Aller au contenu
NISDESK

NIS2 vs DORA: which one applies to my organisation?

If you are a financial entity covered by DORA (EU) 2022/2554, such as a bank, insurer, investment firm or payment institution, DORA's ICT risk-management and incident-reporting rules apply to you as lex specialis. Other organisations in the 18 NIS2 sectors follow NIS2. ICT suppliers to financial entities often feel both through contracts.

Last updated: 2026-09-30

Side by side

NIS2DORA
Legal instrumentDirective (EU) 2022/2555 — transposed into national lawRegulation (EU) 2022/2554 — directly applicable
Applies from18 October 2024 (via national law)17 January 2025
WhoMedium and large entities in 18 sectors (Annex I and II)Financial entities listed in DORA Article 2, plus EU oversight of critical ICT third-party providers
Incident reporting24h early warning, 72h notification, 1-month final reportMajor ICT-related incidents: initial, intermediate and final reports on DORA's own timelines
FinesSet in Article 34 (€10M / 2% and €7M / 1.4% minimum caps)Administrative penalties set by member states

Rule of thumb

  • ▸Bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider → start with DORA.
  • ▸Energy, health, manufacturing, digital or ICT services (non-financial) → start with NIS2.
  • ▸ICT provider to financial entities → check NIS2 for yourself, and expect DORA contract requirements from your customers.

Related question

Can a company be subject to both NIS2 and DORA?

Yes, in different ways. A group can have financial entities under DORA and non-financial entities under NIS2, and an ICT provider can be in NIS2 scope itself while also having to meet DORA-driven contractual requirements from financial-sector customers.

Next steps

For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.