What is the difference between NIS2 and DORA?
NIS2 is a cross-sector cybersecurity directive; DORA is a financial-sector digital operational resilience regulation.
NIS2 vs DORA: NIS2 sets cybersecurity duties across many essential and important sectors through national transposition; DORA sets directly applicable ICT resilience duties for financial entities. Sources: EUR-Lex: NIS2 Directive; EUR-Lex: Digital Operational Resilience Act.
The short version
NIS2 is broader by sector and implemented nationally as a directive. DORA is narrower by sector but more specific on financial ICT risk, incident reporting, testing and third-party risk.
Side by side
Directive
NIS2
NIS2 Directive
- What it is
- NIS2 sets cybersecurity risk-management and incident-reporting duties for essential and important entities across many sectors.
- Scope
- Network and information-system security for listed sectors, including energy, transport, banking, health, digital infrastructure, public administration and other important sectors.
- Who it applies to
- Essential and important entities identified by sector, size and national implementation rules.
- Key dates
- Entered into force in 2023.
- Member States had to transpose NIS2 by 17 October 2024.
- Core obligations
- Take cybersecurity risk-management measures.
- Notify significant incidents under the directive's timetable.
- Meet governance and supply-chain security expectations through national law.
- Penalties
- NIS2 requires maximum administrative fines of at least EUR 10 million or 2% of worldwide turnover for essential entities, and at least EUR 7 million or 1.4% for important entities.
Regulation
DORA
Digital Operational Resilience Act
- What it is
- DORA is the EU financial-sector framework for ICT risk management, incident reporting, resilience testing and ICT third-party risk.
- Scope
- Digital operational resilience for financial entities and oversight of critical ICT third-party service providers.
- Who it applies to
- Financial entities listed in DORA and, through oversight, critical ICT third-party service providers.
- Key dates
- Entered into force in 2023.
- Applies from 17 January 2025.
- Core obligations
- Maintain ICT risk-management frameworks.
- Report major ICT-related incidents and significant cyber threats where required.
- Run digital operational resilience testing and manage ICT third-party risk.
- Penalties
- DORA relies on competent authorities' supervisory and enforcement powers, including administrative measures and penalty payments for critical ICT third-party providers.
Which applies to you?
If you are in a NIS2 listed sector, check national NIS2 implementation. If you are a financial entity, DORA is likely the more specific ICT resilience regime and may sit alongside NIS2-related national rules.
Frequently asked
Does DORA replace NIS2 for financial firms?
DORA is the specialised EU financial-sector ICT resilience regime. NIS2 and national cybersecurity rules still need to be checked for the entity and Member State.
Which one is directly applicable?
DORA is a regulation and directly applicable. NIS2 is a directive and works through national transposition.
Which one has explicit fine thresholds?
NIS2 specifies minimum maximum fine levels for essential and important entities. DORA relies on sector supervisors and competent-authority powers.
Official sources
Comparisons are grounded explainers, not legal advice. Use the linked EUR-Lex texts and official sources for binding legal wording.
Related terms
Does this comparison affect your company?
Enter your company and Lex builds a cited Exposure Map in about 30 seconds. Free, no login.