[REVISION HISTORY]
EU NIS-2, DORA, and CRA implementation trends
Updated 9 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-14 09:13 UTC → 2026-09-14 13:14 UTC ·
added
removed
By late September 2026, the implementation of NIS-2 and DORA continues to reshape the European regulatory landscape. While the European Commission introduced the ‘Digital Omnibus’ in late 2025 to simplify rules regarding data, cybersecurity, and AI, the landscape remains complex due to the gradual nature of legislative changes. As of September 11, 2026, the reporting mandates of the EU Cyber Resilience Act (CRA) have officially become active. Manufacturers of digital products, including hardware, software, and IoT devices, and crypto wallets, must now report actively exploited vulnerabilities and serious security incidents via the CRA Single Reporting Platform to ENISA and national authorities. Under Article 14, this requires an initial warning within 24 hours, a detailed report within 72 hours, and subsequent summaries within 14 days for exploited vulnerabilities or one month for severe security incidents. Non-compliance with these CRA mandates carries heavy penalties, including fines of up to €15 million or 2.5% of global annual turnover. In Germany, significant readiness gaps exist regarding these new mandates. While awareness of the CRA is high, industry readiness varies. A Bitkom survey of German industrial companies indicates that only 29 percent consider themselves fully compliant, and 50 percent lack a dedicated external interface for security reporting. Although broader design and market requirements will not be fully applicable until December 2027, the immediate reporting obligations place significant operational pressure on companies to maintain mature vulnerability management processes. In Germany, the NIS-2 Implementation and Cybersecurity Strengthening Act affects approximately 29,500 to 30,000 entities, with roughly 12,000 failing to meet the July 31 deadline. In the Netherlands, the Cybersecurity Act (Cbw) and the Resilience of Critical Entities Act (Wwke) introduced personal liability for board members as of August 15, 2026. Austria is preparing for its NISG 2026 law to take effect on October 1, 2026, while Polish regulations effective April 2026 impact approximately 38,000 entities.
Versions
- 2026-09-14 13:14 UTC EU NIS-2, DORA, and CRA implementation trends
- 2026-09-14 09:13 UTC EU NIS-2, DORA, and CRA implementation trends
- 2026-09-12 13:58 UTC EU NIS-2, DORA, and CRA implementation trends
- 2026-09-12 12:48 UTC EU NIS-2 and DORA implementation and compliance trends
- 2026-08-28 08:56 UTC EU NIS-2 and DORA implementation and compliance trends
- 2026-08-28 07:44 UTC EU NIS-2 and DORA implementation and compliance trends
- 2026-08-18 12:17 UTC EU DORA & NIS-2 compliance challenges
- 2026-08-18 08:42 UTC EU DORA & NIS-2 compliance challenges
- 2026-08-10 13:52 UTC EU DORA & NIS-2 compliance challenges
- 2026-07-27 09:58 UTC EU DORA & NIS‑2 compliance challenges
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.