Solutions · By Industry · Finserv

Financial Services

DORA + NIS2 + AI Act — three regulations, one sector, all already in force.

Pain

DORA's 4-hour incident clock is stricter than NIS2's 24 hours — most dual-regulated teams build to the wrong one.

What you want

One incident response workflow that satisfies both regulators, not two competing timelines.

What you get

DORA applicability across 21 financial entity categories, 5-pillar obligation mapping, NIS2 x DORA overlap resolved.

Three regulations. One sector. All in force.

DORA (Digital Operational Resilience Act) has applied since 17 January 2025. Banks, investment firms, payment institutions, insurance companies, and their ICT service providers are in scope. The 5 pillars — ICT risk management, incident reporting, TLPT, third-party risk, information sharing — are live obligations.

NIS2 may also apply if your institution is classified as an essential or important entity. Financial sector entities that are both DORA-regulated and NIS2-essential face overlapping obligations. A single incident response programme can satisfy both — but the reporting timelines differ.

AI Act high-risk obligations (Annex III) apply from August 2026 for AI systems used in credit scoring, insurance underwriting, employment decisions, and access to essential services. Prohibited practices (Article 5) — including certain biometric and social scoring systems — have been in force since February 2025.


DORA obligations mapped

Pillar 1 — ICT risk management (Art. 6–16)

  • ICT risk management framework documented and board-approved
  • Risk assessment methodology
  • Business continuity and disaster recovery plans
  • ICT asset inventory

Pillar 2 — ICT incident reporting (Art. 17–23)

  • Major ICT incident classification criteria
  • Reporting timeline: 4h initial notification → 24h intermediate → 30-day final report to competent authority
  • Integration with NIS2 incident reporting if dual-regulated

Pillar 3 — TLPT (Art. 24–27)

  • Significant financial entities: TLPT every 3 years minimum
  • TIBER-EU framework (or equivalent national framework)
  • External qualified testers, competent authority oversight
  • Live production systems in scope

DORA TLPT guide

Pillar 4 — ICT third-party risk (Art. 28–44)

  • Register of all ICT third-party service providers
  • Contractual requirements per Art. 30 (exit strategies, audit rights, security SLAs)
  • Critical ICT Third-Party Service Providers (CTPPs) designated by ESAs — enhanced oversight
  • TLPT may include critical ICT third parties in scope

Pillar 5 — Information sharing (Art. 45)

  • Voluntary participation in cyber threat intelligence sharing arrangements

DORA × NIS2 overlap

Financial entities that are also NIS2 essential entities face overlapping incident reporting obligations:

| Framework | Initial notification | Detailed report | Final report | |---|---|---|---| | DORA | 4 hours | 24 hours | 30 days | | NIS2 | 24 hours | 72 hours | 30 days |

Coordination: DORA's 4-hour notification is more demanding. A single incident response process can satisfy both if the 4-hour trigger covers the NIS2 24-hour obligation. Coordinate with both competent authorities on dual-reporting expectations.


AI Act in financial services

AI systems used in:

  • Credit scoring and credit risk assessment → High-risk (Annex III §5(b))
  • Life and health insurance underwriting → High-risk (Annex III §5(c))
  • Employment and worker management → High-risk (Annex III §4)
  • Biometric identification for authentication → potentially Limited or High-risk depending on use

Prohibited since February 2025 (Art. 5): certain biometric categorisation systems, social scoring, emotion recognition in workplaces.

AI Act prohibited practices


What NexCyber provides for financial services

  • DORA applicability check: 21 financial entity categories covered
  • DORA obligation mapping: 5 pillars, article-level
  • NIS2 × DORA overlap: shared evidence strategy
  • AI Act classification: high-risk determination for your AI systems
  • Evidence layer: ICT risk register, incident log, TLPT documentation, third-party contracts

Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment