NIS2 vs DORA: which cyber rules apply to banks
A bank in Germany meets two EU laws on cyber and ICT security: DORA, written for the financial sector, and NIS2, written for critical sectors in general. For banks DORA takes precedence. The German NIS2 law still reaches them in one place, and some of their IT providers fall under NIS2 in their own right.
A directive and a regulation
DORA is a regulation and applies directly in every member state. NIS2 is a directive, so each state writes it into its own law, as Deloitte's comparison explains. Germany did so in a new version of the BSI Act (BSIG), which the Federal Office for Information Security enforces.
NIS2 covers medium and large organizations in sectors from energy, transport and health to banking, financial market infrastructure, digital infrastructure and digital services. The German act sets the thresholds in section 28: an important entity has at least 50 employees, or turnover and balance sheet above 10 million euros each; a particularly important entity has at least 250 employees, or turnover above 50 million and a balance sheet above 43 million euros.
Why DORA comes first for banks
DORA calls itself lex specialis to NIS2 in its recital 23, a point raised in a question to EIOPA on the two incident reporting channels. Where both laws cover the same ground for a financial entity, DORA's rules apply.
The German act spells this out. Section 28(6) BSIG says that sections 30, 31, 32, 35, 36, 38 and 39 do not apply to financial entities under Article 2(2) of DORA. Those sections hold the risk management measures, the extra duties for operators of critical facilities, the reporting duties, the duties to inform recipients of services, the feedback from the BSI, the duties of management and the evidence duties for critical facilities. A bank manages ICT risk and reports major incidents under DORA, to BaFin.
Where NIS2 still matters to a bank
The exemption in section 28(6) does not list section 33, the duty to register with the BSI. A bank above the thresholds therefore checks whether it has to register.
The larger effect is in the supply chain. A cloud provider, data center operator or managed service provider that runs systems for a bank can fall under NIS2 as digital infrastructure or digital services if it meets the size thresholds, with its own risk measures and its own reports to the BSI. The bank's contract with that provider then sits between two regimes: the DORA third-party rules on the bank's side and NIS2 on the provider's side.
Upcoming events on risk and compliance
Does NIS2 apply to banks in Germany?
Formally yes, since banking is one of the NIS2 sectors. In practice the German BSI Act switches off its risk management, reporting and management duties for financial entities under DORA, so a bank follows DORA for those. The cybersecurity in German finance page covers the wider set of security rules.
How do the incident reporting deadlines differ?
Under NIS2, an entity sends an early warning within 24 hours and an incident notification within 72 hours, according to Clyde & Co. Under DORA, a financial entity reports a major ICT incident within 4 hours of classifying it and no later than 24 hours after detecting it, followed by intermediate and final reports. DORA incident reporting covers the DORA side.
Is DORA stricter than NIS2?
For a financial entity it goes further in several places. DORA adds threat-led penetration tests at least every three years for selected firms, a register of information on all ICT contracts, and direct EU oversight of critical ICT providers. NIS2 has fixed fine ceilings of up to 10 million euros or 2 percent of global turnover for essential entities and 7 million euros or 1.4 percent for important ones.
NIS2, DORA and Finance Loop
Finance Loop is the meeting place for the information security officers and IT risk managers of banks and for the cloud and IT providers that serve them, the two sides that meet DORA and NIS2 in the same contract. Finance Loop announced KI Exchange 2026 in Hamburg, whose program listed DORA compliance, and Finance Loop events take place in Frankfurt, Munich, Berlin and Hamburg.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.