does NIS2 or DORA apply to my bank or insurance company
Banks and insurers fall under DORA, not under NIS2
For a bank, insurer or other financial institution, DORA (the Digital Operational Resilience Act) applies in practice, not the NIS2 Directive. The NIS2 Directive itself establishes that financial institutions already covered by a sector-specific European regulation on digital operational resilience remain outside its scope — DORA is precisely such a regulation. The reason is not that the financial sector is excluded, but that this sector already has an equally strict or stricter regime, with its own requirements for, among others, ICT risk management, incident reporting and supervision of critical ICT service providers.
This does not mean that a financial institution has no obligations in the field of cybersecurity — DORA imposes its own obligations, with its own timeline and its own supervisor. It does mean that the duty of care, registration obligation and incident reporting obligation from the NIS2 Directive and the Cyber Security Act are not the route that applies. Anyone in doubt about whether an organisation truly qualifies as a financial institution within the meaning of DORA, or might instead (partly) fall under NIS2 because other activities are also carried out, can best clarify this question via how do I know if my company falls under NIS2. For those starting completely at the beginning of this entire matter, Where should I start? is a logical next step.
Where this follows from: the delimitation in the directive
The delimitation between NIS2 and DORA follows from the NIS2 Directive itself, which designates the sectors in Annex I and II as essential or important, but exempts financial entities covered by a sector-specific Union act on digital operational resilience. The Cyber Security Act, as the Dutch implementation of that Directive, follows the same delimitation. An overview of which sectors do fall under the Cyber Security Act can be found at which sectors fall under the NIS2 directive. For the precise text of this exemption, the NIS2 Directive itself is the source to consult, as well as the guidance that the supervisor publishes on this matter.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.