Edition Introduction

Two EU cyber-resilience regimes that spent years as distant compliance milestones are now in active enforcement. DORA has been applicable to financial entities since January 2025 and is in its first genuine supervisory cycle. NIS2 missed its original October 2024 transposition deadline in most member states, but national security-measure adoption deadlines are now converging on October 2026, alongside a first formal compliance audit deadline that has already moved once, from December 2025 to June 2026. This edition tracks where enforcement actually stands, what the penalty structure looks like in concrete terms, and what cloud and API governance evidence CISOs need to have ready.

As with every edition of this monitor, the goal is a working, current picture rather than a static compliance summary; both regimes are moving quickly enough in 2026 that guidance written even a few months ago can already be out of date on specific dates and figures.

Key Developments This Edition

Date

Milestone

Applies To

17 October 2024

Original NIS2 transposition deadline; missed by most member states

EU member states (national law)

17 January 2025

DORA becomes directly applicable EU-wide

Financial entities and their ICT third parties

28 November 2024

European Commission opens infringement proceedings against 23 member states

Member states failing to fully transpose NIS2

30 June 2026

First formal NIS2 compliance audit deadline (moved from 31 December 2025)

In-scope essential and important entities

1 October 2026

National security-measure adoption deadlines converge (e.g., Italy's technical annexes, Norway's registration)

Essential and important entities by jurisdiction

DORA Enforcement in Detail

DORA has a cleaner enforcement timeline than NIS2 because it is a regulation, directly applicable across the EU since 17 January 2025, rather than a directive requiring national transposition. That structural difference matters: while NIS2 compliance still depends on which country's transposing law applies, DORA's requirements are uniform across covered financial entities and their ICT third parties regardless of jurisdiction. ComplianceHub.Wiki's analysis of the current enforcement cycle notes that DORA has now entered its first genuine supervisory cycle, with regulators signaling they will act on incident-reporting failures and persistent deficiencies in the Register of Information, rather than treating early submissions as a one-time compliance checkbox [1].

The Register of Information is the specific instrument worth understanding in practical terms. It requires financial entities to maintain detailed, auditable records of their ICT third-party arrangements, including which vendors provide which services, how critical each arrangement is, and what contractual protections are in place. Financial entities are now in the second annual submission cycle, and the shift from first-submission to active audit means that discrepancies between what an organization reported and what its actual API integrations and cloud dependencies show are exactly the kind of gap supervisory reviews are now designed to catch.

Why These Developments Matter

The October 2026 framing is not a single EU-wide statutory deadline changing; it reflects a convergence of national-level milestones as member states' transposing laws come into force on their own timelines. ComplianceHub.Wiki's analysis of the current enforcement cycle describes this directly: national transposition and compliance obligations are culminating around an October 2026 deadline for covered entities across critical sectors, even though the underlying legal mechanism varies by country [1][2]. Italy's technical annexes establishing minimum security requirements take effect by October 2026, and Norway's NIS2-equivalent implementation sets an October 2026 registration deadline as its own national scope expands from roughly 600 to about 5,000 covered organizations [3][4].

Figure 1. EU member states under NIS2 infringement proceedings, November 2024 vs. mid-2025.

Enforcement urgency has a concrete driver: transposition compliance has improved but remains incomplete. The European Commission opened infringement proceedings against 23 member states in November 2024; by mid-2025, that figure had narrowed to 13, with a handful of countries, including France, Ireland, Luxembourg, the Netherlands, and Spain, still completing their legislative process into 2026 [2][5]. For organizations operating across multiple EU jurisdictions, this means NIS2 compliance obligations are not yet fully uniform, and the specific transposing law in each operating country still needs to be tracked individually.

Penalty Structure at a Glance

Entity Classification

Maximum Penalty

Supervision Model

Essential entities

€10 million or 2% of global annual turnover, whichever is higher

Proactive supervision: regular audits, on-site inspections, security scans

Important entities

€7 million or 1.4% of global annual turnover, whichever is higher

Reactive supervision: triggered by incidents or evidence of non-compliance

 

Figure 2. NIS2 maximum penalty as a share of annual global turnover, by entity classification.

These figures are deliberately GDPR-scale, and the classification, essential versus important, depends on sector and company size rather than on how an organization perceives its own risk profile [6]. On the financial-services side, DORA's Register of Information requirement is now in its second annual submission cycle, with regulators actively auditing register deficiencies rather than treating the initial submission as a one-time formality, consistent with the shift from documentation exercise to active supervision this edition tracks across both regimes. Organizations should note that the whichever-is-higher formulation in both penalty tiers means the euro caps function as a floor for smaller entities while the turnover percentage becomes the binding constraint for larger ones, so a large multinational's actual exposure is likely to be calculated on the percentage basis rather than the flat euro figure.

The Detail Most CISOs Miss: Personal Liability

Both regimes attach duties directly to the management body, not only to the organization. ComplianceHub.Wiki's analysis of this dimension is explicit: under both DORA and NIS2, cyber-risk accountability has been deliberately moved out of the IT function and into the boardroom, with duties that cannot be delegated away and, under NIS2, sanctions that can reach individual directors and executives [7]. This changes the practical audience for the evidence this edition discusses. A cloud and API governance gap is no longer only a technical finding for a security team to remediate; it is a governance record that a board member may need to personally account for.

The practical implication for CISOs is a shift in who needs to see governance evidence, and how often. Under NIS2, management bodies are required to approve cybersecurity risk-management measures and oversee their implementation, with training obligations extending to board members directly, not only to technical staff. Under DORA, the management body bears explicit responsibility for the ICT risk management framework, including third-party risk, which means the Register of Information discussed above is not purely a compliance-team deliverable; it is a document the board is expected to understand and, in a supervisory inquiry, may be asked to explain. CISOs who have historically summarized governance posture for the board in general terms should expect that standard to tighten as both regimes move further into active enforcement.

CyberTech Intelligence Perspective

CyberTech Intelligence's reading of this enforcement cycle is that the compliance-theater period for DORA and NIS2 has genuinely ended. The Register of Information's move to active auditing, the narrowing but still incomplete transposition picture, and the October 2026 convergence of national security-measure deadlines together indicate that regulators are now testing whether the evidence organizations claimed to have actually exists, not merely whether a policy document was filed. Organizations whose cloud and https://cybertechintelligence.com/expert-analysis/api-sprawl-cloud-misconfigurations-harder-to-govern data was never structured to answer a regulator's specific request will find that gap surfaces at the worst possible time, during an active supervisory inquiry rather than a scheduled internal review.

There is a specific pattern worth naming directly: both regimes ultimately test the same underlying capability this campaign has documented repeatedly, the ability to produce a current, accurate account of what APIs, cloud services, and third-party integrations an organization actually depends on. A Register of Information that was accurate at initial submission but never updated as vendor relationships changed is not meaningfully different, from a supervisory standpoint, from a NIS2 security-measure attestation that describes controls no longer actually in place. Both fail for the same reason: the underlying inventory was treated as a point-in-time deliverable rather than a continuously maintained record.

Recommended Actions

The actions below are sequenced to reflect what a supervisory review is most likely to test first, entity classification and register accuracy, before moving to the governance and board-level items that depend on those foundations being correct.

  • Confirm your entity classification, essential or important, under each jurisdiction's transposing law where you operate, since supervision models and penalty exposure differ materially between the two.
  • Verify your organization's specific October 2026 obligations against the transposing law in each operating country, rather than assuming a single EU-wide date applies uniformly.
  • Brief the board directly on personal liability exposure under both regimes, given that duties under NIS2 and DORA cannot be delegated away from the management body.
  • Treat your DORA Register of Information as a living document subject to active audit, not a one-time submission, and reconcile it against your actual current API and third-party inventory.
  • Assign a named, standing owner for regulatory evidence accuracy, distinct from whoever originally compiled it, so that updates happen on a defined cadence rather than only when a supervisory request arrives.

Strengthen Your NIS2 and DORA Compliance Evidence with CyberTech Intelligence

CyberTech Intelligence helps CISOs and compliance leaders build the cloud and API governance evidence that NIS2 and DORA supervisory reviews now actively test, connecting entity classification, register accuracy, and board-level liability into a single readiness picture.

To assess your organization's NIS2 and DORA compliance evidence readiness, connect with CyberTech Intelligence for a Cloud & API Regulatory Readiness Review.

Connect With Us

References

  1. ComplianceHub.Wiki. DORA Enforcement Arrives and NIS2 Hits Its October Deadline: The EU Cyber-Resilience Reckoning of 2026. ComplianceHub.Wiki, 2026. https://compliancehub.wiki/dora-nis2-2026-enforcement-eu-financial-cyber-resilience-compliance/ 
  2. ComplianceHub.Wiki. Personally on the Hook: The NIS2 October 2026 Deadline, DORA Enforcement, and Management-Body Liability. ComplianceHub.Wiki, 2026. https://compliancehub.wiki/nis2-october-2026-deadline-dora-management-liability-readiness/ 
  3. ECSO. NIS2 Directive Transposition Tracker. European Cyber Security Organisation, 2026. https://ecs-org.eu/policy/nis2-directive-transposition-tracker/ 
  4. OrbiqHQ. NIS2 Directive (2026): Requirements, Deadlines & Scope. OrbiqHQ, 2026. https://www.orbiqhq.com/eu-regulations/nis2-directive 
  5. Schellman. An Update on European Compliance: NIS2, CRA, DORA. Schellman, 2025. https://www.schellman.com/blog/cybersecurity/european-compliance-nis2-cra-dora 
  6. Persist Security. NIS2 Compliance Guide: Requirements & 2026 Deadlines. Persist Security, 2026. https://persistsec.com/blog-nis2-compliance-guide/ 
  7. ComplianceHub.Wiki. Personally on the Hook: The NIS2 October 2026 Deadline, DORA Enforcement, and Management-Body Liability. ComplianceHub.Wiki, 2026. https://compliancehub.wiki/nis2-october-2026-deadline-dora-management-liability-readiness/