DORA or NIS2: which applies to your organisation?
Both deal with cybersecurity, resilience, incidents and suppliers. The practical difference is who they cover, how detailed the obligations are and which authority supervises them.
The short answer
NIS2
A broad cybersecurity framework for entities in 18 sectors covered by Annexes I and II. It operates through the national law of each Member State.
DORA
A directly applicable and more detailed EU regime for listed financial entities. It requires specific provisions in contracts for ICT services and provides an oversight framework for providers designated as critical.
Why they are easy to confuse
Both regimes require management responsibility, risk management, incident handling, supply-chain controls and evidence that the measures work. DORA is more prescriptive for financial services: it adds a detailed ICT risk framework, a standardised register of ICT arrangements, specific contractual provisions, resilience testing and an EU oversight framework for critical ICT third-party providers.
The practical differences
| Question | DORA | NIS2 |
|---|---|---|
| Legal form | EU regulation; directly applicable | EU directive; implemented through national law |
| Who it applies to | The financial entities listed in Article 2 | Covered entity types in 18 sectors, subject to size rules and exceptions |
| ICT providers | Contractual requirements apply through financial clients; designated critical providers face EU oversight | Cloud, data-centre, managed service, managed security and other covered providers may be directly in scope when the legal criteria are met |
| Main emphasis | Digital operational resilience of financial services and detailed ICT third-party risk | A broad cybersecurity baseline across critical and important parts of the economy |
| Supervision | The competent financial supervisory authority for the type of entity | The competent authority and CSIRT arrangements under national law |
| Testing | A resilience-testing programme; TLPT for selected financial entities | Appropriate and proportionate risk-management measures; no general TLPT duty equivalent to DORA’s |
Do not decide NIS2 scope from headcount alone
The usual starting point is whether the organisation is a type listed in Annex I or II and qualifies as a medium-sized enterprise or exceeds that size. The assessment can also depend on turnover, balance-sheet total, ownership and linked enterprises. Some categories and nationally identified entities are covered regardless of the ordinary size rule. A quick “50 employees or €10 million” test is useful for orientation, but it is not a reliable final decision.
Can both apply?
Yes, but the answer must be mapped to the specific legal entity and obligation. For financial entities covered by both regimes, DORA is treated as a sector-specific Union act for the corresponding NIS2 areas. Its rules apply instead for ICT risk management, incident management and reporting, resilience testing, information sharing and ICT third-party risk. This is not a blanket exemption from every NIS2-related question. Another company in the same group may remain directly subject to NIS2.
What remains of NIS2 when DORA is the sector-specific act
For a financial entity covered by both regimes, the corresponding DORA rules apply instead of the NIS2 rules in the areas listed above. This does not remove every NIS2-related national step or take every company in the group out of NIS2.
- Identification and registration. DORA itself links this sector-specific treatment to financial entities identified as essential or important under national NIS2 rules. Member States maintain the relevant lists or registers, so the national identification and information process must still be checked.
- The CSIRT reporting route. For the sector-specific reporting rules to apply instead of NIS2, the relevant CSIRT, competent authority or single point of contact must have immediate access to incident notifications. DORA also allows a Member State to require some or all financial entities to send the same notification and reports to a competent authority or CSIRT. The route must therefore be confirmed nationally before an incident occurs.
- Other companies in the group. An IT subsidiary, service company or non-financial business may remain directly subject to NIS2 even when the bank or insurer follows DORA. Each legal entity needs its own scope decision.
- Areas not replaced by DORA. The substitution concerns the corresponding entity-level rules. The wider NIS2 framework, including national cybersecurity arrangements and CSIRT functions, continues to include the financial sectors, and other national duties may still need to be checked.
How lex specialis works between DORA and NIS2 →
A useful first assessment
- Check the legal entityIdentify the company, licence, Member State and group relationships.
- Check the activityMatch the actual service or activity to DORA Article 2 and the NIS2 sector lists.
- Check size and exceptionsUse the complete enterprise data and consider special categories and national designation.
- Separate the groundsSeparate direct legal duties, customer-contract requirements and voluntary standards.
- Choose one owner and one evidence mapAvoid two disconnected compliance projects for the same systems and controls.
Incident reporting: similar stages, different clocks
The exact classification and recipient must be confirmed before an incident occurs. The core statutory sequence is:
| Regime | Initial stage | Next report | Final report |
|---|---|---|---|
| NIS2 | Early warning within 24 hours after becoming aware of a significant incident | Incident notification within 72 hours after awareness | Within one month after the incident notification |
| DORA | Within 4 hours after classification as major and no later than 24 hours after awareness | Intermediate report within 72 hours after the initial notification | Within one month after the intermediate report or its latest update |
A common example: an ICT provider serving a bank
The bank is responsible for its DORA obligations. Its ICT contract must therefore contain the required provisions, and the provider must be able to support information requests, incident handling, audit rights, continuity and exit arrangements as agreed. The provider is not automatically subject to the whole of DORA merely because it has a bank as a customer. Separately, the provider may fall directly within NIS2 because of its own activity, size or designation.
What should you do first?
Do not start by writing one policy “for DORA and NIS2”. Start with a short applicability map covering the legal entities, services, licences, size data, customers and existing controls. That shows which duties are direct, which arrive through contracts and which evidence can be reused.
This article provides general information, not legal advice. Applicability depends on the specific entity, activity, licence, size, group structure and national implementation.