DORA vs NIS2: Key Differences, Scope & Compliance Guide (2026)

DORA vs NIS2: Which EU Regulation Applies to Your Business

DORA vs NIS2 : A payments company in Frankfurt gets an email from its cloud provider’s legal team: “we now need to discuss both DORA and NIS2 obligations under our contract.” The compliance lead reads both acronyms, recognizes neither fully, and opens a browser tab. This happens more often than EU regulators probably intended. Two major cybersecurity laws entered into force within weeks of each other, both use the language of “digital resilience” and “incident reporting,” and both apply, in full, since January 2025 — which leaves a lot of companies asking a very reasonable question: which one is actually mine?

The short answer is that the Digital Operational Resilience Act (DORA) and the second Network and Information Security Directive (NIS2) are not competing options you choose between. They are two different EU instruments with different legal mechanics, different sector reach, and — for a meaningful slice of the market — an overlap that both regulations explicitly anticipated and tried to resolve. This guide walks through what each law actually covers, how to tell which one (or both) applies to your organization, where their requirements diverge in ways that matter operationally, and how dual-regulated firms are handling the overlap in practice in 2026.

DORA vs NIS2

DORA vs NIS2 in One Paragraph Each

DORA (Regulation (EU) 2022/2554) is a directly applicable EU regulation built specifically for the financial sector. It sets out detailed, testable obligations for ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing — and it applies the same way, on the same terms, in every Member State, without any national transposition step in between.

NIS2 (Directive (EU) 2022/2555) is a directive, meaning it sets EU-wide policy goals that each Member State then writes into its own national law. It covers a much wider population — 18 sectors and an estimated 160,000-plus organizations across the EU, from energy and healthcare to digital infrastructure and public administration — with ten minimum security measures and a three-stage incident reporting cascade.

Which One Applies to You? A Quick Decision Path

Before getting into the detail, most organizations can answer the “which law applies to me” question with two checks: are you a regulated financial entity, and are you operating in one of NIS2’s listed sectors. The flow below captures the logic regulators themselves use.

 Two edge cases catch people out. First, size matters for NIS2 but not for DORA — a five-person fintech startup is still fully in DORA’s scope the moment it holds a financial license, while NIS2 generally exempts micro and small entities outside a short list of automatic-inclusion categories (DNS providers, TLD registries, qualified trust service providers). Second, being “not directly regulated” doesn’t mean the obligations disappear — they often arrive contractually instead, passed down from a regulated customer.

Scope: Who Each Law Actually Covers

DORA vs NIS2 Comparison
Dimension DORA NIS2
Legal instrument Regulation — directly applicable, identical across the EU Directive — transposed into each Member State's national law
Sector reach Financial sector only: ~21 categories of financial entity 18 sectors: energy, transport, health, digital infrastructure, manufacturing, public administration, and more
Who's covered Banks, insurers, investment firms, payment/e-money institutions, crypto-asset service providers, and their critical ICT vendors "Essential" and "important" entities, split by Annex I / Annex II sector and by company size
Size threshold No general size exemption — applies regardless of headcount or turnover Medium/large entities (50+ staff or €10M+ turnover); a few categories are in scope regardless of size
Estimated population Roughly 22,000 financial entities and their critical ICT providers across the EU Approximately 160,000 organizations across the EU
In force since 17 January 2025 (full application, no transposition needed) 16 January 2023 (entry into force); national transposition deadline 17 October 2024

Legal Nature: Why “Regulation vs. Directive” Actually Matters

This distinction isn’t just legal trivia — it changes how the rules reach your organization. Because DORA is a regulation, its text is the law, word for word, in every Member State; a German bank and an Italian bank are reading the exact same Article 30 contract requirements. NIS2, as a directive, only sets minimum outcomes — each country then writes its own implementing statute (Germany’s NIS2UmsuCG, for example), and those national laws can add stricter requirements or interpret ambiguous provisions differently. A company operating in three EU countries under NIS2 may face three sets of national detail sitting on top of one shared directive.

✎  Practical consequence – If you’re checking NIS2 obligations, always confirm the current status of your specific country’s transposition law rather than relying on the directive text alone — several Member States were still finalizing amendments to their national NIS2 statutes well into 2026.

The Overlap: Lex Specialis and Article 1(2)

The EU anticipated that financial entities would otherwise be caught by both laws at once, so it built in an explicit fix. Article 1(2) of DORA states that, for financial entities within its scope, DORA is to be treated as sector-specific law relative to NIS2 — a legal principle known as lex specialis, meaning the more specific law prevails over the more general one where the two overlap. NIS2’s own recital 28 mirrors this, confirming that DORA should be considered the sector-specific EU act for financial entities.

In practice, this means a regulated bank, insurer, or investment firm does not run two parallel ICT risk and incident-reporting programmes. Where DORA has a rule, DORA’s rule applies, full stop — not NIS2’s version of the same rule. Germany made this explicit in its own NIS2 implementation act, stating outright that financial institutions fulfil their ICT risk management and incident-reporting duties exclusively under DORA.

✎  Lex specialis has limits – The carve-out only covers the areas DORA actually regulates — ICT risk management and ICT incident reporting. NIS2 obligations that sit outside DORA’s text (some governance and general cyber-hygiene expectations, for instance) can still apply to a financial entity, particularly if national transposition law says so explicitly. Full DORA compliance is estimated to satisfy roughly 80% of the equivalent NIS2 requirements — the remaining gap needs its own check against your national NIS2 statute.

Where the Overlap Actually Bites: ICT Vendors

The group that can’t simply pick one law is ICT third-party providers serving both financial and non-financial clients. A cloud provider hosting workloads for a bank and a hospital in the same country ends up navigating two separate frameworks for two separate customer relationships — DORA-driven contract clauses, audit rights, and incident-cooperation duties for the bank; NIS2-driven security measures and reporting timelines for the hospital. Nothing in either law merges those obligations into one; the vendor simply carries both.

  • If you sell to EU financial entities: expect Article 30 clauses in the contract — audit rights, incident cooperation, sub-outsourcing notification, and a documented exit plan — even if you’ve never heard your company described as “DORA-regulated.”
  • If you’re large or systemically important enough to be named a Critical ICT Third-Party Provider (CTPP), you move from indirect, contract-based obligations to direct EU-level supervision by a Lead Overseer.
  • If you serve clients in NIS2 sectors outside finance, check your own size and sector against Annex I/II — you may be directly in scope of NIS2 regardless of what your financial-sector contracts require.

 

Incident Reporting: The Clock Runs Differently

DORA vs NIS2 laws use a staged reporting model, but the clocks don’t match — which is the detail that trips up teams building a single, shared incident-response runbook.

DORA vs NIS2 Incident Reporting Timeline
Stage DORA Timeline NIS2 Timeline
Early warning / initial notification 4 hours from classification as "major" (24h outer limit from detection) 24 hours from becoming aware of a significant incident
Follow-up / intermediate report 72 hours from the initial notification 72 hours from becoming aware (detailed notification)
Final report 1 month from the last intermediate report 1 month from the initial notification

For dual-regulated firms, the practical fix most compliance teams land on is building one incident classification process calibrated to the tighter clock — DORA’s 4-hour window — and then mapping that same classification decision to whichever NIS2 report is also owed, rather than running two separate triage processes under time pressure.

Penalties: Different Ceilings, Different Enforcers

DORA vs NIS2 Penalties
Regulation Who Can Be Fined Maximum Exposure
DORA Financial entities Up to 10% of annual global turnover or €10M, whichever is larger (varies by Member State's national penalty regime)
DORA Designated Critical ICT Third-Party Providers Periodic penalty payments up to 1% of average daily worldwide turnover, per day, for up to 6 months (Article 35)
NIS2 Essential entities Up to €10 million or 2% of global annual turnover, whichever is higher
NIS2 Important entities Up to €7 million or 1.4% of global annual turnover, whichever is higher

✎  Supervision style differs too -DORA vs NIS2 financial entities are supervised by national financial regulators (and, for CTPPs, directly by an ESA Lead Overseer). NIS2 essential entities face proactive, ex-ante supervision — regulators can inspect before anything goes wrong — while NIS2 important entities are generally supervised reactively, ex-post, typically triggered by an incident or complaint.

A Compliance Approach for Dual-Regulated Firms

Financial entities that also pick up NIS2 exposure — directly through a non-exempt activity, or indirectly as an ICT vendor to other sectors — generally do better treating this as one integrated programme rather than two parallel ones. A practical sequence:

  • Build the core ICT risk framework around DORA first — it is the more prescriptive of the two and covers testing, incident classification, and third-party risk in more operational detail.
  • Run a gap assessment of your national NIS2 transposition law against what DORA already covers, focused specifically on governance and supply-chain provisions that sit outside DORA’s lex specialis carve-out.
  • Calibrate incident classification to DORA’s 4-hour clock, then map the same trigger to any NIS2 reporting duty that also applies.
  • Document the equivalence mapping — which DORA control satisfies which NIS2 requirement — so an auditor or supervisor doesn’t have to reconstruct it from scratch.
  • Re-check applicability annually: CTPP designations, national NIS2 amendments, and your own entity classification can all shift year to year.

DORA vs NIS2 & Resources

For anything that needs to be legally authoritative, go to the primary sources rather than a summary:

EUR-Lex — Full text of Regulation (EU) 2022/2554 (DORA) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554

EUR-Lex — Full text of Directive (EU) 2022/2555 (NIS2) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555

ENISA — NIS2 Directive overview and Member State transposition tracker — https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new

European Banking Authority (EBA) — Operational Resilience & DORA — https://www.eba.europa.eu/regulation-and-policy/operational-resilience

European Commission — NIS2 Directive policy page — https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

The Bottom Line

DORA vs NIS2 were never meant to be a choice — they’re two layers of the same EU push toward operational and cyber resilience, aimed at different (and partly overlapping) parts of the economy. If you’re a regulated financial entity, DORA is your primary framework, and lex specialis keeps you out of a duplicate NIS2 ICT risk and incident-reporting regime. If you sit in one of NIS2’s 18 sectors and clear the size threshold, NIS2 is yours, with obligations set largely by your own country’s transposition law. And if you’re an ICT vendor whose customer list spans both worlds, the honest answer is that both frameworks apply to you — not as competing requirements to reconcile, but as two separate customer relationships each carrying its own contractual and regulatory weight.

The organizations handling this cleanly in 2026 aren’t necessarily the ones with the most detailed dual-framework spreadsheet. They’re the ones who did the scoping exercise once, documented it clearly, and can show — to a bank’s procurement team or a national supervisor alike — exactly which law applies to which relationship, and why.

DORA vs NIS2 & Frequently Asked Questions

Q. Can a company be subject to both DORA and NIS2 at the same time?

Yes. This is common for ICT vendors that serve both financial and non-financial clients, and it can also apply to a financial entity if its national NIS2 transposition law extends obligations beyond what DORA’s lex specialis carve-out covers. In those cases, DORA governs ICT risk management and incident reporting, while NIS2 continues to apply to whatever it covers that DORA does not.

Mostly no, but not entirely. Article 1(2) of DORA removes NIS2’s ICT risk management and incident reporting rules for in-scope financial entities. It does not automatically remove every other NIS2-derived obligation that a national transposition law might still impose, so a light-touch check against your country’s specific statute is worth doing rather than assuming full exemption.

Neither is simply “stricter” — they’re built differently. DORA is more prescriptive and detailed within its narrower financial-sector scope, with specific testing regimes (including TLPT) and named contract clauses. NIS2 is broader in reach but leaves more implementation detail to national law and to each organization’s own risk-based judgment.

Indirectly, often yes. A non-EU cloud provider, software vendor, or data processor serving EU financial entities will be pulled into DORA’s Article 30 contract requirements by its customer, and could be designated a Critical ICT Third-Party Provider if its scale warrants it. The same logic applies under NIS2 for vendors serving other EU critical-sector clients.

It depends on two factors together: which Annex (I or II) your sector falls under, and whether your organization meets the medium or large size threshold (roughly 50+ staff/€10M turnover for medium, 250+ staff/€50M turnover for large). A handful of entity types — DNS providers, top-level domain registries, and qualified trust service providers among them — are in scope regardless of size.

What do you think?