NIS2 raises cybersecurity requirements across many sectors; DORA does the same specifically for EU financial entities and their technology providers. They cover similar ground, which is why the overlap question comes up constantly - and the answer is more settled than most people expect.
The legal machinery differs
- NIS2 is a directive. It takes effect through each member state's national implementing law, so scope details, supervision and penalties vary by country. If you operate in several member states, you face several implementations.
- DORA is a regulation. It applies directly and uniformly across the EU without national transposition, supplemented by detailed technical standards.
That distinction has practical consequences: a multi-country NIS2 programme needs per-jurisdiction legal review, whereas DORA gives you one rulebook.
Scope
- NIS2 - essential and important entities across sectors including energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing, digital providers and research. Generally captured by sector plus size, with some entities in scope regardless of size.
- DORA - financial entities: banks, payment and e-money institutions, investment firms, insurers, asset managers, crypto-asset service providers, trading venues, and more. Critically, it also reaches ICT third-party service providers serving them, with the most systemically important designated as critical and supervised directly.
Which wins when both could apply?
For financial entities, DORA is generally treated as the more specialised regime - the lex specialis - taking precedence for the ICT risk matters it covers. In practice a bank works to DORA for ICT risk management, incident reporting, resilience testing and third-party oversight, rather than duplicating the same work under NIS2.
Do not assume that resolves everything. Confirm the position under each member state's NIS2 implementation for your specific entity type - national laws vary, and group structures can put different entities under different regimes.
Map both from one control set
GRC Copilot assesses you against DORA and NIS2 together, reusing your ISO 27001 and ISO 22301 evidence and showing the genuine delta for each regime.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Where the requirements diverge
Incident reporting
Both use staged reporting, but the triggers and timings differ. NIS2 sets an early warning within 24 hours, notification within 72 hours, and a final report within a month. DORA has its own classification criteria and staged reporting for major ICT-related incidents. If you are subject to both across a group, do not assume one process satisfies the other - align the classification logic deliberately.
Third-party oversight
This is DORA's most distinctive requirement. It demands a structured register of information covering all ICT contractual arrangements, specific contractual clauses, concentration risk analysis, and credible exit strategies for critical providers. NIS2 requires supply chain security but without that level of prescription.
Resilience testing
DORA mandates a testing programme, including threat-led penetration testing for significant entities. NIS2 expects testing and effectiveness assessment without prescribing that specific methodology.
Accountability
Both push responsibility upward. NIS2 requires management bodies to approve and oversee risk measures and to be trained, with national implementations attaching consequences. DORA places ICT risk accountability squarely on the management body.
What to do if you might be subject to either
- Determine scope per legal entity, not per group - and per member state for NIS2.
- Check whether you are captured as a supplier. Non-financial ICT providers frequently land inside DORA through their financial customers.
- Build one control library and map both regimes onto it.
- Start the ICT third-party register early if DORA applies - it is the longest lead-time item by some margin.
- Rehearse the reporting clocks with a named, pre-authorised decision-maker. Twenty-four hours cannot be met by committee.
- Reuse ISO 27001 and ISO 22301 evidence - both regimes map heavily onto them.
Frequently asked questions
We are a SaaS vendor, not a bank. Which applies?
Possibly both, by different routes: NIS2 if you fall within a covered sector such as digital providers or ICT service management, and DORA indirectly through contractual obligations from financial customers - or directly if designated critical.
Does complying with DORA satisfy NIS2?
For financial entities, DORA generally takes precedence for the ICT matters it covers. It is not a blanket exemption - verify against the applicable national implementation.
Which has tougher incident reporting?
Both are demanding. NIS2's 24-hour early warning is the tightest single clock; DORA's classification criteria are more prescriptive about what counts as major.
Does ISO 27001 cover either?
It covers much of the underlying substance and is a strong foundation, but neither regime is satisfied by certification alone. The gaps are usually reporting timelines, third-party registers and exit planning.
Key takeaways
- NIS2 is a directive with national variation; DORA is a directly applicable regulation.
- For financial entities DORA generally takes precedence as the specialised regime.
- DORA's register of information and exit strategies have no NIS2 equivalent.
- Scope is per entity and per member state - check, do not assume.