DORA vs. NIS2: Which Regulation Does Your Company Need to Comply With? Detailed Comparison Guide
The European Union has implemented two massive cybersecurity regulations to enhance the security of digital infrastructures and create comprehensive resilience against cyber threats: DORA (Digital Operational Resilience Act) and NIS2 (Network and Information Security Directive).
While both regulations aim to fundamentally change companies' cybersecurity and business continuity standards, they contain significant differences in terms of scope, sanctions, and applicable sectors. In this guide, we will analyze the differences between DORA and NIS2, points of overlap, and how to determine which legal regulation your company is subject to, based on official EU directives and regulations.
1. Official Timeline and Legal Entry into Force Dates
Although both regulations came into force during similar time periods, their legal status and implementation calendars differ:
- NIS2 Directive (Directive (EU) 2022/2555): Entered into force on January 16, 2023. The deadline for Member States to transpose this directive into their national laws was October 17, 2024.
- DORA Regulation (Regulation (EU) 2022/2554): As a "regulation," it is a directly applicable legal text and does not require transposition into national law by Member States. DORA has started to apply across the entire EU as of January 17, 2025.
2. Scope Analysis: Which Regulation Applies to Whom?
The scope of the regulations constitutes the most significant difference between them:
A. NIS2 Scope: Broad and Sectoral
NIS2 targets 18 sectors critical to the EU economy and society. Businesses are divided into two categories based on their size and importance: "Essential Sectors" and "Important Sectors."
- Essential Sectors: Energy, Transport, Health, Water, Banking, Financial Market Infrastructures, Digital Infrastructure (cloud providers, data centers), Public Administration, and Space.
- Important Sectors: Postal and Courier Services, Waste Management, Chemicals Production and Distribution, Food Production and Distribution, Manufacturing Industry, Digital Providers (social networks, e-commerce sites), and Research Organizations.
- Size Cap Rule: As a general rule, all medium and large enterprises (businesses with 50 or more employees and/or annual turnover exceeding 10 million euros) fall within the scope of NIS2.
B. DORA Scope: Vertical and Finance-Focused
DORA aims to ensure the digital resilience of the financial sector and directly targets the financial ecosystem.
- Financial Institutions: Banks, credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), insurance companies, and rating agencies.
- Third-Party ICT Providers (Critical Service Providers): Technology companies (even if not financial) that provide cloud computing, data analytics, software, and data center services to financial institutions are also directly included in the scope of DORA.
3. Lex Specialis Principle: The Relationship Between DORA and NIS2
Since both NIS2 and DORA concern financial institutions, there is an overlap between them. This overlap is resolved by the Lex Specialis (Special Law) principle explicitly stated in Article 4 of the NIS2 Directive.
Lex Specialis Rule: If there is a sectoral EU regulation containing rules equivalent to or stricter than NIS2 requirements for a specific sector, that regulation (i.e., DORA) takes precedence over NIS2.
Accordingly:
- If you are a financial institution or an ICT provider serving such institutions, DORA rules apply directly for cybersecurity compliance, not NIS2 rules.
- However, if you are in a critical sector outside finance (e.g., energy, health, or logistics), you must comply with NIS2 rules.
4. Comparison of Key Requirements
Although DORA and NIS2 demand similar cybersecurity practices, DORA has much more specific and strict operational resilience rules for financial transactions.
| Requirement Area | NIS2 (Network and Information Security) | DORA (Digital Operational Resilience) | | :--- | :--- | :--- | | Focus Point | General cybersecurity, network security, and protection of information systems. | Ensuring the financial system can withstand, respond to, and recover from cyber attacks and IT disruptions (resilience). | | Management Responsibility | The management board must approve cybersecurity measures. There is personal administrative liability in case of breaches. | The management board is directly and personally responsible for all IT risks; mandatory IT risk management training is required. | | Incident Reporting | Significant cyber incidents must be reported to the national CSIRT with an early warning within 24 hours and a detailed report within 72 hours. | Critical IT incidents are reported in real-time to the national supervisory authority (e.g., EU equivalents of BDDK/SPK) using very strict templates. | | Penetration Testing | Regular security tests are required, but the mandatory penetration testing methodology is not bound by strict rules. | Threat-Led Penetration Testing (TLPT) is mandatory at least every 3 years. | | Supply Chain Risk | Monitoring the cybersecurity posture of suppliers is required. | Legal requirements for contracts with critical ICT suppliers (SLAs, exit strategies) are dictated by DORA Article 30. |
5. Compliance Roadmap for Companies
To avoid mistakes in legal compliance processes, companies are recommended to follow these 3 steps:
- Sector and Scale Analysis: Determine your company's employee count, annual turnover, and operating sector. If you are in the financial sector or provide cloud/software services to this sector, prepare a DORA roadmap; otherwise, follow national NIS2 regulations for other critical sectors.
- Conduct a Gap Analysis: Compare your existing information security processes with ISO 27001 or NIST standards. Test how prepared you are for the incident reporting templates required by DORA and NIS2.
- Train the Management Board: Both laws impose heavy sanctions on management boards for cybersecurity-related breaches, including personal fines and disqualification. Therefore, involve management in the processes early.
6. Frequently Asked Questions (FAQ)
Question 1: Our company provides both financial services and operates critical infrastructure. Which regulation should we comply with?
Answer: According to the Lex Specialis principle stated in Article 4 of the NIS2 Directive, if a stricter or equivalent sector-specific regulation (DORA) exists, that regulation takes precedence. Therefore, financial institutions and their critical technology partners are directly subject to the DORA regulation.
Question 2: What is the official final compliance deadline for the NIS2 directive?
Answer: NIS2 entered into force on January 16, 2023, and the deadline for EU Member States to transpose this directive into national law was October 17, 2024. National audits have begun since this date.
Question 3: Are TLPT penetration tests under DORA mandatory for all financial institutions?
Answer: No. Under DORA Article 26, Threat-Led Penetration Testing (TLPT) is mandatory only for large-scale institutions deemed "systemic or critically important" by supervisory authorities that could affect financial stability.
Conclusion
NIS2 and DORA have transformed cybersecurity from being an "IT department issue" to a direct "management board and legal compliance responsibility" for all companies wishing to do business in the European Union market. According to the Lex Specialis principle, aligning the financial ecosystem with DORA and all other critical infrastructures with NIS2 is the most important step during this transition process to ensure operational business continuity.
tuncstudio
EU Compliance Team
Providing clear and actionable EU compliance guides for small and medium enterprises.
