DORA vs NIS2: How the Two EU Frameworks Differ
DORA is a sector-specific EU regulationfor financial entities' ICT operational resilience; NIS2 is a broad EU directive raising cybersecurity across many essential sectors. Where both could apply to a financial entity, DORA takes precedence as lex specialis for ICT resilience matters.
Side-by-side
| Aspect | DORA | NIS2 |
|---|---|---|
| Legal instrument | Regulation (directly applicable) | Directive (nationally transposed) |
| Primary scope | Financial entities + critical ICT providers | Essential & important entities across many sectors |
| Focus | Digital operational resilience of ICT | General cybersecurity risk management |
| Incident reporting | Harmonised, ICT-specific timelines | Sector-wide reporting to national CSIRTs |
| Third-party oversight | Direct EU oversight of critical ICT providers | Supply-chain security obligations |
| Applies since | 17 January 2025 | Transposition deadline 17 October 2024 |
Which one applies to you?
Regulated financial entities should treat DORAas the governing framework for ICT operational resilience. Organisations outside financial services, or financial firms' non-financial group entities, may fall under NIS2 as transposed in their member state. Many groups must map both.
Penalties compared
The two frameworks set fine ceilings very differently. NIS2 writes minimum maximum-fine tiers directly into Article 34 of the directive: essential entities face at least EUR 10 million or 2% of total global annual turnover, whichever is higher, and important entities at least EUR 7 million or 1.4%. Because these are floors, not ceilings, individual member states can and do set higher national limits once they transpose the directive.
DORAtakes the opposite approach for financial entities: the regulation requires competent authorities to have the power to impose administrative penalties, but it deliberately leaves the amount to national law, so there is no single EU-wide figure comparable to NIS2's Article 34 floors. The one DORA-specific number that is fixed at EU level applies only to designated critical ICT third-party providers under the pan-EU oversight regime: periodic penalty payments of up to 1% of average daily worldwide turnover, levied daily for up to six months to compel compliance. For a group that is both a financial entity under DORA and an essential or important entity under NIS2 in the same member state, the NIS2 exposure is often the more predictable number to model, DORA's is set nationally and can vary by jurisdiction. See DORA penalties for the full enforcement picture.
Frequently asked questions
Does DORA or NIS2 apply to my financial firm?
If you are a regulated financial entity, DORA applies to your ICT operational resilience as lex specialis. NIS2 obligations that would otherwise overlap are generally displaced by DORA for those matters.
Is DORA a regulation or a directive?
DORA is a regulation, directly applicable in all member states without national transposition. NIS2 is a directive, which each member state transposes into national law.
Which framework has bigger fines, DORA or NIS2?
NIS2 sets harmonised minimum fine ceilings directly in the directive, at least EUR 10 million or 2% of global annual turnover for essential entities (whichever is higher). DORA leaves fine amounts for financial entities to national law, so there is no single EU-wide ceiling, though critical ICT third-party providers face separate periodic penalty payments. See DORA penalties for the full picture.