NIS2 compliance checklist for financial entities excluded from DORA — banking and finance cybersecurity obligations

Financial Entities DORA Excludes Still Face NIS2: Article 2(3)’s 6 Categories Mapped to a Sector-Specific Checklist

The assumption built into most EU financial sector compliance programmes is that DORA covers everything. Publish the ICT risk management framework, file the resilience testing records, and NIS2 is someone else’s problem. That assumption fails for six categories of financial entity explicitly excluded from DORA under Article 2(3) of Regulation (EU) 2022/2554 — and it fails silently, because these entities have no structured compliance framework pointing them toward the obligations they do have.

DORA applied from 17 January 2025. NIS2’s transposition deadline was 17 October 2024, and competent authorities across the EU are actively conducting supervisory reviews. A sub-threshold alternative investment fund manager with assets under EUR 100 million, an SME insurance intermediary, or a post office giro institution sits outside DORA’s scope entirely. If that entity meets NIS2’s size thresholds, it faces Article 21’s ten security measures, Article 23’s incident reporting obligations, and Article 20’s management accountability requirements — without DORA’s detailed technical standards as a starting point.

This checklist maps each of the six Article 2(3) exclusion categories to their NIS2 position: Annex sector, entity classification, Article 21 obligations, and documentation requirements. It also covers the residual NIS2 obligations that survive DORA’s lex specialis displacement for entities in both frameworks. The goal is to answer the question before a national competent authority does: does your organisation face NIS2 obligations, and if so, what does a defensible compliance programme look like?

How DORA and NIS2 Divide the Financial Sector

DORA and NIS2 were designed to complement each other across the EU financial sector without leaving entities unregulated. The mechanism governing their relationship is the lex specialis principle, codified in Article 4(1) of Directive (EU) 2022/2555. Where a sector-specific Union legal act imposes cybersecurity risk-management or incident notification requirements that are “at least equivalent in effect” to NIS2 Articles 21 and 23, those NIS2 provisions — including supervision and enforcement — do not apply to entities covered by that sector-specific act. [2]

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

DORA invokes this relationship directly. For the 21 financial entity categories listed in DORA Article 2(1) — from credit institutions to crypto-asset service providers — DORA constitutes lex specialis in relation to NIS2’s network and information security provisions. [1]

The critical qualifier is scope. NIS2 Article 4(1) preserves a residual rule that is often missed: where sector-specific Union acts cover only some entities in a particular sector, NIS2 continues to apply to the uncovered entities in that sector. [2] DORA Article 2(3) creates exactly this gap — six categories of financial entity that remain outside DORA’s scope, for which NIS2 operates as the primary cybersecurity framework. Two independent questions determine compliance exposure: first, whether the entity is excluded from DORA under Article 2(3); and second, whether it independently qualifies as an essential or important entity under NIS2 Article 3. Neither question alone is sufficient.

For an overview of how the broader scope determination works across financial entities, see our banking and finance NIS2 scope guide.

The Six Entity Categories DORA Article 2(3) Excludes

DORA Article 2(3) lists six categories of financial entity excluded from its scope. [1] The table below maps each to its NIS2 position, size threshold, and entity classification.

Entity category DORA exclusion provision NIS2 Annex sector Size test for NIS2 scope NIS2 class if threshold met Competent authority
Sub-threshold AIF managers (AUM ≤ EUR 100M leveraged / ≤ EUR 500M unleveraged) Art.2(3)(a) — AIFMD Art.3(2) Financial market infrastructure (Annex I Sector 4) where applicable; member state discretion 250+ employees OR EUR 50M+ turnover → essential; 50+ OR EUR 10M+ → important Essential or Important (if thresholds met); many sub-threshold AIFMs do not meet either bar National financial supervisor (e.g. FCA, BaFin, AMF); NIS2 NCA for cybersecurity supervision
Small insurance/reinsurance undertakings (below Solvency II Art.4 thresholds) Art.2(3)(b) — Solvency II Art.4 No explicit Annex I/II financial sector designation; member state discretion Standard NIS2 size thresholds Important if 50+ employees; potentially out of scope below thresholds National insurance supervisor + NIS2 NCA
Occupational pension institutions with fewer than 15 members Art.2(3)(c) Financial market infrastructure (Annex I Sector 4) where applicable Standard thresholds — rarely met given size Almost always outside NIS2 scope Pension regulator
MiFID II-exempt natural or legal persons (Art.2-3 exemptions) Art.2(3)(d) — MiFID II Art.2-3 Annex I Sector 3 (banking) or Sector 4 depending on activity Standard thresholds Important if size thresholds met Securities regulator + NIS2 NCA
Micro, small, or medium-sized insurance intermediaries Art.2(3)(e) No specific NIS2 Annex designation; member state discretion Micro (<10 employees, <EUR 2M) = NIS2 exempt; small/medium may qualify Important for small/medium (50+ employees); micro always exempt National insurance supervisor + NIS2 NCA
Post office giro institutions (CRD IV Art.2(5)(3)) Art.2(3)(f) Annex I Sector 3 (banking) — credit institution definition Typically medium-to-large national operators Essential (large operators) or Important Financial supervisor (central bank or FSA) + NIS2 NCA

Category (a) — Sub-threshold AIF managers are fund managers whose AUM falls below EUR 100 million for leveraged funds, or EUR 500 million for unleveraged, closed-ended funds with no redemption rights for five years, under AIFMD Article 3(2). [5] They register with their national competent authority rather than seeking full AIFM authorization, which is why DORA excludes them — they operate outside the full AIFMD supervision perimeter. Excluded from DORA, they may still qualify as NIS2 important entities if they exceed NIS2’s 50-employee or EUR 10 million turnover threshold. The majority of sub-threshold AIFMs are operationally small and will not meet this bar, but medium-sized managers close to the AUM threshold frequently do.

Category (b) — Small insurance/reinsurance undertakings are those below the Solvency II Article 4 thresholds: gross written premiums under EUR 5 million and technical provisions under EUR 25 million. [9] These micro-insurers are excluded from DORA but retain potential NIS2 scope if they meet size thresholds. In practice, most are far below the 50-employee threshold.

Category (e) — SME insurance intermediaries are the most commercially significant group. Micro-enterprises (under 10 employees, under EUR 2 million turnover) are exempt from NIS2 outright. Small and medium insurance brokers — 50 or more employees, EUR 10 million or more in annual turnover — qualify as NIS2 important entities and face the full Article 21 obligation set.

Category (f) — Post office giro institutions are national postal financial service providers. They typically operate at the scale of medium-to-large financial institutions and are the most likely of the six categories to qualify as NIS2 essential entities in the banking sector (Annex I Sector 3, which covers credit institutions as defined in CRR Article 4(1)(1)).

Sub-Threshold AIF Managers: The Double Regulatory Trap

Sub-threshold AIF managers face what compliance practitioners have started calling a double regulatory trap: excluded from DORA, and frequently too small to qualify as NIS2 important entities. The practical consequence is a gap in structured cybersecurity obligation — no DORA programme, no NIS2 programme, and often no cybersecurity governance framework at all.

The AIFMD Article 3(2) thresholds that determine DORA exclusion are: AUM at or below EUR 100 million for managers operating leveraged funds or funds with redemption rights exercisable within five years; and AUM at or below EUR 500 million for managers operating only unleveraged funds with no redemption rights for five years. [5] A manager with EUR 85 million in AUM under a leveraged strategy is excluded from DORA. If that manager employs 30 people and generates EUR 6 million in annual turnover, they fall below NIS2’s important-entity threshold (50 employees or EUR 10 million turnover under Article 3) and are also outside NIS2 scope. [3]

The trap closes for medium-sized sub-threshold AIFMs. A fund manager with EUR 90 million AUM, 65 employees, and EUR 13 million in annual management fees is excluded from DORA and qualifies as a NIS2 important entity — with no compliance framework designed for their sector to fall back on. They must implement all ten Article 21(2) measures against NIS2’s principles-based requirements directly.

Three practical implications follow.

NIS2 Annex sector classification is not straightforward. Sub-threshold AIFMs do not automatically fall into NIS2 Annex I Sector 3 (banking, which covers credit institutions only) or Sector 4 (financial market infrastructure, which covers trading venues and central counterparties). Their NIS2 classification depends on member state designation under Article 3(3)-(4), or in some jurisdictions, specific transposition decisions that bring investment management entities into scope. Several member states have extended NIS2 designation to financial market participants not covered by DORA — check the national transposition act, not just the directive text.

AUM threshold monitoring creates a dynamic compliance boundary. AIFMD requires sub-threshold AIFMs to calculate AUM at least annually and notify their regulator without delay if the threshold is temporarily exceeded. [5] A permanent breach requires both notification and a full AIFM authorization application within 30 calendar days. As AUM crosses the EUR 100 million line, the entity transitions from DORA-excluded to DORA-covered — and must build a DORA-compliant ICT risk management framework within the timescales its national competent authority specifies. Compliance teams at growing sub-threshold managers should model this transition before it happens.

Incident reporting requires direct Article 23 implementation. NIS2 Article 23(4) requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month. [7] Sub-threshold AIFMs in NIS2 scope have no DORA incident reporting framework to adapt from — they must build this capability against Article 23 directly, including identifying their national CSIRT or competent authority contact and establishing internal escalation protocols.

Residual NIS2 Obligations That Survive DORA’s Lex Specialis

Payment service providers and other DORA-covered entities are not the primary subject of this checklist — but they face an adjacent compliance exposure that is frequently underestimated. NIS2 Article 4(1)’s lex specialis displacement is not a blanket exemption: it operates only where DORA requirements are “at least equivalent in effect” to NIS2 obligations. [2] Where DORA does not address a NIS2 requirement — or addresses it only for ICT-specific functions — the NIS2 obligation survives alongside DORA.

Three categories of residual NIS2 obligation are most relevant for financial entities nominally covered by DORA.

Human resources security beyond ICT roles. NIS2 Article 21(2)(i) requires human resources security, access control policies, and asset management for all staff with access to network and information systems. DORA’s governance provisions focus primarily on the ICT function, ICT risk management roles, and ICT third-party oversight. Front-office staff at a payment institution — traders, customer service representatives, compliance officers with access to transaction systems — may fall into a gap that DORA’s ICT-centric requirements do not close, but NIS2’s Article 21(2)(i) does.

National transposition extras. NIS2 is a directive, not a regulation: member states may impose additional obligations beyond the directive’s minimum. Several have extended incident reporting timelines, added sector-specific notification channels, or introduced national competent authority registration requirements that DORA does not preempt. Financial entities operating across multiple EU jurisdictions cannot rely solely on DORA compliance — they must audit each member state’s national transposition act for obligations that apply in the gap between DORA’s scope and the national NIS2 implementation. For guidance on how NIS2 entity classification works across your operations, see our essential vs important entity guide.

Broader staff cyber hygiene training. NIS2 Article 21(2)(g) requires basic cyber hygiene practices and cybersecurity training applicable to all employees on a regular basis. DORA’s training requirements concentrate on ICT risk awareness and digital resilience for ICT function staff. An institution fully compliant with DORA’s training obligations may still fall short of NIS2’s broader staff awareness mandate in member states that have implemented it as a distinct obligation covering all personnel with system access.

The Article 21(2) Compliance Checklist: 10 Measures for Non-DORA Financial Entities

For financial entities excluded from DORA under Article 2(3), NIS2 Article 21 is the direct compliance framework. The table below adapts each of the ten Article 21(2) measures to the financial sector operating context. Essential entities face more intensive supervisory scrutiny; important entities have proportionately reduced expectations in practice, though the legal obligation set is the same. [4]

Measure Art.21(2) ref. Financial sector implementation Evidence required Essential vs Important
Risk analysis and information system security policies (a) Document cybersecurity risk across payment processing systems, client data repositories, and market access infrastructure. Risk appetite must be board-approved under Article 20. Written risk assessment policy; board resolution; asset register covering financial data systems Essential: external review recommended. Important: proportionate self-assessment accepted in most jurisdictions
Incident handling (b) Incident response plan covering detection, containment, and escalation for IT system breaches, payment fraud events, and data exfiltration. Article 23 timelines: 24h early warning, 72h notification, 1-month final report. [7] Documented IRP; test record within past 12 months; CSIRT/NCA contact list with escalation thresholds defined Essential: stricter supervisory scrutiny and shorter remediation windows in some jurisdictions. Important: proportionate review
Business continuity, backup, disaster recovery, crisis management (c) Recovery time objectives (RTOs) and recovery point objectives (RPOs) for core systems. For fund managers: NAV calculation platform, order routing, custodian connectivity. For insurers: claims and underwriting systems. Business continuity plan; backup test records; RTO/RPO documentation; crisis management escalation protocol Essential: board sign-off on BCP required. Important: senior management sign-off
Supply chain security (d) Security assessment of ICT vendors, custodians, prime brokers, and data providers. Contractual security requirements for all direct suppliers with access to NIS2-covered systems. Supplier risk register with criticality tiers; contracts with security clauses; annual vendor review records Both: proportionate to vendor criticality and concentration exposure. See supply chain security guide
Security in network and IS acquisition and development (e) Secure coding and configuration practices, vulnerability assessment before deploying new client portals or trading platforms, patch management policy covering all financial system components. Vulnerability management policy; patch management records; security testing evidence for new systems; configuration baseline documentation Essential: regular penetration testing expected. Important: periodic vulnerability scanning
Effectiveness assessment (f) Annual assessment of cybersecurity measure effectiveness. For fund managers: measure against AUM exposure and custodial risk. For insurance intermediaries: client data and premium processing system risk. Annual assessment report; corrective action log; management or board sign-off confirming review completion Both: frequency scales with entity size; essential entities expect documented external validation in some jurisdictions
Cyber hygiene and training (g) Security awareness training for all staff annually, not limited to ICT personnel. Phishing simulation for finance, trading, and client-facing staff with system access. Article 20 requires management body members to follow cybersecurity training. [6] Training records per employee; simulation exercise results; management training completion certificates Both: training must cover all staff with access to network and information systems
Cryptography and encryption policies (h) Encryption at rest and in transit for client financial data, transaction records, and custodial holdings data. TLS 1.2 minimum for API communications with custodians and third-party platforms. Key management policy covering rotation schedules. Encryption policy; technical configuration records; certificate management and key rotation log Both: encryption standard must be explicitly documented; no informal assumption of “we use HTTPS”
Human resources security, access control, and asset management (i) Role-based access control; joiners/movers/leavers process covering all staff with financial system access, not just ICT; privileged access management for systems holding client assets or processing payments. Background screening for staff with direct access to client funds. Access control policy; PAM records; joiners/movers/leavers audit log; screening documentation per role with system access Essential: formal quarterly access review expected. Important: annual review accepted in most jurisdictions
Multi-factor authentication and secured communications (j) MFA for all remote access, privileged accounts, and systems processing client assets or payments. Secured channels for crisis communications — including fallback communication where primary systems are compromised. No legacy-system exception without documented risk acceptance. MFA deployment records; exception register with signed risk acceptance; crisis communications protocol Both: member states are enforcing MFA as a non-negotiable minimum; legacy exceptions require documented management sign-off

Penalties and Director Liability for Non-DORA Financial Entities

Financial entities that incorrectly conclude they are fully covered by DORA — and therefore operate without a NIS2 compliance programme — face the NIS2 penalty regime without the benefit of DORA’s more structured implementation guidance. Under NIS2 Article 34 [8]:

  • Essential entities: maximum administrative fine of at least EUR 10 million or at least 2% of total worldwide annual turnover from the preceding financial year, whichever is higher
  • Important entities: maximum administrative fine of at least EUR 7 million or at least 1.4% of total worldwide annual turnover from the preceding financial year, whichever is higher

Article 34(1) requires fines to be effective, proportionate, and dissuasive. Proportionality criteria include whether the infringement was negligent or intentional, the degree of responsibility of the entity, the severity of harm caused, economic loss to others, and prior infringements. A sub-threshold AIF manager or insurance intermediary that self-assessed as out of NIS2 scope without conducting a proper size-threshold analysis — and then failed to implement Article 21 measures — faces a proportionality argument based on negligence, not good-faith compliance. [8]

Beyond financial penalties, NIS2 Article 20 creates direct management accountability. Management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee their implementation. Management body members are required to follow cybersecurity training. [6] Several member states, including Germany, have transposed Article 20 with provisions allowing personal liability for individuals in a management body for NIS2 infringements by the entity. A fund manager or insurance intermediary with AUM growth approaching the EUR 100 million DORA threshold should note that the same growth trajectory that triggers DORA scope entry also applies to NIS2 important-entity obligations — and both carry management liability exposure.

How Non-DORA Financial Entities Qualify as Essential or Important Under NIS2

The entity classification determines supervisory intensity, the applicable enforcement regime, and the penalty ceiling. The size thresholds from NIS2 Article 3 apply across all sectors unless a specific exception applies. [3]

Classification Size thresholds Sector requirement Supervisory model Penalty ceiling
Essential entity 250+ employees OR EUR 50M+ turnover AND EUR 43M+ balance sheet (large enterprise) Annex I sector (banking = credit institutions; financial market infrastructure = trading venues, CCPs) Ex-ante (proactive) supervision by national competent authority EUR 10M or 2% global turnover (whichever higher)
Important entity 50–249 employees OR EUR 10M–50M turnover (medium enterprise) Annex I or II sector; member state designation possible for additional entities Ex-post (reactive) supervision following incident or complaint EUR 7M or 1.4% global turnover (whichever higher)
Outside NIS2 scope Below 50 employees AND below EUR 10M turnover (micro/small) Any (including Annex I/II) No NIS2 supervision unless member state designates as in-scope No NIS2 fines

Member states retain discretion under NIS2 Article 3(3)-(4) to designate additional entities as essential or important through national assessment. Financial entities not explicitly covered by DORA that a member state considers systemically significant — including sub-threshold fund managers with concentrated exposures in domestic pension fund assets — may be designated in-scope regardless of the general size thresholds. Check the national transposition act for the member states in which your entity operates. For a detailed walkthrough of scope determination, see our NIS2 scope guide.

Frequently Asked Questions

Does being excluded from DORA mean no EU cybersecurity regulation applies?

No. Exclusion from DORA under Article 2(3) removes DORA obligations but does not create an automatic NIS2 exemption. NIS2 scope depends independently on the entity’s size and sector classification. A sub-threshold AIF manager with 70 employees and EUR 15 million in turnover that qualifies as a NIS2 important entity faces Article 21 obligations directly — the absence of DORA does not change that.

Are payment institutions exempt from NIS2?

No — and this is a common misread of Article 2(3). Payment institutions are explicitly included in DORA Article 2(1)(b), including payment institutions exempted pursuant to PSD2 Directive 2015/2366. [1] They are not among the Article 2(3) excluded categories. However, DORA-covered payment institutions face residual NIS2 obligations in areas DORA does not equivalently address — specifically broader staff training under Article 21(2)(g) and human resources security for non-ICT staff under Article 21(2)(i).

Do sub-threshold AIF managers need to register with NIS2 competent authorities?

If a sub-threshold AIFM qualifies as a NIS2 important or essential entity based on size thresholds, most member states require registration with the national competent authority — with the initial registration deadline having passed in April 2025 under Article 3. [3] The NIS2 registration obligation is distinct from AIFMD registration with the financial supervisor. Both may be required simultaneously for medium-sized sub-threshold AIFMs.

Which national authority supervises non-DORA financial entities under NIS2?

This varies by member state. Most EU jurisdictions designate the national cybersecurity agency (e.g. BSI in Germany, ANSSI in France, NCSC in the Netherlands, CERT-SI in Slovenia) as the NIS2 competent authority, but several have designated the financial services regulator as the NIS2 authority for financial sector entities. Cross-sector entities may face dual reporting obligations. Check the national transposition act for the designated authority in each operating jurisdiction.

Does a non-DORA financial entity need ISO 27001 certification for NIS2 compliance?

No. NIS2 Article 21(1) requires “appropriate and proportionate” technical and organisational measures — it does not mandate ISO 27001. [4] Commission Implementing Regulation (EU) 2024/2690 sets technical requirements for specific entity types including digital infrastructure providers, but does not apply to financial sector entities. ISO 27001 is recognised as a useful framework for demonstrating NIS2 compliance and maps well to Article 21(2)’s measure structure, but certification is not required by the directive itself. For full board accountability guidance, see our board directors and NIS2 liability guide.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: