NIS2 and DORA are both in force and both imposing compliance obligations in 2026. For organisations in financial services, the relationship between the two frameworks is the central compliance design question. For organisations in other sectors, NIS2 is the primary cyber framework. Understanding the scope, relationship, and design implications of each is essential before investing in control infrastructure.
What is the relationship between NIS2 and DORA?
NIS2 (Directive 2022/2555) establishes a baseline cybersecurity standard across 18 critical sectors in the EU, including energy, transport, healthcare, digital infrastructure, and financial services. It is a Directive, requiring transposition into national law by October 2024 – though not all member states have completed transposition.
DORA (Regulation 2022/2554) entered into force directly on 17 January 2025, without requiring transposition. It applies exclusively to financial entities – including banks, insurers, investment firms, payment institutions, crypto-asset service providers, and critical ICT third-party providers – and introduces more prescriptive obligations specific to the financial sector's resilience requirements.
The lex specialis principle governs the relationship between the two. Where DORA applies to a financial entity, its requirements take precedence over equivalent NIS2 requirements for the overlapping areas. This is confirmed in Article 1(2) of DORA and Recital 28 of NIS2. Full DORA compliance satisfies equivalent NIS2 obligations for financial entities.
Where do the frameworks genuinely overlap?
Both require documented risk management frameworks covering the identification, assessment, and mitigation of ICT risks. Both impose incident reporting obligations, though DORA's timelines are significantly stricter – an initial notification within 4 hours of classification, compared to 24 hours under NIS2. Both require business continuity and recovery planning. Both impose management accountability, with senior leadership personally liable for gross negligence in cybersecurity oversight.
These overlapping areas allow organisations subject to both to design a single integrated control set rather than maintaining parallel programmes.
Where does DORA go further than NIS2?
DORA introduces three significant requirements absent from NIS2 at the same level of prescriptiveness.
Threat-led penetration testing (TLPT): Financial entities above specified thresholds must conduct threat-led penetration testing at least every three years using qualified external testers. The testing methodology is standardised across the EU.
ICT third-party risk management: DORA requires detailed registers of all ICT contracts, specific contractual provisions in agreements with third-party ICT providers, and ongoing monitoring of third-party dependencies. Critical ICT providers can be designated for direct EU-level supervision by the European Supervisory Authorities.
Register of Information: Financial entities were required to submit their first Register of Information – a structured map of ICT third-party dependencies – by March 2026.
How should compliance programmes approach the overlap?
The most efficient approach is to use DORA as the compliance backbone for financial entities, and to verify where NIS2 adds any residual obligations – mainly around national CSIRT coordination, physical security elements, and some aspects of supply chain security not covered by DORA. The areas where NIS2 adds to DORA for financial entities are narrow.
For organisations subject to NIS2 but not DORA – including ICT service providers, cloud infrastructure providers, and non-financial essential entities – NIS2 is the primary framework, though DORA contractual requirements flow through from financial entity customers.
Senior management must be directly engaged in both frameworks. Neither permits cybersecurity to be delegated entirely to the IT function. Boards are expected to approve cybersecurity strategies, receive regular reporting, and demonstrate awareness of the obligations.
What this means for your organisation
- If you are a financial entity, DORA is your primary compliance framework and its obligations are already enforceable. The first Register of Information submissions were due in March 2026. If you have not completed this, you are already behind.
- If you are subject to NIS2 but not DORA – including digital infrastructure providers, cloud service providers, and non-financial essential entities – the practical NIS2 compliance deadline is October 2026.
- ICT service providers who are not themselves financial entities but whose clients are financial entities face DORA contractual requirements flowing through from those clients. Your compliance posture affects their compliance posture.
- Senior management is personally liable under both frameworks. Cybersecurity cannot be delegated entirely to the IT function – boards must approve strategies, receive regular reporting, and demonstrate informed oversight.
What you should do now
- Determine whether you are in scope for DORA, NIS2, or both, based on your sector, size, and the services you provide.
- If subject to DORA, confirm your Register of Information is complete and your ICT third-party contracts include the required provisions.
- Conduct a gap analysis against NIS2 risk management, incident reporting, and supply chain security obligations.
- Map existing controls against both frameworks to identify where a single control can satisfy multiple obligations and where gaps remain.
- Ensure your incident response playbooks reflect DORA's 4-hour initial reporting timeline for financial entities – this is significantly stricter than most organisations' existing procedures.
How Priventia helps
Priventia's Cybersecurity and Operational Resilience module maps NIS2 obligations across the controls architecture, covering ICT risk management, incident reporting, and supply chain security requirements. DORA-specific controls for financial entities are being integrated. The Compliance Intelligence Assessment covers NIS2 and DORA alongside privacy and due diligence.