DORA-Only or Still NIS2? How Germany’s BaFin and BSIG Draw the Line for Banks, Insurers, and Investment Firms
Germany’s amended BSI Act now reaches roughly 29,500 companies, and a meaningful share of them sit in banking, insurance, and investment services — sectors that assumed the EU’s Digital Operational Resilience Act (DORA) had already taken NIS2 off their desk. That assumption is only half right. DORA’s lex specialis status does displace NIS2’s risk-management and incident-reporting rules for the financial entities it actually covers. But DORA’s own scope article carves a specific population back out — sub-threshold fund managers, small insurers, exempted MiFID II firms, tiny occupational pension schemes — and hands them straight back to full NIS2, transposed in Germany as the amended BSIG. The registration deadline for that law passed on 6 March 2026. This guide draws the exact boundary, using DORA’s own scope article, the BSIG’s transposition of the carve-out, and BaFin’s and the BSI’s own published positions, so you know which side of it your institution sits on.
Does This Apply to You? The Three-Question Test
In plain terms: if you’re a bank, insurer, investment firm, fund manager, or payment provider operating in Germany, you’re almost certainly covered by either DORA or NIS2 — the open question is which one, and “I’m in finance, so DORA covers me” is not a safe answer on its own. Three questions, in order, settle it. Unlike domain registries or telecoms providers, credit institutions and trading venues get no “regardless of size” free pass under NIS2 itself — size matters for them exactly as it does for any other sector [2].
| Question | If yes | If no |
|---|---|---|
| Are you one of the 21 financial-entity types listed in DORA Article 2(1) — credit institution, payment institution, investment firm, insurer, IORP, crypto-asset service provider, and similar [3]? | Go to question 2 | You’re outside DORA. Check the NIS2 Annex I/II sector list and Germany’s size thresholds directly — roughly €10 million annual turnover or 50 employees [7] |
| Are you exempted under DORA Article 2(3) — e.g. a sub-threshold, registered-only fund manager under Article 3(2) of the AIFM Directive, an insurer below the Solvency II premium-income thresholds (Article 4), an occupational pension scheme with fewer than 15 members, an entity exempted under MiFID II Articles 2–3, or a micro/SME insurance intermediary [3]? | You’re “residual NIS2” — see the next section | Go to question 3 |
| Do you meet Germany’s NIS2 size threshold — roughly €10 million annual turnover or 50 employees [7]? | You’re “DORA-only”: the BSIG registration duty still applies, but the substantive risk-management and incident rules don’t | You’re out of scope for now, until you cross the threshold |
The table below turns that test into a quick reference for the entity types compliance teams ask about most, drawn directly from DORA’s own scope and exemption list [3].
| Entity type | DORA status | Falls back to full BSIG? |
|---|---|---|
| Credit institutions, payment/e-money institutions, non-exempt investment firms, CCPs/CSDs/trading venues, insurers above Solvency II thresholds, crypto-asset service providers | Covered, Art.2(1) | No — registration only (see next section) |
| Sub-threshold / registered-only AIFMs (Art.3(2) AIFMD) | Exempted, Art.2(3) | Yes, if size threshold met |
| Insurers below Solvency II premium threshold (Art.4, Directive 2009/138/EC) | Exempted, Art.2(3) | Yes, if size threshold met |
| Occupational pension schemes (IORPs) with under 15 members | Exempted, Art.2(3) | Yes, if size threshold met |
| Entities exempted under MiFID II Articles 2–3 | Exempted, Art.2(3) | Yes, if size threshold met |
| Micro/SME insurance intermediaries | Exempted, Art.2(3) | Yes, if size threshold met |
Why “DORA-Only” Isn’t Automatic: Article 4 and Germany’s Section 28(6) Answer
In plain terms: DORA doesn’t switch NIS2 off for finance as a sector — it switches it off only for the specific entities DORA actually lists, and only for two specific chunks of NIS2 obligation. Everyone DORA’s Article 2(3) leaves out gets neither the switch-off nor a lighter version of NIS2 — they get the whole thing.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The mechanism sits in NIS2 itself, not in DORA. Article 4 of the NIS2 Directive says that where a sector-specific EU legal act imposes cybersecurity risk-management or incident-notification requirements “at least equivalent in effect” to NIS2’s, the corresponding NIS2 provisions — including supervision and enforcement — do not apply to the entities that act actually covers. Equivalence is tested against Article 21(1)–(2) for risk management and Article 23(1)–(6) for notification, including whether the sector regulator has direct access to incident reports the way a NIS2 CSIRT would [1]. DORA’s own preamble states, as a matter of legislative intent rather than binding obligation, that “this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555” — that’s Recital 16, a non-binding statement of purpose, not the operative provision itself; the actual legal switch is Article 4 of NIS2 [4]. The BSI, Germany’s competent authority, states this plainly on its own site: DORA is to be classified, under its own Article 1(2), as the sector-specific act referred to in Article 4 of the NIS2 Directive [5].
Germany’s transposition, the NIS2UmsuCG, wrote that Article 4 test directly into the amended BSIG. German legal commentary describes Section 28(6) BSIG as the provision that dis-applies Sections 30, 31, 32, 35, 36, 38, and 39 BSIG — the risk-management, incident-notification, and management-liability paragraphs — for financial institutions within DORA’s Article 2(1)/(2) scope, including institutions pulled into that scope via cross-references in Germany’s Banking Act and Insurance Supervision Act. Section 33 BSIG, the registration duty, is conspicuously absent from that exemption list in both independent write-ups reviewed for this article [8]. That omission is the whole practical story: a DORA-only institution loses NIS2’s substantive obligations, but not the duty to tell the BSI it exists.
This is a narrower displacement than most cross-posted “NIS2 vs DORA” content implies — our own general comparison of the two regimes walks through the EU-wide version of this boundary in more depth here. What’s specific to Germany is what happens next: a registration duty that survives the carve-out, and a liability question that doesn’t disappear so much as move to a different law.
Registration, Board Liability, and the Deadline That’s Already Passed
In plain terms: every in-scope entity in Germany, DORA-only or not, had to register with the BSI by 6 March 2026. If that didn’t happen, it’s not a future task — it’s an open compliance gap today. And board members at residual-NIS2 financial institutions carry a personal-liability exposure that DORA-only institutions were specifically carved out of.
The NIS2UmsuCG entered into force on 6 December 2025 with no transition period. Sections 33–34 BSIG require registration with the BSI within three months of that date — 6 March 2026 — for entities already in scope, or within three months of becoming in scope for anyone crossing the threshold later. The BSI’s registration portal has been live since 6 January 2026 [6]. Because Section 33 sits outside Section 28(6)’s exemption list, this deadline applied identically to DORA-only financial entities and to residual-NIS2 ones — the carve-out changes what you owe after registering, not whether you register. Our full Germany transposition guide covers the broader BSIG registration and sector-classification mechanics beyond the finance-specific boundary covered here.
Board liability follows the same split. Section 38 BSIG obliges management to approve, actively oversee, and undergo regular training (at least every three years) on cybersecurity risk-management measures — a duty that reaches beyond GmbH managing directors to AG and SE board members. Breach it culpably and liability runs to personal assets, not just the company’s; day-to-day execution can go to a CISO or outside adviser, but the strategic approval and oversight duty itself cannot be delegated away [9]. Because Section 38 is one of the paragraphs Section 28(6) dis-applies for DORA-covered entities, a genuinely DORA-only bank’s board doesn’t carry that specific BSIG exposure. That isn’t the same as no exposure: DORA Article 5 puts equivalent, arguably broader, ultimate responsibility on the management body directly — approving the ICT risk framework, the digital resilience strategy, the business-continuity policy, and the ICT budget, with named individuals expected to keep their own risk knowledge current [10]. Liability doesn’t vanish for a DORA-only board; it moves from Section 38 BSIG to Article 5 DORA, enforced by BaFin rather than the BSI. A residual-NIS2 board — a sub-threshold fund manager, say — keeps the full Section 38 exposure with no DORA equivalent standing in for it.
Enforcement runs through separate channels either way, and the ceilings aren’t interchangeable:
| Regime | Enforcement body | Penalty ceiling |
|---|---|---|
| Residual-NIS2 (full BSIG applies) | BSI | €10,000,000 or 2% of annual worldwide turnover, per essential/important classification [7] |
| DORA-covered (Section 28(6) exemption applies) | BaFin, under Germany’s Finanzmarktdigitalisierungsgesetz (the national DORA-implementing law) | Not stated here — secondary sources conflict on the exact figure. The enforcement channel is confirmed; the ceiling isn’t, so this article won’t guess at one |
Read our breakdown of NIS2’s own Article 23 incident-notification timeline for how the 24-hour/72-hour/one-month structure applies to entities that stay on full NIS2.
Reader Playbook by Role
The three-question test and the Section 28(6) mechanism land differently depending on your seat.
Compliance officer or legal: run the three-question test per legal entity, not per group — a banking group can have a DORA-covered parent and a sub-threshold AIFM subsidiary sitting on opposite sides of the line. Document the classification decision itself; it’s the evidence an auditor or the BSI will ask for first, and it’s the artefact that shows you didn’t just assume finance equals DORA.
CISO or IT security lead: don’t treat “we’re DORA-compliant” as a substitute for a BSIG gap check. If your institution is genuinely DORA-only, your Article 21-equivalent work is already done through DORA’s ICT risk framework — confirm that in writing rather than assuming it, because Section 28(6)’s dis-application only holds while DORA’s requirements stay equivalent [1] [5].
Board or C-suite: ask your compliance function directly which of the two liability regimes — Section 38 BSIG or Article 5 DORA — attaches to you personally, and get that confirmed in the board minutes. “We’re a financial entity, so DORA covers us” is not a defensible answer to a regulator asking why registration didn’t happen on time.
SME owner or smaller entity — a small insurance intermediary or an emerging fund manager: Article 2(3)’s exemption list was written for you, and that’s exactly why it doesn’t help you. If you’re a microenterprise insurance intermediary or a sub-threshold AIFM, DORA’s exemption doesn’t mean less regulation — it means full NIS2 the moment you cross Germany’s size threshold, with none of DORA’s displacement to soften it.
Compliance Checklist
- Classify now (overdue if not done): run the three-question test per legal entity and keep the decision on file.
- Register with the BSI: due 6 March 2026 for entities already in scope on 6 December 2025 — if this hasn’t happened, treat it as an active gap, not a future task [6].
- If residual-NIS2: implement the full Article 21(2) measure set and the 24-hour/72-hour/one-month incident-notification chain; confirm board sign-off under Section 38 BSIG.
- If DORA-only: confirm Article 5 governance approvals are documented and current, and keep registration current even though the substantive BSIG rules don’t apply.
Frequently Asked Questions
Does DORA replace NIS2 for every German bank? No. It replaces NIS2’s risk-management and incident-notification rules only for entities DORA’s Article 2(1) actually covers, and even then the BSIG registration duty survives [1] [8].
What if my institution is small enough to be exempted under DORA Article 2(3)? Being exempted from DORA is not the same as being exempted from regulation — it means you fall back to full NIS2/BSIG if you meet Germany’s size threshold, with no DORA displacement in your favour [3] [7].
Legal Disclaimer
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive, Article 4 — nis-2-directive.com, Article 4 (sector-specific Union acts / lex specialis mechanism)
- NIS2 Directive, Article 2 — nis-2-directive.com, Article 2 (regardless-of-size scope categories)
- DORA (Regulation (EU) 2022/2554), Article 2 — digital-operational-resilience-act.com (scope list and Article 2(3) exemptions; cross-checked against Advisera’s Article 2 summary, not separately linked)
- DORA, Recital 16 — digital-operational-resilience-act.com, Preamble 11–20 (non-binding lex specialis statement)
- BSI (Bundesamt für Sicherheit in der Informationstechnik), official NIS-2/DORA guidance — bsi.bund.de
- DLA Piper, “NIS 2 Directive Transposed in Germany” — dlapiper.com (registration deadlines, BSI portal)
- Reed Smith, “Germany Implements NIS2” — reedsmith.com (size thresholds, penalty ceiling)
- PayTechLaw, “NIS2 meets DORA” — paytechlaw.com (Section 28(6) BSIG mapping; corroborated by Deutscher Presseindex, “BSIG neben DORA,” not separately linked)
- Cortina Consult, “NIS2 Geschäftsführerhaftung nach Paragraph 38 BSIG” — cortina-consult.com (Section 38 BSIG personal-liability detail)
- DORA, Article 5 — digital-operational-resilience-act.com (management body ICT governance)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
