Lex/Compare/NIS2 vs DORA
Compare

What is the difference between NIS2 and DORA?

NIS2 is a cross-sector cybersecurity directive; DORA is a financial-sector digital operational resilience regulation.

In short

NIS2 vs DORA: NIS2 sets cybersecurity duties across many essential and important sectors through national transposition; DORA sets directly applicable ICT resilience duties for financial entities. Sources: EUR-Lex: NIS2 Directive; EUR-Lex: Digital Operational Resilience Act.

Check whether this affects your company
Run a free exposure scan — Lex maps both regimes onto the EU files, deadlines and source records heading your way.

The short version

NIS2 is broader by sector and implemented nationally as a directive. DORA is narrower by sector but more specific on financial ICT risk, incident reporting, testing and third-party risk.

Side by side

Directive

NIS2

NIS2 Directive

What it is
NIS2 sets cybersecurity risk-management and incident-reporting duties for essential and important entities across many sectors.
Scope
Network and information-system security for listed sectors, including energy, transport, banking, health, digital infrastructure, public administration and other important sectors.
Who it applies to
Essential and important entities identified by sector, size and national implementation rules.
Key dates
  • Entered into force in 2023.
  • Member States had to transpose NIS2 by 17 October 2024.
Core obligations
  • Take cybersecurity risk-management measures.
  • Notify significant incidents under the directive's timetable.
  • Meet governance and supply-chain security expectations through national law.
Penalties
NIS2 requires maximum administrative fines of at least EUR 10 million or 2% of worldwide turnover for essential entities, and at least EUR 7 million or 1.4% for important entities.

Regulation

DORA

Digital Operational Resilience Act

What it is
DORA is the EU financial-sector framework for ICT risk management, incident reporting, resilience testing and ICT third-party risk.
Scope
Digital operational resilience for financial entities and oversight of critical ICT third-party service providers.
Who it applies to
Financial entities listed in DORA and, through oversight, critical ICT third-party service providers.
Key dates
  • Entered into force in 2023.
  • Applies from 17 January 2025.
Core obligations
  • Maintain ICT risk-management frameworks.
  • Report major ICT-related incidents and significant cyber threats where required.
  • Run digital operational resilience testing and manage ICT third-party risk.
Penalties
DORA relies on competent authorities' supervisory and enforcement powers, including administrative measures and penalty payments for critical ICT third-party providers.

Which applies to you?

If you are in a NIS2 listed sector, check national NIS2 implementation. If you are a financial entity, DORA is likely the more specific ICT resilience regime and may sit alongside NIS2-related national rules.

Frequently asked

Does DORA replace NIS2 for financial firms?

DORA is the specialised EU financial-sector ICT resilience regime. NIS2 and national cybersecurity rules still need to be checked for the entity and Member State.

Which one is directly applicable?

DORA is a regulation and directly applicable. NIS2 is a directive and works through national transposition.

Which one has explicit fine thresholds?

NIS2 specifies minimum maximum fine levels for essential and important entities. DORA relies on sector supervisors and competent-authority powers.

Official sources

Comparisons are grounded explainers, not legal advice. Use the linked EUR-Lex texts and official sources for binding legal wording.

Related terms

Does this comparison affect your company?

Enter your company and Lex builds a cited Exposure Map in about 30 seconds. Free, no login.