NIS2 vs DORA
If you are a financial entity, DORA takes precedence for ICT risk and incident reporting. That does not mean NIS2 stops applying to you.
Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents […] and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive […] shall not apply.Directive (EU) 2022/2555
This is what makes DORA lex specialis. The carve-out is provision by provision, not blanket: where DORA is at least equivalent, DORA applies; where DORA is silent, NIS2 still governs.
Side by side
| NIS2 | DORA | |
|---|---|---|
| Legal instrument | Directive (EU) 2022/2555 | Regulation (EU) 2022/2554 |
| Applies via | 27 national transposition laws | Directly, identically in all member states |
| In force | 16 January 2023; transposition due 17 October 2024 | Applies from 17 January 2025 |
| Who is covered | 18 sectors, ~160,000 entities | 20 categories of financial entity |
| Risk management | Article 21 — ten minimum measures | ICT risk management framework, articles 5 to 15 |
| Incident reporting | 24h early warning, 72h notification, 1 month final | Initial, intermediate and final reports on regulatory timelines |
| Third-party risk | Article 21(2)(d), direct suppliers | Detailed contractual regime plus register of information |
| Resilience testing | Effectiveness assessment, article 21(2)(f) | Mandatory programme; TLPT for significant entities |
| Oversight of providers | Not addressed | Critical ICT third-party providers supervised directly by the ESAs |
| Management liability | Article 20 plus possible management ban | Management body responsible for the ICT risk framework |
| Maximum fines | €10m or 2% (essential); €7m or 1.4% (important) | Set by national law; ESAs may fine CTPPs up to 1% of daily turnover |
What this means in practice
A bank does not get to ignore NIS2. It applies DORA for ICT risk management and ICT-related incident reporting, and remains within the NIS2 framework for the matters DORA does not cover — which in most member states includes registration with the national authority and the supervisory relationship itself. Several national transposition laws explicitly list financial entities and then carve out the DORA-covered obligations, which is why the answer is national rather than uniform.
The practical failure mode is not over-compliance. It is assuming that because the CISO runs a DORA programme, nobody needs to have registered the entity under national NIS2 law.
Where the two are genuinely different in kind
DORA supervises providers, not only financial entities. Critical ICT third-party providers — typically large cloud and core-banking vendors — are designated and overseen directly by the European Supervisory Authorities. NIS2 has no equivalent: it reaches suppliers only indirectly, through the article 21(2)(d) obligations of their customers.
DORA also mandates threat-led penetration testing for significant entities, on a defined cycle. NIS2 requires you to assess the effectiveness of your measures, and leaves the method to you.
Common questions
We are a bank. Does NIS2 apply to us at all?
Is the carve-out automatic or do we have to claim it?
Which came first, and which is stricter?
Our ICT provider serves banks. Are we in scope of DORA?
Can one incident require reporting under both regimes?
Working on DORA as well?
Our sister platform covers DORA specifically — the five pillars, the RTS/ITS library, and the register of information.