
The Covid-19 pandemic accelerated the digital transformation of society. Many companies and sectors were required to operate remotely without the necessary online resources or digital systems. This increased the overall vulnerability of digital systems within the EU and heightened the threat of cyber-attacks across the Member States. The EU has established the NIS-2 Directive and the Digital Operational Resilience Act (DORA) to address the heightened risk and ensure EU wide cybersecurity. This Just the Facts explains what the NIS-2 Directive and Digital Operational Resilience Act are, the main provisions included in each, and the legal overlap between NIS-2 and DORA.
NIS-2
The NIS-2 Directive is an updated version of the Network and Information Systems Directive which was established in 2016 to ensure EU wide standards on cybersecurity. NIS-2 builds on the original NIS directive by expanding its scope, in addition to addressing the shortcomings of the original directive. NIS-2 applies to all entities providing services in key sectors, including for example, energy, healthcare, transport and banking and financial services. The Directive is aimed at simplifying the implementation of the original NIS and includes significant changes in relation to governance, incident reporting and enforcement. Member States will have until 17 October 2024 to transpose the directive into national law.
DORA
The EU’S Digital Operational Resilience Act (DORA) is designed to create a harmonised regulatory framework and to strengthen digital operational resilience of financial services entities across the EU. The regulation applies to financial services entities and ICT third-party providers and aims to ensure that they can prevent and mitigate cyber-attacks and other ICT related operational disruptions. The DORA regulation focuses on incident reporting, managing third-party risks and liability. It will apply from January 2025.
NIS-2 – What is it?
The NIS-2 directive aims to update the original directive by widening the scope of the law to include more sectors across society.
The updated directive was adopted by the Parliament at the November 2022 plenary session. NIS-2 entered into force in January 2022 and Member States have until 17 October 2024 to transpose the directive into national law.
Broadened Scope of regulation
The expansion of the scope covered by NIS-2 is intended to increase the level of cybersecurity across the EU by obliging more entities and sectors to take measures. Under NIS-2, sectors are divided into groups based on how essential their operations are to society, with sectors of “High Criticality” subject to the strictest measures.
The entities included in the updated directive are considered essential to public interest. Sectors will be divided into “High Criticality” and “Critical”. Organisations within these sectors will be grouped as essential or important. Under the new directive, sectors such as water management, space industry, public administration and ICT service management have been added to the list of “High Criticality”. Sectors including research, food production, postal services, waste management, manufacturing and the production of chemicals have been included in the grouping of “Critical” sectors. The regulation will apply to medium and large entities within these sectors, substantially broadening the scope of the regulation in comparison to the 2016 NIS directive. For a full list of sectors included in NIS-2 see here.
Incident Reporting
NIS-2 includes updated requirements for incident reporting in Member States. Organisations that experience operational failure or possible cybersecurity breaches will have to adhere to a strict incident reporting process. Entities under NIS-2 have 24 hours to submit an initial warning and 72 hours to submit an updated report and are required to submit a final report no later than a month after the incident has occurred. Member States will be able to exchange reports and information from related incidents through the Cooperation Group established in the original NIS directive.
Governance
An important aspect of the NIS-2 is the shift in accountability for cybersecurity within an organisation. Under the updated directive, the Board of Management and high-level executives of an entity will also be held accountable for ensuring compliance, in addition to security teams. Management bodies of “essential” and “important” entities will be required to supervise the implementation of risk management measures in addition to undergoing training in safe cybersecurity practices. In severe cases of non-compliance, the Board of Management can be held personally liable for breaches of cybersecurity.
Penalties for non-compliance
Ireland’s national competent authority for the National Cyber Security Centre (NCSC), will be responsible for imposing more stringent measures for non-compliance under NIS-2. However, the competent authority for the financial services sector will still be the Central Bank of Ireland. These penalties can include ceasing conduct, imposing administrative fines and allocating a monitoring officer to oversee compliance with an entity. The fines can include up to €10m or 2% of total global annual revenue for essential entities or up to €7m or 1.4% of total global annual revenue for important entities, whichever figure is higher.
DORA – what is it?
Since the COVID-19 pandemic, the financial sector has become increasingly reliant on technology and third-party service providers for their digital systems. This increased reliance on digital systems poses an increased risk of cross- border threats to the financial sector in the EU.
The purpose of the Digital Operational Resilience Act (DORA) is to strengthen the IT security systems of financial institutions and services. The legislative proposal for DORA was announced in the Commission’s 2020 workplan under the title, ‘A Europe fit for the Digital Age’. The regulation entered into force on 16 January 2023 and will apply from 17 January 2025.
DORA applies to over twenty different types of financial services, including banks, insurance companies and investment firms.
DORA includes targeted rules on the following areas:
- Information and Communication Technology (ICT) risk management
- ICT-related incident management, classification and reporting
- Digital operational resilience testing
- Management of ICT third-party risks
- Information Sharing arrangements
Compliance and Oversight
Financial entities will be expected to comply with DORA regulation requirements from January 2025; these are set out in the regulatory and implementing standards (RTS and ITS). The development and delivery of the RTS and ITS standards has been led by the ESAs and has been developed in two phases, with the first batch of regulations already adopted by the European Commission. Ahead of the application of DORA, financial entities are expected to assess their existing resilience, outsourcing and ICT risk management frameworks, and any relevant contracts. They should identity any gaps and plan how to address these ahead of January 2025.
As regards outsourcing to ICT third-party providers, financial entities will be subject to specific requirements around the register of information on ICT outsourcing, in addition to standards for subcontracting ICT services for critical or important functions within a financial entity as set out in the RTS and ITS. Under DORA, contracts between regulated financial entities must contain certain minimum requirements as outlined in Article 30 of DORA.
Certain third-party ICT service providers that are identified as critical by the ESAs will also come under the scope of DORA; however, they will be subject to DORA’s oversight, as opposed to its regulatory framework). One of the ESAs will be identified as the “Lead Overseer”, and in conjunction with the relevant national competent authority will be responsible for oversight. The Lead Overseer will assess whether critical third-party ICT service providers have the rules and systems in place to manage cyber risk.
Incident Reporting
The DORA regulation sets out new requirements for incident reporting. Entities must establish systems for monitoring, managing, logging and classifying ICT-related incidents. In the case of a critical incident, entities will have to file three separate reports; an initial report to notify authorities, an intermediate report on the progress made towards resolving the incident, and a final report outlining the changes put in place to prevent a similar incident from occurring again. Financial entities that fail to report major ICT-related incidents or significant cyber threats risk being fined.
Governance
Under the DORA regulation, the responsibility for the failure of a financial entity to comply with requirements in the DORA regulation will fall on the senior executives, board members and company leaders who can be held personally liable in some cases. This shifts the responsibility of cybersecurity compliance from the security teams to those holding the most senior positions in an entity.
Enforcement
The European Supervisory Authorities (ESAs) will have the authority to impose fines on entities that fail to comply with the DORA regulation. Entities found in violation of DORA may face fines of up to 2% of their total worldwide turnover, while individuals could be fined up to €1 million. However, third-party ICT providers, designated as “critical” by the ESAs, could face even higher fines – up to €5 million for a company and €500,000 for an individual, for non-compliance. Meanwhile, national competent authorities – in Ireland’s case the Central bank of Ireland– will have supervisory and investigatory powers and the authority to publish notices of administrative penalties.
Where do they overlap? Which has legal precedent?
The NIS-2 directive and DORA aim to ensure a high level of EU cybersecurity across Member States. Although both regulations include similar measures, there are differences. DORA applies only to a specific list of financial entities (available here), whereas NIS-2 covers a wider scope of sectors and entities across society. Both regulations set out new requirements for incident reporting as well as shifting the legal responsibility of cybersecurity from security teams of a company to the Board of Management.
The overlap between DORA and NIS-2 regulations is avoided due to the lex specialis provision contained in DORA giving it priority over the NIS-2 Directive.
The lex specialis allows for the specialist regulation to override the general regulation. For example, both DORA and NIS-2 set out requirements for incident reporting and third-party risk. However, because the requirements laid out in DORA apply specifically to a financial institution, the financial institutions must prioritise compliance with DORA requirements over NIS-2.
Most recent EMI Publications:
Subscribe now to The EU Inside Track!
Welcome to The EU Inside Track, a new briefing update from EM Ireland. We aim to bring you key developments from Brussels, Strasbourg and beyond in an accessible, digestible format. You can subscribe now for timely updates straight to your email inbox.

