Glossary · DORA
Lex Specialis
The legal principle that a sector-specific law overrides a general one — the reason financial entities follow DORA instead of NIS2.
Explained in depth: DORA overview
Lex specialis derogat legi generali: the specific law takes precedence over the general law. NIS2 codifies this in Article 4: where a sector-specific EU act requires entities to adopt cybersecurity risk-management measures or report significant incidents, and those requirements are at least equivalent to NIS2's, the sector-specific provisions apply instead of the corresponding NIS2 provisions. The European Commission has confirmed DORA as such an act for the financial sector. The effect is scoped, not total: DORA displaces NIS2's provisions on risk management and incident reporting for financial entities, but those entities can remain within NIS2's broader ecosystem (for example in national registries and strategies). Similar interplay exists with other sector rules, and understanding which regime governs which obligation is a recurring scoping task.
Why it matters
"Do we follow NIS2 or DORA?" is one of the most common questions from banks, insurers, and fintechs. The answer, DORA for what DORA covers, decides which authority you report to, which deadlines apply, and which templates you use.
