Comparison
NIS2 vs DORA — which cybersecurity regime governs you?
Published Reviewed
Both laws regulate cyber resilience, both arrived within months of each other, and they deliberately do not overlap: DORA is the special law for financial entities, NIS2 the general law for essential and important sectors. The practical question is rarely "which is stricter" — it is which one applies to which legal entity in your group, and whose clocks your incident process must beat.
Side by side
How they combine
The regimes are wired to not double-charge: where DORA covers a financial entity’s ICT risk and incident reporting, it applies instead of the NIS2 equivalents. The complexity lives in groups: a fintech with a logistics subsidiary can owe DORA on one entity and NIS2 on the other — two supervisors, two incident clocks, one security organisation. Map it per legal entity, not per group.
A quick self-check
Are you ready?
- Could you name, per legal entity, which of the two regimes applies — in writing?
- If one incident hit entities under both regimes, could you serve both reporting clocks at once?
- Does your supplier register satisfy DORA’s register of information where it must — not just NIS2’s contract terms?