NIS2 for Banking
DORA is what actually governs your ICT risk and incident reporting. NIS2 article 4 makes DORA lex specialis, so the practical question is what NIS2 duties remain — typically national registration and the supervisory relationship.
Which entities are covered
Credit institutions as defined in Regulation (EU) No 575/2013.
Sub-sectors named in the annex
- Credit institutions
Scope traps specific to this sector
Trap 1
The DORA carve-out is provision by provision, not blanket. Several national transposition laws list financial entities and then carve out only the DORA-covered obligations.
Trap 2
Assuming a DORA programme discharges NIS2 entirely is the common error: registration with the national competent authority usually still applies.
Trap 3
Group entities that are not financial entities — a shared services company, for instance — remain fully in NIS2 scope.
What else applies to you
DORA (Regulation (EU) 2022/2554) takes precedence for ICT risk management and ICT incident reporting.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.