DEEN
Regulation

NIS2 vs DORA: what applies to banks and their IT?

NIS2 and DORA for banks: compare scope, BSI registration, reporting deadlines and ICT providers, with references to Germany’s BSIG.

First version: Updated: 9 min read

Illustration comparing NIS2 and DORA in the financial sector

DORA and NIS2 interact. For banks, the exact exception matters; for IT subsidiaries and providers, their own scope assessment is decisive. This article separates risk management, registration and incident reporting and explains how to document the distinction.

NIS2 and DORA: the short answer

For financial entities within its scope, DORA is the sector-specific framework for digital operational resilience. NIS2 is the cross-sector cybersecurity framework. In Germany, section 28(6) BSIG specifies the exception for DORA financial entities: sections 30, 31, 32, 35, 36, 38 and 39 BSIG do not apply to the entities it identifies. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception

This is not a complete exemption from every BSIG connection. Registration, the independent scope assessment of an IT subsidiary and service providers’ obligations need separate consideration. Start with the individual entity and its activities. BSIG section 28: scope and DORA exception BSIG section 33: registration

Who falls under which framework?

DORA covers the financial entities in Article 2, including credit institutions, payment institutions, investment firms and insurers, subject to its exceptions. Article 2(2) collectively defines the categories in paragraph 1(a) to (t) as financial entities. ICT third-party service providers appear separately in point (u); this does not turn every IT supplier into a financial entity. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30

The German BSIG requires assessment of entity type, size and special cases. In the ordinary size-based case for an important entity, a covered activity is combined with at least 50 employees or both annual turnover and annual balance-sheet total exceeding EUR 10 million. Essential entities are subject to other thresholds or size-independent cases. Turnover alone is therefore not a complete assessment. Rules for linked undertakings also need consideration. BSIG section 28: scope and DORA exception

What does DORA’s precedence mean?

Article 4 NIS2 disapplies the corresponding NIS2 provisions, including supervision and enforcement, where a sector-specific EU act imposes at least equivalent risk-management or incident-reporting requirements. Article 1(2) DORA identifies DORA as such an act. In Germany, section 28(6) BSIG expressly identifies the excluded provisions. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception

NIS2/BSIG and DORA compared
AspectNIS2 / German BSIGDORA
Legal formEU directive implemented nationally; the new BSIG entered into force on 6 December 2025EU regulation applicable from 17 January 2025
ScopeCovered entity types, size rules and special casesFinancial entities under Article 2, with exceptions; separate rules for ICT third-party providers
Risk managementAppropriate, proportionate and effective measures under section 30 BSIGICT risk management, incident management, testing and ICT third-party risk
ManagementImplementation, oversight and training under section 38 BSIG where applicableManagement-body responsibility under Article 5 DORA
Incident reportingSection 32 BSIG for significant incidents unless an exception appliesArticle 19 DORA and related technical standards for major ICT-related incidents
RegistrationAssess section 33 BSIG against the entity’s own scopeThe DORA exception in section 28(6) BSIG does not list section 33

The comparison distinguishes EU acts from their German implementation. For a specific legal entity, determine the applicable exception, competent authority and any sector-specific rule. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG consolidated text with July 2026 amendments

Must a DORA bank register with the BSI?

Registration is separate from DORA incident reporting. Section 33(1) BSIG requires registration no later than three months after an entity first or again falls within its specified categories. Section 28(6) does not exempt section 33. The conclusion from that wording is that, where a DORA financial entity also falls within section 33, the DORA exception does not remove its registration obligation. DORA status alone does not place every financial entity within the BSIG categories. BSIG section 28: scope and DORA exception BSIG section 33: registration

For critical installations, section 66 BSIG must also be considered. It links the application of certain new definitions and registration provisions to the entry into force of a statutory instrument and requires older versions to continue applying until then. Simply applying the new section 33(2) without checking this transition would be incomplete. BSIG section 66: transitional rules for critical installations

Why are the reporting deadlines different?

Reporting deadlines and their triggers
StageSection 32 BSIGDORA / Article 5 of Regulation (EU) 2025/301
First notificationWithout undue delay, no later than 24 hours after awareness of a significant incidentAs early as possible, generally within four hours of classification as major and no later than 24 hours after awareness of the ICT incident
Further reportWithout undue delay, no later than 72 hours after awareness; an intermediate report on requestIntermediate report no later than 72 hours after the initial notification, even without a status change; an update without undue delay and in any event when regular activities recover
Final reportNo later than one month after the 72-hour notification; a progress report first if the incident continuesNo later than one month after the intermediate report or the latest updated intermediate report

DORA has a specific rule for incidents classified as major more than 24 hours after awareness: under Article 5(2), the initial notification is due within four hours of that classification. Weekend and public-holiday extensions are also not universally available. Credit institutions, central counterparties, trading venues and the other entities listed in paragraph 5 cannot use them for initial notifications and intermediate reports. Delegated Regulation (EU) 2025/301, Article 5: DORA reporting deadlines

The reporting workflow therefore needs separate records of awareness, classification and each submitted report. Under the BSIG, reports go to the joint BSI/BBK reporting point; under DORA, the authority designated under Article 46 is relevant. A bank’s DORA report is not an additional report under section 32 BSIG where that provision is excluded for the bank. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception BSIG section 32: incident reporting

What applies to IT subsidiaries and providers?

An IT subsidiary does not inherit the DORA exception merely by belonging to a banking group. It must assess its own entity type, size and activities. A cloud, data-centre or managed-service provider may have its own BSIG obligations while also being contractually included in its banking clients’ DORA third-party risk management. NIS2: Directive (EU) 2022/2555, Articles 2–4 and 20–23 DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 28: scope and DORA exception

In practice, the bank maintains its DORA contractual arrangements and register of information, while the provider meets its own applicable obligations. Contracts need to support timely information exchange. A register entry replaces neither the provider’s scope assessment nor its reporting to the competent authority. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30

Management duties, personal liability and fines are separate issues

For management bodies of relevant German essential and important entities, section 38 BSIG distinguishes implementation and oversight of risk-management measures from regular training. An IT provider or security officer can perform work, but management still needs its own decisions and oversight. First establish applicability, including the DORA exception.

Personal liability is different from an organisational fine. Section 38(2) concerns culpably caused loss to the entity itself and primarily refers to the corporate-law rules applying to that entity. Section 65 addresses specific administrative offences with differing maximum penalties. A cyberattack alone establishes neither automatic personal liability nor a particular fine.

Practical management records
DecisionTraceable working record
Scope and accountabilityLegal entity, applicable rule, reasoned exception and responsible function.
Priorities and resourcesMaterial risks, agreed actions, budget and assigned implementation.
OversightOpen deviations, effectiveness evidence, escalations and recorded follow-up decision.
TrainingDate, risks covered, participating management members and further learning needs.

A simple decision log can record the trigger, available information, options considered, decision, owner and review date. This helps management return to unresolved issues. It does not provide a blanket exemption from liability.

Legal and professional sources: BSIG § 38: Geschäftsleitung, Umsetzung, Überwachung und Schulung; BSIG § 65: Bußgeldtatbestände und Höchstbeträge; BSIG § 28: Anwendungsbereich und Ausnahmen.

Which fine figures are supported by the law?

Section 65 BSIG assigns different maximum fines to specific offences. For certain infringements, including risk-management and reporting obligations, subsection 5 point 1 sets maxima of EUR 10 million for essential entities and EUR 7 million for important entities. For those offences, where total turnover exceeds EUR 500 million, subsections 6 and 7 provide turnover-based ceilings of two and 1.4 per cent respectively. BSIG section 65: offences and maximum fines

Failure to meet the registration requirement in section 33(1), however, falls under section 65(2) point 6 and subsection 5 point 5, with a maximum of EUR 500,000. Saying that every German NIS2 breach carries up to EUR 10 million or two per cent would be incorrect. DORA has its own sanctioning and enforcement framework; a single generic percentage is not a useful comparison. DORA: Regulation (EU) 2022/2554, Articles 1, 2, 5, 19 and 28–30 BSIG section 65: offences and maximum fines

How to document the assessment in practice

  1. 01Identify legal entities

    Record relevant companies, activities, authorisations, size and organisational connections.

  2. 02Map the applicable rules

    Document DORA scope, BSIG entity type and specific exceptions.

  3. 03Assess registration separately

    Consider section 33 BSIG and, where relevant, transitional rules for critical installations.

  4. 04Test reporting workflows

    Walk through responsibilities, triggers, deadline calculations, cover arrangements and escalation using an example.

  5. 05Include service providers

    Connect contractual terms and information flows with DORA third-party risk management.

  6. 06Maintain the evidence

    Keep the decision, legal version, responsibilities and changes traceable.

FAQ

Common questions about the distinction

Does NIS2 apply alongside DORA to banks?

DORA takes precedence in the covered areas. Section 28(6) BSIG identifies the excluded provisions. Possible registration under section 33 and the scope of other group entities need separate assessment.

Must all DORA financial entities register with the BSI?

It depends on whether the entity also falls within the categories in section 33 BSIG. The DORA exception alone does not remove that obligation, but DORA status alone does not create it either.

Do the 72-hour periods start at the same point?

No. Section 32 BSIG starts from awareness of the significant incident. The DORA intermediate-report deadline runs from the initial notification.

Is a bank’s IT subsidiary automatically exempt?

No. It assesses its own activities and entity type. The parent’s DORA exception is not automatically transferred to the subsidiary.

Does missing registration carry a EUR 10 million maximum?

The registration offence in section 65(2) point 6 BSIG has a separate EUR 500,000 ceiling. Higher amounts and turnover-based ceilings apply to other expressly identified offences.

An offering from T-NEX GmbH

Connect responsibilities and evidence

T-NEX helps assess software needs and design traceable workflows, starting with your specific task and the evidence it requires.

Management: Andreas Unruh and Christoph Gembruch.

Published by T-NEX GmbH.