Compliance

DORA vs NIS2: EU Compliance Guide for CTOs & CIOs

DORA vs NIS2: EU Compliance Guide for CTOs & CIOs

If you run technology, security, or infrastructure for a company that touches EU customers, you’ve probably heard both acronyms thrown around interchangeably — they aren’t the same thing. DORA vs NIS2 comes down to one question: are you a regulated financial entity, a critical-infrastructure operator, or, increasingly, both? Getting the answer wrong means either over-building compliance you don’t need or missing obligations that now carry real fines. This guide breaks down what each regulation actually requires, where they overlap, and how to determine — in minutes, not weeks — which one governs your organization. If you’d rather have someone map this against your actual environment, our compliance audit service does exactly that.

What is DORA?

The Digital Operational Resilience Act (DORA) is Regulation (EU) 2022/2554, and it has been directly applicable across all EU member states since January 17, 2025. Because it’s a regulation rather than a directive, DORA doesn’t need to be transposed into national law — the same rules apply, word for word, in every member state simultaneously.

DORA is a lex specialis: a specialized law built for one sector — finance. It applies to roughly 20 categories of financial entities, including banks, credit institutions, payment and e-money firms, investment firms and asset managers, insurance and reinsurance undertakings, crypto-asset service providers, and crowdfunding platforms. It also reaches the critical ICT third-party providers that serve them — cloud platforms, data centers, and credit rating or data analytics services.

DORA is built around five pillars: ICT risk management, incident reporting (including a strict initial classification window), digital operational resilience testing (with mandatory Threat-Led Penetration Testing every three years for significant institutions), third-party ICT risk management, and voluntary information sharing on cyber threats.

What is NIS2?

NIS2 — Directive (EU) 2022/2555 — is the EU’s horizontal cybersecurity framework. Unlike DORA, it’s a directive, so each member state writes its own implementing legislation. The formal transposition deadline was October 17, 2024, but as of 2026, several countries are still finalizing their national frameworks, which means the practical rules can vary depending on where your entity is established.

NIS2 covers 18 sectors, split into two tiers under the European Commission’s NIS2 framework:

  • Essential entities (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space
  • Important entities (Annex II): postal and courier services, waste management, chemicals, food production, manufacturing, digital providers, and research organizations

A size-cap rule generally brings medium and large organizations (50+ employees or €10 million+ turnover) into scope, though some entities are covered regardless of size due to their criticality. Core obligations include ten minimum risk-management measures — incident handling, business continuity, supply-chain security, vulnerability management, access control, and multi-factor authentication among them — plus a tiered incident-reporting timeline: a 24-hour early warning, a 72-hour detailed notification, and a final report within one month.

DORA vs NIS2: key differences at a glance

AspectDORANIS2
Legal instrumentRegulation — directly applicable, identical across the EUDirective — transposed into national law, varies by member state
Applicable sinceJanuary 17, 2025Transposition deadline October 17, 2024 (still uneven by country in 2026)
ScopeFinancial sector only, plus critical ICT third-party providers18 sectors: energy, transport, health, digital infrastructure, manufacturing, and more
Size thresholdNo general size cap — determined by entity typeMedium/large entities (50+ staff, €10M+ turnover), with some exceptions
Incident reportingInitial classification promptly, with intermediate and final reports on tight timelines24-hour early warning, 72-hour notification, 1-month final report
Resilience testingMandatory Threat-Led Penetration Testing every 3 years for significant entitiesRisk-based vulnerability assessments and penetration testing
Maximum penaltiesUp to 2% of annual worldwide turnover; ICT providers up to 1% of average daily turnover per day (max 6 months)Essential entities: €10M or 2% global turnover. Important entities: €7M or 1.4%
Oversight bodyFinancial supervisory authorities (national competent authorities, ESAs)National cybersecurity authorities / CSIRTs, coordinated via ENISA
DORA vs NIS2: key differences at a glance

Do DORA and NIS2 overlap?

Yes — and this is where most engineering leaders get tripped up. DORA explicitly states that it functions as lex specialis to NIS2 for entities within its scope. In practice, that means a bank or insurer that fully complies with DORA’s ICT risk management, testing, and incident-reporting rules has also satisfied the equivalent NIS2 requirements — you don’t have to run two parallel compliance programs for the same controls.

But the overlap doesn’t stop there. If your company provides cloud infrastructure, managed hosting, or data services to financial-sector clients, you can be pulled into DORA’s oversight regime as a “critical ICT third-party provider” and into NIS2 as a digital infrastructure or ICT service management provider in your own right. According to ENISA’s guidance on the NIS framework, classification depends on the specific service relationship, not just your industry label — so two companies offering nearly identical services can land in different regulatory buckets.

Who typically falls under both

Cloud and hosting providers serving banks, SaaS vendors handling payment data, managed security providers, and data-center operators with financial-sector clients are the groups most likely to face dual obligations. If any of that sounds like your business, treat this as a “when,” not an “if.”

How to determine which regulation applies to you

Work through these questions in order — most companies land on an answer after the first two:

  1. Are you a regulated financial entity? Bank, insurer, investment firm, payment provider, or crypto-asset service provider — if yes, DORA applies to you directly.
  2. Do you operate in one of NIS2’s 18 sectors and meet the size thresholds? If yes, NIS2 applies, and you’ll need to check your national transposition law for local specifics.
  3. Do you supply ICT, cloud, hosting, or data services to financial-sector clients? If yes, you may be designated a critical ICT third-party provider under DORA regardless of your own sector.
  4. Are you headquartered outside the EU but serving EU clients? Both regulations can still apply based on where the services are delivered, not where you’re incorporated.

If more than one answer is “yes,” you’re likely subject to overlapping obligations, and mapping exactly which controls satisfy which regulation becomes the priority — this is precisely the gap analysis our IT audit services team runs for clients before it becomes an audit finding.

What penalties look like in practice

Enforcement stopped being theoretical in 2026. NIS2 penalties are harmonized across the EU: essential entities face fines up to €10 million or 2% of global annual turnover, whichever is higher, while important entities face up to €7 million or 1.4%. DORA doesn’t set one fixed fine — national competent authorities can impose sanctions of up to 2% of annual worldwide turnover for serious violations, and critical ICT third-party providers can be fined daily, up to 1% of average daily turnover, for as long as six months of continued non-compliance. Both frameworks also expose senior management to personal liability for gross negligence, which is why boards are now asking CTOs and CISOs for documented evidence, not verbal assurances.

Building a compliance-ready foundation

Regardless of which regulation applies, the underlying engineering work looks similar. A practical readiness checklist:

  • Map every ICT asset, dependency, and third-party vendor tied to critical business functions
  • Implement continuous monitoring and automated, immutable audit trails for compliance evidence
  • Define and test incident classification and reporting workflows against the applicable deadlines
  • Run regular resilience testing — vulnerability scans at minimum, TLPT if DORA applies
  • Formalize third-party and supply-chain risk management, including contractual audit rights
  • Assign clear management accountability and document board-level oversight

Building DORA or NIS2 compliance into your infrastructure, not bolted on after

Compliance work usually falls on engineering teams already stretched thin on delivery. Gart Solutions works alongside CTOs, CIOs, and platform teams to turn DORA and NIS2 requirements into infrastructure that’s compliant by design — not a spreadsheet exercise re-done every audit cycle.

Compliance & IT Audits Gap analysis against DORA, NIS2, SOC 2, HIPAA, and PCI-DSS, mapped to your actual environment.
DevSecOps by Design Real-time scanning of code, containers, and runtimes, with automated audit trails baked into the pipeline.
SRE & Resilience Testing Disaster recovery, business continuity, and monitoring built to withstand — and prove — operational resilience.
Talk to Our Compliance & DevOps Team

You might also like

Fedir Kompaniiets

Fedir Kompaniiets

Co-founder & CEO, Gart Solutions · Cloud Architect & DevOps Consultant

Fedir is a technology enthusiast with over a decade of diverse industry experience. He co-founded Gart Solutions to address complex tech challenges related to Digital Transformation, helping businesses focus on what matters most — scaling. Fedir is committed to driving sustainable IT transformation, helping SMBs innovate, plan future growth, and navigate the “tech madness” through expert DevOps and Cloud managed services. Connect on LinkedIn.

FAQ

What is the main difference between DORA and NIS2?

DORA is an EU regulation that applies directly, without national transposition, exclusively to the financial sector. NIS2 is a directive that member states transpose into national law, covering 18 broader sectors. Where both could apply to a financial entity, DORA takes precedence as lex specialis.

Does DORA replace NIS2 for financial institutions?

Largely, yes, for matters DORA already regulates. A bank or insurer that fully complies with DORA's ICT risk management, incident reporting, and resilience testing has satisfied the equivalent NIS2 obligations. NIS2 can still apply for activities outside DORA's scope.

Who needs to comply with DORA?

Roughly 20 categories of financial entities operating in the EU — credit institutions, payment and e-money firms, investment firms, insurers, crypto-asset service providers, crowdfunding platforms, and credit rating agencies — plus the critical ICT third-party providers that serve them.

Which sectors does NIS2 cover?

18 sectors split into essential entities (energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space) and important entities (postal, waste management, chemicals, food, manufacturing, digital providers, research).

Can a company be subject to both DORA and NIS2?

Yes. Cloud providers, data centers, and managed service providers serving financial clients can be classified as critical ICT third-party providers under DORA and, separately, as digital infrastructure providers under NIS2 — based on the specific service, not just your industry.

What are the penalties for non-compliance?

NIS2 fines reach €10 million or 2% of global turnover for essential entities, and €7 million or 1.4% for important entities. DORA allows penalties up to 2% of annual worldwide turnover, plus daily fines for critical ICT providers of up to 1% of average daily turnover for up to six months. Both allow for personal liability of senior management.

How do I know which regulation applies to my company?

Start with your sector and client base: regulated financial entities fall under DORA; NIS2-sector companies meeting the size thresholds fall under NIS2; ICT and cloud vendors serving financial clients may face both. A compliance audit is the fastest way to confirm your exact obligations rather than guessing from sector labels alone.
arrow arrow

Thank you
for contacting us!

Please, check your email

arrow arrow

Thank you

You've been subscribed

We use cookies to enhance your browsing experience. By clicking "Accept," you consent to the use of cookies. To learn more, read our Privacy Policy