NIS2 vs DORA: which one applies to my organisation?
If you are a financial entity covered by DORA (EU) 2022/2554, such as a bank, insurer, investment firm or payment institution, DORA's ICT risk-management and incident-reporting rules apply to you as lex specialis. Other organisations in the 18 NIS2 sectors follow NIS2. ICT suppliers to financial entities often feel both through contracts.
Last updated: 2026-09-30
Side by side
| NIS2 | DORA | |
|---|---|---|
| Legal instrument | Directive (EU) 2022/2555 — transposed into national law | Regulation (EU) 2022/2554 — directly applicable |
| Applies from | 18 October 2024 (via national law) | 17 January 2025 |
| Who | Medium and large entities in 18 sectors (Annex I and II) | Financial entities listed in DORA Article 2, plus EU oversight of critical ICT third-party providers |
| Incident reporting | 24h early warning, 72h notification, 1-month final report | Major ICT-related incidents: initial, intermediate and final reports on DORA's own timelines |
| Fines | Set in Article 34 (€10M / 2% and €7M / 1.4% minimum caps) | Administrative penalties set by member states |
Rule of thumb
- ▸Bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider → start with DORA.
- ▸Energy, health, manufacturing, digital or ICT services (non-financial) → start with NIS2.
- ▸ICT provider to financial entities → check NIS2 for yourself, and expect DORA contract requirements from your customers.
Related question
Can a company be subject to both NIS2 and DORA?
Yes, in different ways. A group can have financial entities under DORA and non-financial entities under NIS2, and an ICT provider can be in NIS2 scope itself while also having to meet DORA-driven contractual requirements from financial-sector customers.
Next steps
Official sources
More answers:
For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.