NIS2 and DORA are both EU cybersecurity laws that apply from early 2025, but they don’t compete — they layer. NIS2 is a broad directive covering 18 sectors; DORA is a financial-sector regulation for digital operational resilience. For financial entities, DORA is lex specialis: where the two overlap, DORA’s rules take precedence. So the real question isn’t “NIS2 or DORA?” — it’s “which one governs my ICT obligations, and could I be caught by both?”

NIS2 vs DORA at a glance

  • NIS2: Directive (EU) 2022/2555 — broad, 18 sectors, transposed into national law
  • DORA: Regulation (EU) 2022/2554 — financial sector + its ICT providers, directly applicable
  • Applies from: NIS2 (national rules) 18 Oct 2024 · DORA 17 January 2025
  • Relationship: DORA is lex specialis — it prevails over NIS2 for financial entities where they overlap

What is DORA?

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is the EU’s rulebook for the digital operational resilience of the financial sector. It applies from 17 January 2025 to banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and more — and, critically, to the ICT third-party providers that serve them. Because it is a regulation, it applies directly and uniformly across the EU with no national transposition. It is built on five pillars:

NIS2, by contrast, is the horizontal cybersecurity baseline across 18 sectors — for the full picture see our complete guide to NIS2.

NIS2 vs DORA: the differences

NIS2DORA
Legal instrumentDirective — transposed into each member state’s lawRegulation — directly applicable, uniform EU-wide
Who it covers18 sectors; essential & important entitiesFinancial entities + their ICT third-party providers
FocusBroad cyber-risk management for critical servicesOperational resilience of financial ICT (incl. resilience testing)
Third partiesSupply-chain security duty (Art. 21)Full ICT third-party regime; EU oversight of critical providers
PenaltiesUp to €10M / 2% (essential); €7M / 1.4% (important)Set by national authorities; critical ICT providers face EU penalties up to 1% of average daily worldwide turnover

Which one applies to you?

Do I need to comply with both?

Often, in practice, yes — at group level. A banking group is primarily under DORA, but a mixed conglomerate may have entities that fall under NIS2 for non-financial activities. And an ICT vendor can face DORA’s third-party obligations (imposed contractually by its financial clients) while being a NIS2 entity itself. The lex specialis rule prevents you from having to satisfy two overlapping ICT-risk regimes at once — but it doesn’t stop both from touching a large organisation.

The good news: the underlying discipline is the same. Both demand continuous ICT risk management, incident reporting, third-party assurance, and demonstrable governance. Build that once, and you evidence it against whichever regime applies.

Quantify it once, map it to both

Whether you answer to NIS2, DORA, or both, the starting point is the same: an objective, board-ready read of your actual exposure. Cyber Risk Quantification maps your external attack surface, translates it into an Expected Annual Loss in euros, and shows your regulatory liability under the applicable frameworks. See how the Nisura framework models NIS2, GDPR and DORA applicability, or run a free simulation to see your projected exposure in minutes.

Sources & official references

General information, not legal advice. Whether DORA or NIS2 governs a specific entity depends on its activities and national implementing law — confirm with qualified counsel.