Skip to content
atlas

Don't confuse these

DORA vs NIS2 Directive

Why they differ

NIS2 covers many sectors; DORA is the stricter, more detailed rulebook for finance, and where both apply to a financial firm, DORA's rules take the lead.

DORA

Compliance & regulation

The EU law that makes banks, insurers and other financial firms able to keep running through IT failures and cyber attacks.

Formal

An EU regulation of 14 December 2022, applying directly in every member state from 17 January 2025, that sets one set of rules for the financial sector on IT risk management, incident reporting, testing, and control of IT suppliers such as cloud providers.

In plain English

Like fire rules that ask a bank not just to hang smoke alarms, but to prove in a drill that it can get everyone out, keep serving customers and tell the fire service what happened.

In practice

The IT risk manager at a Danish pension fund keeps a register of every IT supplier contract, tests switching over to the backup site each year and, after a major outage, sends the first report to the Danish financial supervisor within hours.

Why it matters

Payments, savings and trading now depend almost wholly on IT and a few shared cloud providers, so one failure can spread across the whole financial system; DORA makes firms plan for that and lets supervisors check.

NIS2 Directive

Compliance & regulation

The EU cybersecurity law that sets shared security duties for organisations in important and critical sectors.

Formal

Directive (EU) 2022/2555, to be written into national law by 17 October 2024, which obliges essential and important entities in 18 sectors to manage cyber risk, report significant incidents in stages and make their management body answerable.

In plain English

Like common building safety rules for the whole EU - every country must write them into its own law, and those who keep society running must build by them.

In practice

The board of a mid-sized Danish shipping company learns it falls under NIS2, so it approves a risk assessment, a routine for reporting incidents within 24 hours and security terms for its suppliers.

Why it matters

The first NIS rules covered too few sectors and were applied unevenly; NIS2 brings in thousands more organisations, fines of up to 10 million euro or 2% of turnover, and personal liability for leaders.

Shared connections

Atlas is in beta.