NIS2 and DORA: which rules apply to banks and financial entities
Credit institutions and financial market infrastructures appear in NIS2's scope, yet DORA governs their ICT risk management and incident reporting. This page explains how the two texts fit together and how equivalence with other sector-specific acts is assessed.
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
DORA as a sector-specific act
The NIS2 recitals state that Regulation (EU) 2022/2554 (DORA) is a sector-specific Union legal act in relation to NIS2 for financial entities. DORA's provisions on ICT risk management, incident reporting, resilience testing and ICT third-party risk apply instead of NIS2's.
Member States therefore should not apply NIS2's provisions on cybersecurity risk-management, reporting, supervision and enforcement to financial entities covered by DORA. NIS2 also does not apply to entities that Member States have exempted from DORA under Article 2(4) of that Regulation.
The equivalence test of Article 4
Article 4(1) provides that where a sector-specific Union act requires risk-management measures or incident notification that are at least equivalent in effect to NIS2, the corresponding NIS2 provisions, including supervision and enforcement in Chapter VII, do not apply.
According to the Commission guidelines, risk-management measures are equivalent where they are at least equivalent in effect to Article 21(1) and (2). Reporting requirements are equivalent where the sector act gives CSIRTs, competent authorities or single points of contact immediate access to notifications and the requirements are at least equivalent in effect to Article 23(1) to (6).
Questions fréquentes
Is the financial sector cut off from NIS2 cooperation?
No. Under DORA, the European Supervisory Authorities and financial competent authorities may participate in the activities of the NIS Cooperation Group and exchange information and cooperate with the NIS2 single points of contact and CSIRTs. Member States should continue to include the financial sector in their cybersecurity strategies.
Do NIS2 bodies learn about major ICT incidents at banks?
Yes. DORA competent authorities transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, competent authorities or single points of contact under NIS2.
How does NIS2 relate to the Critical Entities Resilience Directive?
The scopes have been largely aligned. Entities identified as critical under the CER Directive also become subject to NIS2's cybersecurity obligations, and the authorities under both directives must cooperate and exchange information regularly.
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.