Comparison

NIS2 vs DORA: Do Financial Entities Have to Comply with Both? A Guide for UK Groups with EU Operations

The Kopik team7 min read

For an EU financial entity covered by DORA, the answer is DORA, not both. NIS2 Article 4 switches off its own cyber security risk-management, incident-reporting, supervision and enforcement provisions where a sector-specific EU act imposes at least equivalent requirements, and the Commission's 2023 guidelines confirm that DORA (Regulation (EU) 2022/2554) is that act for financial entities. Yet NIS2 is not irrelevant to a financial group: it still governs non-financial group companies in its sectors, it keeps national crisis management structures covering finance, and it meets DORA again where an ICT provider sits under both regimes.

Setting the scene for UK groups

Both NIS2 and DORA are EU instruments. For a UK-headquartered group, the question arises for its EU-authorised entities: a credit institution, an investment firm, a trading venue, a central counterparty, an insurer or a payment institution, for example. UK domestic operational resilience rules are not part of the sources indexed in the NIS2 knowledge base, and this guide says nothing about them. Equally, the base indexes NIS2 materials, not the DORA Regulation itself, so DORA's own technical requirements are only described here as the NIS2 sources describe them.

How the lex specialis rule works

Article 4(1) of Directive (EU) 2022/2555 provides that where a sector-specific Union act requires essential or important entities to adopt cyber security risk-management measures or to notify significant incidents, and those requirements are "at least equivalent in effect", the relevant NIS2 provisions, "including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to such entities".

Equivalence is tested under Article 4(2): risk-management measures at least equivalent to Article 21(1) and (2); and, for reporting, requirements at least equivalent to Article 23(1) to (6) together with immediate access, where appropriate automatic and direct, for the NIS2 CSIRTs, competent authorities or single points of contact to the incident notifications.

The Commission's guidelines (2023/C 328/02) add how to read that test. The sector act should "at a minimum, correspond to the requirements of those provisions or go beyond them"; it should rest on an all-hazards approach that also protects the physical environment of systems from events such as sabotage, theft, fire, flood or power failure; and reporting rules should match NIS2 on recipients, content and time frames.

DORA's designation, in the guidelines' own words

The guidelines' Appendix records that Article 1(2) of DORA makes it "a sector-specific Union legal act for the purposes of Article 4" of NIS2 for financial entities, mirrored in NIS2 recital 28. As a result, DORA's provisions on ICT risk management, ICT-related incident management and major incident reporting, digital operational resilience testing, information-sharing arrangements and ICT third-party risk "shall apply instead of those provided for in Directive (EU) 2022/2555".

"Financial entities" are those in DORA Article 2(1)(a) to (t). The guidelines identify credit institutions, trading venues and central counterparties as types that fall within both DORA and NIS2. The Commission's NIS2 Q&A makes the same point: although NIS2 includes credit institutions, operators of trading venues and central counterparties, "DORA will apply to these entities as regards cybersecurity risk management and reporting obligations".

Topic by topic: which regime governs the financial entity?

For an EU financial entity within DORA Article 2(1)(a)-(t)

TopicGoverning regimeBasis in the NIS2 sources
Security and risk-management measuresDORAGuidelines, Appendix point 1; NIS2 Art. 4
Incident reportingDORA (major ICT-related incidents)Guidelines, Appendix point 1
Supervision, enforcement and finesDORA authoritiesNIS2 Art. 4(1); Guidelines para. 28
Management body duties and training (NIS2 Art. 20)Not NIS2Guidelines para. 37
NIS2 entity list and registration (Arts. 3(3), 27(2))Not required; Member States may still listGuidelines para. 37
National cyber crisis framework, EU-CyCLONe (Arts. 9, 16)NIS2 continues to applyGuidelines paras. 34-36; Appendix point 2
National cyber security strategy (Art. 7)NIS2 continues to applyGuidelines paras. 30-32

Your DORA report can travel

The guidelines expect DORA competent authorities to transmit details of major ICT-related incidents, and where relevant significant cyber threats, to the NIS2 CSIRTs, competent authorities or single points of contact, for example through a single entry point. The NIS2 community can therefore see the incident without a separate NIS2 filing by the financial entity.

Supervision follows the same logic. Paragraph 28 of the guidelines states that, where a sector act is at least equivalent, it is not only the NIS2 obligations that fall away but also the Chapter VII supervision and enforcement provisions. Paragraph 29, drawing on NIS2 recital 25, adds that the sector act's authorities may exercise their powers with the assistance of the NIS2 competent authorities, under cooperation arrangements that can cover the coordination of supervisory activities, investigations and on-site inspections, and the exchange of information. For an EU bank in a UK group, the practical consequence is a single supervisory line for cyber security, the DORA one, with the NIS2 authorities in a supporting role.

Where NIS2 still reaches a financial group

  • Entities outside DORA. Article 4(1): where the sector act does not cover all entities in a sector within NIS2's scope, NIS2 "shall continue to apply to the entities not covered".
  • Technology subsidiaries. A group company that provides cloud computing, data centre, managed or managed security services to third parties is a digital infrastructure or ICT service management entity under NIS2 Annex I in its own right, subject to the size cap.
  • DORA-exempt entities. Under NIS2 Article 2(10), NIS2 does not apply to entities that Member States have exempted from DORA under its Article 2(4).
  • ICT providers designated under DORA. If an essential or important NIS2 entity is designated a critical ICT third-party service provider under DORA Article 31, NIS2 Articles 32(10) and 33(6) require the NIS2 authorities to inform DORA's Oversight Forum when supervising it.

For a UK fintech or technology provider selling into EU financial institutions, this is the scenario to watch: in scope of NIS2 as a cloud or managed service provider (with an EU representative under Article 26(3) if it has no EU establishment), while bound by DORA-driven contractual requirements from its clients. The DORA side lies outside this base's documents.

A working method for compliance teams

  1. List every EU entity in the group and classify it: DORA financial entity, NIS2 entity, both, or neither.
  2. For DORA financial entities, record the Article 4 analysis and the Commission's guidelines as the basis for not running NIS2 Articles 21 and 23 separately.
  3. For non-DORA entities in NIS2 sectors, apply the NIS2 scope test: Annex I or II activity, size cap (with group aggregation), essential or important status, jurisdiction under Article 26.
  4. Check with each national competent authority whether DORA entities are nonetheless included in the NIS2 list.
  5. Prepare for dual-regime incidents: one event may produce a DORA report for a bank and a NIS2 early warning, within 24 hours, for an in-scope ICT subsidiary.
  6. Track NIS2 transposition in each relevant Member State.

Transposition remains patchy. The Commission's tracker, as consulted on 2 October 2026, records reasoned opinions sent to 19 Member States on 7 May 2025 and the referral of Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 for failing to notify transposition measures. To check a specific boundary question, ask the base, for instance: "Our bank is already fully compliant with DORA. Do we also have to separately comply with NIS2's cybersecurity and incident-reporting rules?"

Answer NIS2-DORA boundary questions with citations

The NIS2 knowledge base indexes the directive, the Commission's Article 4 guidelines and the Q&A, so each answer points to the passage that supports it.

Primary sources: Commission Guidelines 2023/C 328/02 and Directive (EU) 2022/2555. The guidelines state that they are without prejudice to the Court of Justice's interpretation of EU law. This guide is not legal advice.

Frequently asked questions

Do EU banks have to comply with NIS2 and DORA?

For financial entities covered by DORA, DORA applies instead of NIS2's cyber security risk-management, incident-reporting, supervision and enforcement provisions, under NIS2 Article 4 and the Commission's 2023 guidelines.

What does lex specialis mean in NIS2?

Under Article 4, where a sector-specific EU act imposes requirements at least equivalent in effect to NIS2's Article 21 measures or Article 23 reporting, the corresponding NIS2 provisions and Chapter VII supervision do not apply to the entities it covers.

Do NIS2 national crisis rules still cover the financial sector?

Yes. The guidelines state that Articles 9 (national cyber crisis management frameworks) and 16 (EU-CyCLONe) continue to apply to entities within DORA's scope.

Does NIS2 apply to a UK fintech serving EU banks?

It can, if the fintech is itself an in-scope NIS2 entity, such as a medium-sized or larger cloud or managed service provider offering services in the EU; without an EU establishment it would need an EU representative under Article 26(3). Its DORA-related obligations towards bank clients are outside this base.

Are DORA-exempt entities subject to NIS2 instead?

No. NIS2 Article 2(10) states that the directive does not apply to entities that Member States have exempted from DORA's scope under Article 2(4) of that Regulation.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.