DORA or NIS2 — which one applies to your business?
A 30-second answer, the side-by-side, and the precise rule most guidance gets wrong — including what it means for the ILR, the CSSF and threat-led penetration testing.
The short answer: if your company is a financial entity supervised by the CSSF or the Commissariat aux Assurances, your cyber-risk obligations come from DORA, not from the NIS2 law — but "not NIS2" is too simple, and getting the nuance wrong is expensive in both directions.
Most guidance you will read flattens this to "finance is exempt from NIS2." It is not. The two regimes interlock through a specific legal mechanism, and the practical consequence — which authority supervises you, what you must test, and what you owe your clients — depends on understanding it precisely.
The 30-second answer
Before the detail, here is where most Luxembourg companies land:
| You are… | Your cyber rulebook |
|---|---|
| A financial entity supervised by the CSSF or CAA (bank, investment firm, insurer, payment/e-money institution, fund manager, crypto-asset provider…) | DORA — it overrides NIS2 for you |
| In another critical sector (energy, transport, health, water, digital infrastructure, food, in-scope manufacturing…) and medium-sized or larger | NIS2 — the law of 5 May 2026, under the ILR |
| An IT, cloud or managed-service provider to the financial sector | DORA reaches you through your clients' contracts — and NIS2 may apply in your own right |
In three questions:
- Are you authorised or registered by the CSSF or the CAA? Yes → DORA, and you can stop here.
- If not: are you in a NIS2 sector at roughly 50+ staff (or a size-agnostic type like DNS/TLD, trust services or telecom)? Yes → NIS2.
- Neither, but you serve financial clients? DORA flows down your contracts, and you may be a NIS2 entity too.
Why DORA takes precedence: the lex specialis rule
Article 4 of the NIS2 law resolves the overlap. Where a sector-specific EU act imposes ICT risk-management and incident-reporting obligations that are at least equivalent to NIS2, that act prevails. For the financial sector, that act is DORA — Regulation (EU) 2022/2554, directly applicable across the EU since 17 January 2025. DORA is therefore lex specialis: for ICT risk management and ICT-related incident reporting, its rules replace the equivalent NIS2 rules.
This is a precedence rule, not a carve-out. Financial entities are not deleted from NIS2 — DORA simply governs the parts it covers. NIS2 concepts can still matter at the edges, for ICT supply-chain relationships and for infrastructure outside DORA's reach. In practice, a financial entity runs its cyber programme to DORA and stops asking whether the ILR is watching.
Are you a "financial entity" under DORA?
DORA's scope is broad. It covers, among roughly twenty categories: credit institutions (banks), payment and electronic-money institutions, investment firms, crypto-asset service providers, central securities depositories and central counterparties, trading venues, fund managers — AIFMs and UCITS management companies, insurance and reinsurance undertakings and intermediaries, credit rating agencies, and crowdfunding service providers. If you are authorised or registered by the CSSF or the CAA, you are almost certainly in scope.
In Luxembourg, your authority is the CSSF or the CAA — not the ILR
This is the point that surprises people. The ILR is the default cybersecurity authority under the NIS2 law, but financial entities fall — by derogation — under their prudential supervisor. The CSSF supervises banks, investment firms, fund managers, payment and e-money institutions and crypto-asset service providers; the Commissariat aux Assurances (CAA) supervises insurance and reinsurance undertakings. Luxembourg adopted its DORA implementing law in July 2024, designating these two authorities and equipping them with supervisory and enforcement powers.
The mistake that cuts both ways. Register with the ILR when DORA governs you, and you have answered to the wrong regulator. Assume DORA covers everything and ignore NIS2 entirely, and you can miss the residual obligations at the edges. Neither error is fatal on its own — but for a firm that sells trust, being visibly confused about which regime applies is its own reputational cost.
NIS2 vs DORA, at a glance
| NIS2 | DORA | |
|---|---|---|
| Type of law | EU directive, transposed nationally (LU: law of 5 May 2026) | EU regulation, directly applicable |
| Applies from | National obligations phasing in (Luxembourg, 2026) | 17 January 2025 |
| Who is covered | Essential & important entities across ~18 critical sectors | Financial entities + their critical ICT providers |
| Size trigger | Generally 50+ staff or €10M+ turnover; some types at any size | By entity type — largely size-independent |
| Luxembourg authority | ILR (+ national CSIRT) | CSSF (banking/markets), CAA (insurance) |
| Mandatory testing | Risk-based; testing your defences is expected | Resilience testing; threat-led pen-testing (TLPT) if significant |
What DORA actually requires
DORA is built on five pillars, and they are more demanding than the NIS2 baseline:
- ICT risk management — a documented framework, owned and approved by the management body, covering the full lifecycle of your ICT systems.
- ICT incident management and reporting — classification of incidents against defined thresholds, and reporting of major incidents to the CSSF or CAA on a harmonised timeline that prevails over NIS2's.
- Digital operational resilience testing — a regular programme of testing, rising to threat-led penetration testing (TLPT) for the entities the CSSF identifies as significant.
- ICT third-party risk — a mandatory Register of Information on every ICT service arrangement, contractual clauses that DORA prescribes, and oversight of critical third-party providers at EU level.
- Information sharing — voluntary exchange of cyber-threat intelligence among financial entities.
TLPT: the testing DORA makes non-optional
For significant financial entities, DORA requires threat-led penetration testing — a controlled, intelligence-driven red team exercise against live production systems supporting your critical or important functions. In Luxembourg the CSSF is the TLPT authority under Article 46 of DORA and runs the national TIBER-LU framework, derived from the ECB's TIBER-EU and detailed by Commission Delegated Regulation (EU) 2025/1190. The CSSF identifies who must test and validates the scope. This is not a checkbox pentest; it is a full adversary simulation with a formal framework around it.
If you supply ICT services to a financial entity
DORA reaches beyond the financial entities themselves. Because they must impose DORA-compliant clauses on their ICT providers and register every arrangement, those obligations flow down your contracts if you serve the sector. A software vendor, a managed service provider or a cloud integrator selling into Luxembourg finance will increasingly be asked to evidence DORA-aligned controls — contractually, by the client, rather than by a regulator. This is the same supply-chain dynamic NIS2 creates, one regime over.
How we help
We are independent testers and assessors. For financial entities we map your posture against the DORA pillars, prepare your ICT risk documentation and Register of Information, and run the operational-resilience testing — including scoped adversary simulation that mirrors the TLPT model. For ICT providers to the sector, we evidence the controls your financial clients now require. We are not a certification body and we do not act for the CSSF; a supervisor signs off its own view. What we give you is a tested, documented position you can put in front of one.
Unsure which regime you fall under, or whether a specific entity in your group is in DORA scope? That is a short conversation and it is worth having before you build anything to the wrong standard.
DORA vs NIS2 in Luxembourg: quick FAQ
What is the difference between DORA and NIS2?
NIS2 is a broad EU cybersecurity directive covering around eighteen critical sectors; DORA is an EU regulation covering the financial sector specifically. For a financial entity, DORA takes precedence over NIS2 under the lex specialis rule. In short: finance follows DORA; other critical sectors follow NIS2.
Does DORA apply in Luxembourg?
Yes. DORA is an EU regulation, directly applicable in Luxembourg since 17 January 2025 — no national transposition was needed. In Luxembourg the supervisory authorities are the CSSF (banking and markets) and the Commissariat aux Assurances (insurance).
Is my Luxembourg company subject to DORA or NIS2?
If you are a financial entity supervised by the CSSF or the CAA, DORA governs your ICT-risk obligations. If you operate in another NIS2 sector — energy, transport, health, digital infrastructure, food, in-scope manufacturing — at medium size or above, NIS2 applies under the Luxembourg law of 5 May 2026. See the 30-second answer and the three-question test above.