How lex specialis works between DORA and NIS2
Lex specialis is not a switch that turns NIS2 off. It resolves an overlap: where two valid rules govern the same entity and the same subject, the more specific rule displaces the general one only for that overlapping part.
The rule in one sentence
Where the rule comes from
The relationship is written expressly into both legal acts. It does not depend on an analogy or a general preference for financial legislation.
- NIS2 Article 4. Where a sector-specific Union act requires cybersecurity risk-management measures or significant-incident reporting that are at least equivalent in effect, the corresponding NIS2 provisions do not apply. This includes the related supervision and enforcement rules in Chapter VII.
- DORA Article 1(2). For financial entities identified as essential or important under national rules transposing NIS2 Article 3, DORA is deemed a sector-specific Union act for the purposes of NIS2 Article 4.
- The equivalence test. Risk measures must be at least equivalent to NIS2 Article 21(1) and (2). Incident reporting must be at least equivalent to Article 23(1) to (6), and the relevant CSIRT, competent authority or single point of contact must have immediate access to the notifications.
Apply it on three axes
- The same legal entityThe rule concerns a financial entity listed in DORA Article 2 that is also essential or important under the applicable national NIS2 rules. It does not automatically extend to an IT subsidiary, service company or cloud provider simply because it serves that financial entity.
- The same subjectThe overlap must concern the same obligation. The Commission identifies ICT risk management, ICT-incident management and reporting, digital operational resilience testing, information-sharing arrangements and ICT third-party risk as the corresponding DORA areas.
- Equivalent effectThe sector-specific requirements must meet the test in NIS2 Article 4. For DORA, the EU legislature and the Commission guidance have already established this relationship for covered financial entities.
What the financial entity follows
| Subject | DORA route | What is not duplicated under NIS2 |
|---|---|---|
| ICT risk management | Chapter II, Articles 5–16 and the applicable technical standards | A separate Article 21 programme for the same systems and controls |
| ICT incidents | Chapter III, Articles 17–23 and the applicable reporting standards | A second independent NIS2 reporting programme for the same major ICT-related incident |
| Resilience testing | Chapter IV, Articles 24–27, including TLPT for selected entities | A separate general NIS2 testing regime for the same scope |
| ICT third-party risk | Chapter V, Articles 28–44, the register of information and contractual provisions | A separate NIS2 supply-chain file for the same ICT arrangements |
| Information sharing | DORA Article 45 | A parallel scheme merely because NIS2 also addresses information sharing |
Supervision follows the specific duties
For the DORA areas that replace the corresponding NIS2 rules, the primary supervisory relationship is with the competent financial supervisory authority for the entity and its licence. In Bulgaria this will commonly involve the Bulgarian National Bank or the Financial Supervision Commission, depending on the entity. The corresponding NIS2 supervision and enforcement rules do not create a second full audit of the same duties.
Incident reporting still needs an agreed route
Equivalence for incident reporting requires the relevant NIS2 CSIRT, competent authority or single point of contact to have immediate access to the DORA notification. The Commission describes forwarding, direct access or a single entry point as possible mechanisms. DORA also allows a Member State to require some or all financial entities to submit the same notification and reports to a competent authority or CSIRT. Confirm the national route before an incident occurs rather than running two disconnected playbooks.
What lex specialis does not remove
- Identification and information needed for a national NIS2 list or register, where national law requires it.
- The separate NIS2 status of another company in the group or of an ICT provider based on its own activity, size or designation.
- The national cybersecurity strategy, CSIRT functions and cyber-crisis arrangements that continue to cover the financial sectors.
- The need to check duties outside the provisions that DORA replaces.
- Proportionality and the simplified ICT risk-management framework under DORA Article 16 for the entities listed there; the specific regime remains DORA, but its depth may differ.
A practical working method
- Start with the legal entityRecord the entity, licence, Member State and group relationships.
- Confirm both scope testsCheck DORA Article 2 and the entity’s status under the applicable national NIS2 law.
- Build an obligation mapFor each subject, record: DORA replaces; NIS2 or national law remains; contractual only; or not applicable.
- Use one control and evidence mapReuse the same systems, controls and records instead of creating two artificial compliance programmes.
- Fix the incident route in advanceName the classifier, the first recipient and the mechanism that gives the national cyber authority the access required by law.
- Repeat for every group entityDo not inherit the bank’s answer for its subsidiaries, service companies or providers.
Two common mistakes
“We are under DORA, so NIS2 and national cybersecurity law do not apply.”
For the overlapping ICT duties, follow DORA. Then identify the NIS2 or national steps that remain.
“Our provider is under DORA because it serves us.”
The financial entity remains responsible under DORA. The provider assumes contractual commitments, while its own NIS2 status and any critical-provider oversight are assessed separately.
The phrase to keep
First compare DORA and NIS2 → · DORA →
This article provides general information, not legal advice. The result for a specific organisation depends on the entity, licence, activity, group structure and applicable national law.