DORA and NIS2: Why Bank Audits Are Now Colliding
Since January 2025 DORA has been in force, and since November 2025 AWS, Azure, Google Cloud, Bloomberg, LSEG and IBM have appeared on the ESAs-CTPP list. From Q1 2026 the Joint Examination Teams will carry out their first audits. At the same time NIS2 is rolling out in Wave Two. 2026 will make one thing clear: the two regimes overlap, and their audit paths run in parallel.
Key Takeaways
- Dual application does not mean dual audit-it means nested audit. DORA examines ICT risk, incidents, tests and third-party supply chains at financial institutions. NIS2 examines risk management, reporting obligations and responsibilities at entities deemed essential or important. Where banks are NIS2 addressees, the obligations stack rather than replace each other.
- 2026 is the year of evidence, not politics. The ESAs shift expectations from paper to proof. Resilience tests, TLPT exercises, incident classification with hard thresholds and machine-readable third-party inventories. If you set policies in 2025 but cannot produce the evidence in 2026, the audit will flag you.
- The real bottleneck isn’t the tools-it’s the auditors. Over the past twelve months banks have often staffed ICT-risk, NIS2 and DORA streams with overlapping personnel. Running both programs with the same 30-person audit team will create a bottleneck in Q3 that no tool can resolve.
RelatedNIS2 compliance for mid-sized firms in practice / NIS2 technical minimum requirements for mid-sized firms 2026
What separates DORA and NIS2 in the parallel world of 2026
At first glance DORA and NIS2 look like two sides of the same compliance program. Both regulate ICT risk management, incident reporting and third-party relationships, both spring from the EU cyber wave, and both carry fines. In practice 2026 they diverge at three decisive points: scope of addressees, supervisory structure and depth of requirements.
DORA covers 20 types of financial entities, from banks and insurers to crypto-asset service providers and central counterparties. Supervision sits with national financial watchdogs with clear ESA links-in Germany that means BaFin with interfaces to EBA, EIOPA and ESMA. NIS2, by contrast, covers essential and important entities across 18 sectors, with Germany’s BSI as the central authority. A large bank is both a DORA and a NIS2 addressee, an asset manager may be only DORA depending on size, and a cloud provider is primarily NIS2.
Classic compliance metrics aren’t wrong-they’re just half the picture. What distinguishes a DORA audit from a NIS2 audit is the depth of ICT evidence expected: DORA demands robust TLPT reports, resilience-test documentation and machine-readable third-party contract registers. NIS2 demands risk-management measures focused on governance and reporting obligations. Both are cyber disciplines, but the required artefacts overlap only partially.
Reality 1: The Shared Program Setup That Doesn’t Hold Up
By 2025, many banks launched a consolidated compliance program that bundled DORA and NIS2 under one roof. The logic sounded solid: one risk-management framework, one incident-reporting system, one third-party inventory, one audit team. In practice, the two regimes clash. DORA audits drill down into individual ICT components and tests, while NIS2 audits cast a wide net across governance structures and reporting pathways. A single program manager splits attention between both worlds and sacrifices the granularity DORA demands.
Concrete example from a DACH universal bank (anonymized): a program staffed with 32 ICT-risk specialists and a central PMO. In Q1 2026, 14 TLPT tests were scheduled alongside 22 NIS2 risk-management reviews. In April the PMO prioritized TLPT prep; in May it pivoted to NIS2 reviews. The audit team never reached the level of detail regulators expect in either phase. Both streams now face findings that would have been avoided in two separate programs.
Reality 2: The Siloed Programs That Don’t Share Their Data
The opposite extreme spins up two parallel tracks. A DORA squad focused on ICT risk, a NIS2 squad focused on governance, each with its own tooling stack and reporting channels. Methodologically clean, operationally wasteful. Both programs rely on the same asset inventory, the same vendor list, the same incident data. Without a shared data backbone, they duplicate every source-and inevitably drift apart.
The usual outcome: the DORA third-party inventory lists AWS with 47 service components, while the NIS2 vendor register shows 39. Neither figure is wrong; they simply measure different granularities. When the supervisor’s JET audit demands both lists and spots discrepancies, the explanation cycle tacks two extra weeks onto the schedule. One central data source with two tailored views solves the problem. Two separate databases reconciled once a year does not.
Reality 3: The Audit Team That Cracks in Q3
The real bottleneck in 2026 isn’t tooling, methodology, or executive sponsorship-it’s human capacity inside the audit team. ICT-risk professionals with hands-on DORA experience are scarce; NIS2-savvy compliance auditors fluent in risk-management frameworks are equally rare. Over the past twelve months most banks have staffed roles with overlap: three-quarters of the team serve both streams, one-quarter is locked into a single track.
That works until the audit pressure peaks. A pattern emerges in 2026: TLPT testing and JET prep in Q2, parallel NIS2 reporting deadlines in Q3. The audit team delivers at full throttle in both phases, but by Q3 six key people are burned out or have left. The planned Q4 deliverable slips, and the next supervisory round kicks off with half the team missing.
The dividing line is long-term consistency. Banks that treat DORA and NIS2 as six-month sprints win quarterly milestones and lose the twelve-month setup. Those that assign clear responsibilities and capacity-plan across eighteen months avoid the Q3 meltdown the rest experience.
Three Levers to Pull in the Next 90 Days
- Capacity-plan the audit team across eighteen months, not six. Map every personnel bottleneck through Q4 2027. Where does DORA TLPT prep collide with NIS2 reporting deadlines? Which six people hold critical roles in both streams? Pre-empt relief before it becomes an emergency.
- Build one data backbone with two views, not two databases that must be reconciled. Asset inventories, third-party registers, and incident data must not be duplicated across separate tools. A single source of truth-with DORA- and NIS2-specific lenses-pays for itself in the first JET audit.
- Separate program leadership, share data and tooling. Appoint a DORA program lead steeped in ICT risk and a NIS2 program lead steeped in governance, both operating off the same data foundation. Bundling both roles in one person produces audits that satisfy neither supervisor.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Are all banks addressed by DORA also subject to NIS2?
In practice, yes; formally, there are differences. Most banks fall under NIS2 as essential entities due to their size. Smaller asset managers and specialized financial service providers may be addressed by DORA without being subject to NIS2. In 2026 compliance practice, dual addressing will be the norm, not the exception.
How does DORA-TLPT differ from a classic red-team test?
DORA-TLPT mandates threat-led penetration testing under harmonized standards with clear supervisory involvement. Classic red-teaming shares methodological similarities but lacks the regulatory framework that accompanies DORA-TLPT. If, in 2026, you market a red-team program as TLPT, it will fail the first JET audit. The required artifacts and supervisory workflows are not identical.
What role does BaFin play for German banks in the DORA audit?
BaFin is the competent national authority and collaborates with the ESAs within Joint Examination Teams. For German banks, this means the primary interface remains BaFin, but the ESAs participate in JET audits and can directly demand findings. The assumption that DORA audits will remain purely national is no longer tenable by 2026.
How are CTPP-designated cloud providers responding to supervision?
AWS, Microsoft Azure, and Google Cloud have established dedicated DORA teams in recent months and now deliver structured compliance packages to financial customers. The quality of these packages varies in 2026. Banks that adopt these packages without their own review risk findings related to hosting depth not covered in vendor packages.
When is it time to decouple a consolidated program?
When audit findings from both authorities converge in the same division and escalation to program leadership takes more than three weeks. This signals that the joint setup is no longer viable. Decoupling mid-program is costly; decoupling at program-end is far more expensive.
Editor’s Reading List
- NIS2 Compliance for SMEs: Practical Steps and Avoidable Pitfalls
- NIS2 Technical Minimum Requirements for SMEs in 2026
- Machine Identities: The Accounts Nobody Counts
Editor’s Picks
Editor’s PickNIS2 for Mid-Sized Firms: Achievable Steps, Avoidable MistakesEditor’s PickWhere the SME Sector Still Lags Technically on NISEditor’s PickMachine Identities: the accounts that no one counts
More from the MBF Media Network
cloudmagazinAWS and Nvidia: GPU Surge Forces Platform Teams to AdaptMyBusinessFutureEU Hydrogen Bank: 1.3 billion change the distributionDigital ChiefsThe Invisible Bottleneck Role: Why PMOs Often Derail the AI Rollout in 2026





