Logo Teldat

• Cybersecurity Glossary

DORA vs NIS2: What is the difference?

DORA and NIS2 are two European Union cybersecurity laws that took effect around the same time but differ in scope and legal form. DORA, Regulation (EU) 2022/2554, is directly applicable and governs the Digital operational resilience of the financial sector and its ICT providers. NIS2, Directive (EU) 2022/2555, is transposed into national law and sets a broad cybersecurity baseline for essential and important entities across many sectors. For financial entities DORA acts as Lex specialis, taking precedence over NIS2 where they overlap. This page compares scope, authorities, reporting timelines and penalties, and shows how Teldat supports both.

DORA and NIS2 at a glance

DORA and NIS2 are the two pillars of the European Union’s current cybersecurity framework, and because they arrived together they are often confused. The simplest way to tell them apart is that NIS2 is broad and horizontal, while DORA is narrow and deep.

NIS2, the Directive (EU) 2022/2555, raises the baseline of cybersecurity across a wide range of sectors, from energy and transport to health and digital infrastructure. As a directive, it sets objectives that each member state writes into its own national law, so the details can vary slightly from country to country while the core obligations stay common.

DORA, the Regulation (EU) 2022/2554, focuses entirely on the financial sector and its technology suppliers, setting detailed rules for digital operational resilience. As a regulation it applies directly and identically in every member state, with no national transposition. For a financial entity that could in theory fall under both, DORA takes precedence on the matters it covers, a relationship that the rest of this page explains. For a European infrastructure manufacturer like Teldat, both laws point to the same need: resilient, sovereign network and security solutions.

DORA vs NIS2 compared

The clearest way to understand the two laws is side by side. The table sets out the dimensions that matter most, from legal form and scope to reporting and penalties.

Dimension DORA NIS2
Legal instrument Regulation (EU) 2022/2554, directly applicable Directive (EU) 2022/2555, transposed nationally
Scope Financial sector and its ICT providers Essential and important entities across sectors
Focus Digital operational resilience of finance Broad network and information security
Authority Financial competent authorities and ESAs National CSIRTs and competent authorities
Incident reporting 4h initial, 72h intermediate, 1 month final 24h early warning, 72h notification, 1 month final
Maximum penalty Up to 2% of annual worldwide turnover Up to 10 million euros or 2% of turnover
Precedence Lex specialis for finance, takes priority General baseline where DORA does not apply

Scope and who is affected

The biggest practical difference between the two laws is who they cover. Understanding scope is the first step in working out which regime, or both, applies to a given organization.

1
NIS2 covers many sectors
NIS2 applies to essential and important entities across around 18 sectors, including energy, transport, banking, health, water, digital infrastructure and public administration. It casts a wide net over the economy, aiming to raise the cybersecurity baseline everywhere that a disruption would have serious knock on effects.
2
DORA covers finance and its ICT providers
DORA applies to more than 22,000 financial entities, from banks and insurers to investment firms, payment institutions and crypto asset providers, plus their critical ICT third party providers. Its scope is narrower than NIS2 but far more detailed, reflecting the systemic importance of financial stability.
3
The overlap in the financial sector
Banking is named in both laws, which is where confusion arises. A bank could in theory be an essential entity under NIS2 and a financial entity under DORA at once. The regulations resolve this deliberately, so a financial entity does not have to satisfy two overlapping sets of rules for the same thing.
4
Groups with mixed activities
Large groups may contain both financial entities and non financial ones, such as an energy company with a captive finance arm. Each legal entity must be mapped to the right regime, so a single organization can end up managing DORA and NIS2 in parallel across its different parts.

Incident reporting timelines

Incident reporting is where the two laws differ most visibly, and where getting it wrong is easiest. Both use a staged model, but the clocks and recipients are not the same. The table compares them.

Stage DORA NIS2
First alert Initial notification within 4 hours of classification Early warning within 24 hours of awareness
Detailed report Intermediate report within 72 hours Incident notification within 72 hours
Final report Within one month Within one month
Report to Financial competent authority National CSIRT or competent authority

The four hour clock: DORA’s 4 hour initial notification is the tightest reporting deadline in EU regulation, far shorter than NIS2’s 24 hour early warning. A financial entity subject to both will always hit DORA’s clock first. Meeting a 4 hour deadline is only realistic with strong monitoring and detection in place, which is exactly where extended detection and response such as Teldat be.Safe XDR contributes.

The lex specialis rule

The single most important concept for anyone comparing DORA and NIS2 is lex specialis. It is the rule that stops the two laws from clashing, and it decides which one a financial entity actually follows.

1
What Lex specialis means
Lex specialis is a legal principle under which a specialized law takes precedence over a general one covering the same subject. Applied here, DORA is the specialized law for the financial sector, so its detailed rules override the more general requirements of NIS2 wherever the two would otherwise overlap.
2
NIS2 explicitly defers to DORA
NIS2 itself recognizes DORA as lex specialis for financial entities. This is not a matter of interpretation but is written into the framework, so a bank follows DORA’s ICT risk and incident rules rather than trying to satisfy NIS2’s parallel provisions on the same topics.
3
It avoids double regulation
The purpose of the rule is to prevent financial entities from having to comply with two overlapping regimes for the same obligation. Without it, a bank might face conflicting ICT risk or reporting duties under both laws; with it, DORA provides one clear, authoritative rulebook for the sector.
4
NIS2 still matters for the rest
Lex specialis only displaces NIS2 where DORA actually applies. NIS2 continues to govern the many sectors DORA does not touch, and can still be relevant to a financial group’s non financial entities, so most large organizations need to understand both rather than just one.

Penalties compared

Both DORA and NIS2 are backed by significant penalties, and both can reach individual managers, not just organizations. The specifics differ because one is a regulation and the other a directive.

1
NIS2 penalties
Under NIS2, essential entities can face fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Important entities face somewhat lower ceilings. As a directive, exact amounts are set by each member state in its transposing law, so figures vary across the EU.
2
DORA penalties for entities
Under DORA, financial entities can face administrative fines of up to 2% of total annual worldwide turnover for serious breaches. Because DORA is directly applicable, this ceiling is consistent across the EU, though member states set the detailed enforcement rules around it.
3
DORA penalties for ICT providers
DORA adds a distinct regime for designated critical ICT third party providers: the lead overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover for each day of non compliance, for up to six months. NIS2 has no equivalent direct oversight of providers.
4
Personal liability in both
Both laws can hold senior management personally accountable for governance failures, reflecting a wider EU trend of making boards responsible for cyber resilience. This raises the stakes under either regime and makes demonstrable, well documented resilience a direct concern for executives.

When both apply together

In practice, many organizations must think about DORA and NIS2 at the same time. Rather than treating them as two separate burdens, it helps to see where they align and to build once for both.

1
Shared technical foundations
Despite their differences, both laws demand the same technical fundamentals: strong ICT risk management, resilient networks, effective monitoring and rapid incident detection and reporting. An organization that builds these well is moving toward compliance with both at once, rather than solving each in isolation.
2
One incident process, aligned reports
Where an incident could trigger both regimes, a single, well instrumented incident response process that produces consistent, timestamped records lets an organization meet each law’s timeline from one source of truth, rather than running conflicting parallel processes that risk contradicting each other.
3
The third party dimension
Both laws push organizations to scrutinize their supply chains, and DORA goes further by supervising critical ICT providers directly. Choosing resilient, European infrastructure partners helps satisfy the third party expectations that run through both regimes, turning supplier choice into part of compliance.
4
European sovereignty as common ground
Both DORA and NIS2 are expressions of the EU’s drive for digital sovereignty and resilience. Infrastructure that is designed, built and operated under European jurisdiction aligns naturally with the spirit of both, which is where a European manufacturer like Teldat fits the picture.

DORA and NIS2 with Teldat

Teldat is not a compliance consultancy; it is a European manufacturer of the network and security infrastructure that both regimes rely on. Its be.Safe Pro and be.Safe XDR solutions, together with SD-WAN, support the technical requirements DORA and NIS2 share.

1
be.Safe XDR for detection and reporting
be.Safe XDR provides extended detection and response, correlating signals across the network to spot incidents fast. This monitoring and visibility is what makes meeting DORA’s 4 hour and NIS2’s 24 hour reporting clocks realistic, turning detection into the timely, evidenced notifications both laws require.
2
be.Safe Pro for cloud security
be.Safe Pro delivers cloud security with Secure Web Gateway and Next Generation Firewall functions, protecting how users and branches reach the internet and cloud. This supports the ICT risk management and protective measures that sit at the heart of both DORA and NIS2.
3
Resilient SD-WAN connectivity
Teldat SD-WAN provides self healing, redundant connectivity that keeps services running through disruptions. Operational resilience of this kind is a direct requirement of DORA and a core expectation of NIS2, making resilient connectivity foundational to both.
4
European manufacturer and third party risk
As a European manufacturer under European jurisdiction, Teldat offers a sovereign infrastructure partner that helps address the ICT third party and supply chain expectations in both laws, especially DORA’s direct oversight of critical providers, with technology aligned to EU rules.

One European partner for both regimes: because DORA and NIS2 demand the same technical fundamentals, resilient connectivity, strong security and fast incident detection, Teldat’s combination of SD-WAN, be.Safe Pro and be.Safe XDR helps organizations build once and satisfy both. As a European manufacturer under European jurisdiction, Teldat provides sovereign infrastructure without certifying compliance itself.

FAQ’s DORA and NIS2

❯ What is the difference between DORA and NIS2?

The core difference is scope and legal form. DORA, Regulation (EU) 2022/2554, is a regulation that applies directly across the EU and targets the financial sector and its ICT providers, focusing specifically on digital operational resilience. NIS2, Directive (EU) 2022/2555, is a directive that each member state transposes into national law, and it sets a broad cybersecurity baseline across around 18 sectors of essential and important entities. In short, NIS2 is the wide horizontal baseline for the economy, while DORA is the deep, finance specific rulebook. Where both could apply to a financial entity, DORA takes precedence as lex specialis.

❯ Do DORA and NIS2 apply to the same organizations?

They can overlap, but the rules resolve it. NIS2 covers essential and important entities across sectors such as energy, transport, health, water, digital infrastructure and more. DORA covers financial entities such as banks, insurers, investment firms and payment institutions, plus their critical ICT third party providers. A bank could in principle fall under both, but because DORA is lex specialis for the financial sector, financial entities follow DORA rather than NIS2 for the requirements the two share. Organizations outside finance generally look to NIS2, while some groups with mixed activities must map each entity carefully to the right regime.

❯ What are the incident reporting timelines under DORA and NIS2?

Both use a staged model but with different clocks. DORA requires major ICT incidents to be reported to the competent authority with an initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within one month. NIS2 requires significant incidents to be reported to the national CSIRT or competent authority with an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month. DORA’s 4 hour initial deadline is the tightest in EU regulation, so financial entities subject to both will always meet DORA’s clock first.

❯ What does lex specialis mean for DORA and NIS2?

Lex specialis is a legal principle meaning a specialized law takes precedence over a general one on the same subject. NIS2 itself recognizes DORA as lex specialis for the financial sector: where DORA and NIS2 would both cover the same ICT risk management or incident reporting obligation for a financial entity, DORA’s more detailed, finance specific rules apply instead of NIS2’s general ones. This avoids double regulation and gives financial entities a single, clear rulebook for digital operational resilience, while NIS2 continues to apply to sectors and matters DORA does not address.

❯ What are the penalties under DORA versus NIS2?

Both regimes carry significant penalties. Under NIS2, essential entities can face fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher, with important entities facing somewhat lower caps, and member states set the specifics as it is a directive. Under DORA, financial entities can face administrative fines up to 2% of total annual worldwide turnover for serious breaches, while designated critical ICT third party providers face periodic penalty payments of up to 1% of average daily worldwide turnover for up to six months. Both regimes also allow personal liability for senior management.

❯ How does Teldat help with DORA and NIS2 compliance?

Teldat supports the technical requirements shared by DORA and NIS2 as a European infrastructure manufacturer. be.Safe Pro delivers cloud security with Secure Web Gateway and Next Generation Firewall functions, while be.Safe XDR provides extended detection and response with the monitoring and visibility needed to detect, classify and report incidents within the tight DORA and NIS2 timelines. Combined with resilient Teldat SD-WAN connectivity and operation under European jurisdiction, this helps both financial entities under DORA and essential or important entities under NIS2 build and demonstrate the operational resilience both laws demand.

Meet DORA and NIS2 demands with Teldat

Teldat combines resilient SD-WAN connectivity, be.Safe Pro cloud security and be.Safe XDR detection and response as a European manufacturer under European jurisdiction, helping organizations meet the technical requirements shared by DORA and NIS2.