Your CISO is not the one who gets held personally liable in October. Your board is.

NIS2 compliance obligations culminate in an October 2026 deadline across 18 critical sectors, and DORA has entered its first real supervisory enforcement cycle for financial entities. If you sell into, operate in, or supply the EU, this is your regulation too — headquarters location is not the test.
WHAT THE RULES ACTUALLY REQUIRE
NIS2 sets a baseline for medium and large organizations: ten risk-management measures, incident reporting on a 24-hour / 72-hour / one-month clock, and personal liability for the management body.
DORA has applied since January 2025, with enforcement for serious incident reporting failures and persistent Register of Information deficiencies expected in the 2026 supervisory cycle. Supervisory expectations around governance, resilience testing, third-party exit strategies and audit rights are still hardening. Separately, EU AI Act Article 50 transparency obligations landed on 2 August 2026 and were not deferred.
WHY THE 24-HOUR CLOCK IS THE HARD PART
Most organizations can produce a good incident report. In a month. NIS2 wants an early warning within 24 hours of becoming aware — which means the deciding factor is not your forensics quality, it is whether someone is authorized to file before the investigation is finished.
That is an organizational problem wearing a technical costume. Teams miss the deadline because approval chains stall, not because telemetry is missing.
WHAT TO DO NOW
PRE-AUTHORIZE THE 24-HOUR NOTIFICATION — name the person who can file an early warning with incomplete facts, and put it in writing before you need it.
FINISH THE THIRD-PARTY REGISTER — the Register of Information is where DORA enforcement is expected to bite first, and it is tedious rather than difficult.
BRIEF THE BOARD IN WRITING — NIS2 attaches personal liability to the management body, so "nobody told us" is now a legal exposure, not an excuse.
TEST AN EXIT PLAN FOR ONE CRITICAL PROVIDER — supervisors want evidence you could actually leave a cloud or ICT provider, not a paragraph saying you could.
Compliance deadlines do not create risk. They just publish the date on which your existing risk becomes someone's legal problem.
If a serious incident started tonight, who is authorized to notify a regulator by tomorrow evening?