DORA vs NIS2: differences, overlaps and what to do if both apply to you

By the QuantumSec team

If your company operates in the financial sector in Europe, both DORA and NIS2 probably apply to you — and the most common question is: are they redundant? Do I have to do the work twice? The short answer is no, but there are important nuances worth understanding before starting any compliance project.

What DORA is and who it applies to

The Digital Operational Resilience Act (DORA) is an EU regulation (directly applicable, with no national transposition needed) that took effect in January 2025. It applies specifically to the financial sector: credit institutions, investment firms, payment institutions, crypto-asset service providers, fund managers, insurers and their critical ICT providers. The goal is to ensure the financial sector can withstand, respond to and recover from ICT-related disruptions.

What NIS2 is and who it applies to

The NIS2 Directive (Network and Information Security 2) covers more sectors and applies to 18 critical sectors: energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT, space, public administration and several additional sectors (manufacturing, food, postal services). Unlike DORA, it's a directive (requiring national transposition) and applies to medium and large companies in those sectors.

Key differences between DORA and NIS2

Legal instrument: DORA is a regulation (direct application); NIS2 is a directive (requires transposition).

Sectors: DORA covers exclusively the financial sector and its ICT providers; NIS2 covers 18 critical sectors.

Technical depth: DORA is far more specific and demanding on digital operational resilience, ICT risk management, resilience testing (including TLPT — Threat-Led Penetration Testing) and third-party management. NIS2 sets more general risk management and notification requirements.

Fines: DORA can impose fines of up to 2% of global turnover and criminal penalties on executives. NIS2 goes up to €10M or 2% of turnover for essential entities.

Overlaps: what you can reuse

Both regulations require ICT risk management, incident management, business continuity and disaster recovery, third-party supply chain management, and staff training. If you already have an ISMS based on ISO 27001, many controls are reusable with adaptations. The key is running one integrated project instead of two parallel ones.

What to do if both apply to you

The starting point is an integrated gap analysis that maps your current controls against DORA and NIS2 requirements simultaneously. You identify the common controls (only need to be implemented once), the DORA-specific controls (especially those related to TLPT and advanced third-party management) and the NIS2-specific ones (24/72-hour notification, entity registration). The resulting compliance plan is more efficient and avoids duplicate effort and documentation.

FAQ

Does DORA replace NIS2 for the financial sector?

Not exactly. DORA is lex specialis relative to NIS2 for financial entities within its scope: where there's overlap, DORA prevails. But NIS2 can still apply to aspects or entities not covered by DORA within the financial sector.

Are financial-sector ICT providers required to comply with DORA?

Critical ICT providers designated by the European supervisory authorities (ESAs) are subject to direct supervision under DORA. All other ICT providers to financial entities are covered indirectly, through the third-party management requirements DORA imposes on their financial clients.