DORA vs NIS2: what they share and how they differ
DORA and NIS2 share 4 of 24 control themes and 3 checks. 75% of NIS2 requirements can be proven with checks DORA already uses, 50% the other way round.
In force
DORA
How to cover AI systems in your DORA compliance
6 requirementsNext —
Phasing in
NIS2
How to bring your AI systems into NIS2 compliance
4 requirementsNext —
4/24shared control themes
3shared checks
75%of NIS2 requirements covered by DORA evidence
50%of DORA requirements covered by NIS2 evidence
At a glance
| DORA | NIS2 | |
|---|---|---|
| Jurisdiction | European Union same | European Union same |
| Kind | Regulation | Directive |
| Status | In force | Phasing in |
| Binding | Yes same | Yes same |
| Object analysed | Organisation same | Organisation same |
| Scope | Financial entities and critical ICT third-party providers. | Essential and important entities in 18 sectors. |
| Territorial reach | European Union. | European Union, via national transposition. |
| Penalties | Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers. | Essential: €10M or 2% of turnover; important: €7M or 1.4%. |
| Qualification axes | Supports a critical or important function | Entity category |
| Roles | Financial entity, ICT provider | Entity |
| Requirements | 6 | 4 |
| Next milestone | — same | — same |
Theme by theme
requirements per theme
DORANIS2
Governance
Build
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
3
| Code | Check | Requirements DORA | Requirements NIS2 |
|---|---|---|---|
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | ||
| VER-022-F-01 | Risk and incident response procedure | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
DORA
3
DORA-08
DORA-24
DORA-11
NIS2
1
NIS2-27
Registration with the authority (ANSSI) Art. 3, 27
Timelines
PastSet in the textPotentialTo verify
Jan 16, 2023DORA · Entry into force
Jan 16, 2023NIS2 · Entry into force
Oct 17, 2024NIS2 · Transposition deadline
Jan 17, 2025DORA · Application date
Apr 30, 2025DORA · First register of information submitted
Nov 18, 2025DORA · First critical ICT providers designated
2026NIS2 · French transposition (resilience law): final adoption to verify
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.