Home › DORA › DORA vs NIS2

DORA Compliance

DORA vs NIS2: How They Differ & Overlap

Key takeaway

DORA and NIS2 are complementary EU frameworks for digital resilience. For the ICT risk and incident topics DORA covers, it acts as lex specialis for financial entities — so in-scope firms follow DORA rather than the equivalent NIS2 provisions. Other obligations may still apply.

If your firm is caught by both frameworks on paper, this page explains how they fit together.

Two frameworks, one goal

Venn-style diagram showing where DORA, NIS2 and ISO 27001 overlap and differ, including DORA's lex specialis status for financial entities
Where DORA, NIS2 and ISO 27001 overlap — and where each stands alone.

Both DORA and NIS2 aim to raise digital and cyber resilience across the EU. NIS2 is broad, covering many sectors; DORA is sector-specific to financial services and more prescriptive.

Lex specialis explained

For the subject-matter DORA covers, it operates as lex specialis — the more specific law that takes precedence. For financial entities, this means following DORA’s ICT risk-management and incident-reporting rules instead of the equivalent NIS2 provisions, avoiding duplication.

Which applies to you

If you are a financial entity in DORA’s scope, DORA governs the areas it covers. NIS2 may still be relevant for matters outside DORA’s remit. The two are best seen as complementary rather than competing.

See also DORA vs ISO 27001.

Next step

Want to map your obligations across frameworks? Book a readiness assessment.