← All cheat sheets

NIS2 vs DORA COMPARISON

Plain-text reference · 9 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

NIS2: Network and Information Security Directive 2 (EU 2022/2555)
DORA: Digital Operational Resilience Act (EU 2022/2554)

NIS2 Type:     Directive (transposed into national law)
DORA Type:     Regulation (directly applicable in all EU member states)

NIS2 Effective: 18 October 2024 (transposition deadline)
DORA Effective: 17 January 2025

NIS2 Focus:    Cybersecurity across critical sectors
DORA Focus:    ICT resilience for financial sector specifically

SCOPE COMPARISON#

NIS2 Sectors (Essential):
- Energy (electricity, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking
- Financial market infrastructures
- Health
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management (B2B)
- Public administration
- Space

NIS2 Sectors (Important):
- Postal and courier
- Waste management
- Chemicals
- Food
- Manufacturing (medical devices, electronics, machinery, motor vehicles)
- Digital providers (marketplaces, search engines, social platforms)
- Research

DORA Scope:
- Credit institutions (banks)
- Payment institutions
- Electronic money institutions
- Investment firms
- Crypto-asset service providers
- Central securities depositories
- Trading venues
- Central counterparties
- Insurance and reinsurance undertakings
- Insurance intermediaries
- Pension funds (IORPs)
- Credit rating agencies
- Crowdfunding service providers
- Securitisation repositories
- ICT third-party service providers (critical)

OVERLAP: Banking and financial market infrastructures fall under BOTH
DORA is lex specialis: For financial entities, DORA prevails over NIS2

KEY REQUIREMENTS SIDE-BY-SIDE#


            

GOVERNANCE#

NIS2:
- Management body approves cybersecurity measures
- Management body oversees implementation
- Management body must undergo cybersecurity training
- Personal liability for management

DORA:
- Management body defines ICT risk management framework
- Management body approves ICT risk tolerance
- Management body reviews ICT audit plans
- Specific role assignments for ICT risk
- At least one board member with ICT expertise or training

RISK MANAGEMENT#

NIS2 (Article 21):
- Risk analysis and information system security policies
- Incident handling
- Business continuity and crisis management
- Supply chain security
- Security in network and information systems
- Policies on cryptography and encryption
- Human resources security
- Access control and asset management
- Multi-factor authentication

DORA (Articles 5-16):
- ICT risk management framework (comprehensive)
- ICT asset inventory and classification
- Protection and prevention measures
- Detection mechanisms
- Response and recovery plans
- ICT business continuity policy
- ICT disaster recovery plans
- Learning and evolving processes
- Communication policies

INCIDENT REPORTING#

NIS2 Timelines:
- Early warning:        24 hours (significant incident)
- Incident notification: 72 hours
- Final report:          1 month after notification
- Report to:            National CSIRT or competent authority

DORA Timelines:
- Initial notification:  4 hours after classification as major
- Intermediate report:   72 hours after initial notification
- Final report:          1 month after incident resolution
- Report to:            Competent authority (e.g., CSSF in Luxembourg)

NIS2 Criteria (significant incident):
- Severe operational disruption or financial loss
- Affected other persons with considerable damage

DORA Criteria (major ICT incident):
- Number of clients/counterparts affected
- Duration
- Geographic spread
- Data losses
- Impact on critical/important functions
- Economic impact

TESTING REQUIREMENTS#

NIS2:
- Regular security testing (not specifically defined)
- Vulnerability assessments
- Penetration testing (implied by risk management)
- Member states may define specific requirements

DORA:
- Digital operational resilience testing programme
- Annual testing of critical ICT systems
- Threat-Led Penetration Testing (TLPT) every 3 years
  - Based on TIBER-EU framework
  - For significant financial entities
  - Must use external testers
  - Red team exercises
- Vulnerability assessments
- Network security assessments
- Gap analyses
- Source code reviews
- Scenario-based testing
- Compatibility testing
- Performance testing

SUPPLY CHAIN / THIRD-PARTY#

NIS2:
- Supply chain security measures
- Risk assessment of suppliers
- Consideration of supplier vulnerabilities
- No specific register requirement
- No specific contractual requirements defined

DORA:
- ICT third-party risk management policy
- Pre-contractual risk assessment
- Mandatory contractual provisions (Article 30)
- Register of all ICT third-party arrangements
- Exit strategies for critical providers
- Sub-outsourcing controls
- Oversight framework for critical ICT third-party providers
- ESA designation of critical providers
- Direct oversight powers by ESAs

PENALTIES AND ENFORCEMENT#

NIS2 (Essential Entities):
- Up to EUR 10 million or 2% of global annual turnover
- Temporary suspension of certifications
- Temporary ban of management from exercising functions

NIS2 (Important Entities):
- Up to EUR 7 million or 1.4% of global annual turnover

DORA:
- Financial supervisory penalties (varies by member state)
- For critical ICT third-party providers:
  - Periodic penalty payments up to 1% of average daily worldwide turnover
  - Per day until compliance (max 6 months)
- Administrative penalties defined by national law
- Public statements, withdrawal of authorisation

LUXEMBOURG SPECIFICS#

NIS2 Transposition:
- ILR (Institut Luxembourgeois de Regulation) designated authority
- National CSIRT: CIRCL (Computer Incident Response Center Luxembourg)
- CNPD involved for data protection aspects

DORA Implementation:
- CSSF is competent authority for financial entities
- Circular 25/893 implements DORA specifics
- eDesk portal for incident reporting
- TIBER-LU for threat-led penetration testing
- Third-party register submission via eDesk

INFORMATION SHARING#

NIS2:
- Voluntary information sharing between entities
- Cooperation Group and CSIRTs Network
- EU-CyCLONe for large-scale incidents
- Peer reviews among member states

DORA:
- Voluntary information sharing arrangements (Article 45)
- Trusted communities for threat intelligence
- Must notify competent authority of participation
- Safeguards for shared information
- ESA coordination mechanisms

COMPLIANCE CHECKLIST#

For entities subject to BOTH NIS2 and DORA:

1. Determine primary regulation (DORA for financial entities)
2. Map requirements to existing controls
3. Implement ICT risk management framework (DORA Article 5-16)
4. Establish incident classification and reporting (DORA 4h initial)
5. Build digital resilience testing programme (DORA annual + TLPT)
6. Create ICT third-party register (DORA Article 28)
7. Define exit strategies for critical providers
8. Ensure supply chain risk assessment (NIS2 Article 21)
9. Train management body on ICT/cyber risks
10. Participate in information sharing arrangements
11. Document everything for regulatory inspections
12. Regular gap assessments against both frameworks

KEY REGULATORY TECHNICAL STANDARDS (RTS)#

DORA RTS (developed by ESAs):
- RTS on ICT risk management framework
- RTS on classification of major ICT incidents
- RTS on ICT incident reporting
- RTS on TLPT (threat-led penetration testing)
- RTS on ICT third-party policy
- RTS on register of information
- RTS on subcontracting critical functions
- ITS on register of information templates

NIS2 Implementing Acts:
- Implementing acts on technical and methodological requirements
- Implementing acts for digital infrastructure providers
- Member state-specific transposition measures

QUICK REFERENCE TABLE#

Feature              | NIS2                  | DORA
---------------------|-----------------------|----------------------
Legal form           | Directive             | Regulation
Sector               | Cross-sector          | Financial sector
Risk management      | Article 21            | Articles 5-16
Incident report (1st)| 24 hours              | 4 hours
Incident report (mid)| 72 hours              | 72 hours
Final report         | 1 month               | 1 month
Pen testing          | Implied               | TLPT every 3 years
Third-party register | No                    | Yes (mandatory)
Exit strategies      | Not required          | Required (critical)
TLPT/Red team        | Not required          | Every 3 years
Max fine             | EUR 10M / 2% turnover | National law + 1%/day
LU Authority         | ILR                   | CSSF
Reporting portal     | National CSIRT        | eDesk

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.