RISI

EU Cybersecurity Regulations › NIS2 › Related EU regulations

NIS2 vs NIS1, DORA and CER

The most common question new readers bring to NIS2 is how it relates to the regulations it replaces or sits alongside. This page is a side-by-side comparison.

NIS2 vs NIS1 — what changed

DimensionNIS1 (Directive 2016/1148)NIS2 (Directive 2022/2555)
Sectors7 sectors of Operators of Essential Services + a handful of Digital Service Providers18 sectors across Annex I (11) and Annex II (7), including public administration and space
Identification of entitiesMember-state-by-member-state designation of OESs — wildly inconsistentSize-cap rule (medium-sized and large) → automatic in-scope, no per-entity designation needed
Risk-management baselineHigh-level: "appropriate technical and organisational measures"Article 21(2) names 10 minimum categories incl. supply chain, MFA, encryption
Reporting timeline"Without undue delay" — interpreted variably (anything from days to weeks)24h early warning · 72h notification · 1 month final report
PenaltiesSet entirely by member states — "effective, proportionate, dissuasive"EU-wide floor: €10M/2% (essential) · €7M/1.4% (important)
GovernanceNot addressedManagement-body approval, oversight, personal liability, mandatory training (Article 20)
Supply-chain securityNot addressedRequired as one of the 10 measures, plus coordinated EU-level supply-chain risk assessments (Article 22)
EnforcementLargely reactiveProactive supervision for essential entities (audits, scans, monitoring officer)

NIS2 vs DORA — the financial-sector overlap

DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is lex specialis for the financial sector. Where DORA covers the same ground as NIS2 — risk management, incident reporting, third-party risk — financial entities discharge their NIS2 obligations by complying with DORA, not in addition to it. Practical differences:

  • DORA applies as a regulation (directly binding, uniform across the EU). NIS2 applies as a directive (transposed differently in each member state).
  • DORA's reporting timeline mirrors NIS2's (24h, 72h, 1mo) but with sector-specific templates issued by the European Supervisory Authorities (EBA, EIOPA, ESMA).
  • DORA introduces an oversight regime for critical ICT third-party providers — hyperscalers, major SaaS — that has no NIS2 equivalent.
  • NIS2 still applies to financial entities for issues outside DORA's scope (e.g. physical incidents not affecting ICT systems).

NIS2 vs CER — cyber and physical resilience

The CER Directive (Critical Entities Resilience, Directive (EU) 2022/2557) was adopted on the same day as NIS2 and has the same transposition deadline. It is the physical-security counterpart: where NIS2 covers cybersecurity, CER covers everything else (natural hazards, terrorism, sabotage, insider threats, public-health emergencies).

  • An entity designated as a critical entity under CER is automatically an essential entity under NIS2, regardless of size.
  • CER sectors overlap heavily with NIS2 Annex I: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, public administration, space, food.
  • Member states must designate critical entities by 17 July 2026, applying common criteria set out in CER. The list partially drives NIS2 supervisory priorities.