NIS2 and DORA are both EU cybersecurity laws that apply from early 2025, but they don’t compete — they layer. NIS2 is a broad directive covering 18 sectors; DORA is a financial-sector regulation for digital operational resilience. For financial entities, DORA is lex specialis: where the two overlap, DORA’s rules take precedence. So the real question isn’t “NIS2 or DORA?” — it’s “which one governs my ICT obligations, and could I be caught by both?”
NIS2 vs DORA at a glance
- NIS2: Directive (EU) 2022/2555 — broad, 18 sectors, transposed into national law
- DORA: Regulation (EU) 2022/2554 — financial sector + its ICT providers, directly applicable
- Applies from: NIS2 (national rules) 18 Oct 2024 · DORA 17 January 2025
- Relationship: DORA is lex specialis — it prevails over NIS2 for financial entities where they overlap
What is DORA?
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is the EU’s rulebook for the digital operational resilience of the financial sector. It applies from 17 January 2025 to banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and more — and, critically, to the ICT third-party providers that serve them. Because it is a regulation, it applies directly and uniformly across the EU with no national transposition. It is built on five pillars:
- ICT risk management
- ICT-related incident reporting
- Digital operational resilience testing (including threat-led penetration testing)
- ICT third-party risk management and oversight of critical providers
- Information and intelligence sharing
NIS2, by contrast, is the horizontal cybersecurity baseline across 18 sectors — for the full picture see our complete guide to NIS2.
NIS2 vs DORA: the differences
| NIS2 | DORA | |
|---|---|---|
| Legal instrument | Directive — transposed into each member state’s law | Regulation — directly applicable, uniform EU-wide |
| Who it covers | 18 sectors; essential & important entities | Financial entities + their ICT third-party providers |
| Focus | Broad cyber-risk management for critical services | Operational resilience of financial ICT (incl. resilience testing) |
| Third parties | Supply-chain security duty (Art. 21) | Full ICT third-party regime; EU oversight of critical providers |
| Penalties | Up to €10M / 2% (essential); €7M / 1.4% (important) | Set by national authorities; critical ICT providers face EU penalties up to 1% of average daily worldwide turnover |
Which one applies to you?
- A financial entity (bank, insurer, investment/payment firm…): DORA governs your ICT operational resilience. As lex specialis, it displaces NIS2’s equivalent risk-management and incident-reporting provisions for you.
- An ICT provider serving the financial sector: you may be pulled into DORA’s third-party regime — and, if you’re also in a NIS2 sector like digital infrastructure or ICT service management, into NIS2 in your own right.
- Everyone else in the 18 NIS2 sectors: NIS2 is your regime. Check whether NIS2 applies to you.
Do I need to comply with both?
Often, in practice, yes — at group level. A banking group is primarily under DORA, but a mixed conglomerate may have entities that fall under NIS2 for non-financial activities. And an ICT vendor can face DORA’s third-party obligations (imposed contractually by its financial clients) while being a NIS2 entity itself. The lex specialis rule prevents you from having to satisfy two overlapping ICT-risk regimes at once — but it doesn’t stop both from touching a large organisation.
The good news: the underlying discipline is the same. Both demand continuous ICT risk management, incident reporting, third-party assurance, and demonstrable governance. Build that once, and you evidence it against whichever regime applies.
Quantify it once, map it to both
Whether you answer to NIS2, DORA, or both, the starting point is the same: an objective, board-ready read of your actual exposure. Cyber Risk Quantification maps your external attack surface, translates it into an Expected Annual Loss in euros, and shows your regulatory liability under the applicable frameworks. See how the Nisura framework models NIS2, GDPR and DORA applicability, or run a free simulation to see your projected exposure in minutes.
Sources & official references
- Regulation (EU) 2022/2554 (DORA) — applies from 17 January 2025; five pillars and the critical-ICT-third-party oversight framework.
- Directive (EU) 2022/2555 (NIS2), Article 4 — sector-specific Union acts (such as DORA) apply instead of NIS2 where their requirements are at least equivalent (lex specialis).
- European Supervisory Authorities (EBA, ESMA, EIOPA) — DORA oversight of critical ICT third-party providers.
General information, not legal advice. Whether DORA or NIS2 governs a specific entity depends on its activities and national implementing law — confirm with qualified counsel.