS2
6 December 2025The German implementation act enters into force, with no transition period at all
20 January 2026Commission proposes targeted amendments to NIS2 as part of a wider cybersecurity package
Through 2026In many member states the transition period to have the security measures in place expires
8 July 2026Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice of the EU
15 August 2026The Dutch NIS2 law enters into force

Every country sets its own clock. You self-identify, register with your national authority, and then get a transition period to put the measures in place, which runs from nothing at all in Germany to about a year elsewhere, and that is what pushes the real deadline into late 2026.


What NIS2 actually requires

There are three articles that carry most of the operational weight.

Article 21 sets ten minimum areas your security measures have to cover:

  • Risk analysis and security policies
  • Incident handling
  • Business continuity
  • Supply chain security
  • Secure acquisition, development and maintenance
  • Checking the measures actually work
  • Cyber hygiene and training
  • Cryptography and encryption
  • Staff security, access control and asset management
  • Multi-factor authentication and secured communications

Article 20 puts the management body on the hook. It approves the measures, oversees them, can be held liable, and must follow cybersecurity training. "Our IT team handles that" is no longer an answer a board can give.

Article 23 sets the reporting cascade for a significant incident: an early warning within 24 hours, an incident notification with an initial impact assessment within 72 hours, and a final report within one month. The clock starts when you become aware of the incident, not when it began. Reports go to the national CSIRT or competent authority, which differs in every member state.

On penalties, Article 34 sets floors rather than ceilings, and they apply specifically to breaches of the risk-management or reporting obligations in Articles 21 and 23: a maximum of at least 10 million euro or at least 2% of total worldwide annual turnover for essential entities, and at least 7 million euro or 1.4% for important entities, whichever is higher. 

Member states are free to set their ceilings higher, and several have, so the number that applies to you is the one in your national law.


Where DORA fits in

DORA (Digital Operational Resilience Act), Regulation (EU) 2022/2554, is the financial sector's version. It has applied since 17 January 2025 and, being a regulation, binds directly and identically in every member state.

What matters for software procurement is its third-party chapter. Financial entities must list every ICT provider contract in a Register of Information, write mandatory terms on audit rights, data access, subcontracting and exit into those contracts, and test their exit plans. 

Banks, insurers, payment institutions and investment firms are usually in scope for both regimes, and the controls overlap heavily.


Project management tool in scope

Article 21( 2)(d) makes supplier security your obligation, and software vendors get caught as suppliers to in-scope customers who push the requirements down the contract.

A project management platform matters because of what sits inside it: 

  • delivery plans
  • engineering documentation
  • supplier records
  • incident tickets
  • access rights. 

Article 21 makes that an asset requiring access control, and Article 23 can turn its timestamps into evidence.

There is no NIS2 certification, and no vendor can sell you compliance. The obligation is yours. Software only makes it easier to prove.

So ask any project management vendor for:

  • Deployment options, including on-premises and isolated environments, not just a regional cloud
  • The legal entity and jurisdiction of the operating company and its hosting providers
  • ISO 27001 certification status and scope
  • A current subprocessor list, with notification of changes
  • Role-based access control, granular permissions and audit logging
  • Incident notification terms in the contract, with a defined timeframe
  • Backup, recovery and business continuity commitments
  • Data export and exit terms, which DORA makes mandatory for financial entities


Easy8 Private WorkOps Platform: NIS2-ready deployment

Easy8 is a Private WorkOps Platform built for organisations that cannot treat where their work data lives as a detail. 

It runs on European cloud infrastructure, in a Private Cloud or EU Sovereign Cloud, fully on-premises, or in an air-gapped environment, so the jurisdiction question has an answer you choose rather than inherit. That comes with ISO 27001 certification, GDPR compliance, role-based permissions across projects and portfolios, and audit trails on the work itself.

Still mapping your exposure? Start with the comparison of EU project management tools or the on-premises and air-gapped shortlist. 

Try Easy8 for free, contact us and we will walk through the deployment and documentation your assessment requires.

Róbert Kováčik

Róbert, quality guru and Head of QA at Easy8, has been with the company since its early stages and knows every nook and cranny of our software. He is responsible for quality management and overseeing the release of new versions.

With a rigorous approach to testing and a commitment to continuous improvement, he leads our QA team in delivering an excellent user experience and maintaining the highest performance and security standards. Róbert is a member of Mensa Czech Republic and an enthusiast of skiing and mountains.

Frequently asked questions

What is NIS2 audit?

A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.

What is NIS2 audit?

A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.

What is NIS2 in cyber security?

NIS2 is the EU's main cybersecurity law. It requires medium and large organisations in critical sectors to manage cyber risks, report significant incidents and make management accountable for security. It replaced the original NIS Directive, with member states required to transpose it by 17 October 2024.

What is NIS2 in cyber security?

NIS2 is the EU's main cybersecurity law. It requires medium and large organisations in critical sectors to manage cyber risks, report significant incidents and make management accountable for security. It replaced the original NIS Directive, with member states required to transpose it by 17 October 2024.

What is NIS2 and DORA?

NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.

Related articles

Data security
7 minutes read
Atlassian changes its AI data collection policy

Atlassian has announced changes to how it will use customer metadata and in-app data from 17 August 2026. Alongside this, new in-app settings have been rolling out since 16 April 2026. What could this mean for your organisation? Read on!

Read more
Data security
5 minutes read
Atlassian Isolated Cloud in 2026: Why US law still reaches your EU data

Isolated but not immune? With Atlassian phasing out Data Center and embracing the cloud, not even their 'Isolated Cloud' can shield regulated teams from US laws such as the CLOUD Act. What can you do about it? Read on to find out.

Read more
Data security
10 minutes read
Overview of cybersecurity in Easy8

Easy8 Group, demonstrates its commitment to the security of its products, processes, and overall ISMS in various ways. Read on to find resources relevant to your concerns.

Read more

Try Easy8 in 30 days free trial

  • Access all features
  • SSL protected
  • No credit card required