DORA vs NIS2 vs GDPR — What's the Difference?

Published 24 August 2026 · Reading time: 7 minutes

If you run a website that serves users in the European Union, you have probably heard three acronyms: GDPR, NIS2 and DORA. They all impose obligations on digital operations — but they apply to different entities, cover different risks, and require different things from your website.

This guide explains the differences in plain language, with a focus on what each regulation means for your website's compliance posture — and how to check all three with a single scan.

Quick references

Comparison at a glance

AspectGDPRNIS2DORA
Full nameGeneral Data Protection RegulationNetwork and Information Security DirectiveDigital Operational Resilience Act
Effective25 May 201817 October 202417 January 2025
TypeRegulation (directly binding)Directive (must be transposed into national law)Regulation (directly binding)
Who it coversAny organisation processing EU personal dataEssential and important entities in 18+ critical sectorsFinancial entities + ICT third-party providers
Primary focusProtection of personal data and privacyCybersecurity and incident management for critical infrastructureOperational resilience and ICT risk management in finance
PenaltiesUp to €20M or 4 % of annual turnoverUp to €10M or 2 % of annual turnoverUp to €10M or 2 % of annual turnover (varies by entity)
Website-specific requirementsPrivacy policy, cookie consent, data processing transparency, security measures (Art. 32)Security measures, incident reporting, risk assessmentsICT risk management, resilience testing, incident reporting, business continuity

1. GDPR — Everyone's data protection baseline

GDPR is the broadest of the three. It applies to any organisation that collects or processes personal data from individuals in the EU — regardless of where the organisation is based. This means a single-person blog in Canada with EU readers, a Shopify store in Australia, and a SaaS company in the US all need GDPR-compliant websites.

What GDPR requires on your website

Who enforces GDPR

Each EU member state's data protection authority (DPA). Examples: the Irish DPC, the French CNIL, the German DSK. Fines can reach €20 million or 4 % of global annual turnover — whichever is higher.

2. NIS2 — Security for critical sectors

NIS2 is narrower than GDPR. It targets essential and important entities in sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration. If you operate a small e-commerce site, NIS2 likely does not apply to you directly — but if you provide ICT services to a NIS2-regulated entity, you may be covered.

What NIS2 requires

How NIS2 affects your website

Even if you are not a NIS2 entity, if your customers are, your website and service become part of their supply chain. NIS2 pushes compliance requirements down the chain — so a compliance badge, documented security headers, and a published privacy policy are increasingly expected.

3. DORA — Financial-sector resilience

DORA is the most specific. It applies to financial entities — banks, investment firms, payment processors, insurance companies, and their ICT third-party providers. If your SaaS product serves a financial institution, DORA compliance will be in your contracts.

What DORA requires

DORA on your website

Financial-sector websites should demonstrate operational resilience at minimum: published security headers, HTTPS enforcement, a documented incident-reporting channel (security.txt recommended), and a business-continuity or resilience statement available on the site.

Where they overlap

RequirementGDPRNIS2DORA
Risk assessment✓ (Art. 32, 35)✓ (Art. 21)✓ (Art. 6–16)
Incident reporting✓ (72 h, Art. 33)✓ (24 h / 72 h)✓ (initial / intermediate / final)
Supply-chain oversight✓ (processor due diligence)✓ (supply chain security)✓ (third-party ICT risk)
Security measures✓ (Art. 32)✓ (Art. 21)✓ (ICT risk management)
Third-party contracts✓ (DPA, Art. 28)✓ (contractual measures)✓ (contractual clauses)
Penalties€20M / 4 %€10M / 2 %€10M / 2 %

In practice, if you are compliant with GDPR Article 32 (security measures) and Article 28 (data processing agreements), you already meet a significant portion of NIS2 and DORA's baseline expectations for website security. The main additional areas are incident-reporting procedures, resilience testing, and published operational documentation.

What your website needs — across all three

Regardless of which regulation applies to your organisation, the following checks cover the common ground across GDPR, NIS2 and DORA's website-related expectations:

  1. HTTPS with HSTS — TLS encryption and Strict-Transport-Security headers. Required by GDPR Art. 32 and recommended by NIS2 and DORA baseline security measures.
  2. Cookie consent mechanism — A visible banner or widget that obtains prior consent for non-essential cookies and trackers. Required under GDPR and the ePrivacy Directive.
  3. Privacy policy link — Clear and accessible privacy notice linked from your homepage and data-collection points. Required by GDPR Art. 13.
  4. Legal pages — Imprint (impressum), terms of service, and where applicable an EAA accessibility statement. Required varies by jurisdiction, but increasingly expected under NIS2's transparency obligations.
  5. Security headers — Content-Security-Policy (CSP), X-Content-Type-Options, Referrer-Policy, frame protection. OWASP baseline and recommended by all three frameworks.
  6. Operational resilience signals — For entities under DORA or supplying to financial-sector clients: security.txt, business-continuity or ICT risk-management disclosure on your site.

Check your website free — one scan covers all six

The EUComply free scanner checks your site against GDPR, NIS2, DORA and EAA requirements in under 30 seconds. No sign-up, no installation, no platform lock-in — enter your URL, get the results.

Run free scan →

Summary: Which regulation matters to you?

The most practical starting point for any organisation is to get the technical basics right: HTTPS, cookie consent, privacy policy, security headers. The free EUComply scan tells you exactly where you stand, and the Pro tier turns those findings into the documented evidence that auditors and compliance officers expect.

Going further

📖 DORA Compliance Practical Guide — detailed walkthrough
📖 NIS2 Supply Chain Compliance — for vendors serving critical entities
📖 European Accessibility Act Guide — EAA requirements
📖 Compliance document templates — DPA, NIS2 clauses, NDA, EAA statement