Three regulations. One sector. All in force.
DORA (Digital Operational Resilience Act) has applied since 17 January 2025. Banks, investment firms, payment institutions, insurance companies, and their ICT service providers are in scope. The 5 pillars — ICT risk management, incident reporting, TLPT, third-party risk, information sharing — are live obligations.
NIS2 may also apply if your institution is classified as an essential or important entity. Financial sector entities that are both DORA-regulated and NIS2-essential face overlapping obligations. A single incident response programme can satisfy both — but the reporting timelines differ.
AI Act high-risk obligations (Annex III) apply from August 2026 for AI systems used in credit scoring, insurance underwriting, employment decisions, and access to essential services. Prohibited practices (Article 5) — including certain biometric and social scoring systems — have been in force since February 2025.
DORA obligations mapped
Pillar 1 — ICT risk management (Art. 6–16)
- ICT risk management framework documented and board-approved
- Risk assessment methodology
- Business continuity and disaster recovery plans
- ICT asset inventory
Pillar 2 — ICT incident reporting (Art. 17–23)
- Major ICT incident classification criteria
- Reporting timeline: 4h initial notification → 24h intermediate → 30-day final report to competent authority
- Integration with NIS2 incident reporting if dual-regulated
Pillar 3 — TLPT (Art. 24–27)
- Significant financial entities: TLPT every 3 years minimum
- TIBER-EU framework (or equivalent national framework)
- External qualified testers, competent authority oversight
- Live production systems in scope
Pillar 4 — ICT third-party risk (Art. 28–44)
- Register of all ICT third-party service providers
- Contractual requirements per Art. 30 (exit strategies, audit rights, security SLAs)
- Critical ICT Third-Party Service Providers (CTPPs) designated by ESAs — enhanced oversight
- TLPT may include critical ICT third parties in scope
Pillar 5 — Information sharing (Art. 45)
- Voluntary participation in cyber threat intelligence sharing arrangements
DORA × NIS2 overlap
Financial entities that are also NIS2 essential entities face overlapping incident reporting obligations:
| Framework | Initial notification | Detailed report | Final report | |---|---|---|---| | DORA | 4 hours | 24 hours | 30 days | | NIS2 | 24 hours | 72 hours | 30 days |
Coordination: DORA's 4-hour notification is more demanding. A single incident response process can satisfy both if the 4-hour trigger covers the NIS2 24-hour obligation. Coordinate with both competent authorities on dual-reporting expectations.
AI Act in financial services
AI systems used in:
- Credit scoring and credit risk assessment → High-risk (Annex III §5(b))
- Life and health insurance underwriting → High-risk (Annex III §5(c))
- Employment and worker management → High-risk (Annex III §4)
- Biometric identification for authentication → potentially Limited or High-risk depending on use
Prohibited since February 2025 (Art. 5): certain biometric categorisation systems, social scoring, emotion recognition in workplaces.
What NexCyber provides for financial services
- DORA applicability check: 21 financial entity categories covered
- DORA obligation mapping: 5 pillars, article-level
- NIS2 × DORA overlap: shared evidence strategy
- AI Act classification: high-risk determination for your AI systems
- Evidence layer: ICT risk register, incident log, TLPT documentation, third-party contracts
Tools
- DORA Applicability Checker — scope determination in 2 minutes
- NIS2 Applicability Checker — entity classification
- AI Act Risk Classifier — high-risk AI determination
- Penalty Calculator — DORA + NIS2 + AI Act exposure
Related answers
NexCyber — EU Market Access Compliance Platform