DORA Excludes 6 Financial Entity Types from NIS2 — But 4-Hour vs 24-Hour Notification Deadlines Trap Most in Both
Two EU cybersecurity regulations applied simultaneously to financial entities from 2025 onward: DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, and NIS2 (Directive (EU) 2022/2555), transposed into national law by October 2024. For compliance officers and CISOs, the critical question is not where the two regulations differ in theory — it is which obligations survive for entities caught by both, and how to manage the operational conflicts that arise.
DORA’s relationship to NIS2 operates through a lex specialis mechanism built into both regulations. DORA Article 1(2) declares the regulation lex specialis to NIS2, and NIS2 Article 4(1) creates the gateway by which sector-specific EU acts displace NIS2 requirements where they are at least equivalent in effect. But the displacement is not total: it covers three specific regulatory pillars — ICT risk management, incident reporting, and digital resilience testing — not every NIS2 obligation.
Before examining that scope, the first question is whether DORA applies at all. Article 2(3) excludes six categories of financial entities from DORA entirely. Those entities, if they fall within NIS2’s scope, face NIS2 without any lex specialis relief. This guide covers both — which entities fall under each regulation, where both apply simultaneously, and how to resolve the operational conflicts, starting with the 4-hour vs 24-hour notification deadline that presents the most immediate compliance risk.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Free DownloadGet the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The Lex Specialis Architecture: What DORA Article 1(2) Actually Covers
DORA’s lex specialis status comes from two paired provisions that must be read together.
DORA Article 1(2) states: “This Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555 (NIS2).” For financial entities, this makes DORA the more specific, authoritative law in areas where both regulations address the same matter.
NIS2 Article 4(1) provides the mechanism: where a sector-specific EU legal act requires entities to adopt cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at least equivalent in effect to NIS2 obligations, the relevant NIS2 provisions do not apply to those entities.
Critically, DORA’s lex specialis coverage is scoped to three specific pillars — not the full breadth of NIS2:
- ICT risk management (DORA Articles 6 et seq.) — displaces NIS2 Article 21 requirements for ICT risk governance, protection, detection, response, and recovery
- ICT-related incident reporting (DORA Articles 17 et seq.) — displaces NIS2 Article 23 notification obligations for major ICT incidents
- Digital operational resilience testing (DORA Articles 24 et seq.) — displaces NIS2’s general security testing requirements
Outside these three pillars, NIS2 continues to apply in full. This is the most common misconception in compliance programs: many financial entities conclude that DORA compliance equals NIS2 compliance. It does not. The lex specialis principle is narrow — it applies where DORA and NIS2 address the same requirement and DORA is the stricter instrument. For requirements NIS2 imposes that DORA does not address — governance beyond ICT, physical security, non-ICT supply chain, national registration — NIS2 applies without displacement.
| NIS2 Obligation | DORA lex specialis applies? | Reason |
|---|---|---|
| ICT risk management (Art. 21) | Yes — DORA Arts. 6–15 take precedence | Equivalent in effect; DORA is more detailed |
| ICT incident reporting (Art. 23) | Yes — DORA Arts. 17–23 take precedence | Equivalent obligation; DORA sets tighter timeline |
| Digital resilience testing (Art. 21(2)(m)) | Yes — DORA Arts. 24–27 take precedence | More prescriptive than NIS2 general testing |
| Non-ICT supply chain security (Art. 21(2)(d)) | No | DORA covers ICT third parties only |
| Physical and environmental security (Art. 21(2)(e)) | No | No DORA equivalent |
| Human resources security (Art. 21(2)(i)) | No | No DORA equivalent |
| National registration obligations | No | Different supervisory authority; no DORA equivalent |
DORA Article 2(3): The Six Categories Excluded from DORA’s Scope
DORA Article 2(3) excludes six specific categories of financial sector entities from the regulation’s scope entirely. These entities do not benefit from DORA’s lex specialis displacement of NIS2 — if they meet NIS2’s size thresholds (medium enterprise: 50 or more employees, with annual turnover and balance sheet each exceeding €10 million) and operate in a NIS2 Annex I or II sector, they face NIS2 obligations directly.
(a) Sub-threshold alternative investment fund managers
AIFMs falling under the registration-only regime of Article 3(2) of Directive 2011/61/EU (AIFMD) — primarily managers whose total assets under management fall below the €100 million threshold (or €500 million for unleveraged, closed-ended funds with redemption rights locked for five years from initial investment). Larger AIFM firms managing above these thresholds are within DORA scope as standard managers of alternative investment funds.
(b) Sub-threshold insurance and reinsurance undertakings
Undertakings excluded from Solvency II under Article 4 of Directive 2009/138/EC — specifically those with annual gross written premiums below €5 million and technical provisions below €25 million that do not operate cross-border and are not part of a group. The large majority of insurance undertakings that fall under the Solvency II framework are within DORA scope. This exclusion captures only very small, domestically-focused insurers.
(c) Small occupational pension funds
Institutions for occupational retirement provision (IORPs) that operate pension schemes with a total of 15 or fewer members across all their schemes combined. Given the concentration of retirement assets in larger professionally-managed funds, most IORPs operating at commercial scale are within DORA scope. This exclusion targets small employer-run schemes.
(d) MiFID II-exempt natural and legal persons
Natural or legal persons exempt from the Markets in Financial Instruments Directive under Articles 2 and 3 of Directive 2014/65/EU. This covers proprietary trading firms that deal exclusively for their own account and do not provide services to third parties, certain commodity dealers, and persons using a member state’s Article 3 optional exemption. A financial entity licensed as an investment firm under MiFID II is within DORA scope; the exempted categories are comparatively narrow.
(e) Insurance intermediaries that are micro-enterprises or SMEs
Insurance intermediaries, reinsurance intermediaries, and ancillary insurance intermediaries that qualify as microenterprises (fewer than 10 employees, annual turnover or balance sheet not exceeding €2 million) or small and medium-sized enterprises under EU definitions. Large insurance brokerage groups are within DORA scope under Article 2(1)(o). Independent agents and small brokers generally are not.
(f) Post office giro institutions
Post office giro institutions referred to in Article 2(5)(3) of Directive 2013/36/EU (the Capital Requirements Directive IV). This exclusion covers certain state-operated financial service arms of postal service providers — an entity type specific to a small number of EU member states.
For entities in any of these categories, the compliance question shifts: they must assess NIS2 scope directly. A sub-threshold AIFM with 60 employees and €15 million turnover operating in the financial services sector almost certainly falls under NIS2 as an important entity, with direct Article 21 and Article 23 obligations.
What Stays Under NIS2 Even After DORA Compliance
For entities fully within DORA’s scope, four categories of NIS2 obligations persist regardless of DORA compliance status.
Non-ICT supply chain security
DORA’s third-party risk provisions (Articles 28–44) are detailed and prescriptive — but they cover ICT third-party service providers exclusively. NIS2 Article 21(2)(d) requires entities to address security in the supply chain, including the relationships between each entity and its direct suppliers or service providers across all categories. This captures physical suppliers, logistics contractors, facility management providers, and any third party whose compromise could affect operational continuity — not only ICT vendors. For financial entities with significant physical infrastructure or operational dependencies on non-ICT service providers, this gap is material.
National registration and reporting under NIS2 transpositions
NIS2 is a directive: member states transposed it into national law by October 2024, and implementations vary in scope and procedure. Most national transpositions require essential and important entities to register with the national competent NIS2 authority — typically the national cybersecurity agency (ENISA-coordinated but nationally administered), which is a distinct body from the financial sector regulator. DORA’s supervisory relationship sits with the financial NCA; meeting DORA’s requirements does not satisfy the separate obligation to register with the NIS2 national competent authority. Entities operating across multiple EU member states may face registration obligations in each jurisdiction.
Physical security and human resources security
DORA is explicitly an ICT-focused regulation. NIS2 Article 21(2)(e) requires physical and environmental security, including for the protection of network and information systems. Article 21(2)(i) addresses human resources security, access policies, and asset management. Neither has a direct DORA equivalent. Both remain fully in force for DORA-covered financial entities and must be addressed through NIS2-specific controls.
Member-state additions under national transpositions
Several member states exceeded NIS2’s minimum floor in their national transpositions. Germany’s NIS2 implementation law (NIS2UmsuCG) added obligations around security audit requirements and management training that go beyond the directive itself. Financial entities operating in those jurisdictions must perform a gap analysis against the national transposition law specifically, not the parent EU directive alone.
The practical implication: a financial entity that is fully DORA-compliant has addressed NIS2 in three areas. The remaining gap — non-ICT supply chain, physical security, HR security, national registration, and transposition-specific additions — requires a separate, NIS2-specific compliance stream.
Dual Reporting Deadlines: DORA’s 4-Hour vs NIS2’s 24-Hour Early Warning
The notification timeline divergence between DORA and NIS2 is the sharpest operational compliance problem for financial entities subject to both regimes, and the one most likely to produce a missed deadline.
| Phase | DORA | NIS2 |
|---|---|---|
| Phase 1 (initial) | 4 hours after classifying incident as major (DORA Art. 18 criteria) | 24 hours after becoming aware of a significant incident (NIS2 Art. 23) |
| Phase 2 (intermediate) | 72 hours | 72 hours |
| Phase 3 (final) | 1 month after incident resolution | 1 month after incident resolution |
| Reporting authority | Financial sector NCA (e.g., BaFin, ACPR, Central Bank of Ireland) | National CSIRT or NIS2 competent authority |
The notification triggers are different, and this creates three distinct operational scenarios:
DORA-only trigger: The incident meets DORA Article 18 criteria for a major ICT incident but does not cross NIS2’s significance threshold. Only the 4-hour DORA notification to the financial NCA applies.
NIS2-only trigger: The incident is significant under NIS2 Article 23 criteria but does not meet DORA’s definition of a major ICT incident. Only the 24-hour NIS2 early warning to the CSIRT applies.
Dual trigger: The incident crosses both thresholds simultaneously. Both obligations apply. The DORA 4-hour deadline is the binding constraint — it is shorter and will lapse first. Meeting it does not automatically satisfy the NIS2 obligation, because the reporting authorities are different and use different forms and classification frameworks.
A deconfliction provision exists within NIS2’s Article 4 framework: where an entity reports the same incident under DORA and that information is shared with the NIS2 competent authority through established national cooperation mechanisms, the NIS2 notification obligation may be considered satisfied. In practice, this requires advance coordination with national regulators to confirm the information-sharing channel is operational in that jurisdiction. Absent that confirmation, the safe approach is to treat both as independent obligations and file with each authority separately.
The practical resolution is a single internal incident classification protocol that applies DORA Article 18 criteria and NIS2 significance thresholds simultaneously at first triage. Pre-assign staff accountability for each reporting channel, pre-populate the DORA notification form template, and establish a documented escalation path that can trigger both filings within the 4-hour window without requiring a management decision on the process itself.
DORA TLPT vs NIS2 Security Testing: Where the Gap Opens
Security testing is where DORA’s requirements most clearly exceed anything NIS2 demands — but the gap applies only to a designated subset of entities.
NIS2’s testing requirement (Article 21(2)(m)): Entities must have policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including cybersecurity testing. The directive specifies no methodology, minimum frequency, or scope. Any structured, documented, human-led penetration test covering core systems and producing tracked remediation evidence supports NIS2 compliance.
DORA’s two-tier testing framework:
Tier 1 — Basic testing (all DORA entities): Annual basic resilience testing covering all ICT systems and applications supporting critical or important functions. Methods include vulnerability assessments, open-source analysis, and where appropriate, network security assessments. This tier is lex specialis for NIS2’s testing requirement — a DORA-compliant Tier 1 testing program satisfies NIS2 Article 21(2)(m) for entities not designated as significant.
Tier 2 — Threat-Led Penetration Testing (TLPT), significant entities only: TLPT must be conducted at least every three years and applies only to entities that national competent authorities designate as significant — typically systemically important banks, major insurers, and institutions whose failure would have broad market impact. TLPT follows the TIBER-EU framework: intelligence-led, using real threat intelligence specific to the institution and sector, conducted on live production systems (not replicas), using a red team over an extended engagement period, with pre-authorization from the supervisory authority required before the test begins. Results and remediation plans are reviewed by the management body and reported to the NCA.
A standard annual penetration test cannot substitute for TLPT. For non-significant DORA entities, one well-scoped annual ICT test satisfies both DORA Tier 1 and NIS2. For TLPT-designated entities, that test is a necessary baseline — TLPT is a separate, structurally distinct obligation on top of it.
Compliance Strategy: One Control Set, Two Regulatory Outputs
The most practical approach treats DORA as the ICT baseline and builds an explicit NIS2 gap-fill layer, rather than operating two parallel compliance programs. In practice, compliance practitioners estimate 60–70% overlap between DORA and NIS2 operational requirements — the ICT risk management frameworks, testing programs, incident handling procedures, and third-party ICT controls serve both regulations simultaneously.
Where consolidation is effective:
- ICT risk management governance: DORA’s board-approved ICT risk framework (Article 6) is more detailed than NIS2 Article 21. Full DORA compliance here satisfies NIS2 ICT risk management automatically.
- Incident response: One internal incident management process with two output channels — financial NCA (DORA) and CSIRT (NIS2) — on dual-trigger incidents.
- ICT third-party risk: DORA’s Register of Information (Article 28) is more demanding than NIS2’s ICT supply chain requirements. Meeting DORA here satisfies NIS2 for ICT third parties.
- Basic security testing: DORA Tier 1 annual testing satisfies NIS2 Article 21(2)(m) for non-significant entities.
Where consolidation is not possible:
- Non-ICT supply chain: Must be addressed as a separate NIS2-specific control stream.
- National registration: Different authorities, different processes; cannot be satisfied through DORA supervisory engagement.
- Physical and HR security: NIS2-specific obligations with no DORA equivalent.
- TLPT (significant entities): An additional obligation that standard penetration testing cannot substitute for.
| Role | DORA primary responsibility | NIS2 gap-fill responsibility |
|---|---|---|
| CISO | ICT risk framework; TLPT programme; DORA incident classification | Physical security controls; NIS2 incident classification; HR security policies |
| Compliance Officer | Register of Information (Art. 28); financial NCA reporting | NIS2 national registration; CSIRT reporting; non-ICT supplier risk |
| Legal | ICT third-party contract terms (Art. 28 DORA); ESA oversight cooperation | Non-ICT supplier contracts; national transposition gap analysis |
| Board / Management | ICT strategy approval; DORA risk tolerance governance (Art. 5) | NIS2 governance obligations; management accountability per national transposition |
For a full overview of NIS2 Article 21 requirements and implementation templates, see our NIS2 Banking and Finance Compliance Guide. For the Article 23 incident notification obligations that remain in force for financial entities, see NIS2 Article 23 Incident Notification Requirements. If you’re assessing which entities in your sector fall under NIS2, the NIS2 Scope and Applicability guide covers the Annex I and II sector definitions in full.
Frequently Asked Questions
Does DORA completely replace NIS2 for banks?
No. DORA displaces NIS2 in three specific areas: ICT risk management, ICT incident reporting, and digital resilience testing. Physical security, non-ICT supply chain security, national registration, and member-state transposition additions remain NIS2 obligations for banks in DORA scope.
If a financial entity meets DORA’s notification requirements, does it still need to report under NIS2?
Only if the incident crosses both DORA’s “major” threshold and NIS2’s “significant” threshold. Where both are triggered, the NIS2 obligation may be considered satisfied by DORA reporting if an established information-sharing mechanism exists between the financial NCA and the NIS2 competent authority in that jurisdiction. Without confirmed deconfliction, file with both authorities independently.
Are insurance intermediaries covered by DORA?
Large insurance intermediaries are covered by DORA under Article 2(1)(o). Insurance intermediaries, reinsurance intermediaries, and ancillary intermediaries that are microenterprises or SMEs are excluded under Article 2(3)(e). Excluded intermediaries that meet NIS2’s size thresholds must assess NIS2 obligations directly.
Does DORA apply to cloud providers serving financial entities?
ICT third-party service providers — including cloud providers and data centre operators contracted by in-scope financial entities — fall under DORA Article 2(1)(u) as critical ICT third-party providers. They may also independently fall under NIS2 as digital infrastructure providers in their own right.
When does the TLPT requirement apply?
TLPT applies to entities that national competent authorities specifically designate as “significant” under DORA — typically systemically important financial institutions. Most DORA-covered entities are subject to Tier 1 basic annual testing only. TLPT is an additional layer for the designated subset, not a requirement for all 22,000+ entities in DORA scope.
Are entities in the DORA Article 2(3) exclusion categories entirely free of NIS2?
Not automatically. Exclusion from DORA removes the lex specialis benefit — but NIS2 has its own size and sector thresholds. A sub-threshold AIFM with 60 employees operating in the financial sector may qualify as an NIS2 important entity and face Article 21 and Article 23 obligations directly. Each excluded entity must assess NIS2 scope independently.
Sources
- Regulation (EU) 2022/2554 (DORA) — Article 2 Scope: digital-operational-resilience-act.com
- Regulation (EU) 2022/2554 (DORA) — EUR-Lex official text: eur-lex.europa.eu
- NIS2 Directive (EU) 2022/2555 — Article 4, Sector-Specific Union Legal Acts: nis2resources.eu
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
