EU regulation

DORA vs NIS2: which one applies, and how they fit together

Both are EU cybersecurity laws with incident reporting and supplier rules. DORA is the sector law for finance; NIS2 covers 18 sectors through national laws. Here is how to tell which applies and how to run both.

Short answer

DORA vs NIS2 comes down to sector and legal form. DORA is a regulation that applies directly to EU financial entities and their critical ICT providers since 17 January 2025. NIS2 is a directive, applied through national laws, covering medium and large entities in 18 sectors. For financial entities, DORA takes precedence where both cover the same ground.

Key takeaways

  • DORA is a directly applicable regulation; NIS2 works through each member state's law.
  • For financial entities, DORA is the sector-specific law and takes precedence over NIS2.
  • Incident reporting differs: DORA starts at 4 hours after classification, NIS2 at 24 hours after awareness.
  • Both expect board accountability, supplier risk management and tested continuity.

Who each law covers

DORA, Regulation (EU) 2022/2554, applies to around 20 types of financial entity, from banks and insurers to payment institutions and crypto-asset service providers, and to ICT providers the European Supervisory Authorities designate as critical. NIS2, Directive (EU) 2022/2555, applies to medium and large entities in 18 sectors listed in its Annexes I and II, such as energy, transport, health, digital infrastructure and manufacturing, plus some entities regardless of size.

NIS2 lists banking and financial market infrastructure among its sectors, but it also says that where a sector-specific EU act sets equivalent requirements, that act applies. DORA is that act for finance, so a bank follows DORA for ICT risk, incident reporting and testing rather than the national NIS2 rules.

DORANIS2
Legal formRegulation, directly applicableDirective, transposed into national law
Applies since17 January 2025National laws from October 2024 onwards
WhoEU financial entities and critical ICT providersMedium and large entities in 18 sectors
Incident reportingInitial notice within 4 h of classifying a major incident (and 24 h of awareness), 72 h intermediate, 1 month finalEarly warning within 24 h, notification within 72 h, final report within 1 month
SuppliersRegister of information, mandatory contract terms, exit plansSupply chain security as one of ten Article 21 measures
TestingYearly tests of critical systems; TLPT every 3 years where requiredAssess effectiveness of measures
PenaltiesSet by member states; periodic penalties for critical ICT providersAt least up to €10m or 2% of turnover for essential entities

What the two laws share

Both put the management body on the hook. DORA Article 5 makes it responsible for the ICT risk framework; NIS2 Article 20 requires management to approve and oversee the cybersecurity measures and to be trained. Both expect risk assessment, incident handling, business continuity, supplier security and testing. A control set built on ISO/IEC 27001 and ISO 22301 covers much of both.

When both apply in one group

Groups often contain a regulated financial entity and other companies that fall under NIS2, for example an IT services subsidiary that is an essential entity in its own right. The financial entity reports major incidents under DORA; the IT subsidiary reports significant incidents under its national NIS2 law. A single incident log with both sets of deadlines avoids two parallel processes.

Checklist

Running DORA and NIS2 together

0 of 5 done

Put this into practice on QULDEX

Frequently asked questions

Does NIS2 apply to banks?

Banking is listed in NIS2, but DORA is the sector-specific act for financial entities, so banks follow DORA for ICT risk management, incident reporting and testing.

Which has faster incident reporting, DORA or NIS2?

DORA. Its initial notification is due within 4 hours of classifying an incident as major, and no later than 24 hours after becoming aware of it. NIS2's early warning is due within 24 hours.

Can one programme meet both DORA and NIS2?

Largely yes. Both expect governance, risk management, incident handling, continuity and supplier security, so one control set with entity-specific reporting covers most of the work.

Sources

  1. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), EUR-Lex
  2. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2), EUR-Lex
  3. Commission Delegated Regulation (EU) 2025/301 on major ICT-related incident reporting, EUR-Lex