Directive NIS2 European Union
Cart 0
Annex I · sector 3 of 18

NIS2 for Banking


DORA is what actually governs your ICT risk and incident reporting. NIS2 article 4 makes DORA lex specialis, so the practical question is what NIS2 duties remain — typically national registration and the supervisory relationship.

Annex
I
Default class
Essential
Supervision
ex ante
Maximum fine
10 M€ / 2 %

Which entities are covered


Credit institutions as defined in Regulation (EU) No 575/2013.

Sub-sectors named in the annex

  • Credit institutions

Scope traps specific to this sector


Trap 1

The DORA carve-out is provision by provision, not blanket. Several national transposition laws list financial entities and then carve out only the DORA-covered obligations.

Trap 2

Assuming a DORA programme discharges NIS2 entirely is the common error: registration with the national competent authority usually still applies.

Trap 3

Group entities that are not financial entities — a shared services company, for instance — remain fully in NIS2 scope.

What else applies to you


DORA (Regulation (EU) 2022/2554) takes precedence for ICT risk management and ICT incident reporting.

NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.

Cart 0