NIS2 and DORA: which rules apply to banks and financial entities
Credit institutions and financial market infrastructures appear in NIS2's scope, yet DORA governs their ICT risk management and incident reporting. This page explains how the two texts fit together and how equivalence with other sector-specific acts is assessed.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
DORA as a sector-specific act
The NIS2 recitals state that Regulation (EU) 2022/2554 (DORA) is a sector-specific Union legal act in relation to NIS2 for financial entities. DORA's provisions on ICT risk management, incident reporting, resilience testing and ICT third-party risk apply instead of NIS2's.
Member States therefore should not apply NIS2's provisions on cybersecurity risk-management, reporting, supervision and enforcement to financial entities covered by DORA. NIS2 also does not apply to entities that Member States have exempted from DORA under Article 2(4) of that Regulation.
The equivalence test of Article 4
Article 4(1) provides that where a sector-specific Union act requires risk-management measures or incident notification that are at least equivalent in effect to NIS2, the corresponding NIS2 provisions, including supervision and enforcement in Chapter VII, do not apply.
According to the Commission guidelines, risk-management measures are equivalent where they are at least equivalent in effect to Article 21(1) and (2). Reporting requirements are equivalent where the sector act gives CSIRTs, competent authorities or single points of contact immediate access to notifications and the requirements are at least equivalent in effect to Article 23(1) to (6).
Frequently asked questions
Is the financial sector cut off from NIS2 cooperation?
No. Under DORA, the European Supervisory Authorities and financial competent authorities may participate in the activities of the NIS Cooperation Group and exchange information and cooperate with the NIS2 single points of contact and CSIRTs. Member States should continue to include the financial sector in their cybersecurity strategies.
Do NIS2 bodies learn about major ICT incidents at banks?
Yes. DORA competent authorities transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, competent authorities or single points of contact under NIS2.
How does NIS2 relate to the Critical Entities Resilience Directive?
The scopes have been largely aligned. Entities identified as critical under the CER Directive also become subject to NIS2's cybersecurity obligations, and the authorities under both directives must cooperate and exchange information regularly.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs β¬0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_β¦"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_β¦"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_β¦" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_β¦with your key. - Full details (responses, errors, JS and Python examples): developer docs.