Tech & productVerified by Kopik: Official sources reviewed and answers tested by Kopik

NIS2 and DORA: which rules apply to banks and financial entities

Credit institutions and financial market infrastructures appear in NIS2's scope, yet DORA governs their ICT risk management and incident reporting. This page explains how the two texts fit together and how equivalence with other sector-specific acts is assessed.

Ask your question

Free account required

Each question stands alone Β· 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

DORA as a sector-specific act

The NIS2 recitals state that Regulation (EU) 2022/2554 (DORA) is a sector-specific Union legal act in relation to NIS2 for financial entities. DORA's provisions on ICT risk management, incident reporting, resilience testing and ICT third-party risk apply instead of NIS2's.

Member States therefore should not apply NIS2's provisions on cybersecurity risk-management, reporting, supervision and enforcement to financial entities covered by DORA. NIS2 also does not apply to entities that Member States have exempted from DORA under Article 2(4) of that Regulation.

The equivalence test of Article 4

Article 4(1) provides that where a sector-specific Union act requires risk-management measures or incident notification that are at least equivalent in effect to NIS2, the corresponding NIS2 provisions, including supervision and enforcement in Chapter VII, do not apply.

According to the Commission guidelines, risk-management measures are equivalent where they are at least equivalent in effect to Article 21(1) and (2). Reporting requirements are equivalent where the sector act gives CSIRTs, competent authorities or single points of contact immediate access to notifications and the requirements are at least equivalent in effect to Article 23(1) to (6).

Frequently asked questions

Is the financial sector cut off from NIS2 cooperation?

No. Under DORA, the European Supervisory Authorities and financial competent authorities may participate in the activities of the NIS Cooperation Group and exchange information and cooperate with the NIS2 single points of contact and CSIRTs. Member States should continue to include the financial sector in their cybersecurity strategies.

Do NIS2 bodies learn about major ICT incidents at banks?

Yes. DORA competent authorities transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, competent authorities or single points of contact under NIS2.

How does NIS2 relate to the Critical Entities Resilience Directive?

The scopes have been largely aligned. Entities identified as critical under the CER Directive also become subject to NIS2's cybersecurity obligations, and the authorities under both directives must cooperate and exchange information regularly.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-nis2-cybersecurity
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-nis2-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.