INSIGHTS · REGULATION

NIS2 vs DORA: which one applies to you?

Leighton Wilson, Indura Labs
Reviewed 4 September 2026. Current as of Cybersäkerhetslagen (2025:1506) and the transfer of registration duties to NCSC on 1 July 2026.

Not sure if NIS2 or DORA applies to you? You're not alone. A lot of organisations assume it's whichever one they've heard of most, or that neither applies to them at all, and get it wrong in both directions. For most organisations only one of the two is relevant, and you can usually tell which within a couple of minutes. This guide covers how to place yourself, what each regime actually requires, the cases where it genuinely is unclear, and what is due to change next.

The short version

If you're a bank, insurer, investment firm, payment or e-money institution, or another regulated financial entity, DORA is almost certainly the one that applies to you, not NIS2.

If you're not a financial entity but you operate in a sector like energy, transport, health, water, digital infrastructure, public administration, waste, food, or manufacturing of certain critical products, and you're above the size threshold, NIS2 is the one to check.

Most organisations fall cleanly into one bucket. A smaller number, particularly ICT providers who serve financial clients, end up touched by both. And a third group, covered further down, isn't directly in scope for either but gets pulled into the same requirements through their customers' contracts.

 NIS2 (Cybersäkerhetslagen)DORA
Legal formEU directive, implemented as Swedish law (SFS 2025:1506)EU regulation, applies directly in every member state
In force15 January 2026 in Sweden17 January 2025 EU-wide
Who it coversEssential and important entities across 18 sectorsAround 20 defined types of financial entity, plus their critical ICT providers
Size testBroadly 50+ staff or over €10M turnover / balance sheet, with exceptionsNo single size bar; proportionate to size and risk profile
Incident reporting24h early warning, 72h notification, final report within a monthInitial, intermediate and final reports on defined timelines
SupervisionSector-based Swedish authoritiesFinancial supervisors, plus EU-level oversight of critical ICT providers
TestingRequired as part of risk management, not separately specifiedExplicit resilience testing programme, with threat-led testing for larger entities

Part A — NIS2 in Sweden

NIS2 is the EU's broader cybersecurity directive. Sweden implemented it as the Cybersecurity Act, Cybersäkerhetslagen (SFS 2025:1506), together with the Cybersecurity Ordinance (2025:1507). Both entered into force on 15 January 2026 and replaced the older NIS Act (2018:1174). There was no transition period: the obligations applied from day one.

It covers "essential" and "important" entities across 18 sectors, which is far more organisations than the law it replaced. Roughly speaking, larger organisations in the highest-criticality sectors are essential entities, and medium-sized ones plus the other covered sectors are important entities. The practical difference is supervision. Essential entities can expect proactive, ex-ante oversight. Important entities are supervised reactively, which usually means after something has gone wrong or been reported.

The size threshold, and when it doesn't apply

The general rule is medium and large organisations: 50 or more employees, or turnover and balance sheet over €10M. But this is the single most misread part of the law, because a set of entity types are in scope regardless of size. That includes providers of public electronic communications networks and services, trust service providers, DNS service providers, TLD name registries, and public administration entities. It also includes any organisation that is the sole provider in Sweden of a service that is essential to society.

If you are a small kommun, a small trust service provider, or the only supplier of something critical, the headcount question does not save you. Being under 50 people is not on its own a reason to conclude you're out of scope. This is where most self-assessments go wrong, and it goes wrong in the direction that leaves you exposed rather than over-prepared.

Who you actually register with

This has moved twice in eight months, and a lot of published guidance is still out of date. The notification service opened on 2 February 2026 under regulation MCFFS 2026:1, and entities were expected to notify without undue delay, with authorities able to act if a notification did not arrive within 14 days. It was originally run by Myndigheten för civilt försvar (MCF), which took over the relevant functions from MSB. Then, on 1 July 2026, cyber activity transferred again to Nationellt cybersäkerhetscenter (NCSC) at FRA, which has received notifications since that date.

Supervision itself is sector-based rather than centralised. Post- och telestyrelsen covers electronic communications, Finansinspektionen the financial sector, Energimyndigheten energy, and Transportstyrelsen transport and part of manufacturing, with other authorities covering the remaining sectors. If you registered under the old NIS Act, that registration did not carry over. You have to notify again.

What it requires once you're in

Part B — DORA

DORA, the Digital Operational Resilience Act, is narrower and specific to the financial sector. It is an EU regulation, so it applies directly without national implementation, and it has been applicable EU-wide since 17 January 2025. It has been in force a full year longer than the Swedish NIS2 law, which surprises people who assume NIS2 came first.

The part that catches ICT vendors out is the contractual one. DORA specifies things that must appear in contracts between financial entities and their ICT providers. If you sell software or services into a Swedish bank, you will meet DORA through your customer's procurement and contract renewal process whether or not you have ever read the regulation.

Where it genuinely gets less clear

Three cases account for most of the real uncertainty.

Overlap. NIS2 explicitly steps back where a sector-specific EU law imposes at least equivalent requirements on the same ground. DORA is the standard example. So being in a NIS2-covered sector does not automatically mean both apply, and financial entities are generally looking at DORA rather than doubling up. The interaction is legal rather than intuitive, and it is worth confirming rather than assuming in either direction.

ICT providers into finance. If you are not a financial entity yourself but supply critical services into the financial sector, you can be reached by DORA through the third-party regime, while also potentially sitting in a NIS2 sector such as digital infrastructure. That is the one population that regularly does have to deal with both.

Multi-sector organisations. A group with a manufacturing arm, a logistics arm and an internal IT services company may find that scope, entity classification and supervisory authority differ across the group. Scope attaches to the legal entity, not the brand.

The third case: you're not in scope, and it still lands on you

This is the fastest-growing version of the question and the one almost nobody writes about. NIS2 requires in-scope entities to manage the security of their supply chains. In practice that obligation gets passed down as contract terms and security questionnaires. So a twelve-person engineering firm that supplies a regional energy company is not an essential or important entity, has no registration duty, and no direct obligations at all, and will still be asked to evidence its security posture before the next contract renews.

If that is you, the honest answer is that you are not solving a compliance problem, you are solving a sales problem. The requirements you need to satisfy are your customer's, not the regulator's, and the right response is proportionate evidence rather than a full programme. Working out which of those two situations you are in is usually the first useful thing to establish.

What changes next

Do not treat a 2026 scope assessment as permanent. On 20 January 2026 the European Commission proposed a package of targeted amendments to NIS2 alongside a revision of the Cybersecurity Act, aimed at clarifying scope, simplifying jurisdictional rules, harmonising technical measures and strengthening cross-border supervision. That package is still in negotiation between the Parliament and the Council, with political agreement targeted for early 2027 and a transposition period after that. Sweden's brand-new law will very likely need amending again.

Two practical implications. First, an assessment done today is a snapshot, and the sensible cadence is to revisit scope annually rather than treating it as done. Second, be sceptical of anyone selling a permanent fix for a moving target.

This is a starting point, not a legal determination. If you want it mapped properly to your own organisation, including the size-cap exceptions and the supply-chain case, that's the kind of work I do.