Skip to main content
DORA Auditor

DORA vs NIS2: How the Two EU Frameworks Differ

Last updated: 2 authoritative sourcesDORA Auditor Editorial Team

DORA is a sector-specific EU regulationfor financial entities' ICT operational resilience; NIS2 is a broad EU directive raising cybersecurity across many essential sectors. Where both could apply to a financial entity, DORA takes precedence as lex specialis for ICT resilience matters.

Side-by-side

AspectDORANIS2
Legal instrumentRegulation (directly applicable)Directive (nationally transposed)
Primary scopeFinancial entities + critical ICT providersEssential & important entities across many sectors
FocusDigital operational resilience of ICTGeneral cybersecurity risk management
Incident reportingHarmonised, ICT-specific timelinesSector-wide reporting to national CSIRTs
Third-party oversightDirect EU oversight of critical ICT providersSupply-chain security obligations
Applies since17 January 2025Transposition deadline 17 October 2024

Which one applies to you?

Regulated financial entities should treat DORAas the governing framework for ICT operational resilience. Organisations outside financial services, or financial firms' non-financial group entities, may fall under NIS2 as transposed in their member state. Many groups must map both.

Penalties compared

The two frameworks set fine ceilings very differently. NIS2 writes minimum maximum-fine tiers directly into Article 34 of the directive: essential entities face at least EUR 10 million or 2% of total global annual turnover, whichever is higher, and important entities at least EUR 7 million or 1.4%. Because these are floors, not ceilings, individual member states can and do set higher national limits once they transpose the directive.

DORAtakes the opposite approach for financial entities: the regulation requires competent authorities to have the power to impose administrative penalties, but it deliberately leaves the amount to national law, so there is no single EU-wide figure comparable to NIS2's Article 34 floors. The one DORA-specific number that is fixed at EU level applies only to designated critical ICT third-party providers under the pan-EU oversight regime: periodic penalty payments of up to 1% of average daily worldwide turnover, levied daily for up to six months to compel compliance. For a group that is both a financial entity under DORA and an essential or important entity under NIS2 in the same member state, the NIS2 exposure is often the more predictable number to model, DORA's is set nationally and can vary by jurisdiction. See DORA penalties for the full enforcement picture.

Frequently asked questions

Does DORA or NIS2 apply to my financial firm?
Is DORA a regulation or a directive?
Which framework has bigger fines, DORA or NIS2?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  2. Directive (EU) 2022/2555 (NIS2), EUR-Lex