After NIS2 and DORA: What Comes Next?
NIS2 and DORA have dominated compliance conversations in security operations for 2 years. NIS2 has technically been enforceable law since October 2024 and DORA since January 2025, though both are still settling into practice. A third piece of regulation, the UK’s own Cyber Security and Resilience Bill, is close behind them, and the European Commission has now proposed changes to NIS2 itself. Here is where things stand, and what a security team should be doing about it.
DORA Has Moved from Applicable to Enforced
DORA became applicable in January 2025, giving financial entities and their ICT suppliers a defined rulebook for operational resilience. Through 2026, supervisors have shifted from checking that a framework exists to checking that it works. 2 requirements stand out for scrutiny. The Register of Information, the record every financial entity must keep of its ICT third party contracts, has its second annual submission due on 20 March 2026, and national regulators, including the Dutch central bank, have confirmed the reporting template is unchanged from the previous year, so there is no excuse for treating it as new work. Alongside that, incident reporting is under closer scrutiny, with entities expected to classify a major incident against DORA’s materiality criteria and produce a compliant initial report within hours rather than days.
Coverage of DORA readiness through 2026 has been inconsistent on exactly how many firms have reached full compliance, with different surveys reporting different figures and none of them a clear, verifiable primary source. Rather than repeat an industry wide number here, check your own status directly against the requirements and your national regulator’s published guidance.
NIS2 Enforcement Is Uneven, and Amendments Are Coming
NIS2’s own transposition deadline has already passed. Member states were required to transpose the directive into national law by 17 October 2024, and it replaced the original NIS Directive the following day. That does not mean enforcement is settled. Transposition and enforcement readiness have varied significantly by country, and reporting through 2026 continues to describe national authorities in several member states still building out registration, supervision and enforcement mechanisms nearly 2 years after the nominal deadline.
The bigger news for 2026 is not a new deadline but a proposed rewrite. On 20 January 2026 the European Commission proposed targeted amendments to NIS2 as part of its wider digital simplification package, alongside a related proposal for a new Cybersecurity Act. The amendments would let the Commission set harmonised technical requirements that member states could not add to nationally, introduce an EU wide cyber posture certification that could reduce duplicate audits, expand ENISA’s role in supervising cross border services, and narrow scope in places, including a new small mid cap category for entities under 750 employees and under 150 million euros turnover. The proposal is working through the ordinary legislative procedure, with Parliament and Council negotiation expected later in 2026 and a proposed 12-month transposition period once agreed. None of this is final. If it passes broadly as proposed, it will change what NIS2 compliance looks like in practice, not just when it applies.
The UK’s Own Version Is Close but Not Law Yet
The UK Cyber Security and Resilience Bill, the closest domestic equivalent to NIS2, has cleared every stage in the House of Commons and is now working through the House of Lords. As of late August 2026, it has completed its first and second reading in the Lords and moved into committee stage, with report stage, third reading and Royal Assent still to come. The Bill is not yet law. Once it receives Royal Assent, expect secondary legislation and codes of practice to follow before the detailed obligations, such as expanded scope to cover managed service providers and data centres, take effect. Organisations that wait for Royal Assent before starting work will be behind. The direction of the Bill is settled even if the exact commencement date is not.
What This Means for Your Security Data Strategy
Taken together, DORA, NIS2 and the UK Bill place 2 demands on the same security data infrastructure. Regulators want proof rather than assurance, meaning your logging, retention and incident classification need to produce evidence on demand rather than after the fact. And regulators increasingly hold management personally accountable, which pushes security data from an operational concern into a board level one.
The practical response is not to build 3 separate compliance programmes. It is to build a security data architecture that can answer any one of these frameworks’ questions from the same underlying data, tagged and retained in a way that supports whichever regulator asks first. That is a data architecture decision as much as a compliance one, and it is worth making before the next deadline arrives rather than after.
Ready to Modernise?
HOOP Cyber helps security teams audit their data estate, design the routing and normalisation that sits behind it, and rebuild security operations around a data architecture they control. If you cannot currently produce the three pieces of information at the top of this article, that is where we would start. Get in touch via .