NIS2 vs DORA: Do Financial Entities Have to Comply With Both?
In short: no, a financial entity covered by DORA does not run a second, parallel NIS2 compliance program for the same obligations. Article 4 of NIS2 says that where a sector-specific EU act imposes at least equivalent cybersecurity or incident-reporting requirements, the matching NIS2 provisions, including supervision and enforcement, do not apply. The Commission's 2023 guidelines confirm that DORA, Regulation (EU) 2022/2554, is such an act for financial entities: its rules on ICT risk management, ICT incident reporting, resilience testing, information sharing and ICT third-party risk apply instead of NIS2's. But NIS2 does not disappear entirely from a financial group, and the details matter.
The legal mechanism: NIS2 Article 4
Article 4(1) of Directive (EU) 2022/2555 provides that where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents, and those requirements are "at least equivalent in effect" to NIS2's, "the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to such entities."
Article 4(2) defines equivalence in two parts:
- Risk management: measures at least equivalent in effect to Article 21(1) and (2), the ten minimum security measures.
- Reporting: requirements at least equivalent in effect to Article 23(1) to (6), plus "immediate access, where appropriate automatic and direct" to the incident notifications for the NIS2 CSIRTs, competent authorities or single points of contact.
The Commission's guidelines (2023/C 328/02, published in the Official Journal on 18 September 2023) explain that the sector-specific act should "at a minimum, correspond to the requirements of those provisions or go beyond them", may be more granular, should follow an "all-hazard approach" covering physical and environmental security, and for reporting should match NIS2 on recipients, content and time frames.
DORA is the designated lex specialis for financial entities
The Appendix to the guidelines lists DORA as a sector-specific act. It notes that Article 1(2) of DORA itself provides that, for financial entities covered by NIS2, DORA "shall be considered a sector-specific Union legal act for the purposes of Article 4", mirrored by recital 28 of NIS2. Consequently, the guidelines say, DORA's provisions on:
- ICT risk management (DORA Article 6 et seq.);
- management of ICT-related incidents and, in particular, major ICT-related incident reporting (Article 17 et seq.);
- digital operational resilience testing (Article 24 et seq.);
- information-sharing arrangements (Article 25);
- ICT third-party risk (Article 28 et seq.)
"shall apply instead of those provided for in Directive (EU) 2022/2555." Member States "should therefore not apply the provisions of Directive (EU) 2022/2555 on cybersecurity risk-management and reporting obligations, and supervision and enforcement, to financial entities covered by Regulation (EU) 2022/2554."
"Financial entities" here means the entities in DORA Article 2(1)(a) to (t). The guidelines name the overlap explicitly: credit institutions, trading venues and central counterparties are within both DORA and NIS2's Annex I (banking and financial market infrastructures). For a US bank with an EU-authorized credit institution, or a US exchange group operating an EU trading venue or CCP, that EU entity follows DORA for these topics.
Which NIS2 provisions fall away, and which remain
NIS2 provisions for a DORA-covered financial entity (Commission Guidelines 2023/C 328/02)
| NIS2 provision | Applies to the financial entity? |
|---|---|
| Article 21: cybersecurity risk-management measures | No, DORA applies instead |
| Article 23: incident reporting | No, DORA's major ICT-related incident reporting applies instead |
| Chapter VII: supervision and enforcement (incl. Articles 32-34 fines) | No, not for these obligations |
| Article 20: management body approval, oversight, liability and training | No, being intrinsically linked to Article 21 |
| Articles 3(3)-(4) and 27(2)-(3): listing and registration information | Not required, though Member States may still include such entities in the list |
| Article 7: national cybersecurity strategy covering the sector | Yes, at Member State level |
| Article 9: national cyber crisis management frameworks | Yes, apply in their entirety |
| Article 16: EU-CyCLONe | Yes, carries out its tasks for these sectors |
| Articles 10-11: CSIRTs covering the sector | Yes, CSIRTs should be in a position to cover the financial sector |
The provisions that remain are mostly obligations on Member States and authorities, not on the bank. They matter in a crisis: national cyber crisis plans and EU-CyCLONe still treat the financial sector as part of the picture. The guidelines also say DORA authorities "should also transmit details of major ICT-related incidents and, where relevant, significant cyber threats" to the NIS2 CSIRTs, competent authorities or single points of contact, for instance through a single entry point. Your DORA incident report may therefore reach the NIS2 community without you filing anything under NIS2.
Where NIS2 can still apply inside a financial group
Article 4(1) ends with an important qualifier: where sector-specific acts "do not cover all entities in a specific sector falling within the scope of this Directive, the relevant provisions of this Directive shall continue to apply to the entities not covered". In a diversified US financial group, check entity by entity:
- Non-financial subsidiaries. A group company that is itself, say, a data center service provider, cloud provider or managed service provider for third parties is an Annex I digital entity in its own right. DORA's carve-out covers financial entities, not every company in the group.
- Entities not covered by DORA. If an entity in a NIS2 sector is not a DORA financial entity, NIS2 continues to apply to it.
- DORA exemptions. Conversely, NIS2 Article 2(10) states that NIS2 "does not apply to entities which Member States have exempted from the scope of Regulation (EU) 2022/2554 in accordance with Article 2(4) of that Regulation."
- ICT providers to the financial sector. A cloud or managed service provider supervised under NIS2 can also be designated a critical ICT third-party service provider under DORA. NIS2 Articles 32(10) and 33(6) then require the NIS2 authorities to inform DORA's Oversight Forum when they exercise supervisory powers over it.
If you are a US cloud or MSP serving EU banks
You may sit on both sides: subject to NIS2 as an Annex I digital provider (with the significance thresholds of Implementing Regulation (EU) 2024/2690 and jurisdiction at your main EU establishment), and subject to your bank clients' DORA third-party risk requirements by contract. The DORA side is outside the documents indexed in this NIS2 base.
Practical steps for compliance teams
- Map every EU legal entity: DORA financial entity (Article 2(1)(a)-(t)), NIS2 entity, both, or neither.
- For DORA entities, document that DORA is applied as the lex specialis under NIS2 Article 4, citing the Commission's guidelines.
- For group entities outside DORA but in a NIS2 sector, run the NIS2 scope test (sector, size cap, essential or important).
- Check with national authorities whether they still list DORA entities in their NIS2 register; the guidelines allow it.
- Align incident taxonomies: a single event may need a DORA report for the bank and a NIS2 report for an in-scope ICT subsidiary.
- Keep watch on the national transposition of NIS2 in each Member State where your non-DORA entities operate.
On that last point, the status is uneven. According to the Commission's transposition page as consulted on 2 October 2026, reasoned opinions went to 19 Member States on 7 May 2025, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition. You can check specific points in the NIS2 knowledge base, for example: "Our bank is already fully compliant with DORA. Do we also have to separately comply with NIS2's cybersecurity and incident-reporting rules?"
Settle NIS2-DORA questions with the source text
The NIS2 knowledge base includes the Commission's Article 4 guidelines and the directive's recitals, so every answer on the NIS2-DORA boundary comes with a citation.
Primary sources: the Commission Guidelines on Article 4(1) and (2) NIS2 and Directive (EU) 2022/2555. The guidelines are without prejudice to the Court of Justice's interpretation of EU law. This article is not legal advice.
Frequently asked questions
Does NIS2 apply to banks?
Credit institutions are listed in NIS2 Annex I, but for financial entities covered by DORA, DORA is the sector-specific act under NIS2 Article 4. Its ICT risk-management, incident-reporting, testing, information-sharing and third-party risk rules apply instead of NIS2's, together with the related supervision and enforcement.
Is DORA lex specialis to NIS2?
Yes. DORA Article 1(2), NIS2 recital 28 and the Commission's 2023 guidelines on Article 4 all treat DORA as a sector-specific Union legal act for financial entities under NIS2 Article 4.
Do NIS2 management liability rules apply to DORA entities?
According to the Commission's guidelines, Article 20 of NIS2 should not apply where a sector-specific act applies to cybersecurity risk management, because Article 20 is intrinsically linked to Article 21.
Do DORA-covered entities have to register under NIS2?
The guidelines say Articles 3(3) and 27(2) should not apply to entities covered by a sector-specific act for risk management and reporting, but this does not preclude Member States from including them in the NIS2 list.
Can a company in a financial group still be subject to NIS2?
Yes. Article 4(1) keeps NIS2 applicable to entities not covered by the sector-specific act. A group company that is, for example, a cloud, data center or managed service provider in its own right can be a NIS2 entity.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.