Tech & produitVérifiée par Kopik: Sources officielles relues et réponses testées par Kopik

NIS2 and DORA: which rules apply to banks and financial entities

Credit institutions and financial market infrastructures appear in NIS2's scope, yet DORA governs their ICT risk management and incident reporting. This page explains how the two texts fit together and how equivalence with other sector-specific acts is assessed.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

DORA as a sector-specific act

The NIS2 recitals state that Regulation (EU) 2022/2554 (DORA) is a sector-specific Union legal act in relation to NIS2 for financial entities. DORA's provisions on ICT risk management, incident reporting, resilience testing and ICT third-party risk apply instead of NIS2's.

Member States therefore should not apply NIS2's provisions on cybersecurity risk-management, reporting, supervision and enforcement to financial entities covered by DORA. NIS2 also does not apply to entities that Member States have exempted from DORA under Article 2(4) of that Regulation.

The equivalence test of Article 4

Article 4(1) provides that where a sector-specific Union act requires risk-management measures or incident notification that are at least equivalent in effect to NIS2, the corresponding NIS2 provisions, including supervision and enforcement in Chapter VII, do not apply.

According to the Commission guidelines, risk-management measures are equivalent where they are at least equivalent in effect to Article 21(1) and (2). Reporting requirements are equivalent where the sector act gives CSIRTs, competent authorities or single points of contact immediate access to notifications and the requirements are at least equivalent in effect to Article 23(1) to (6).

Questions fréquentes

Is the financial sector cut off from NIS2 cooperation?

No. Under DORA, the European Supervisory Authorities and financial competent authorities may participate in the activities of the NIS Cooperation Group and exchange information and cooperate with the NIS2 single points of contact and CSIRTs. Member States should continue to include the financial sector in their cybersecurity strategies.

Do NIS2 bodies learn about major ICT incidents at banks?

Yes. DORA competent authorities transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, competent authorities or single points of contact under NIS2.

How does NIS2 relate to the Critical Entities Resilience Directive?

The scopes have been largely aligned. Entities identified as critical under the CER Directive also become subject to NIS2's cybersecurity obligations, and the authorities under both directives must cooperate and exchange information regularly.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-nis2-cybersecurity
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-nis2-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.