Comparison guide · EU regulation

NIS2 vs DORA: which one applies to you, which one prevails, and how to comply with both

NIS2 is the EU-wide cybersecurity directive for essential and important entities in 18 sectors; DORA is the regulation that governs ICT risk in the financial sector. Where both could apply, DORA prevails as lex specialis. Groups with financial and non-financial companies, and ICT providers serving banks, usually end up under both — and are best served by one control set built on the stricter requirement.

Start here

Which regulation applies to you?

Five situations that cover most EU organisations. Find yours; the rest of the page explains the consequences.

A bank, insurer, investment firm or payment institution

DORA

DORA is lex specialis for financial entities: where it regulates ICT risk, incident reporting, resilience testing and third-party risk, it applies instead of NIS2 (NIS2 Art. 4; DORA Art. 1(2)). NIS2 remains relevant only for anything DORA does not cover.

An ICT provider serving financial entities (cloud, SaaS, data centre, managed services)

DORA by contract — and possibly NIS2 directly

Your financial customers must impose DORA's contractual requirements on you (Art. 30) and may only use you if you meet them. If you are also a digital-infrastructure or ICT-service-management entity under NIS2 Annex I, you are directly in scope of NIS2 as well.

A critical ICT third-party provider designated by the ESAs

DORA oversight framework

Designated CTPPs fall under direct oversight by the European Supervisory Authorities (Arts. 31–44), with a lead overseer, information requests and recommendations. This is on top of NIS2 obligations if they apply.

An energy, transport, health, water, manufacturing or public-sector entity

NIS2

You are an essential or important entity under NIS2 Annex I or II. DORA does not apply unless a group company is a financial entity, in which case that company follows DORA and the rest follow NIS2.

A group with both financial and non-financial subsidiaries

Both, by entity

Each legal entity follows the regime that applies to it. The efficient answer is one group-wide control set, built on the stricter requirement wherever the two overlap, with entity-specific reporting on top.

Not sure which case you are? The regulatory assessment maps NIS2, DORA, ENS and ISO 27001 to your sector, size and customers.

Side by side

NIS2 vs DORA: nine differences that change how you organise compliance

NIS2DORAWhat it means for a group
Legal instrumentDirective (EU) 2022/2555 — transposed into national law, with national variationsRegulation (EU) 2022/2554 — directly applicable, identical across the EUDORA is uniform; NIS2 obligations, deadlines and penalties differ by member state.
Application date17 October 2024 (transposition deadline; several states, including Spain, are late)17 January 2025DORA is enforceable now everywhere; NIS2 enforcement depends on each national law.
Who is in scopeEssential and important entities in 18 sectors, generally 50+ staff or €10M+ turnover, plus criticality exceptions20 types of financial entity, plus ICT third-party providers via contract and CTPPs via oversightMap every legal entity; the same group can have both.
SupervisorNational competent authority and CSIRT per stateFinancial supervisors (ECB/NCAs, EBA, EIOPA, ESMA) and a lead overseer for CTPPsTwo different regulators, two different reporting channels.
Incident reportingEarly warning 24 h, notification 72 h, final report 1 month, to the CSIRT or authorityInitial notification 4 h after classification / 24 h after awareness, intermediate 72 h, final 1 month, to the financial supervisorOne classification process, two clocks and two templates.
Resilience testingNo prescriptive programme; measures must be 'appropriate and proportionate'Annual testing programme for all entities, TLPT every 3 years for designated onesBuild the DORA testing programme and reuse its evidence for NIS2.
Third partiesSupply-chain security as one of ten Art. 21 measuresFull ICT third-party risk framework: register of information, contract clauses, exit strategies, concentration riskRun the DORA register group-wide; it satisfies NIS2 supply-chain evidence.
Management bodyMust approve and oversee measures and attend training; personal liabilityDefines, approves and oversees the ICT risk framework; personal liabilityOne governance model, one training record, two board resolutions.
PenaltiesUp to €10M or 2% of worldwide turnover (essential); €7M or 1.4% (important); set by national lawSet by member states; for CTPPs, periodic penalties up to 1% of average daily worldwide turnoverNeither is symbolic; DORA adds oversight measures for providers.

Sources: Directive (EU) 2022/2555 · Regulation (EU) 2022/2554. Incident deadlines under DORA follow the RTS on major incident reporting.

The efficient answer

One control set for both regimes

Running NIS2 and DORA as two projects doubles documentation and splits ownership. The model that works: build each domain once, on the stricter requirement, and add the regulation-specific reporting on top.

Governance

One risk framework approved by each management body, one training curriculum for directors, one committee with entity-level minutes.

Risk management

A single risk register with an entity and regulation column, so the same risk shows its NIS2 and DORA treatment side by side.

Incident management

One detection and classification playbook with two reporting workflows: DORA's 4/24-72 h-1 month clock and NIS2's 24-72 h-1 month clock.

Third-party risk

The DORA register of information as the group standard. It is stricter than NIS2 and its evidence covers both.

Resilience testing

DORA's annual programme, extended to non-financial entities where the same systems are shared. TLPT where designated.

Evidence repository

Requirement → control → procedure → record, tagged by regulation, so the same artefact answers two supervisors.

NIS2 vs DORA: frequently asked questions

Does DORA replace NIS2 for financial entities?
For the matters DORA regulates — ICT risk management, incident reporting, resilience testing and ICT third-party risk — yes: DORA applies as lex specialis and NIS2 does not (NIS2 Article 4, DORA Article 1(2)). Financial entities remain subject to NIS2 for anything outside DORA's scope, and to national NIS2 provisions on supervision that do not conflict with DORA.
We are a SaaS provider with banks as customers. Are we regulated by DORA?
Not directly, unless you are designated as a critical ICT third-party provider. But your bank customers are obliged to impose DORA's contractual requirements on you (Article 30) — audit rights, incident cooperation, exit plans, subcontracting controls — and to include you in their register of information. In practice, you comply with DORA through your contracts. If you also qualify as a digital-infrastructure or ICT-service-management entity, NIS2 applies to you directly. Our third-party risk management service covers both sides.
Which incident reporting deadlines are stricter?
DORA's. It requires an initial notification within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours and a final report within one month. NIS2 requires an early warning within 24 hours, a notification within 72 hours and a final report within one month. A group should design one classification process that can feed both clocks.
Can one set of controls satisfy both regulations?
Yes, if you build it on the stricter requirement wherever the two overlap — usually DORA's — and add entity-specific reporting on top. The common core is governance, risk management, incident handling, business continuity and third-party risk. Where a company is only under NIS2, DORA-grade evidence is more than enough. We explain the four-framework picture, including ISO 27001 and Spain's ENS, in ENS vs ISO 27001 vs NIS2 vs DORA.
Does NIS2 require penetration testing like DORA's TLPT?
No. NIS2 requires 'appropriate and proportionate' measures and policies to assess their effectiveness, without a prescriptive programme. DORA requires every financial entity to run an annual ICT testing programme and designated entities to run threat-led penetration testing every three years under the TIBER-EU framework. Our Red Team service covers TLPT, and we explain the regime in TLPT under DORA.
NIS2 is a directive: does that matter for a multinational group?
It matters a lot. Each member state transposes NIS2 into its own law, so registration duties, competent authorities, deadlines and penalties vary — and some states, including Spain, are late. DORA is a regulation and applies identically everywhere. A group should track NIS2 country by country and treat DORA as a single baseline. See what the CJEU referral changes for Spain.
Where does Hard2bit fit in?
We run NIS2 consulting and DORA consulting from a single Compliance and GRC practice, so a group gets one control set and one evidence repository rather than two parallel projects. We operate certified to ISO 27001 and Spain's ENS at the HIGH category, and our managed SOC and incident response teams provide the operational evidence both regimes ask for.

Map NIS2 and DORA to your group in one assessment

We identify which regime applies to each entity, where the overlap is and what a single control set looks like for you.

Last reviewed: . This page is general guidance, not legal advice; national NIS2 transposition may add or modify obligations.