Does DORA Exempt Your Financial Institution from NIS2? The Article 2(3) Entity List with Residual Obligations That Still Apply
DORA entered into force on 17 January 2025. For most EU financial entities, that date also marked a change in their NIS2 compliance posture — not because NIS2 went away, but because the two frameworks now interact through a lex specialis rule that displaces some NIS2 obligations while leaving others fully intact.
The practical question compliance teams face is not simply “does DORA apply to us?” It is three questions in sequence: Does DORA cover our entity type? Does the lex specialis rule then displace our NIS2 obligations? And if it does, which obligations survive regardless?
This guide answers all three. It sets out the complete DORA Article 2(3) exclusion list with the NIS2 consequence for each category, provides an entity-by-entity determination table, and enumerates the specific NIS2 obligations that remain binding on DORA-covered entities — including the Article 20 management liability provision that national regulators can enforce independently of DORA.
Who this is for: Compliance officers and legal counsel determining dual-framework exposure; finance directors at payment institutions and e-money institutions assessing whether DORA’s scope reaches their entity type; boards approving cybersecurity governance arrangements who need to understand what management liability remains after DORA applies.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
NIS2 Annex I: Which Banking and Financial Market Infrastructure Entities Are Covered
NIS2 Directive (EU) 2022/2555 covers financial entities through two Annex sectors, both classified as essential entities subject to proactive supervision and the higher penalty tier.
| NIS2 Annex | Sector | Entity Types Covered | Supervision Tier |
|---|---|---|---|
| Annex I, Sector 8 | Banking | Credit institutions as defined in Article 4(1)(1) of Regulation (EU) No 575/2013 (CRR) | Essential entity — proactive supervision; penalties up to €10M or 2% of global turnover |
| Annex I, Sector 9 | Financial market infrastructure | Operators of trading venues as defined in Article 4(1)(24) of Directive 2014/65/EU (MiFID II); central counterparties (CCPs) as defined in Article 2(1) of Regulation (EU) No 648/2012 (EMIR) | Essential entity — proactive supervision; same penalty ceiling |
Three entity types absent from NIS2 Annex I and II are worth noting: investment firms, insurance undertakings, and alternative investment fund managers. NIS2 does not include these categories in its Annex scope. They face DORA obligations (see below) without a separate NIS2 obligation running in parallel — unless their national transposition creates an independent duty, which varies by member state.
Payment institutions and the banking classification of electronic money institutions require separate analysis, addressed in the section on PIs and EMIs below.
DORA Article 2(1): The 21 Entity Types Covered by the Regulation
DORA Regulation (EU) 2022/2554 applies to 21 categories of financial entities under Article 2(1). The full list, verbatim from the regulation, is:
| Art. 2(1) Sub-point | Entity Type |
|---|---|
| (a) | Credit institutions |
| (b) | Payment institutions, including payment institutions exempted pursuant to Directive (EU) 2015/2366 |
| (c) | Account information service providers |
| (d) | Electronic money institutions, including electronic money institutions exempted pursuant to Directive 2009/110/EC |
| (e) | Investment firms |
| (f) | Crypto-asset service providers (MiCA) and issuers of asset-referenced tokens |
| (g) | Central securities depositories |
| (h) | Central counterparties (CCPs) |
| (i) | Trading venues |
| (j) | Trade repositories |
| (k) | Managers of alternative investment funds (above AIFMD thresholds) |
| (l) | Management companies (UCITS managers) |
| (m) | Data reporting service providers |
| (n) | Insurance and reinsurance undertakings (above Solvency II threshold) |
| (o) | Insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries |
| (p) | Institutions for occupational retirement provision (IORPs) |
| (q) | Credit rating agencies |
| (r) | Administrators of critical benchmarks |
| (s) | Crowdfunding service providers |
| (t) | Securitisation repositories |
| (u) | ICT third-party service providers (critical third-party designation route) |
Entities in points (a)–(t) are collectively defined as “financial entities” under DORA Article 2(2). Point (u) — ICT third-party service providers — is subject to DORA’s oversight chapter (Chapter V) but is not a financial entity for the purposes of the main ICT risk management obligations.
DORA Article 2(3): The Six Exclusion Categories and Their NIS2 Consequence
DORA Article 2(3) excludes six categories of entities from the regulation’s scope. For each category, the critical follow-on question is whether NIS2 applies independently. The answer depends on whether the entity qualifies as a credit institution, trading venue, or CCP — the entity types NIS2 Annex I actually names.
| DORA Art. 2(3) Point | Excluded Entity Type | What Triggers the Exclusion | NIS2 Position |
|---|---|---|---|
| (a) | Small alternative investment fund managers | Below AIFMD thresholds: AUM < €100M; or AUM < €500M for unleveraged portfolios with no redemption rights exercisable within 5 years, per Article 3(2) of Directive 2011/61/EU | AIFMs are not named in NIS2 Annex I or II. No independent NIS2 obligation. |
| (b) | Sub-threshold insurance and reinsurance undertakings | Below Solvency II scope: subject to multiple conditions including annual gross written premiums ≤ €5M and technical provisions ≤ €25M, per Article 4 of Directive 2009/138/EC (see that provision for the full criteria) | Insurance undertakings are not named in NIS2 Annex I or II. No independent NIS2 obligation. |
| (c) | Micro-IORPs | Institutions for occupational retirement provision operating pension schemes with 15 or fewer total members | IORPs are not in NIS2 Annex I or II. No independent NIS2 obligation. |
| (d) | MiFID II-exempt persons | Natural or legal persons exempt under Articles 2 and 3 of Directive 2014/65/EU — includes certain commodity dealers, intra-group service entities, and member-state-optioned small investment firms | Depends on the entity’s primary business. Most MiFID II-exempt entities are not in NIS2 Annex I or II. Entities that also operate energy infrastructure may fall under NIS2 Annex I, Sector 1 (Energy), independent of financial sector classification. |
| (e) | SME insurance intermediaries | Insurance intermediaries, reinsurance intermediaries, and ancillary insurance intermediaries that are microenterprises, small enterprises, or medium-sized enterprises | Insurance intermediaries are not named in NIS2 Annex I or II. No independent NIS2 obligation from the financial sector provisions. |
| (f) | Post office giro institutions | Post office giro institutions operating payment or savings services within national post networks | May fall under NIS2 Annex II, Sector 1 (Postal and Courier Services) if they provide postal services meeting size thresholds (50+ employees or €10M+ turnover). Postal NIS2 scope analysis is separate from banking sector analysis. |
A fifth exclusion route exists under DORA Article 2(4): member states may exclude certain credit institutions listed in Article 2(5), points (4) to (23), of Directive 2013/36/EU (CRD IV) from DORA’s scope. These are specialised or nationally-specific credit institutions — including certain cooperative credit institutions, central banks acting in a commercial capacity in some jurisdictions, and other special-purpose entities designated by the Commission. Member states must notify the Commission of such exclusions. A credit institution excluded via this route remains subject to NIS2 Annex I Sector 8 in full, because the DORA lex specialis no longer applies.
How the Lex Specialis Rule Works: NIS2 Article 4 and DORA Article 1(2)
The displacement mechanism runs on a two-step chain. Understanding each link is necessary to identify where NIS2 obligations survive.
Step 1 — DORA designates itself as a sector-specific act. DORA Article 1(2) states: “In relation to financial entities identified as essential or important entities pursuant to national rules transposing Article 3 of Directive (EU) 2022/2555, this Regulation shall be considered a sector-specific Union legal act for the purposes of Article 4 of that Directive.” [1] This self-designation is the entry point. It works only for financial entities that are also classified as NIS2 essential or important entities under national transposition — meaning the lex specialis mechanism is irrelevant for DORA-covered entities that fall entirely outside NIS2 Annex I and II scope.
Step 2 — NIS2 Article 4 sets the equivalence condition. NIS2 Article 4(1) provides that a sector-specific Union legal act displaces NIS2 requirements only where its measures are “at least equivalent in effect to the obligations laid down in this Directive.” [3] Article 4(2) sets the equivalence criteria: for risk management measures, equivalence requires meeting the standard of Article 21(1) and (2); for incident notification, equivalence requires matching Article 23(1)–(6) and providing immediate access to national CSIRTs and competent authorities. [3]
DORA is widely understood to satisfy the Article 4(2)(a) equivalence test for ICT risk management — its Chapters II and III (Articles 5–15) impose comprehensive ICT risk management requirements that are generally treated as meeting or exceeding NIS2 Article 21(1) and (2) in their domain. However, DORA’s scope is ICT operational resilience. It does not comprehensively address all NIS2 Article 21(2) measures. The obligations DORA does not cover in full remain binding on NIS2 essential and important entities regardless of DORA compliance.
The practical implication: full DORA compliance does not produce full NIS2 compliance. A supervisory assessment of NIS2 obligations requires mapping each Article 21(2) measure against DORA’s chapter structure and identifying the gaps where NIS2 creates a separate, independent obligation.
Residual NIS2 Obligations That Survive Lex Specialis — Penalty Exposure Remains
The following NIS2 obligations remain binding on financial entities subject to DORA lex specialis. Each survives because DORA either does not address the underlying obligation or addresses it with materially different structure, leaving the NIS2 requirement independently enforceable by the national competent authority.
| Residual NIS2 Obligation | NIS2 Provision | Why It Survives | Practical Implication |
|---|---|---|---|
| Registration with the national NIS2 competent authority | Article 3 (national transposition) | DORA routes supervision to the European Supervisory Authorities (EBA, ESMA, EIOPA). National NIS2 competent authority registration is a separate obligation in national transposing law. | Financial entities must register with their national NCA (e.g., BSI in Germany, ANSSI in France) in addition to meeting DORA registration requirements. This obligation is confirmed in multiple national transpositions. [4] |
| National CSIRT incident notification | Article 23 (via Article 4(2)(b) equivalence condition) | DORA’s major ICT incident notification runs to ESAs and designated national authorities under the financial sector regulatory framework. NIS2 Article 4(2)(b) requires incidents to also reach national CSIRTs — a channel DORA does not replicate. | Where DORA’s incident notification chain does not automatically reach the national CSIRT, a supplementary notification obligation may arise under national NIS2 transposition. Verify whether your national transposition routes DORA notifications to the CSIRT or requires a separate submission. |
| Physical security measures | Article 21(2) read with national implementation | DORA’s ICT risk management framework (Chapters II–III) addresses digital operational resilience. Physical security of premises, physical access control, and environmental protections are not covered with the same specificity as in NIS2 Article 21(2). | Financial entities should maintain a physical security policy documented separately from DORA ICT risk management outputs — specifically for NIS2 audit-trail purposes. |
| Non-ICT supply chain risk | Article 21(2)(d) | DORA Articles 28–44 address ICT third-party risk comprehensively. NIS2 Article 21(2)(d) extends to “security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” without limiting scope to ICT. Non-ICT vendors — facilities management, courier services, physical security contractors — fall under NIS2 but not DORA. | Supply chain security documentation should explicitly cover non-ICT supplier relationships. A gap exists where DORA third-party registers capture ICT vendors but miss the broader NIS2 supply chain obligation. See the existing finance supply chain security guidance for the full framework. |
| Coordinated vulnerability disclosure | Article 12 | DORA addresses vulnerability management within its ICT risk framework but does not create an equivalent to NIS2’s coordinated vulnerability disclosure mechanism. | Maintain a vulnerability disclosure policy that satisfies both DORA’s internal handling requirements and NIS2 Article 12 coordination obligations with national CSIRTs. |
| Management body approval and cybersecurity governance | Article 20 | Article 20 creates an independent obligation requiring the management body to approve, supervise, and be accountable for cybersecurity risk management measures. National competent authorities can enforce this provision against management independently of whether underlying technical controls are DORA-compliant. See Article 20 section below. | Board resolutions approving cybersecurity risk management measures must be documented and traceable. A technically sound DORA programme does not satisfy Article 20 if the management body has not formally approved it. |
As a general guideline, full DORA compliance covers most NIS2 Article 21 obligations by equivalence — but the residual items above represent enforcement exposure that national competent authorities can act on independently. The German NIS2UmsuCG confirms this structure explicitly: Section 28(6) BSIG-E displaces only “the provisions on ICT risk management and on reporting obligations” for DORA-covered financial institutions — registration, cooperation, and governance obligations run in parallel. [4]
Payment Institutions and E-Money Institutions: The Exempted-Entity Trap
Payment institutions and e-money institutions require specific attention because both DORA and NIS2 treat them differently from credit institutions — and in opposite directions.
DORA scope: both PIs and EMIs are fully included, even when licensing-exempt. DORA Article 2(1)(b) covers “payment institutions, including payment institutions exempted pursuant to Directive (EU) 2015/2366.” Article 2(1)(d) covers “electronic money institutions, including electronic money institutions exempted pursuant to Directive 2009/110/EC.” [2] The deliberate inclusion of “exempted” entities means a payment institution that has obtained an exemption from full PSD2 licensing requirements — for example, a fintech operating below national volume thresholds — remains subject to DORA’s ICT risk management, incident reporting, and third-party oversight obligations. There is no DORA scope exemption based on PSD2 or EMD2 licensing status.
NIS2 scope: EMIs and PIs are not separately named in the Annex — classification depends on legal form. NIS2 Annex I Sector 8 (Banking) defines the in-scope entity type as “credit institutions” as defined in Article 4(1)(1) of Regulation (EU) No 575/2013 (CRR). The CRR definition of credit institution has historically included electronic money institutions within its scope, which means EMIs that meet NIS2 size thresholds — medium-sized (50+ employees or €10M+ annual turnover) — are generally considered essential entities under Annex I Sector 8. Payment institutions are not credit institutions under CRR, which means pure PIs do not fall under NIS2 Annex I Sector 8 on the basis of their payment institution licence alone.
The practical consequence differs by entity type:
| Entity | DORA Scope | NIS2 Annex I Scope | Lex Specialis Applies? | Action Required |
|---|---|---|---|---|
| Large EMI (50+ employees or €10M+ turnover, operating as credit institution per CRR) | Yes — Art. 2(1)(d) | Yes — Annex I, Sector 8 | Yes — DORA displaces most NIS2 obligations | Full DORA compliance + residual NIS2 obligations (registration, CSIRT, governance, non-ICT supply chain) |
| Small EMI (PSD2/EMD2-exempt, below NIS2 size threshold) | Yes — Art. 2(1)(d) including exempted EMIs | No — below medium-enterprise threshold | No NIS2 obligation to displace | Full DORA compliance; no separate NIS2 obligation |
| Large PI (credit institution assessment required) | Yes — Art. 2(1)(b) including exempted PIs | Depends on national transposition and whether PI qualifies as CRR credit institution | Depends | Confirm NIS2 classification with national NCA; assume DORA applies regardless |
| Small PI (PSD2-exempt, below NIS2 size threshold) | Yes — Art. 2(1)(b) including exempted PIs | No — below medium-enterprise threshold | No NIS2 obligation to displace | Full DORA compliance, simplified ICT risk framework (DORA Art. 16) available for microenterprises and small entities |
The proportionality principle is relevant for small PIs and EMIs. DORA Article 16 provides a simplified ICT risk management framework for microenterprises and small entities. The simplified framework reduces documentation obligations but does not eliminate DORA scope. A PI that obtained a PSD2 exemption to avoid licensing obligations has not obtained an exemption from digital resilience requirements.
Payment institutions considering their NIS2 classification should also verify whether any national transposition has designated specific payment institution types as essential or important entities outside the standard CRR credit institution definition — several member states have exercised the discretion available under NIS2 Article 3(1) to add entities based on systemic importance.
Article 20 Management Body Liability: An Independently Enforceable Obligation
NIS2 Article 20 requires the management body of essential and important entities to approve the cybersecurity risk management measures implemented under Article 21, supervise their implementation, and bear accountability for compliance failures. National competent authorities can enforce Article 20 directly against individual members of the management body — including issuing temporary prohibitions on board-level functions for repeated or negligent breaches, depending on the member state’s transposition.
Article 20 operates independently of the DORA lex specialis rule. Even where DORA displaces the underlying Article 21 technical requirements, the NIS2 governance obligation — that the management body formally approves, oversees, and is accountable for the measures in place — survives as a separate enforcement vector. An organisation with a technically sound DORA programme that lacks documented management body approval of its cybersecurity risk management framework remains exposed to Article 20 enforcement.
The practical control is straightforward: a board resolution approving the organisation’s DORA ICT risk management framework, explicitly referencing Article 21 NIS2 obligations and the management body’s supervisory role, closes the Article 20 gap. Most Article 21(2) documentation templates include a Board Resolution Template for this purpose (see Doc 59 in the complete toolkit). Tracking this against the banking and finance NIS2 compliance checklist provides a structured audit trail.
Frequently Asked Questions
Does DORA replace NIS2 entirely for banks? No. DORA displaces most NIS2 Article 21 risk management and Article 23 incident notification obligations for credit institutions, CCPs, and trading venues through the lex specialis rule in DORA Article 1(2) and NIS2 Article 4. However, registration with the national NIS2 competent authority, national CSIRT incident notification channels, physical security obligations, non-ICT supply chain risk management, and Article 20 management body accountability all survive and are independently enforceable.
If our payment institution has a PSD2 exemption, does DORA still apply? Yes. DORA Article 2(1)(b) explicitly includes “payment institutions exempted pursuant to Directive (EU) 2015/2366.” A PSD2 licence exemption does not produce a DORA scope exemption. [2]
Which entities are excluded from DORA under Article 2(3)? Six categories: small AIFMs below AIFMD thresholds, sub-threshold insurance undertakings below Solvency II scope, pension schemes with 15 or fewer members, persons exempt under MiFID II Articles 2 and 3, microenterprises and SMEs operating as insurance intermediaries, and post office giro institutions.
Does a DORA-excluded entity automatically face full NIS2 obligations? Not automatically. For most DORA-excluded financial entity types — small AIFMs, small insurers, micro-IORPs, and SME insurance intermediaries — there is no corresponding NIS2 Annex I or II sector obligation. The exception is post office giro institutions, which may fall under NIS2 Annex II postal sector if they meet size thresholds, and credit institutions excluded via the Article 2(4) member state discretion route, which remain fully subject to NIS2 Annex I Sector 8.
Where can I find the Article 23 incident notification requirements for banks? The full notification timeline and content requirements are covered in the NIS2 Article 23 incident notification guide. For banking entities, verify whether your national transposition routes DORA major incident notifications to the CSIRT automatically or requires a separate submission.
Key Takeaways
- DORA Article 1(2) designates DORA as a sector-specific act for NIS2 Article 4 purposes, but only for financial entities that are also identified as NIS2 essential or important entities under national transposition.
- DORA Article 2(3) excludes six entity categories from DORA scope. Most of these entities are also outside NIS2 Annex I and II, so neither framework applies independently — except post office giro institutions (potential NIS2 Annex II postal sector coverage) and credit institutions excluded by member state discretion under Article 2(4) (full NIS2 Annex I obligation).
- For entities covered by both DORA and NIS2 Annex I, six categories of NIS2 obligation survive lex specialis: national NCA registration, national CSIRT notification, physical security, non-ICT supply chain, coordinated vulnerability disclosure, and Article 20 management body accountability.
- Payment institutions are in DORA scope regardless of PSD2 licensing status. EMIs operating as CRR credit institutions may also be in NIS2 Annex I scope at medium-enterprise size thresholds.
- Article 20 management body liability is independently enforceable by national competent authorities even where DORA displaces the underlying Article 21 technical requirements.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- DORA Article 1 — Subject Matter (digital-operational-resilience-act.com)
- DORA Article 2 — Scope (digital-operational-resilience-act.com)
- NIS2 Article 4 — Sector-specific Union legal acts (nis-2-directive.com)
- NIS2 meets DORA — changes for financial institutions (PayTechLaw)
- DORA Article 2 Scope (Advisera)
- DORA vs NIS2 (regulation-dora.eu)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
