Comparison

NIS2 vs DORA — which cybersecurity regime governs you?

Published Reviewed

Both laws regulate cyber resilience, both arrived within months of each other, and they deliberately do not overlap: DORA is the special law for financial entities, NIS2 the general law for essential and important sectors. The practical question is rarely "which is stricter" — it is which one applies to which legal entity in your group, and whose clocks your incident process must beat.

Side by side

Dimension NIS2 DORA
Who is in scope Essential and important entities across eighteen sectors (energy, transport, health, digital infrastructure, manufacturing and more), generally from 50 employees or €10 million turnover. More than twenty categories of financial entities — banks, insurers, investment firms, payment institutions, MiCA-authorised crypto firms — plus critical ICT providers to them.
Legal nature A directive: applies through national transpositions that differ in detail and timing, country by country. A regulation: one directly applicable text, identical in every member state since 17 January 2025.
Incident clocks Early warning within 24 hours, notification within 72 hours, final report within one month (Article 23). Initial, intermediate and final reports on windows set by technical standards — the initial notification due within hours of classifying a major incident.
Management accountability Management bodies approve measures, train, and can be personally liable; essential-entity managers risk temporary bans. The management body owns the ICT risk framework outright — approval, oversight and periodic review are its named duties.
Third parties Supply-chain security is one of the required Article 21 measures; suppliers feel it through contract terms. A register of information over every ICT contract, mandatory clauses, exit strategies, concentration analysis — and EU-level oversight of critical providers.
Testing Testing sits inside the general risk-management measures; no named methodology. Threat-led penetration testing at least every three years for designated entities, TIBER-EU aligned.
Fines At least €10 million or 2% of worldwide turnover (essential); €7 million or 1.4% (important). National sanction regimes for entities; periodic penalties up to 1% of average daily worldwide turnover for critical ICT providers.

How they combine

The regimes are wired to not double-charge: where DORA covers a financial entity’s ICT risk and incident reporting, it applies instead of the NIS2 equivalents. The complexity lives in groups: a fintech with a logistics subsidiary can owe DORA on one entity and NIS2 on the other — two supervisors, two incident clocks, one security organisation. Map it per legal entity, not per group.

A quick self-check

Are you ready?

  • Could you name, per legal entity, which of the two regimes applies — in writing?
  • If one incident hit entities under both regimes, could you serve both reporting clocks at once?
  • Does your supplier register satisfy DORA’s register of information where it must — not just NIS2’s contract terms?

This comparison is general information about public law and standards, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official sources and seek qualified advice where needed.