DORA and NIS2 are complementary EU frameworks for digital resilience. For the ICT risk and incident topics DORA covers, it acts as lex specialis for financial entities — so in-scope firms follow DORA rather than the equivalent NIS2 provisions. Other obligations may still apply.
If your firm is caught by both frameworks on paper, this page explains how they fit together.
Two frameworks, one goal
Both DORA and NIS2 aim to raise digital and cyber resilience across the EU. NIS2 is broad, covering many sectors; DORA is sector-specific to financial services and more prescriptive.
Lex specialis explained
For the subject-matter DORA covers, it operates as lex specialis — the more specific law that takes precedence. For financial entities, this means following DORA’s ICT risk-management and incident-reporting rules instead of the equivalent NIS2 provisions, avoiding duplication.
Which applies to you
If you are a financial entity in DORA’s scope, DORA governs the areas it covers. NIS2 may still be relevant for matters outside DORA’s remit. The two are best seen as complementary rather than competing.
See also DORA vs ISO 27001.
Want to map your obligations across frameworks? Book a readiness assessment.