NIS2 in Central East Europe: Between the Paper and the Reality

NIS2 in Central East Europe: Between the Paper and the Reality

NIS2 is officially in force. Registrations are underway, compliance programmes are running, and management presentations have been delivered. On paper, the region is moving in the right direction. Talk to the teams actually doing the implementation and a different picture emerges.

The question is no longer what NIS2 requires. That part is largely understood. The real work is turning those requirements into something an organisation can consistently execute, measure, and evidence.

What does “enough” actually mean?

The core principles of NIS2 are not controversial. Risk management, supply chain security, incident reporting: all of it makes sense at a conceptual level.

The difficulty begins the moment an organisation tries to put those principles into practice. The questions that follow don’t have standard answers.

What does “adequate” third-party due diligence actually look like? How much documentation satisfies an auditor? What does meaningful management oversight look like in practice, not just on paper?

Without clear answers, implementation becomes a matter of interpretation and every organisation draws its own line. Those operating across multiple jurisdictions face an additional layer of complexity. NIS2 overlaps with GDPR, DORA, national cybersecurity laws, and the incoming Cyber Resilience Act. Aligning all of those is an organisational challenge, not a technical one.

Security teams aren’t doing less work

Regulatory programmes have expanded. Operational pressure has not eased.

Attack surfaces keep growing as organisations move to cloud and increase outsourcing. Identity-based attacks remain among the most common entry points. Ransomware increasingly targets operational disruption, not just data exfiltration.

Many organisations, especially in manufacturing, healthcare, and critical infrastructure, are still running legacy systems. These are not modernisation projects waiting to happen. They are the daily operational reality.

The result is predictable: teams expected to raise maturity levels are simultaneously managing live threats. Compliance work ends up running alongside operational security rather than being part of it.

Supply chain risk is now central

The way organisations describe their own risk boundaries has shifted.

A few years ago, suppliers and service providers were support functions. Today, cloud providers, managed service partners, software vendors, and outsourced infrastructure carry critical business functions. They are part of the operational core.

Visibility has not kept pace with that dependency.

Most organisations still assess supplier security through documentation, attestations, and periodic questionnaires. Those mechanisms provide structure, but they rarely reflect actual security conditions in real time. An organisation can be fully formally compliant while having no clear picture of what is happening inside the systems of its most critical partners.

Governance is where NIS2 actually changes behaviour

Under NIS2, management bodies carry explicit responsibility for cybersecurity.

In organisations where security has always lived inside IT or compliance, this requires a real change in who makes decisions and how those decisions get reported upward.

Some organisations have already made that shift. Cybersecurity sits inside enterprise risk management, with clear accountability and structured decision-making processes.

In others, the formal structures exist but security is still functionally an IT matter that surfaces to leadership through periodic reports. NIS2 does not close that gap. It makes it harder to ignore.

Compliance is not the finish line

Every large regulatory rollout carries the same risk: organisations start treating compliance as the goal.

In that model, success means clean documentation, a passed audit, completed procedures. None of that is unimportant, but it is not sufficient.

An organisation can be fully aligned with formal requirements while still lacking real visibility into its dependencies, not knowing how quickly it could respond to a serious incident, or having no clear picture of whether its controls are actually working.

The more mature organisations treat compliance as a baseline and measure success by whether security controls are genuinely improving operational resilience over time.

An uneven picture across the region

Implementation maturity across CEE varies considerably and probably always will.

Financial services are generally ahead. Years of regulatory pressure have had an effect. Critical infrastructure varies significantly depending on national investment levels and governance structures. Manufacturing, retail, and healthcare often face structural constraints that NIS2 alone cannot resolve: legacy systems, limited budgets, a shortage of qualified people.

The public sector is the most heterogeneous. Maturity depends less on which sector an institution belongs to and more on the specific institution and the people running it.

The underlying challenge is consistent across almost all of them though: moving from regulatory interpretation to operational execution is harder than it looked from the outside.

Conclusion

The NIS2 implementation gap is a structural problem. It is about translating regulatory intent into operational capability across organisations that differ significantly in maturity, resources, and complexity.

The gap between organisations that are compliant and those that are genuinely resilient will become more visible over time. That distinction will depend less on how tidy the documentation is and more on how deeply cybersecurity is embedded in real operational decision-making.

APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials