DORA or NIS2
DORA or NIS2: which one applies to you, and what it actually asks for
DORA demands a standing, filed, dated body of evidence. NIS2 demands appropriate measures and proof when asked. Which one binds you depends on whether you are a financial entity, and whether you serve one.
Transposition status verified on .
Regulation or directive: why the difference matters
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), is a regulation. It has applied directly, in the same words, in all 27 member states since 17 January 2025. There is no national law to wait for and no national variant to track.
NIS2 (Directive (EU) 2022/2555) is a directive. It binds you through your member state's own implementing law, and those laws have arrived years apart. As at 30 September 2026, 24 member states have adopted one. France, Ireland and Spain have not, and the Commission referred them to the Court of Justice on 8 July 2026.
Financial entities are carved out. Their ICT providers are in both.
DORA is the sector-specific act for the financial sector. Under Article 4 of NIS2, where a sector-specific act imposes equivalent requirements, NIS2's risk-management measures (Article 21) and its incident notification (Article 23) do not apply. A bank, an insurer or an investment firm is therefore supervised on ICT risk and incidents under DORA, by its financial supervisor, and not twice.
The supply chain is where the two meet
The ICT providers those institutions depend on are in both. DORA reaches them through their customers' contracts: every financial entity must hold the Article 30 provisions in its ICT contracts and record each provider in its register of information. And a medium or large cloud, data centre, managed or managed security services provider is usually an essential or important entity under NIS2 in its own right.
What each one asks for
| DORA | NIS2 | |
|---|---|---|
| Obligation type | Prescriptive. An ICT risk management framework (Arts. 5 to 16), incident classification and reporting (Arts. 17 to 23), resilience testing including TLPT (Arts. 24 to 27) and ICT third-party risk (Arts. 28 to 30), detailed further in technical standards. | Principle-based. Cybersecurity measures that are "appropriate and proportionate" across ten areas (Art. 21), incident notification (Art. 23) and management body accountability (Art. 20). |
| The difference that mattersStanding evidence deliverable | Yes, and it is dated and filed. A register of information on every ICT third-party arrangement, in the ESA template (Art. 28(3)). The Article 30 provisions in every ICT contract. A documented ICT risk framework reviewed at least once a year (Art. 6). Major incident reports on the regulatory templates. | None at EU level. You must be able to demonstrate your measures when the authority asks, through audits, inspections and requests for information (Arts. 32 and 33). There is no register and no filing template. |
| Filing cadence | Register reported to the competent authority each year. Major incidents: initial notification within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it, intermediate within 72 hours of that, final within a month. Framework reviewed annually. TLPT every three years where required. | Registration with the national authority, updated on change. Significant incidents: early warning within 24 hours, notification within 72 hours, final report within a month. Nothing else on a schedule. |
| Supervision model | Financial supervisors: the national competent authority, the ECB for significant banks, with EBA, EIOPA and ESMA. Critical ICT third-party providers are overseen directly by a Lead Overseer. | National cybersecurity authorities. Essential entities are supervised proactively; important entities only after the authority has cause to look. |
| Penalties | Set by each member state for financial entities (Art. 50). For critical ICT third-party providers, periodic penalty payments of up to 1% of average daily worldwide turnover (Art. 35). | Up to €10m or 2% of worldwide turnover for essential entities, and €7m or 1.4% for important entities (Art. 34). Members of the management body can be held personally liable (Art. 20). |
Why the register matters: in the ESAs' 2024 dry run, fewer than 7% of submitted registers passed every data quality check.
Which one applies to you
Five questions at most. The answer is decided by fixed rules from the text of DORA and NIS2, not by a model, and the same answers always give the same result.
Where each member state stands on NIS2
The status of each national implementing law as at 30 September 2026. Authority names and registration routes change; check the authority's own site before you file anything.
| Member state | Status | Authority |
|---|---|---|
| Austria | Adopted, applies later | Bundesamt für Cybersicherheit |
| Belgium | In force | CCB |
| Bulgaria | In force | National cybersecurity authority |
| Croatia | In force | National framework |
| Cyprus | In force | Digital Security Authority |
| Czechia | In force | NÚKIB |
| Denmark | In force | SAMSIK |
| Estonia | In force | RIA |
| Finland | In force | Traficom, NCSC-FI |
| France | Not transposed | ANSSI, MonEspaceNIS2 |
| Germany | In force | BSI |
| Greece | In force | National Cyber Security Authority |
| Hungary | In force | SZTFH |
| Ireland | Not transposed | NCSC-IE |
| Italy | In force | ACN |
| Latvia | In force | National cybersecurity authority |
| Lithuania | In force | NKSC |
| Luxembourg | In force | ILR |
| Malta | Adopted, applies later | Malta Digital Innovation Authority |
| Netherlands | In force | NCSC |
| Poland | In force | Ministry of Digital Affairs |
| Portugal | In force | CNCS |
| Romania | In force | DNSC |
| Slovakia | In force | NBÚ |
| Slovenia | In force | URSIV |
| Spain | Not transposed | Not yet designated in law |
| Sweden | In force | NCSC (FRA) |
Sources
- European Commission, referral of Ireland, Spain, France and the Netherlands to the CJEU for failure to transpose NIS2, 8 July 2026
- National gazettes and authority sites for each member state (full review 2 August 2026, statuses re-checked 30 September 2026)
- Independent trackers cross-checked 30 September 2026: 23 member states with a law in force on 17 September 2026, Austria applying from 1 October 2026
Common questions
Does NIS2 apply to banks?
Not for ICT risk management or incident reporting. DORA is the sector-specific act for financial entities, so under Article 4 of NIS2 a bank's Article 21 measures and Article 23 notifications are replaced by DORA's requirements and supervised by its financial supervisor.
Is an ICT provider to a bank subject to DORA?
Indirectly, yes. The bank must hold the Article 30 contract provisions in its contract with the provider, record the provider in its register of information and evidence its oversight. Only providers designated as critical by the ESAs are overseen directly.
Which member states have not transposed NIS2?
As at 30 September 2026: France, Ireland and Spain. All three were referred to the Court of Justice of the EU on 8 July 2026.
What is the difference between DORA and NIS2?
DORA is a regulation for the financial sector that demands a standing, filed body of evidence: a register of information, Article 30 contract clauses, incident reports on templates and an annually reviewed ICT risk framework. NIS2 is a directive for eighteen sectors that demands appropriate measures and incident notification, with evidence produced when the authority asks.
Book a call for a DORA readiness review
Whether you are the institution or the provider, we read your contracts and register data against DORA and return a gap report in which every finding is cited to its source.
Book a call