Glossary
DORA
A European digital operational resilience regulation specifically designed for the financial sector, which takes precedence over NIS 2 under the Lex Specialis principle.
DORA (Digital Operational Resilience Act) is a European regulation that acts as a sibling to NIS 2, specifically designed for the financial and banking sector (banks, insurers, crypto-assets). Under the legal rule of Lex Specialis, entities subject to DORA's requirements are exempted from NIS 2's overlapping obligations, with DORA taking precedence for that sector.
Scope
DORA applies to a wide range of financial players:
- Credit institutions and banks
- Investment firms
- Insurance and reinsurance companies
- Crypto-asset service providers
- Financial market infrastructures (clearing houses, central securities depositories)
The Lex Specialis principle
The Lex Specialis derogat legi generali rule means that the specific law (DORA, designed for finance) takes precedence over the general law (NIS 2). A bank subject to DORA is not, however, exempt from all cybersecurity obligations — it is simply regulated under a more precise sector-specific framework tailored to its specific risks.