DORA and NIS2 interact. For banks, the exact exception matters; for IT subsidiaries and providers, their own scope assessment is decisive. This article separates risk management, registration and incident reporting and explains how to document the distinction.
NIS2 and DORA: the short answer
For financial entities within its scope, DORA is the sector-specific framework for digital operational resilience. NIS2 is the cross-sector cybersecurity framework. In Germany, section 28(6) BSIG specifies the exception for DORA financial entities: sections 30, 31, 32, 35, 36, 38 and 39 BSIG do not apply to the entities it identifies. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception
This is not a complete exemption from every BSIG connection. Registration, the independent scope assessment of an IT subsidiary and service providers’ obligations need separate consideration. Start with the individual entity and its activities. BSIG section 28: scope and DORA exception BSIG section 33: registration
Who falls under which framework?
DORA covers the financial entities in Article 2, including credit institutions, payment institutions, investment firms and insurers, subject to its exceptions. Article 2(2) collectively defines the categories in paragraph 1(a) to (t) as financial entities. ICT third-party service providers appear separately in point (u); this does not turn every IT supplier into a financial entity. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30
The German BSIG requires assessment of entity type, size and special cases. In the ordinary size-based case for an important entity, a covered activity is combined with at least 50 employees or both annual turnover and annual balance-sheet total exceeding EUR 10 million. Essential entities are subject to other thresholds or size-independent cases. Turnover alone is therefore not a complete assessment. Rules for linked undertakings also need consideration. BSIG section 28: scope and DORA exception
What does DORA’s precedence mean?
Article 4 NIS2 disapplies the corresponding NIS2 provisions, including supervision and enforcement, where a sector-specific EU act imposes at least equivalent risk-management or incident-reporting requirements. Article 1(2) DORA identifies DORA as such an act. In Germany, section 28(6) BSIG expressly identifies the excluded provisions. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception
| Aspect | NIS2 / German BSIG | DORA |
|---|---|---|
| Legal form | EU directive implemented nationally; the new BSIG entered into force on 6 December 2025 | EU regulation applicable from 17 January 2025 |
| Scope | Covered entity types, size rules and special cases | Financial entities under Article 2, with exceptions; separate rules for ICT third-party providers |
| Risk management | Appropriate, proportionate and effective measures under section 30 BSIG | ICT risk management, incident management, testing and ICT third-party risk |
| Management | Implementation, oversight and training under section 38 BSIG where applicable | Management-body responsibility under Article 5 DORA |
| Incident reporting | Section 32 BSIG for significant incidents unless an exception applies | Article 19 DORA and related technical standards for major ICT-related incidents |
| Registration | Assess section 33 BSIG against the entity’s own scope | The DORA exception in section 28(6) BSIG does not list section 33 |
The comparison distinguishes EU acts from their German implementation. For a specific legal entity, determine the applicable exception, competent authority and any sector-specific rule. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG consolidated text with July 2026 amendments
Must a DORA bank register with the BSI?
Registration is separate from DORA incident reporting. Section 33(1) BSIG requires registration no later than three months after an entity first or again falls within its specified categories. Section 28(6) does not exempt section 33. The conclusion from that wording is that, where a DORA financial entity also falls within section 33, the DORA exception does not remove its registration obligation. DORA status alone does not place every financial entity within the BSIG categories. BSIG section 28: scope and DORA exception BSIG section 33: registration
For critical installations, section 66 BSIG must also be considered. It links the application of certain new definitions and registration provisions to the entry into force of a statutory instrument and requires older versions to continue applying until then. Simply applying the new section 33(2) without checking this transition would be incomplete. BSIG section 66: transitional rules for critical installations
Why are the reporting deadlines different?
| Stage | Section 32 BSIG | DORA / Article 5 of Regulation (EU) 2025/301 |
|---|---|---|
| First notification | Without undue delay, no later than 24 hours after awareness of a significant incident | As early as possible, generally within four hours of classification as major and no later than 24 hours after awareness of the ICT incident |
| Further report | Without undue delay, no later than 72 hours after awareness; an intermediate report on request | Intermediate report no later than 72 hours after the initial notification, even without a status change; an update without undue delay and in any event when regular activities recover |
| Final report | No later than one month after the 72-hour notification; a progress report first if the incident continues | No later than one month after the intermediate report or the latest updated intermediate report |
DORA has a specific rule for incidents classified as major more than 24 hours after awareness: under Article 5(2), the initial notification is due within four hours of that classification. Weekend and public-holiday extensions are also not universally available. Credit institutions, central counterparties, trading venues and the other entities listed in paragraph 5 cannot use them for initial notifications and intermediate reports. Delegated Regulation (EU) 2025/301, Article 5: DORA reporting deadlines
The reporting workflow therefore needs separate records of awareness, classification and each submitted report. Under the BSIG, reports go to the joint BSI/BBK reporting point; under DORA, the authority designated under Article 46 is relevant. A bank’s DORA report is not an additional report under section 32 BSIG where that provision is excluded for the bank. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception BSIG section 32: incident reporting
What applies to IT subsidiaries and providers?
An IT subsidiary does not inherit the DORA exception merely by belonging to a banking group. It must assess its own entity type, size and activities. A cloud, data-centre or managed-service provider may have its own BSIG obligations while also being contractually included in its banking clients’ DORA third-party risk management. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception
In practice, the bank maintains its DORA contractual arrangements and register of information, while the provider meets its own applicable obligations. Contracts need to support timely information exchange. A register entry replaces neither the provider’s scope assessment nor its reporting to the competent authority. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30
Management duties, personal liability and fines are separate issues
For management bodies of relevant German essential and important entities, section 38 BSIG distinguishes implementation and oversight of risk-management measures from regular training. An IT provider or security officer can perform work, but management still needs its own decisions and oversight. First establish applicability, including the DORA exception.
Personal liability is different from an organisational fine. Section 38(2) concerns culpably caused loss to the entity itself and primarily refers to the corporate-law rules applying to that entity. Section 65 addresses specific administrative offences with differing maximum penalties. A cyberattack alone establishes neither automatic personal liability nor a particular fine.
| Decision | Traceable working record |
|---|---|
| Scope and accountability | Legal entity, applicable rule, reasoned exception and responsible function. |
| Priorities and resources | Material risks, agreed actions, budget and assigned implementation. |
| Oversight | Open deviations, effectiveness evidence, escalations and recorded follow-up decision. |
| Training | Date, risks covered, participating management members and further learning needs. |
A simple decision log can record the trigger, available information, options considered, decision, owner and review date. This helps management return to unresolved issues. It does not provide a blanket exemption from liability.
Legal and professional sources: BSIG § 38: Geschäftsleitung, Umsetzung, Überwachung und Schulung; BSIG § 65: Bußgeldtatbestände und Höchstbeträge; BSIG § 28: Anwendungsbereich und Ausnahmen.
Which fine figures are supported by the law?
Section 65 BSIG assigns different maximum fines to specific offences. For certain infringements, including risk-management and reporting obligations, subsection 5 point 1 sets maxima of EUR 10 million for essential entities and EUR 7 million for important entities. For those offences, where total turnover exceeds EUR 500 million, subsections 6 and 7 provide turnover-based ceilings of two and 1.4 per cent respectively. BSIG section 65: offences and maximum fines
Failure to meet the registration requirement in section 33(1), however, falls under section 65(2) point 6 and subsection 5 point 5, with a maximum of EUR 500,000. Saying that every German NIS2 breach carries up to EUR 10 million or two per cent would be incorrect. DORA has its own sanctioning and enforcement framework; a single generic percentage is not a useful comparison. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 65: offences and maximum fines
How to document the assessment in practice
01Identify legal entities
Record relevant companies, activities, authorisations, size and organisational connections.
02Map the applicable rules
Document DORA scope, BSIG entity type and specific exceptions.
03Assess registration separately
Consider section 33 BSIG and, where relevant, transitional rules for critical installations.
04Test reporting workflows
Walk through responsibilities, triggers, deadline calculations, cover arrangements and escalation using an example.
05Include service providers
Connect contractual terms and information flows with DORA third-party risk management.
06Maintain the evidence
Keep the decision, legal version, responsibilities and changes traceable.
Common questions about the distinction
Sources & further reading
- NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23eur-lex.europa.eu
- DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30eur-lex.europa.eu
- BSIG section 28: scope and DORA exceptiongesetze-im-internet.de
- BSIG section 33: registrationgesetze-im-internet.de
- BSIG section 32: incident reportinggesetze-im-internet.de
- Delegated Regulation (EU) 2025/301, Article 5: DORA reporting deadlineseur-lex.europa.eu
- BSIG section 65: offences and maximum finesgesetze-im-internet.de
- BSIG section 66: transitional rules for critical installationsgesetze-im-internet.de
- BSIG consolidated text with July 2026 amendmentsgesetze-im-internet.de
- BSIG § 38: Geschäftsleitung, Umsetzung, Überwachung und Schulunggesetze-im-internet.de
An offering from T-NEX GmbH
Connect responsibilities and evidence
T-NEX helps assess software needs and design traceable workflows, starting with your specific task and the evidence it requires.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
