Compliance and Regulations Across East Central Europe: Fragmented Implementation, Converging Expectations

Compliance and Regulations Across East Central Europe: Fragmented Implementation, Converging Expectations

Cybersecurity regulation has moved from a technical compliance function into a strategic topic for boards and executive leadership across Europe. It now influences how organizations structure governance, manage risk, and approach operational resilience.

In East Central Europe, this shift is shaped by the introduction of major EU frameworks such as the NIS2 Directive and the Digital Operational Resilience Act (DORA). While these frameworks originate at EU level, their practical impact is increasingly visible across a wider set of countries and industries through regulatory alignment, supply chain dependencies, and contractual requirements.

What is emerging is not a uniform regulatory environment, but a gradual convergence of expectations across a fragmented legal landscape.

Fragmented Legal Frameworks, Shared Direction

Across EU member states in the region, including Poland, Czechia, Slovakia, Hungary, Romania and Bulgaria, NIS2 is currently being transposed into national legislation. The approaches differ in timing, supervisory structures, sectoral scope and enforcement models, reflecting national legal and institutional differences.

At the same time, DORA is already setting a more standardized baseline for financial institutions across the EU, particularly in areas such as ICT risk management, incident reporting, resilience testing and third-party risk oversight.

Outside the EU framework, organizations across East Central Europe are not directly subject to these regulations. However, many are still affected in practice. This influence comes through cross-border business relationships, integration into European supply chains, outsourcing arrangements and client-driven security requirements that reference EU standards.

In this way, regulatory expectations extend beyond formal jurisdiction through operational and commercial dependencies.

A Region with Different Levels of Maturity

Cybersecurity maturity across the region remains uneven. Some countries and sectors have already established structured approaches to critical infrastructure protection, incident reporting and financial sector oversight. Others are still developing foundational governance models and regulatory capacity.

Despite these differences, the direction of travel is becoming increasingly consistent.

Across industries and jurisdictions, organizations are focusing more on governance clarity, defined accountability, structured incident response processes, supply chain risk management and operational resilience. These priorities appear both in formal regulatory requirements and in how organizations interpret customer and partner expectations.

From Regulatory Text to Operational Implementation

One of the key challenges across the region is the translation of regulatory requirements into operational reality.

On paper, frameworks such as NIS2 and DORA define clear expectations. In practice, implementation depends on how organizations integrate these requirements into existing systems, processes and responsibilities.

This often reveals structural gaps rather than purely technical ones. Incident reporting requires clear internal escalation paths and decision-making authority. Third-party risk management depends on visibility across complex vendor ecosystems. Governance models need to reflect increased expectations around executive accountability and oversight.

In discussions with security leaders, the challenge is rarely resistance to regulation itself. It is the effort required to operationalize it consistently across different business units, legacy environments and external dependencies.

Learning Across a Connected Ecosystem of Organizations

Although regulatory frameworks differ across jurisdictions, organizations across East Central Europe are often addressing similar challenges in practice.

Implementation approaches vary. Some organizations focus first on governance and board-level reporting structures. Others prioritize incident response maturity or third-party risk management, particularly in sectors with complex outsourcing models.

There is no single implementation path. The same regulatory objectives are interpreted through different organizational contexts and levels of maturity.

This makes peer exchange particularly valuable. Practical experience often provides more actionable insight than regulatory text alone, especially when it comes to aligning compliance requirements with operational constraints.

Why This Matters

The discussion around NIS2, DORA and related frameworks is often framed as an EU regulatory development. In practice, its influence extends further.

For EU member states, these frameworks define binding legal obligations. For organizations outside the EU framework in the region, they increasingly shape expectations through supply chain integration, client requirements and market standards.

This results in a regulatory environment that is formally fragmented, but increasingly aligned in practice.

The key development is not full harmonization, but gradual convergence of expectations driven by shared dependencies and interconnected business environments.

Looking Ahead

As implementation of NIS2 and DORA continues, organizations across East Central Europe will continue to face similar challenges. These include interpreting overlapping requirements, aligning internal governance with external expectations, and translating compliance obligations into measurable security improvements.

These challenges cannot be addressed in isolation.

This is why dialogue across the region remains important, not only to understand regulatory differences, but to understand how similar requirements are being implemented in practice across different organizational and national contexts.

At Next IT Security East Central Europe, compliance and regulation will remain a key topic precisely for this reason. The focus is not on presenting regulation as a uniform system, but on understanding how fragmented frameworks are driving increasingly similar expectations across a connected business environment.

The overall direction is becoming clearer. While implementation differs, expectations are converging.

Get your pass

The most exclusive Cyber Security EVENTS in the world.

Exclusive C-level cybersecurity gatherings across Europe. Limited seats, maximum impact.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security · East Central
Main Conference Ticket
€495
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. September 30, Belgrade.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Workshops — Sold Separately
Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans. Participants work through actual compliance gaps, build a self-assessment framework, and leave with a prioritised action list — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Capacity
Limited seats
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment. Participants map their own shadow AI exposure and build a proportionate governance framework.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Capacity
Limited seats
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations. Participants conduct a structured dependency audit, evaluate viable European alternatives, and leave with a vendor risk strategy that is operationally grounded.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Capacity
Limited seats
Workshop 4 Chapter 4 · Cybercrime in a Borderless Threat Landscape
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement. Participants learn how cybercrime investigations unfold across borders and how to build an incident posture that works with — not against — public sector constraints.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Capacity
Limited seats
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials