DORA vs NIS2: Which Legal Act Applies to Us?

DORA (Regulation (EU) 2022/2554) and NIS2 (Directive (EU) 2022/2555) side by side: scope, regulatory depth, reporting duties and supervision — and why sector-specific law takes precedence for financial entities.

DORA vs. NIS2DORALast reviewed:

DORA and NIS2 came into being almost simultaneously. They address the same concern, the dependence of entire sectors of the economy on IT that works, and they use largely the same building blocks: risk management, incident reporting, management of third parties, responsibility of the management body. For those responsible for compliance, the first question is therefore one of allocation, and only then one of substance.

The allocation question is usually answered faster than it looks. DORA applies to financial entities and to critical ICT third-party service providers. NIS2 applies, in Germany through the BSI Act, to entities in a range of critical sectors, determined by sector and company size. Anyone who neither belongs to the financial sector nor works for it as an ICT service provider need not concern themselves with DORA.

The borderline cases are harder, and more frequent than expected. A financial entity can also come into view sectorally under NIS2, and that is where the precedence of sector-specific law applies. An IT service provider can fall under the BSIG and at the same time be exposed to DORA requirements through its customers' contracts without being an addressee of the regulation itself. And in groups with both financial and non-financial companies, both regimes apply alongside each other, only to different entities.

Side by side

CriterionDORANIS2
Legal formRegulation (EU) 2022/2554. As a regulation it applies directly in all Member States and in identical wording; no national transposition act is needed for that.Directive (EU) 2022/2555. As a directive it is addressed to the Member States and takes effect only through national law: in Germany through the NIS-2-Umsetzungsgesetz, which anchors the requirements in the BSI Act.
Application in GermanyApplicable since January 2025. The regulation is given detail by technical regulatory and implementing standards from the European supervisory authorities.The NIS-2-Umsetzungsgesetz has been in force since 6 December 2025. The governing text is therefore the BSIG, which may differ in detail from other national transpositions.
Scope of applicationFinancial entities in a broad sense, among them credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, management companies and providers of crypto-asset services. Critical ICT third-party service providers are additionally covered.Entities in sectors of high criticality and in other critical sectors, among them energy, transport, health, water, digital infrastructure, waste, chemicals, food and manufacturing. What governs are sector and company size under § 28 BSIG. Public administration does not appear in the BSIG annexes: federal administration bodies sit in § 29 BSIG, and Land law applies to the administrations of the Länder.
Which one gives waySector-specific law for the financial sector. For the areas DORA regulates, the regulation takes precedence over the corresponding requirements of NIS2.The general framework. The directive expressly gives precedence to equivalent sector-specific requirements; for financial entities that is DORA.
Regulatory depthHigh. The regulation is already detailed in its own text and is given further detail by binding technical standards. The room for interpretation is correspondingly narrow.Minimum harmonisation. The directive names minimum content and Member States may go further. The detail is added nationally, through the BSIG and the practice of the BSI.
ICT risk managementChapter II (Articles 5 to 16) requires a documented ICT risk management framework with strategies, policies, procedures and tools: from protection and detection through response and recovery to learning and communication. A simplified framework is provided for small entities.§ 30 BSIG requires appropriate, proportionate technical and organisational measures on the basis of an all-hazards approach. The areas of measures are listed; the methodology is left open.
Reporting dutiesChapter III (Articles 17 to 23). Major ICT-related incidents have to be classified and reported to the competent supervisory authority in stages: initial notification, intermediate report, final report. Voluntary notification is provided for significant cyber threats.§ 32 BSIG. Significant security incidents have to be reported in stages to a reporting office set up jointly by the BSI and the BBK: early initial notification, a fuller follow-up notification, final notification. Criteria and deadlines follow from the act.
Resilience testingChapter IV (Articles 24 to 27) requires a programme for testing digital operational resilience. For certain entities, threat-led penetration testing comes on top.Requires policies to assess the effectiveness of the measures, along with basic training and awareness measures. The act does not prescribe a standalone, formalised testing programme of comparable depth.
Third parties and supply chainChapter V Section I (Articles 28 to 30) governs contractual content, exit strategies, concentration risk and a register of information on all contractual arrangements for the use of ICT services.Supply chain security and the relationships with direct suppliers and service providers are among the required areas of measures. The BSIG has no register of information.
Supervision of service providersChapter V Section II (Articles 31 to 44) establishes a European oversight framework for critical ICT third-party service providers. The European supervisory authorities published a first list of such providers in November 2025.No separate supervisory regime. A provider is covered only where it falls within the scope as an entity in its own right.
Responsibility of the management bodyThe management body bears ultimate responsibility for ICT risk management, sets responsibilities, approves the strategy and must keep its own knowledge of ICT risk up to date.§ 38 BSIG obliges the management body to implement the risk-management measures and oversee their implementation, attaches company-law liability to that duty and provides for a training duty.
Competent supervisory authorityThe financial supervisor; in Germany, BaFin. For critical ICT third-party service providers, the European oversight framework of the European supervisory authorities comes on top.The BSI, with powers to request information, examine and issue orders. The intensity of examination depends on the entity category.

Our verdict

The first answer is an allocation, not a weighing-up. You cannot choose between DORA and NIS2; the scope decides about you.

Financial entities follow DORA. Where the regulation governs ICT risk management, incident reporting, resilience testing and third-party risk, it takes precedence over the corresponding requirements of NIS2. That is a relief: no second, parallel regime arises for the same subject matter. It is a relief only where DORA actually governs, however. Other duties under national law remain untouched, and the demarcation in an individual case belongs in a legal assessment.

Companies outside the financial sector follow the BSIG, provided they are in scope by sector and size. DORA is relevant to them only indirectly, namely where they supply ICT services to financial entities. The DORA requirements then reach them through contractual clauses, rights to information and audit, and exit arrangements, without their being an addressee of the regulation. This contractual pass-through is the route by which DORA actually reaches most non-financial companies. Groups with a mixed portfolio have to classify company by company: a blanket group-wide answer regularly misleads, because scope and supervision attach to the individual entity.

On substance, the overlap is worth a look. ICT risk management, incident detection and handling, business continuity, access control and the management of service providers are required under both regimes. Anyone running a common foundation for them — an information security management system with a clean link to assets and risks — can use the same measures and evidence more than once and need only keep the regime-specific superstructures apart.

The differences that cannot be merged are the formal ones: different reporting routes to different authorities, different thresholds and classifications and, in DORA's case, the register of information and the testing programme, for which NIS2 has no equivalent of comparable depth. Plan those parts separately rather than forcing them into a shared grid.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework