Short answer
DORA vs NIS2 comes down to sector and legal form. DORA is a regulation that applies directly to EU financial entities and their critical ICT providers since 17 January 2025. NIS2 is a directive, applied through national laws, covering medium and large entities in 18 sectors. For financial entities, DORA takes precedence where both cover the same ground.
Key takeaways
- DORA is a directly applicable regulation; NIS2 works through each member state's law.
- For financial entities, DORA is the sector-specific law and takes precedence over NIS2.
- Incident reporting differs: DORA starts at 4 hours after classification, NIS2 at 24 hours after awareness.
- Both expect board accountability, supplier risk management and tested continuity.
Who each law covers
DORA, Regulation (EU) 2022/2554, applies to around 20 types of financial entity, from banks and insurers to payment institutions and crypto-asset service providers, and to ICT providers the European Supervisory Authorities designate as critical. NIS2, Directive (EU) 2022/2555, applies to medium and large entities in 18 sectors listed in its Annexes I and II, such as energy, transport, health, digital infrastructure and manufacturing, plus some entities regardless of size.
NIS2 lists banking and financial market infrastructure among its sectors, but it also says that where a sector-specific EU act sets equivalent requirements, that act applies. DORA is that act for finance, so a bank follows DORA for ICT risk, incident reporting and testing rather than the national NIS2 rules.
| DORA | NIS2 | |
|---|---|---|
| Legal form | Regulation, directly applicable | Directive, transposed into national law |
| Applies since | 17 January 2025 | National laws from October 2024 onwards |
| Who | EU financial entities and critical ICT providers | Medium and large entities in 18 sectors |
| Incident reporting | Initial notice within 4 h of classifying a major incident (and 24 h of awareness), 72 h intermediate, 1 month final | Early warning within 24 h, notification within 72 h, final report within 1 month |
| Suppliers | Register of information, mandatory contract terms, exit plans | Supply chain security as one of ten Article 21 measures |
| Testing | Yearly tests of critical systems; TLPT every 3 years where required | Assess effectiveness of measures |
| Penalties | Set by member states; periodic penalties for critical ICT providers | At least up to €10m or 2% of turnover for essential entities |
What the two laws share
Both put the management body on the hook. DORA Article 5 makes it responsible for the ICT risk framework; NIS2 Article 20 requires management to approve and oversee the cybersecurity measures and to be trained. Both expect risk assessment, incident handling, business continuity, supplier security and testing. A control set built on ISO/IEC 27001 and ISO 22301 covers much of both.
When both apply in one group
Groups often contain a regulated financial entity and other companies that fall under NIS2, for example an IT services subsidiary that is an essential entity in its own right. The financial entity reports major incidents under DORA; the IT subsidiary reports significant incidents under its national NIS2 law. A single incident log with both sets of deadlines avoids two parallel processes.
Checklist
Running DORA and NIS2 together
0 of 5 done
Put this into practice on QULDEX
Frequently asked questions
Does NIS2 apply to banks?
Banking is listed in NIS2, but DORA is the sector-specific act for financial entities, so banks follow DORA for ICT risk management, incident reporting and testing.
Which has faster incident reporting, DORA or NIS2?
DORA. Its initial notification is due within 4 hours of classifying an incident as major, and no later than 24 hours after becoming aware of it. NIS2's early warning is due within 24 hours.
Can one programme meet both DORA and NIS2?
Largely yes. Both expect governance, risk management, incident handling, continuity and supplier security, so one control set with entity-specific reporting covers most of the work.
Sources
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), EUR-Lex
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2), EUR-Lex
- Commission Delegated Regulation (EU) 2025/301 on major ICT-related incident reporting, EUR-Lex