DORA vs NIS2: Complete Comparison Guide for 2026 — Who Must Comply, Overlaps and Key Differences
Published 29 Revisado / June 2026 · IgeraSolutions Editorial Team · 11 min read
DORA and NIS2 are the two most significant EU cybersecurity and digital resilience regulations in force as of 2026. Both impose ICT risk management requirements, incident reporting obligations and third-party risk management rules. Yet they have fundamentally different scopes, governance structures and enforcement mechanisms. Understanding which applies to your organisation — and how to handle the overlap — is one of the most common compliance questions reaching RegTech teams across Europe. This guide provides the definitive 2026 comparison.
Key takeaway
DORA is a sector-specific regulation that overrides NIS2 for financial entities (Art. 1(2) DORA). If your organisation is a bank, insurer, investment firm, payment institution or crypto-asset service provider in the EU, DORA is your primary cybersecurity regulation — not NIS2. However, if you provide ICT services to financial entities, NIS2 may apply to you even if DORA does not. And many large organisations fall under both.
At a glance: DORA vs NIS2
| Dimension | DORA | NIS2 |
|---|---|---|
| Full name | Digital Operational Resilience Act (EU) 2022/2554 | Network and Information Security Directive 2022/2555 |
| Legal form | EU Regulation — directly applicable in all member states | EU Directive — transposed into national law by each member state |
| Application date | 17 January 2025 | 17 October 2024 (transposition deadline; varies by member state) |
| Who it covers | Financial entities (banks, insurers, investment firms, payment institutions, crypto, CCPs, etc.) | Essential and important entities across 18 sectors (energy, transport, health, digital infrastructure, manufacturing, etc.) |
| Supervisory body | National financial supervisors (ECB, national competent authorities) + ESAs for critical ICT providers | National cybersecurity authorities (ENISA coordinates; Spain: INCIBE-CERT/CCN-CERT) |
| Max penalty | Up to 1% of total annual worldwide turnover (per day, up to 5 years for critical ICT providers) | €10M or 2% of worldwide turnover (essential entities); €7M or 1.4% (important entities) |
| ICT testing | Mandatory TLPT every 3 years (significant entities); basic tests annually (all) | Member state discretion; no mandatory TLPT in NIS2 itself |
Scope deep-dive: who must comply with each
DORA scope (Art. 2)
- Credit institutions (banks)
- Payment institutions and e-money institutions
- Insurance and reinsurance undertakings
- Investment firms and fund managers (UCITS/AIFM)
- Central counterparties (CCPs) and trade repositories
- Crypto-asset service providers (CASPs under MiCA)
- Credit rating agencies and data reporting services
- ICT third-party service providers (when designated as critical)
NIS2 scope (Annex I & II)
- Energy (electricity, gas, district heating, oil)
- Transport (air, rail, road, maritime)
- Banking sector (but DORA overrides for core requirements)
- Health (hospitals, pharma, medical devices)
- Drinking water and waste water
- Digital infrastructure (DNS, cloud, data centres, CDN)
- ICT service management and digital providers
- Manufacturing, food, chemicals, postal services
The DORA–NIS2 overlap: organisations subject to both
Art. 1(2) DORA states that for financial entities, DORA's requirements on ICT risk management, incident reporting and testing take precedence over equivalent NIS2 requirements. However, this lex specialis rule does not eliminate NIS2 obligations entirely. Key overlap scenarios:
Cloud providers serving financial entities
A cloud provider (AWS, Azure, Google Cloud, or a tier-2 regional provider) serving banks falls under NIS2 as a digital infrastructure provider AND may be designated as a Critical ICT Third-Party Provider under DORA Art. 31, triggering direct ESA supervision. DORA's third-party requirements flow down to the provider; NIS2 applies independently.
Energy-sector insurance companies
An insurer that primarily underwrites energy sector risks is subject to DORA as an insurance undertaking. But if it also operates energy-adjacent digital infrastructure (e.g., a subsidiary running smart-grid software), that subsidiary may separately fall under NIS2's energy sector scope.
Healthcare fintech
A startup providing health insurance analytics via a SaaS platform may trigger both NIS2 (as a health sector digital service provider) and DORA (as a technology provider to regulated insurance firms). The compliance officer must map obligations from both regulations and identify where DORA's lex specialis applies.
Incident reporting: critical differences
| Aspect | DORA (Arts. 19–20) | NIS2 (Art. 23) |
|---|---|---|
| Initial notification | 4 hours (early warning) | 24 hours (early warning) |
| Intermediate report | 72 hours | 72 hours |
| Final report | 1 month after resolution | 1 month after early warning |
| Notify to | Lead financial supervisor (e.g., ECB, national competent authority) | National NIS authority (INCIBE/CCN-CERT in Spain); may notify ENISA |
| Client notification | Required when incident impacts clients | Required for significant incidents affecting service recipients |
Practical tip: use one incident management process for both
If your organisation falls under both DORA and NIS2, design a single incident detection-classification-notification workflow that satisfies the stricter of the two requirements at each step. Since DORA's 4-hour initial notification is stricter than NIS2's 24-hour window, DORA drives the timeline. The notification goes to your financial supervisor (DORA) and, if NIS2 also applies, to the national NIS authority. IgeraRegTech can generate the notification templates for both regulators from a single incident record.
For more information and a reference guide about this vertical, visit our Igera pillar page.
DORA, NIS2 and beyond — one platform for all EU regulatory questions
IgeraRegTech has DORA, NIS2, all 14 ESA technical standards and national transpositions indexed and searchable. Ask any compliance question and get the exact article citation. No hallucinations.
See IgeraRegTechReviewed by: IgeraSolutions Compliance Team
How does IgeraRegTech help with regulatory compliance?
IgeraRegTech indexes complex regulations like DORA, NIS2, or the AI Act and answers compliance questions in seconds, citing the exact article and paragraph of the legal text.
Does the system hallucinate or invent regulatory articles?
No. Thanks to the RAG architecture, IgeraRegTech only answers based on the official texts of the directives and regulations loaded into the knowledge base.
Is it secure to upload sensitive corporate documentation to the system?
Absolutely. Documents are stored securely on encrypted servers in the EU and processed under strict security controls that guarantee confidentiality.
What advantages does it offer over conventional search tools?
It allows semantic and complex searches in natural language, finding cross-references between different regulations without needing to know the exact legal terms.
How are regulations kept updated in the system?
Our team continuously updates the regulatory repository as the EU and national regulators publish new technical standards and implementation guidelines.
Does IgeraRegTech provide legal advice?
No. IgeraRegTech is a compliance assistance and auditing tool that facilitates quick access to legal texts, but it does not replace qualified legal counsel.