NIS2 and DORA: Key Differences and Overlaps

NIS2 is a broad sectoral directive. DORA is a regulation specific to the financial sector. Both reached the European market in the same period, and many organizations are asking which framework applies to them and how to manage both at once.
At the end of 2024 and beginning of 2025, the European market saw two major cybersecurity and digital resilience frameworks enter into force in a very short period: NIS2 in October 2024 and DORA in January 2025. For many organizations, especially in the financial and technology sectors, the immediate question was the same: does one apply to us, the other, or both? What happens when they coincide?
Both frameworks share terminology, general objectives and some similar technical requirements. But they have different legal natures, different scopes and a logic of interaction that has important practical consequences.
Different origins and legal natures
NIS2 is a European directive. Directives are not directly applicable in Member States, they require transposition into national law, allowing some margin of adaptation in thresholds, penalties and supervisory mechanisms. The concrete NIS2 requirements applying to a company are established by national transposition legislation, not by the directive text directly.
DORA is a European regulation. Regulations are directly applicable in all Member States from their entry into force date, without transposition, giving DORA greater legal uniformity across the EU. This distinction has a practical consequence: DORA is more predictable in its specific requirements than NIS2.
Scope: who falls under each framework
NIS2 has a broad sectoral scope, covering highly critical sectors (energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space) and important sectors (postal services, waste management, chemicals, food, critical product manufacturing, digital providers and research).
DORA has a sector-specific scope: the financial sector. It applies to credit institutions, investment firms, payment and electronic money institutions, crypto-asset service providers under MiCA, alternative investment fund managers, occupational pension funds, insurers, credit rating agencies, statutory auditors and, significantly, third-party ICT service providers deemed critical for financial entities.
The lex specialis principle: what happens when both apply
Article 4 of NIS2 establishes that when Member States apply the directive to entities already subject to equivalent sectoral regulation, they must take into account the provisions of that sectoral regulation to avoid duplication. In practice, financial entities subject to DORA are not required to additionally comply with NIS2 risk management and incident requirements separately, because DORA is considered the specific framework for that sector.
However, the exemption is not total in all respects. NIS2 remains relevant for financial entities in aspects DORA does not fully cover, such as certain national supervision obligations or notification to national CSIRTs in specific scenarios. The most complex scenario is that of ICT providers serving the financial sector: they may be classified as important or essential entities under NIS2 as digital service providers, and simultaneously fall under direct DORA supervision if designated as critical providers by the European Supervisory Authorities (ESAs). In that case, both frameworks run in parallel.
Key differences in requirements
Resilience testing. DORA establishes a digital operational resilience testing program with basic annual tests for all entities and advanced threat-led penetration tests (TLPT) for the most significant entities every three years. NIS2 requires security controls but does not specify as detailed a testing regime.
Third-party ICT management. DORA dedicates an entire chapter to third-party ICT risk management, with specific requirements on vendor contracts, and creates a direct supervisory regime for critical ICT providers. NIS2 also requires supply chain management, but with less detail.
Incident notification. Both require rapid notification of significant incidents, but recipients differ. DORA requires notification to the competent financial supervisory authority; NIS2 requires notification to the national CSIRT. A financial entity affected by an incident may need to notify both concurrently.
Governance and management accountability. Both establish senior management accountability, but DORA is more specific: it requires the management body to formally approve the ICT resilience strategy and receive regular training on ICT risks.
Overlaps: what both frameworks share
The overlaps are substantial and, well managed, allow building a single program that produces evidence valid for both frameworks: ICT risk management (a formal, documented process for identifying, assessing and treating cybersecurity risks); business continuity and disaster recovery; staff training and awareness; and incident management (detection, classification, containment, recovery and post-incident documentation).
Critical ICT providers: the category falling under both
The most complex case is technology companies providing services to the financial sector. Under NIS2, a cloud, data center or managed security service provider may be classified as an important or essential entity if they exceed size thresholds. Under DORA, that same provider may be designated a "critical third-party ICT provider" (CTPP) by the ESAs if a significant number of European financial entities depend on their services. CTPP designation means direct supervision by European authorities, including inspection visits and information requests.
How to build a program covering both NIS2 and DORA
Build the common controls once with sufficient specificity to satisfy both frameworks: a management-approved security policy, critical asset and system inventory, risk assessment with documented methodology, incident management process with both frameworks' notification timelines integrated, continuity plan with cyberattack scenarios, and staff training program. Then add the DORA-specific requirements on top: the resilience testing program with TLPT where applicable, specific ICT vendor contract documentation, ICT critical provider exit plans, and third-party information registers in the ESA-required format.
How CB Partners helps
The question generated by the NIS2-DORA intersection is legal, operational and strategic at the same time. We work with financial entities, ICT providers and companies operating in sectors covered by NIS2 through a structured four-phase process: scope analysis (determining precisely whether the organization falls within NIS2, DORA, both, or neither); differential gap analysis for each applicable framework; program design and implementation starting from the common layer; and evidence documentation and supervision preparation, including support through the first inspection.
Frequently Asked Questions
Does a bank complying with DORA also need to comply with NIS2?
Generally, financial entities subject to DORA are exempt from equivalent NIS2 requirements by application of the lex specialis principle. However, the exemption is not total in all respects, so verifying with up-to-date legal advice is recommended in each specific case.
What are TLPTs that DORA requires and NIS2 does not mention?
Threat-Led Penetration Testing simulates real attacks by sophisticated threat actors based on threat intelligence specific to the financial sector. DORA requires them for the most significant financial entities every three years; it has no direct equivalent in NIS2.
What is a critical ICT provider under DORA?
DORA creates the category of "critical third-party ICT service providers" (CTPPs), technology companies whose services a significant number of European financial entities depend on for critical functions. The designation is made by the European Supervisory Authorities.
Are incident notification timelines the same under NIS2 and DORA?
The timelines are similar but recipients differ. NIS2 requires notification to the national CSIRT; DORA requires notification to the competent financial supervisory authority. Both may be mandatory concurrently for a financial entity.
Does ISO 27001 cover the requirements of both NIS2 and DORA?
ISO 27001 is an excellent but insufficient foundation on its own. It provides the management system both frameworks assume exists, but does not specifically cover notification deadlines, DORA's TLPTs, or CTPP supervision requirements.
What is the main difference in penalties between NIS2 and DORA?
NIS2 sets a maximum of €10 million or 2% of global annual turnover for essential entities, and €7 million or 1.4% for important entities. DORA does not set a single fine ceiling in the regulation, leaving penalty graduation to Member States and competent supervisory authorities.
Ready to talk about your compliance roadmap?
Tell us which frameworks apply to you and we'll scope an engagement within days.
