Comparison guide · EU regulation
NIS2 vs DORA: which one applies to you, which one prevails, and how to comply with both
NIS2 is the EU-wide cybersecurity directive for essential and important entities in 18 sectors; DORA is the regulation that governs ICT risk in the financial sector. Where both could apply, DORA prevails as lex specialis. Groups with financial and non-financial companies, and ICT providers serving banks, usually end up under both — and are best served by one control set built on the stricter requirement.
Start here
Which regulation applies to you?
Five situations that cover most EU organisations. Find yours; the rest of the page explains the consequences.
A bank, insurer, investment firm or payment institution
DORADORA is lex specialis for financial entities: where it regulates ICT risk, incident reporting, resilience testing and third-party risk, it applies instead of NIS2 (NIS2 Art. 4; DORA Art. 1(2)). NIS2 remains relevant only for anything DORA does not cover.
An ICT provider serving financial entities (cloud, SaaS, data centre, managed services)
DORA by contract — and possibly NIS2 directlyYour financial customers must impose DORA's contractual requirements on you (Art. 30) and may only use you if you meet them. If you are also a digital-infrastructure or ICT-service-management entity under NIS2 Annex I, you are directly in scope of NIS2 as well.
A critical ICT third-party provider designated by the ESAs
DORA oversight frameworkDesignated CTPPs fall under direct oversight by the European Supervisory Authorities (Arts. 31–44), with a lead overseer, information requests and recommendations. This is on top of NIS2 obligations if they apply.
An energy, transport, health, water, manufacturing or public-sector entity
NIS2You are an essential or important entity under NIS2 Annex I or II. DORA does not apply unless a group company is a financial entity, in which case that company follows DORA and the rest follow NIS2.
A group with both financial and non-financial subsidiaries
Both, by entityEach legal entity follows the regime that applies to it. The efficient answer is one group-wide control set, built on the stricter requirement wherever the two overlap, with entity-specific reporting on top.
Not sure which case you are? The regulatory assessment maps NIS2, DORA, ENS and ISO 27001 to your sector, size and customers.
Side by side
NIS2 vs DORA: nine differences that change how you organise compliance
| NIS2 | DORA | What it means for a group | |
|---|---|---|---|
| Legal instrument | Directive (EU) 2022/2555 — transposed into national law, with national variations | Regulation (EU) 2022/2554 — directly applicable, identical across the EU | DORA is uniform; NIS2 obligations, deadlines and penalties differ by member state. |
| Application date | 17 October 2024 (transposition deadline; several states, including Spain, are late) | 17 January 2025 | DORA is enforceable now everywhere; NIS2 enforcement depends on each national law. |
| Who is in scope | Essential and important entities in 18 sectors, generally 50+ staff or €10M+ turnover, plus criticality exceptions | 20 types of financial entity, plus ICT third-party providers via contract and CTPPs via oversight | Map every legal entity; the same group can have both. |
| Supervisor | National competent authority and CSIRT per state | Financial supervisors (ECB/NCAs, EBA, EIOPA, ESMA) and a lead overseer for CTPPs | Two different regulators, two different reporting channels. |
| Incident reporting | Early warning 24 h, notification 72 h, final report 1 month, to the CSIRT or authority | Initial notification 4 h after classification / 24 h after awareness, intermediate 72 h, final 1 month, to the financial supervisor | One classification process, two clocks and two templates. |
| Resilience testing | No prescriptive programme; measures must be 'appropriate and proportionate' | Annual testing programme for all entities, TLPT every 3 years for designated ones | Build the DORA testing programme and reuse its evidence for NIS2. |
| Third parties | Supply-chain security as one of ten Art. 21 measures | Full ICT third-party risk framework: register of information, contract clauses, exit strategies, concentration risk | Run the DORA register group-wide; it satisfies NIS2 supply-chain evidence. |
| Management body | Must approve and oversee measures and attend training; personal liability | Defines, approves and oversees the ICT risk framework; personal liability | One governance model, one training record, two board resolutions. |
| Penalties | Up to €10M or 2% of worldwide turnover (essential); €7M or 1.4% (important); set by national law | Set by member states; for CTPPs, periodic penalties up to 1% of average daily worldwide turnover | Neither is symbolic; DORA adds oversight measures for providers. |
Sources: Directive (EU) 2022/2555 · Regulation (EU) 2022/2554. Incident deadlines under DORA follow the RTS on major incident reporting.
The efficient answer
One control set for both regimes
Running NIS2 and DORA as two projects doubles documentation and splits ownership. The model that works: build each domain once, on the stricter requirement, and add the regulation-specific reporting on top.
Governance
One risk framework approved by each management body, one training curriculum for directors, one committee with entity-level minutes.
Risk management
A single risk register with an entity and regulation column, so the same risk shows its NIS2 and DORA treatment side by side.
Incident management
One detection and classification playbook with two reporting workflows: DORA's 4/24-72 h-1 month clock and NIS2's 24-72 h-1 month clock.
Third-party risk
The DORA register of information as the group standard. It is stricter than NIS2 and its evidence covers both.
Resilience testing
DORA's annual programme, extended to non-financial entities where the same systems are shared. TLPT where designated.
Evidence repository
Requirement → control → procedure → record, tagged by regulation, so the same artefact answers two supervisors.
NIS2 vs DORA: frequently asked questions
Does DORA replace NIS2 for financial entities?
We are a SaaS provider with banks as customers. Are we regulated by DORA?
Which incident reporting deadlines are stricter?
Can one set of controls satisfy both regulations?
Does NIS2 require penetration testing like DORA's TLPT?
NIS2 is a directive: does that matter for a multinational group?
Where does Hard2bit fit in?
Map NIS2 and DORA to your group in one assessment
We identify which regime applies to each entity, where the overlap is and what a single control set looks like for you.
Last reviewed: . This page is general guidance, not legal advice; national NIS2 transposition may add or modify obligations.