NIS2 vs DORA COMPARISON
OVERVIEW#
NIS2: Network and Information Security Directive 2 (EU 2022/2555) DORA: Digital Operational Resilience Act (EU 2022/2554) NIS2 Type: Directive (transposed into national law) DORA Type: Regulation (directly applicable in all EU member states) NIS2 Effective: 18 October 2024 (transposition deadline) DORA Effective: 17 January 2025 NIS2 Focus: Cybersecurity across critical sectors DORA Focus: ICT resilience for financial sector specifically
SCOPE COMPARISON#
NIS2 Sectors (Essential): - Energy (electricity, oil, gas, hydrogen) - Transport (air, rail, water, road) - Banking - Financial market infrastructures - Health - Drinking water - Waste water - Digital infrastructure - ICT service management (B2B) - Public administration - Space NIS2 Sectors (Important): - Postal and courier - Waste management - Chemicals - Food - Manufacturing (medical devices, electronics, machinery, motor vehicles) - Digital providers (marketplaces, search engines, social platforms) - Research DORA Scope: - Credit institutions (banks) - Payment institutions - Electronic money institutions - Investment firms - Crypto-asset service providers - Central securities depositories - Trading venues - Central counterparties - Insurance and reinsurance undertakings - Insurance intermediaries - Pension funds (IORPs) - Credit rating agencies - Crowdfunding service providers - Securitisation repositories - ICT third-party service providers (critical) OVERLAP: Banking and financial market infrastructures fall under BOTH DORA is lex specialis: For financial entities, DORA prevails over NIS2
KEY REQUIREMENTS SIDE-BY-SIDE#
GOVERNANCE#
NIS2: - Management body approves cybersecurity measures - Management body oversees implementation - Management body must undergo cybersecurity training - Personal liability for management DORA: - Management body defines ICT risk management framework - Management body approves ICT risk tolerance - Management body reviews ICT audit plans - Specific role assignments for ICT risk - At least one board member with ICT expertise or training
RISK MANAGEMENT#
NIS2 (Article 21): - Risk analysis and information system security policies - Incident handling - Business continuity and crisis management - Supply chain security - Security in network and information systems - Policies on cryptography and encryption - Human resources security - Access control and asset management - Multi-factor authentication DORA (Articles 5-16): - ICT risk management framework (comprehensive) - ICT asset inventory and classification - Protection and prevention measures - Detection mechanisms - Response and recovery plans - ICT business continuity policy - ICT disaster recovery plans - Learning and evolving processes - Communication policies
INCIDENT REPORTING#
NIS2 Timelines: - Early warning: 24 hours (significant incident) - Incident notification: 72 hours - Final report: 1 month after notification - Report to: National CSIRT or competent authority DORA Timelines: - Initial notification: 4 hours after classification as major - Intermediate report: 72 hours after initial notification - Final report: 1 month after incident resolution - Report to: Competent authority (e.g., CSSF in Luxembourg) NIS2 Criteria (significant incident): - Severe operational disruption or financial loss - Affected other persons with considerable damage DORA Criteria (major ICT incident): - Number of clients/counterparts affected - Duration - Geographic spread - Data losses - Impact on critical/important functions - Economic impact
TESTING REQUIREMENTS#
NIS2: - Regular security testing (not specifically defined) - Vulnerability assessments - Penetration testing (implied by risk management) - Member states may define specific requirements DORA: - Digital operational resilience testing programme - Annual testing of critical ICT systems - Threat-Led Penetration Testing (TLPT) every 3 years - Based on TIBER-EU framework - For significant financial entities - Must use external testers - Red team exercises - Vulnerability assessments - Network security assessments - Gap analyses - Source code reviews - Scenario-based testing - Compatibility testing - Performance testing
SUPPLY CHAIN / THIRD-PARTY#
NIS2: - Supply chain security measures - Risk assessment of suppliers - Consideration of supplier vulnerabilities - No specific register requirement - No specific contractual requirements defined DORA: - ICT third-party risk management policy - Pre-contractual risk assessment - Mandatory contractual provisions (Article 30) - Register of all ICT third-party arrangements - Exit strategies for critical providers - Sub-outsourcing controls - Oversight framework for critical ICT third-party providers - ESA designation of critical providers - Direct oversight powers by ESAs
PENALTIES AND ENFORCEMENT#
NIS2 (Essential Entities): - Up to EUR 10 million or 2% of global annual turnover - Temporary suspension of certifications - Temporary ban of management from exercising functions NIS2 (Important Entities): - Up to EUR 7 million or 1.4% of global annual turnover DORA: - Financial supervisory penalties (varies by member state) - For critical ICT third-party providers: - Periodic penalty payments up to 1% of average daily worldwide turnover - Per day until compliance (max 6 months) - Administrative penalties defined by national law - Public statements, withdrawal of authorisation
LUXEMBOURG SPECIFICS#
NIS2 Transposition: - ILR (Institut Luxembourgeois de Regulation) designated authority - National CSIRT: CIRCL (Computer Incident Response Center Luxembourg) - CNPD involved for data protection aspects DORA Implementation: - CSSF is competent authority for financial entities - Circular 25/893 implements DORA specifics - eDesk portal for incident reporting - TIBER-LU for threat-led penetration testing - Third-party register submission via eDesk
INFORMATION SHARING#
NIS2: - Voluntary information sharing between entities - Cooperation Group and CSIRTs Network - EU-CyCLONe for large-scale incidents - Peer reviews among member states DORA: - Voluntary information sharing arrangements (Article 45) - Trusted communities for threat intelligence - Must notify competent authority of participation - Safeguards for shared information - ESA coordination mechanisms
COMPLIANCE CHECKLIST#
For entities subject to BOTH NIS2 and DORA: 1. Determine primary regulation (DORA for financial entities) 2. Map requirements to existing controls 3. Implement ICT risk management framework (DORA Article 5-16) 4. Establish incident classification and reporting (DORA 4h initial) 5. Build digital resilience testing programme (DORA annual + TLPT) 6. Create ICT third-party register (DORA Article 28) 7. Define exit strategies for critical providers 8. Ensure supply chain risk assessment (NIS2 Article 21) 9. Train management body on ICT/cyber risks 10. Participate in information sharing arrangements 11. Document everything for regulatory inspections 12. Regular gap assessments against both frameworks
KEY REGULATORY TECHNICAL STANDARDS (RTS)#
DORA RTS (developed by ESAs): - RTS on ICT risk management framework - RTS on classification of major ICT incidents - RTS on ICT incident reporting - RTS on TLPT (threat-led penetration testing) - RTS on ICT third-party policy - RTS on register of information - RTS on subcontracting critical functions - ITS on register of information templates NIS2 Implementing Acts: - Implementing acts on technical and methodological requirements - Implementing acts for digital infrastructure providers - Member state-specific transposition measures
QUICK REFERENCE TABLE#
Feature | NIS2 | DORA ---------------------|-----------------------|---------------------- Legal form | Directive | Regulation Sector | Cross-sector | Financial sector Risk management | Article 21 | Articles 5-16 Incident report (1st)| 24 hours | 4 hours Incident report (mid)| 72 hours | 72 hours Final report | 1 month | 1 month Pen testing | Implied | TLPT every 3 years Third-party register | No | Yes (mandatory) Exit strategies | Not required | Required (critical) TLPT/Red team | Not required | Every 3 years Max fine | EUR 10M / 2% turnover | National law + 1%/day LU Authority | ILR | CSSF Reporting portal | National CSIRT | eDesk
NIS2 vs DORA COMPARISON CHEATSHEET ===================================== Source: https://cheatsheet.johlem.net OVERVIEW -------- NIS2: Network and Information Security Directive 2 (EU 2022/2555) DORA: Digital Operational Resilience Act (EU 2022/2554) NIS2 Type: Directive (transposed into national law) DORA Type: Regulation (directly applicable in all EU member states) NIS2 Effective: 18 October 2024 (transposition deadline) DORA Effective: 17 January 2025 NIS2 Focus: Cybersecurity across critical sectors DORA Focus: ICT resilience for financial sector specifically SCOPE COMPARISON ================= NIS2 Sectors (Essential): - Energy (electricity, oil, gas, hydrogen) - Transport (air, rail, water, road) - Banking - Financial market infrastructures - Health - Drinking water - Waste water - Digital infrastructure - ICT service management (B2B) - Public administration - Space NIS2 Sectors (Important): - Postal and courier - Waste management - Chemicals - Food - Manufacturing (medical devices, electronics, machinery, motor vehicles) - Digital providers (marketplaces, search engines, social platforms) - Research DORA Scope: - Credit institutions (banks) - Payment institutions - Electronic money institutions - Investment firms - Crypto-asset service providers - Central securities depositories - Trading venues - Central counterparties - Insurance and reinsurance undertakings - Insurance intermediaries - Pension funds (IORPs) - Credit rating agencies - Crowdfunding service providers - Securitisation repositories - ICT third-party service providers (critical) OVERLAP: Banking and financial market infrastructures fall under BOTH DORA is lex specialis: For financial entities, DORA prevails over NIS2 KEY REQUIREMENTS SIDE-BY-SIDE =============================== GOVERNANCE ---------- NIS2: - Management body approves cybersecurity measures - Management body oversees implementation - Management body must undergo cybersecurity training - Personal liability for management DORA: - Management body defines ICT risk management framework - Management body approves ICT risk tolerance - Management body reviews ICT audit plans - Specific role assignments for ICT risk - At least one board member with ICT expertise or training RISK MANAGEMENT ---------------- NIS2 (Article 21): - Risk analysis and information system security policies - Incident handling - Business continuity and crisis management - Supply chain security - Security in network and information systems - Policies on cryptography and encryption - Human resources security - Access control and asset management - Multi-factor authentication DORA (Articles 5-16): - ICT risk management framework (comprehensive) - ICT asset inventory and classification - Protection and prevention measures - Detection mechanisms - Response and recovery plans - ICT business continuity policy - ICT disaster recovery plans - Learning and evolving processes - Communication policies INCIDENT REPORTING =================== NIS2 Timelines: - Early warning: 24 hours (significant incident) - Incident notification: 72 hours - Final report: 1 month after notification - Report to: National CSIRT or competent authority DORA Timelines: - Initial notification: 4 hours after classification as major - Intermediate report: 72 hours after initial notification - Final report: 1 month after incident resolution - Report to: Competent authority (e.g., CSSF in Luxembourg) NIS2 Criteria (significant incident): - Severe operational disruption or financial loss - Affected other persons with considerable damage DORA Criteria (major ICT incident): - Number of clients/counterparts affected - Duration - Geographic spread - Data losses - Impact on critical/important functions - Economic impact TESTING REQUIREMENTS ===================== NIS2: - Regular security testing (not specifically defined) - Vulnerability assessments - Penetration testing (implied by risk management) - Member states may define specific requirements DORA: - Digital operational resilience testing programme - Annual testing of critical ICT systems - Threat-Led Penetration Testing (TLPT) every 3 years - Based on TIBER-EU framework - For significant financial entities - Must use external testers - Red team exercises - Vulnerability assessments - Network security assessments - Gap analyses - Source code reviews - Scenario-based testing - Compatibility testing - Performance testing SUPPLY CHAIN / THIRD-PARTY ============================ NIS2: - Supply chain security measures - Risk assessment of suppliers - Consideration of supplier vulnerabilities - No specific register requirement - No specific contractual requirements defined DORA: - ICT third-party risk management policy - Pre-contractual risk assessment - Mandatory contractual provisions (Article 30) - Register of all ICT third-party arrangements - Exit strategies for critical providers - Sub-outsourcing controls - Oversight framework for critical ICT third-party providers - ESA designation of critical providers - Direct oversight powers by ESAs PENALTIES AND ENFORCEMENT ========================== NIS2 (Essential Entities): - Up to EUR 10 million or 2% of global annual turnover - Temporary suspension of certifications - Temporary ban of management from exercising functions NIS2 (Important Entities): - Up to EUR 7 million or 1.4% of global annual turnover DORA: - Financial supervisory penalties (varies by member state) - For critical ICT third-party providers: - Periodic penalty payments up to 1% of average daily worldwide turnover - Per day until compliance (max 6 months) - Administrative penalties defined by national law - Public statements, withdrawal of authorisation LUXEMBOURG SPECIFICS ===================== NIS2 Transposition: - ILR (Institut Luxembourgeois de Regulation) designated authority - National CSIRT: CIRCL (Computer Incident Response Center Luxembourg) - CNPD involved for data protection aspects DORA Implementation: - CSSF is competent authority for financial entities - Circular 25/893 implements DORA specifics - eDesk portal for incident reporting - TIBER-LU for threat-led penetration testing - Third-party register submission via eDesk INFORMATION SHARING ==================== NIS2: - Voluntary information sharing between entities - Cooperation Group and CSIRTs Network - EU-CyCLONe for large-scale incidents - Peer reviews among member states DORA: - Voluntary information sharing arrangements (Article 45) - Trusted communities for threat intelligence - Must notify competent authority of participation - Safeguards for shared information - ESA coordination mechanisms COMPLIANCE CHECKLIST ===================== For entities subject to BOTH NIS2 and DORA: 1. Determine primary regulation (DORA for financial entities) 2. Map requirements to existing controls 3. Implement ICT risk management framework (DORA Article 5-16) 4. Establish incident classification and reporting (DORA 4h initial) 5. Build digital resilience testing programme (DORA annual + TLPT) 6. Create ICT third-party register (DORA Article 28) 7. Define exit strategies for critical providers 8. Ensure supply chain risk assessment (NIS2 Article 21) 9. Train management body on ICT/cyber risks 10. Participate in information sharing arrangements 11. Document everything for regulatory inspections 12. Regular gap assessments against both frameworks KEY REGULATORY TECHNICAL STANDARDS (RTS) ========================================== DORA RTS (developed by ESAs): - RTS on ICT risk management framework - RTS on classification of major ICT incidents - RTS on ICT incident reporting - RTS on TLPT (threat-led penetration testing) - RTS on ICT third-party policy - RTS on register of information - RTS on subcontracting critical functions - ITS on register of information templates NIS2 Implementing Acts: - Implementing acts on technical and methodological requirements - Implementing acts for digital infrastructure providers - Member state-specific transposition measures QUICK REFERENCE TABLE ====================== Feature | NIS2 | DORA ---------------------|-----------------------|---------------------- Legal form | Directive | Regulation Sector | Cross-sector | Financial sector Risk management | Article 21 | Articles 5-16 Incident report (1st)| 24 hours | 4 hours Incident report (mid)| 72 hours | 72 hours Final report | 1 month | 1 month Pen testing | Implied | TLPT every 3 years Third-party register | No | Yes (mandatory) Exit strategies | Not required | Required (critical) TLPT/Red team | Not required | Every 3 years Max fine | EUR 10M / 2% turnover | National law + 1%/day LU Authority | ILR | CSSF Reporting portal | National CSIRT | eDesk
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.