• Cybersecurity Glossary
DORA vs NIS2: What is the difference?
DORA and NIS2 are two European Union cybersecurity laws that took effect around the same time but differ in scope and legal form. DORA, Regulation (EU) 2022/2554, is directly applicable and governs the Digital operational resilience of the financial sector and its ICT providers. NIS2, Directive (EU) 2022/2555, is transposed into national law and sets a broad cybersecurity baseline for essential and important entities across many sectors. For financial entities DORA acts as Lex specialis, taking precedence over NIS2 where they overlap. This page compares scope, authorities, reporting timelines and penalties, and shows how Teldat supports both.
DORA and NIS2 at a glance
DORA and NIS2 are the two pillars of the European Union’s current cybersecurity framework, and because they arrived together they are often confused. The simplest way to tell them apart is that NIS2 is broad and horizontal, while DORA is narrow and deep.
NIS2, the Directive (EU) 2022/2555, raises the baseline of cybersecurity across a wide range of sectors, from energy and transport to health and digital infrastructure. As a directive, it sets objectives that each member state writes into its own national law, so the details can vary slightly from country to country while the core obligations stay common.
DORA, the Regulation (EU) 2022/2554, focuses entirely on the financial sector and its technology suppliers, setting detailed rules for digital operational resilience. As a regulation it applies directly and identically in every member state, with no national transposition. For a financial entity that could in theory fall under both, DORA takes precedence on the matters it covers, a relationship that the rest of this page explains. For a European infrastructure manufacturer like Teldat, both laws point to the same need: resilient, sovereign network and security solutions.
DORA vs NIS2 compared
The clearest way to understand the two laws is side by side. The table sets out the dimensions that matter most, from legal form and scope to reporting and penalties.
| Dimension | DORA | NIS2 |
|---|---|---|
| Legal instrument | Regulation (EU) 2022/2554, directly applicable | Directive (EU) 2022/2555, transposed nationally |
| Scope | Financial sector and its ICT providers | Essential and important entities across sectors |
| Focus | Digital operational resilience of finance | Broad network and information security |
| Authority | Financial competent authorities and ESAs | National CSIRTs and competent authorities |
| Incident reporting | 4h initial, 72h intermediate, 1 month final | 24h early warning, 72h notification, 1 month final |
| Maximum penalty | Up to 2% of annual worldwide turnover | Up to 10 million euros or 2% of turnover |
| Precedence | Lex specialis for finance, takes priority | General baseline where DORA does not apply |
Scope and who is affected
The biggest practical difference between the two laws is who they cover. Understanding scope is the first step in working out which regime, or both, applies to a given organization.
Incident reporting timelines
Incident reporting is where the two laws differ most visibly, and where getting it wrong is easiest. Both use a staged model, but the clocks and recipients are not the same. The table compares them.
| Stage | DORA | NIS2 |
|---|---|---|
| First alert | Initial notification within 4 hours of classification | Early warning within 24 hours of awareness |
| Detailed report | Intermediate report within 72 hours | Incident notification within 72 hours |
| Final report | Within one month | Within one month |
| Report to | Financial competent authority | National CSIRT or competent authority |
The four hour clock: DORA’s 4 hour initial notification is the tightest reporting deadline in EU regulation, far shorter than NIS2’s 24 hour early warning. A financial entity subject to both will always hit DORA’s clock first. Meeting a 4 hour deadline is only realistic with strong monitoring and detection in place, which is exactly where extended detection and response such as Teldat be.Safe XDR contributes.
The lex specialis rule
The single most important concept for anyone comparing DORA and NIS2 is lex specialis. It is the rule that stops the two laws from clashing, and it decides which one a financial entity actually follows.
Penalties compared
Both DORA and NIS2 are backed by significant penalties, and both can reach individual managers, not just organizations. The specifics differ because one is a regulation and the other a directive.
When both apply together
In practice, many organizations must think about DORA and NIS2 at the same time. Rather than treating them as two separate burdens, it helps to see where they align and to build once for both.
DORA and NIS2 with Teldat
Teldat is not a compliance consultancy; it is a European manufacturer of the network and security infrastructure that both regimes rely on. Its be.Safe Pro and be.Safe XDR solutions, together with SD-WAN, support the technical requirements DORA and NIS2 share.
One European partner for both regimes: because DORA and NIS2 demand the same technical fundamentals, resilient connectivity, strong security and fast incident detection, Teldat’s combination of SD-WAN, be.Safe Pro and be.Safe XDR helps organizations build once and satisfy both. As a European manufacturer under European jurisdiction, Teldat provides sovereign infrastructure without certifying compliance itself.
FAQ’s DORA and NIS2
❯ What is the difference between DORA and NIS2?
The core difference is scope and legal form. DORA, Regulation (EU) 2022/2554, is a regulation that applies directly across the EU and targets the financial sector and its ICT providers, focusing specifically on digital operational resilience. NIS2, Directive (EU) 2022/2555, is a directive that each member state transposes into national law, and it sets a broad cybersecurity baseline across around 18 sectors of essential and important entities. In short, NIS2 is the wide horizontal baseline for the economy, while DORA is the deep, finance specific rulebook. Where both could apply to a financial entity, DORA takes precedence as lex specialis.
❯ Do DORA and NIS2 apply to the same organizations?
They can overlap, but the rules resolve it. NIS2 covers essential and important entities across sectors such as energy, transport, health, water, digital infrastructure and more. DORA covers financial entities such as banks, insurers, investment firms and payment institutions, plus their critical ICT third party providers. A bank could in principle fall under both, but because DORA is lex specialis for the financial sector, financial entities follow DORA rather than NIS2 for the requirements the two share. Organizations outside finance generally look to NIS2, while some groups with mixed activities must map each entity carefully to the right regime.
❯ What are the incident reporting timelines under DORA and NIS2?
Both use a staged model but with different clocks. DORA requires major ICT incidents to be reported to the competent authority with an initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within one month. NIS2 requires significant incidents to be reported to the national CSIRT or competent authority with an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month. DORA’s 4 hour initial deadline is the tightest in EU regulation, so financial entities subject to both will always meet DORA’s clock first.
❯ What does lex specialis mean for DORA and NIS2?
Lex specialis is a legal principle meaning a specialized law takes precedence over a general one on the same subject. NIS2 itself recognizes DORA as lex specialis for the financial sector: where DORA and NIS2 would both cover the same ICT risk management or incident reporting obligation for a financial entity, DORA’s more detailed, finance specific rules apply instead of NIS2’s general ones. This avoids double regulation and gives financial entities a single, clear rulebook for digital operational resilience, while NIS2 continues to apply to sectors and matters DORA does not address.
❯ What are the penalties under DORA versus NIS2?
Both regimes carry significant penalties. Under NIS2, essential entities can face fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher, with important entities facing somewhat lower caps, and member states set the specifics as it is a directive. Under DORA, financial entities can face administrative fines up to 2% of total annual worldwide turnover for serious breaches, while designated critical ICT third party providers face periodic penalty payments of up to 1% of average daily worldwide turnover for up to six months. Both regimes also allow personal liability for senior management.
❯ How does Teldat help with DORA and NIS2 compliance?
Teldat supports the technical requirements shared by DORA and NIS2 as a European infrastructure manufacturer. be.Safe Pro delivers cloud security with Secure Web Gateway and Next Generation Firewall functions, while be.Safe XDR provides extended detection and response with the monitoring and visibility needed to detect, classify and report incidents within the tight DORA and NIS2 timelines. Combined with resilient Teldat SD-WAN connectivity and operation under European jurisdiction, this helps both financial entities under DORA and essential or important entities under NIS2 build and demonstrate the operational resilience both laws demand.
Meet DORA and NIS2 demands with Teldat
Teldat combines resilient SD-WAN connectivity, be.Safe Pro cloud security and be.Safe XDR detection and response as a European manufacturer under European jurisdiction, helping organizations meet the technical requirements shared by DORA and NIS2.







