Article · published 13 September 2026

DORA or NIS2: which applies to your organisation?

Both deal with cybersecurity, resilience, incidents and suppliers. The practical difference is who they cover, how detailed the obligations are and which authority supervises them.

The short answer

NIS2

A broad cybersecurity framework for entities in 18 sectors covered by Annexes I and II. It operates through the national law of each Member State.

DORA

A directly applicable and more detailed EU regime for listed financial entities. It requires specific provisions in contracts for ICT services and provides an oversight framework for providers designated as critical.

If you are a financial entity listed in DORA, start with DORA. If you operate in a sector covered by NIS2, assess NIS2 and the applicable national law. An ICT provider serving a financial institution may assume DORA-related requirements through its contracts without becoming subject to every DORA obligation.

Why they are easy to confuse

Both regimes require management responsibility, risk management, incident handling, supply-chain controls and evidence that the measures work. DORA is more prescriptive for financial services: it adds a detailed ICT risk framework, a standardised register of ICT arrangements, specific contractual provisions, resilience testing and an EU oversight framework for critical ICT third-party providers.

The practical differences

QuestionDORANIS2
Legal formEU regulation; directly applicableEU directive; implemented through national law
Who it applies toThe financial entities listed in Article 2Covered entity types in 18 sectors, subject to size rules and exceptions
ICT providersContractual requirements apply through financial clients; designated critical providers face EU oversightCloud, data-centre, managed service, managed security and other covered providers may be directly in scope when the legal criteria are met
Main emphasisDigital operational resilience of financial services and detailed ICT third-party riskA broad cybersecurity baseline across critical and important parts of the economy
SupervisionThe competent financial supervisory authority for the type of entityThe competent authority and CSIRT arrangements under national law
TestingA resilience-testing programme; TLPT for selected financial entitiesAppropriate and proportionate risk-management measures; no general TLPT duty equivalent to DORA’s

Do not decide NIS2 scope from headcount alone

The usual starting point is whether the organisation is a type listed in Annex I or II and qualifies as a medium-sized enterprise or exceeds that size. The assessment can also depend on turnover, balance-sheet total, ownership and linked enterprises. Some categories and nationally identified entities are covered regardless of the ordinary size rule. A quick “50 employees or €10 million” test is useful for orientation, but it is not a reliable final decision.

Can both apply?

Yes, but the answer must be mapped to the specific legal entity and obligation. For financial entities covered by both regimes, DORA is treated as a sector-specific Union act for the corresponding NIS2 areas. Its rules apply instead for ICT risk management, incident management and reporting, resilience testing, information sharing and ICT third-party risk. This is not a blanket exemption from every NIS2-related question. Another company in the same group may remain directly subject to NIS2.

What remains of NIS2 when DORA is the sector-specific act

For a financial entity covered by both regimes, the corresponding DORA rules apply instead of the NIS2 rules in the areas listed above. This does not remove every NIS2-related national step or take every company in the group out of NIS2.

  • Identification and registration. DORA itself links this sector-specific treatment to financial entities identified as essential or important under national NIS2 rules. Member States maintain the relevant lists or registers, so the national identification and information process must still be checked.
  • The CSIRT reporting route. For the sector-specific reporting rules to apply instead of NIS2, the relevant CSIRT, competent authority or single point of contact must have immediate access to incident notifications. DORA also allows a Member State to require some or all financial entities to send the same notification and reports to a competent authority or CSIRT. The route must therefore be confirmed nationally before an incident occurs.
  • Other companies in the group. An IT subsidiary, service company or non-financial business may remain directly subject to NIS2 even when the bank or insurer follows DORA. Each legal entity needs its own scope decision.
  • Areas not replaced by DORA. The substitution concerns the corresponding entity-level rules. The wider NIS2 framework, including national cybersecurity arrangements and CSIRT functions, continues to include the financial sectors, and other national duties may still need to be checked.
The applicability map should therefore show, for each legal entity, which obligations are governed by DORA, which NIS2 or national steps remain, and who owns them. “Start with DORA” must not be read as “NIS2 no longer matters”.

How lex specialis works between DORA and NIS2 →

A useful first assessment

  1. Check the legal entityIdentify the company, licence, Member State and group relationships.
  2. Check the activityMatch the actual service or activity to DORA Article 2 and the NIS2 sector lists.
  3. Check size and exceptionsUse the complete enterprise data and consider special categories and national designation.
  4. Separate the groundsSeparate direct legal duties, customer-contract requirements and voluntary standards.
  5. Choose one owner and one evidence mapAvoid two disconnected compliance projects for the same systems and controls.

Incident reporting: similar stages, different clocks

The exact classification and recipient must be confirmed before an incident occurs. The core statutory sequence is:

RegimeInitial stageNext reportFinal report
NIS2Early warning within 24 hours after becoming aware of a significant incidentIncident notification within 72 hours after awarenessWithin one month after the incident notification
DORAWithin 4 hours after classification as major and no later than 24 hours after awarenessIntermediate report within 72 hours after the initial notificationWithin one month after the intermediate report or its latest update
These are not interchangeable timers. DORA uses its own classification of a major ICT-related incident and detailed reporting rules. NIS2 is applied through the relevant national reporting channel.

A common example: an ICT provider serving a bank

The bank is responsible for its DORA obligations. Its ICT contract must therefore contain the required provisions, and the provider must be able to support information requests, incident handling, audit rights, continuity and exit arrangements as agreed. The provider is not automatically subject to the whole of DORA merely because it has a bank as a customer. Separately, the provider may fall directly within NIS2 because of its own activity, size or designation.

What should you do first?

Do not start by writing one policy “for DORA and NIS2”. Start with a short applicability map covering the legal entities, services, licences, size data, customers and existing controls. That shows which duties are direct, which arrive through contracts and which evidence can be reused.

This article provides general information, not legal advice. Applicability depends on the specific entity, activity, licence, size, group structure and national implementation.

Primary sources

All articles →