NIS2 vs DORA: which one applies to you?
Not sure if NIS2 or DORA applies to you? You're not alone. A lot of organisations assume it's whichever one they've heard of most, or that neither applies to them at all, and get it wrong in both directions. For most organisations only one of the two is relevant, and you can usually tell which within a couple of minutes. This guide covers how to place yourself, what each regime actually requires, the cases where it genuinely is unclear, and what is due to change next.
The short version
If you're a bank, insurer, investment firm, payment or e-money institution, or another regulated financial entity, DORA is almost certainly the one that applies to you, not NIS2.
If you're not a financial entity but you operate in a sector like energy, transport, health, water, digital infrastructure, public administration, waste, food, or manufacturing of certain critical products, and you're above the size threshold, NIS2 is the one to check.
Most organisations fall cleanly into one bucket. A smaller number, particularly ICT providers who serve financial clients, end up touched by both. And a third group, covered further down, isn't directly in scope for either but gets pulled into the same requirements through their customers' contracts.
| NIS2 (Cybersäkerhetslagen) | DORA | |
|---|---|---|
| Legal form | EU directive, implemented as Swedish law (SFS 2025:1506) | EU regulation, applies directly in every member state |
| In force | 15 January 2026 in Sweden | 17 January 2025 EU-wide |
| Who it covers | Essential and important entities across 18 sectors | Around 20 defined types of financial entity, plus their critical ICT providers |
| Size test | Broadly 50+ staff or over €10M turnover / balance sheet, with exceptions | No single size bar; proportionate to size and risk profile |
| Incident reporting | 24h early warning, 72h notification, final report within a month | Initial, intermediate and final reports on defined timelines |
| Supervision | Sector-based Swedish authorities | Financial supervisors, plus EU-level oversight of critical ICT providers |
| Testing | Required as part of risk management, not separately specified | Explicit resilience testing programme, with threat-led testing for larger entities |
Part A — NIS2 in Sweden
NIS2 is the EU's broader cybersecurity directive. Sweden implemented it as the Cybersecurity Act, Cybersäkerhetslagen (SFS 2025:1506), together with the Cybersecurity Ordinance (2025:1507). Both entered into force on 15 January 2026 and replaced the older NIS Act (2018:1174). There was no transition period: the obligations applied from day one.
It covers "essential" and "important" entities across 18 sectors, which is far more organisations than the law it replaced. Roughly speaking, larger organisations in the highest-criticality sectors are essential entities, and medium-sized ones plus the other covered sectors are important entities. The practical difference is supervision. Essential entities can expect proactive, ex-ante oversight. Important entities are supervised reactively, which usually means after something has gone wrong or been reported.
The size threshold, and when it doesn't apply
The general rule is medium and large organisations: 50 or more employees, or turnover and balance sheet over €10M. But this is the single most misread part of the law, because a set of entity types are in scope regardless of size. That includes providers of public electronic communications networks and services, trust service providers, DNS service providers, TLD name registries, and public administration entities. It also includes any organisation that is the sole provider in Sweden of a service that is essential to society.
Who you actually register with
This has moved twice in eight months, and a lot of published guidance is still out of date. The notification service opened on 2 February 2026 under regulation MCFFS 2026:1, and entities were expected to notify without undue delay, with authorities able to act if a notification did not arrive within 14 days. It was originally run by Myndigheten för civilt försvar (MCF), which took over the relevant functions from MSB. Then, on 1 July 2026, cyber activity transferred again to Nationellt cybersäkerhetscenter (NCSC) at FRA, which has received notifications since that date.
Supervision itself is sector-based rather than centralised. Post- och telestyrelsen covers electronic communications, Finansinspektionen the financial sector, Energimyndigheten energy, and Transportstyrelsen transport and part of manufacturing, with other authorities covering the remaining sectors. If you registered under the old NIS Act, that registration did not carry over. You have to notify again.
What it requires once you're in
- Risk management measures that are documented and proportionate, not a checklist run through unchanged.
- Supply chain security, including assessing the security of your direct suppliers and service providers.
- Business continuity, backup management and crisis handling.
- Incident reporting: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.
- Management accountability. Governing bodies must approve and oversee the measures, and can be held personally responsible for failures. Management is also required to undergo training.
- Registration with the competent authority, as above.
Part B — DORA
DORA, the Digital Operational Resilience Act, is narrower and specific to the financial sector. It is an EU regulation, so it applies directly without national implementation, and it has been applicable EU-wide since 17 January 2025. It has been in force a full year longer than the Swedish NIS2 law, which surprises people who assume NIS2 came first.
- Covers around 20 types of financial entity: banks, insurers and intermediaries, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers, trading venues, credit rating agencies and others.
- Reaches ICT third-party providers that serve those entities. Providers designated as critical fall under a direct EU-level oversight framework, which is unusual: it means a software or cloud vendor can be supervised because of who its customers are.
- Requires a documented ICT risk-management framework, incident classification and reporting, and a register of contractual arrangements with ICT providers.
- Requires a testing programme, with threat-led penetration testing for entities above a certain significance.
- Applies proportionately. Smaller and less complex entities can use a simplified ICT risk management framework rather than the full regime.
The part that catches ICT vendors out is the contractual one. DORA specifies things that must appear in contracts between financial entities and their ICT providers. If you sell software or services into a Swedish bank, you will meet DORA through your customer's procurement and contract renewal process whether or not you have ever read the regulation.
Where it genuinely gets less clear
Three cases account for most of the real uncertainty.
Overlap. NIS2 explicitly steps back where a sector-specific EU law imposes at least equivalent requirements on the same ground. DORA is the standard example. So being in a NIS2-covered sector does not automatically mean both apply, and financial entities are generally looking at DORA rather than doubling up. The interaction is legal rather than intuitive, and it is worth confirming rather than assuming in either direction.
ICT providers into finance. If you are not a financial entity yourself but supply critical services into the financial sector, you can be reached by DORA through the third-party regime, while also potentially sitting in a NIS2 sector such as digital infrastructure. That is the one population that regularly does have to deal with both.
Multi-sector organisations. A group with a manufacturing arm, a logistics arm and an internal IT services company may find that scope, entity classification and supervisory authority differ across the group. Scope attaches to the legal entity, not the brand.
The third case: you're not in scope, and it still lands on you
This is the fastest-growing version of the question and the one almost nobody writes about. NIS2 requires in-scope entities to manage the security of their supply chains. In practice that obligation gets passed down as contract terms and security questionnaires. So a twelve-person engineering firm that supplies a regional energy company is not an essential or important entity, has no registration duty, and no direct obligations at all, and will still be asked to evidence its security posture before the next contract renews.
If that is you, the honest answer is that you are not solving a compliance problem, you are solving a sales problem. The requirements you need to satisfy are your customer's, not the regulator's, and the right response is proportionate evidence rather than a full programme. Working out which of those two situations you are in is usually the first useful thing to establish.
What changes next
Do not treat a 2026 scope assessment as permanent. On 20 January 2026 the European Commission proposed a package of targeted amendments to NIS2 alongside a revision of the Cybersecurity Act, aimed at clarifying scope, simplifying jurisdictional rules, harmonising technical measures and strengthening cross-border supervision. That package is still in negotiation between the Parliament and the Council, with political agreement targeted for early 2027 and a transposition period after that. Sweden's brand-new law will very likely need amending again.
Two practical implications. First, an assessment done today is a snapshot, and the sensible cadence is to revisit scope annually rather than treating it as done. Second, be sceptical of anyone selling a permanent fix for a moving target.