Directive NIS2 European Union
Cart 0

NIS2 vs DORA


If you are a financial entity, DORA takes precedence for ICT risk and incident reporting. That does not mean NIS2 stops applying to you.

Art. 4(1) NIS2
Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents […] and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive […] shall not apply.
Directive (EU) 2022/2555

This is what makes DORA lex specialis. The carve-out is provision by provision, not blanket: where DORA is at least equivalent, DORA applies; where DORA is silent, NIS2 still governs.

Side by side


Comparison of NIS2 and DORA obligations
  NIS2 DORA
Legal instrument Directive (EU) 2022/2555 Regulation (EU) 2022/2554
Applies via 27 national transposition laws Directly, identically in all member states
In force 16 January 2023; transposition due 17 October 2024 Applies from 17 January 2025
Who is covered 18 sectors, ~160,000 entities 20 categories of financial entity
Risk management Article 21 — ten minimum measures ICT risk management framework, articles 5 to 15
Incident reporting 24h early warning, 72h notification, 1 month final Initial, intermediate and final reports on regulatory timelines
Third-party risk Article 21(2)(d), direct suppliers Detailed contractual regime plus register of information
Resilience testing Effectiveness assessment, article 21(2)(f) Mandatory programme; TLPT for significant entities
Oversight of providers Not addressed Critical ICT third-party providers supervised directly by the ESAs
Management liability Article 20 plus possible management ban Management body responsible for the ICT risk framework
Maximum fines €10m or 2% (essential); €7m or 1.4% (important) Set by national law; ESAs may fine CTPPs up to 1% of daily turnover

What this means in practice

A bank does not get to ignore NIS2. It applies DORA for ICT risk management and ICT-related incident reporting, and remains within the NIS2 framework for the matters DORA does not cover — which in most member states includes registration with the national authority and the supervisory relationship itself. Several national transposition laws explicitly list financial entities and then carve out the DORA-covered obligations, which is why the answer is national rather than uniform.

The practical failure mode is not over-compliance. It is assuming that because the CISO runs a DORA programme, nobody needs to have registered the entity under national NIS2 law.

Where the two are genuinely different in kind

DORA supervises providers, not only financial entities. Critical ICT third-party providers — typically large cloud and core-banking vendors — are designated and overseen directly by the European Supervisory Authorities. NIS2 has no equivalent: it reaches suppliers only indirectly, through the article 21(2)(d) obligations of their customers.

DORA also mandates threat-led penetration testing for significant entities, on a defined cycle. NIS2 requires you to assess the effectiveness of your measures, and leaves the method to you.

Common questions

We are a bank. Does NIS2 apply to us at all?
Yes, but not for everything. Banking is an Annex I sector, so you are within NIS2 scope. Article 4 of NIS2 then disapplies the specific NIS2 provisions where a sector-specific act — here DORA — imposes requirements at least equivalent in effect. So you apply DORA for ICT risk management and ICT-related incident reporting, and remain under the NIS2 framework for what DORA does not cover, which in most member states includes registration with the national competent authority and the supervisory relationship itself.
Is the carve-out automatic or do we have to claim it?
It operates by law rather than by application, but it is provision by provision and depends on national transposition. Several member states list financial entities explicitly in their NIS2 law and then carve out the DORA-covered obligations. Because the drafting differs, the safe approach is to check the national text of each member state where you are established rather than to assume a uniform result.
Which came first, and which is stricter?
NIS2 and DORA were adopted within days of each other in December 2022. DORA applies from 17 January 2025; NIS2 required national transposition by 17 October 2024. DORA is more prescriptive and more detailed in its scope — mandatory resilience testing programmes, a full contractual regime for ICT third parties, a register of information, and direct ESA oversight of critical providers. NIS2 is broader in reach but sets outcomes rather than methods.
Our ICT provider serves banks. Are we in scope of DORA?
Not directly, unless you are designated a critical ICT third-party provider by the European Supervisory Authorities, which applies to a small number of large providers. You will nevertheless feel DORA through your contracts, because your financial-sector customers must impose specific contractual terms on you. Separately, if you are a managed service provider you are likely in NIS2 scope in your own right under the ICT service management sector of Annex I.
Can one incident require reporting under both regimes?
For a financial entity, ICT-related incident reporting is governed by DORA rather than by NIS2 article 23, so you would not normally file twice for the same ICT incident. But an incident can still trigger DORA reporting and GDPR article 33 notification simultaneously, and a non-financial group company in the same incident may owe a NIS2 filing. Map the obligations per legal entity, not per group.

Working on DORA as well?

Our sister platform covers DORA specifically — the five pillars, the RTS/ITS library, and the register of information.

regulation-dora.eu →

Cart 0