NIS2 vs NIST vs CIS vs DORA: A Guide for Financial Services

NIS2, DORA, NIST CSF 2.0 and CIS Controls v8.1 are often treated as rivals. In practice they answer different questions. A mapping guide for UK financial services firms.

Read

NIS2 vs NIST vs CIS vs DORA: A Guide for Financial Services

Most UK financial services firms do not have an NIS2 problem, a DORA problem, a NIST problem and a CIS problem. They have one problem, evidence that their controls are good enough, and four different audiences asking for it. NIS2 and DORA are regulations with penalties attached. NIST CSF 2.0 and CIS Controls v8.1 are voluntary frameworks you adopt to prove the first two. Treating all four as separate compliance projects is the most expensive mistake we see.

This guide explains what each one is, who it binds, when it applies, and how to map your existing controls to all four without running four programmes.

Key Takeaways

  • NIS2 and DORA are binding EU law for in-scope entities; NIST CSF 2.0 and CIS Controls v8.1 are voluntary frameworks, not regulations.
  • DORA has applied since 17 January 2025 and covers 20 types of financial entity, including many UK firms with EU operations or EU clients.
  • The FCA’s operational resilience rules (in force since 31 March 2022) are the UK home regime most financial firms should build on first.
  • A single control map satisfies NIS2, DORA, NIST, and CIS at once. Building four separate programmes multiplies cost for the same evidence.
  • Supplier and third-party risk is where the four frameworks overlap most, and where the UK’s assurance gap is widest.

The short answer: they do different jobs

If you only read one section, read this. The four are not alternatives, and the comparison is not like-for-like.

modelNIS2DORANIST CSF 2.0CIS Controls v8.1
What it isEU directive (2022/2555)EU regulation (2022/2554)Voluntary frameworkVoluntary control set
Binding?Yes, once transposed into national lawYes, directly applicableNoNo
Applies to18 critical sectors, medium and large entities20 types of financial entity plus ICT providersAny organisationAny organisation
AppetiteRisk management and incident notificationDigital operational resilience, five pillarsSix core functions: Govern, Identify, Protect, Detect, Respond, Recover18 prioritised controls in three implementation groups
EnforcementNational authorities; top-management accountabilityCompetent authorities; oversight of critical ICT providersNoneNone

The practical reading: NIS2 and DORA tell you what you must achieve. NIST and CIS tell you how to organise the work. A financial services firm generally uses NIST CSF 2.0 or CIS Controls to run the programme and maps the output to NIS2 and DORA obligations where they apply.

Stacks of paper documents and file folders representing regulatory obligations on a desk

What each framework actually requires

NIS2: the EU directive that replaced NIS1

NIS2 (Directive (EU) 2022/2555) replaced the original NIS Directive and expanded scope to 18 critical sectors. The general rule is that medium-sized and large entities in those sectors must take appropriate risk-management measures and notify national authorities of significant incidents. Finance was already in scope under NIS1, so for most financial firms NIS2 is a tightening rather than a first introduction.

Two changes matter more than the rest. First, member states had until 17 October 2024 to transpose the directive into national law, which is why the rules you actually face differ by country. Second, NIS2 introduces top-management accountability for non-compliance, cyber risk is formally a board matter, not a technology matter. On 20 January 2026 the European Commission proposed targeted amendments to simplify compliance, expected to ease the burden for around 28,700 companies including roughly 6,200 micro and small enterprises (European Commission, retrieved 16 September 2026). Transposition has not been clean: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose it.

For a UK firm, NIS2 bites when you have EU establishments, EU subsidiaries, or you sit in an EU client’s supply chain and inherit its supplier obligations.

DORA: binding resilience rules for financial entities

DORA (Regulation (EU) 2022/2554) is a regulation, not a directive, so it applies directly in every member state without national transposition. It entered into application on 17 January 2025 and applies to around 20 different types of financial entity plus the ICT third-party providers that serve them.

DORA is built on five pillars: ICT risk management; ICT third-party risk management with mandatory contractual provisions; digital operational resilience testing, from basic to advanced; reporting of major ICT-related incidents to competent authorities; and voluntary information sharing between firms. Alongside those sits an EU-wide oversight framework for critical ICT third-party providers, aimed squarely at concentration risk (EIOPA, retrieved 16 September 2026).

The part that catches UK firms is the third-party pillar. If you supply ICT services to EU financial entities, your contracts need the DORA provisions, your subcontracting needs visibility, and you may be asked to sit on the register of information. That obligation determines whether or not you are an EU entity yourself.

NIST CSF 2.0: the organising framework

The NIST Cybersecurity Framework is voluntary and designed for any organisation, not just critical infrastructure. Version 2.0 added a sixth function, Govern, to the original five, giving the core functions: Govern, Identify, Protect, Detect, Respond, Recover (NIST, retrieved 16 September 2026).

Govern is the addition that matters most for financial services. It makes explicit what boards are accountable for, risk appetite, roles, and policy, which maps neatly onto both NIS2’s management accountability and the FCA’s expectation that firms own their resilience. CSF 2.0 comes with profiles, quick-start guides, and informative references that map its outcomes onto other standards, which is exactly what makes it useful as a translation layer.

CIS Controls v8.1: the prescriptive shortcut

The CIS Critical Security Controls are a prioritised, prescriptive set of 18 controls with three implementation groups (IG1, IG2, IG3) that let you start with the essentials and mature. Version 8.1 added a Governance security function, aligning it conceptually with NIST CSF 2.0’s Govern.

The 18 controls run from inventory and control of enterprise and software assets, through data protection, secure configuration, access management, and continuous vulnerability management, to incident response management and penetration testing (CIS, retrieved 16 September 2026).

CIS is the fastest way to get defensible answers to a regulator’s questions, because each control has defined safeguards and a clear maturity path. If your team is small, CIS Implementation Group 1 is a more honest starting point than a sprawling NIST profile you cannot populate.

Bar chart comparing the number of core elements each framework defines, from NIST CSF core functions to CIS controls and NIS2 and DORA scope

How the timelines line up

The frameworks do not arrive at once, and knowing the sequence prevents panic.

Timeline chart of key UK and EU cyber regulatory dates for financial services from 2022 to 2027

The FCA’s operational resilience rules, published with the Bank of England and the PRA, came into force on 31 March 2022, with firms given until 31 March 2025 to be able to operate their important business services within impact tolerances. DORA has applied since 17 January 2025. New FCA incident reporting and third-party notification rules published on 18 March 2026 come into force on 18 March 2027, with 12 months to prepare (FCA, retrieved 16 September 2026).

The critical date for most UK firms is not a single deadline but the sequencing: DORA obligations flowed through contracts from early 2025, and the 2027 FCA rules will require incident and third-party data that only disciplined mapping produces.

What this means for a UK financial services firm

If you serve EU clients, DORA is already in your contracts

DORA’s third-party pillar flows down. EU financial entities must impose contractual provisions on their ICT suppliers, maintain a register of information, and treat concentration risk seriously. If you are a UK fintech, cloud provider or managed service provider selling into the EU, you are on the receiving end of those clauses now. An EU-wide oversight framework for critical ICT third-party providers means the largest suppliers face direct supervision, and their customers inherit stricter diligence.

The FCA is your home regime

For UK-authorised firms, the FCA’s operational resilience rules are the base layer, not an optional extra. The regime requires you to identify important business services, set impact tolerances, map the people, processes, technology, and third parties that deliver them, test against disruption, remediate vulnerabilities, and learn from incidents.

Two developments sharpen this. A Critical Third Parties regime lets the FCA, Bank of England and PRA jointly oversee designated critical third parties without removing the firm’s own accountability. And CBEST, the regulator-led threat-intelligence-led penetration testing framework, published its first thematic analysis of adversary tactics and techniques in January 2026.

Frontier AI is now a resilience question

In May 2026 the FCA, Bank of England and Treasury issued a joint statement on frontier AI models and cyber resilience, followed in September 2026 by a multi-firm review. The Bank’s cross-market operational resilience group, CMORG, published frontier AI guidance in June 2026 setting out 38 key activities and 31 questions for firms. If your board is asking where AI fits into resilience, that guidance is the current UK reference point.

How to map one control set to all four frameworks

This is the section that saves money. The goal is a single control register with mappings outward, not four parallel programmes.

  1. Start from your important business services. Identify them the way the FCA requires. Everything else hangs off this list, because it determines which controls are material.
  2. Build one control register. Use CIS Controls v8.1 or NIST CSF 2.0 outcomes as the spine. Both have informative references that map to other standards, so you are not inventing structure.
  3. Map outward, once. Tag each control with the NIS2 measure, DORA pillar, NIST function or CIS safeguard it evidences. A spreadsheet is fine; a GRC tool is nice to have, not a prerequisite.
  4. Cover the third-party gap first. DORA’s contractual provisions, the FCA’s third-party notification rules and NIS2’s supply chain expectations all converge here. Standardise your supplier questionnaire and minimum security standards once.
  5. Right-size the testing. DORA separates basic and advanced testing and names threat-led penetration testing; the FCA runs CBEST. Decide which services warrant advanced testing rather than testing everything to the highest bar.
  6. Build incident reporting once, report many times. The ICO expects personal data breaches reported within 72 hours where feasible, DORA has its own incident classification and reporting process, and the FCA’s 2027 rules add another. One well-run incident process, with the right fields captured, serves all three.
  7. Evidence governance, not just technology. NIS2 management accountability and NIST’s Govern function both want board-level ownership. Minutes, risk appetite statements and a named accountable executive are cheap to produce and disproportionately convincing.
  8. Review on a fixed cadence. Regulations move, NIS2 simplification, FCA 2027 rules, frontier AI guidance. A quarterly mapping review is cheaper than an annual scramble.

If you need help structuring this, our regulatory compliance support is built around exactly this mapping exercise, and our NIS2, DORA, NIST and CIS service pages cover each framework’s specifics.

Common mistakes

  • Treating NIST and CIS as regulators. They are tools. Nobody is fined for a weak NIST profile; you are fined for the NIS2 or DORA obligation the framework was supposed to evidence.
  • Assuming DORA is an EU-only problem. It reaches UK suppliers through contracts and the register of information.
  • Mapping to four frameworks in four spreadsheets. Duplicated effort, drifting evidence, and a painful audit.
  • Leaving supplier security to procurement. The UK Cyber Security Breaches Survey 2025 found only 14% of businesses review cyber risk from immediate suppliers and just 7% review the wider supply chain.
  • Ignoring frontier AI until 2027. UK supervisors are already publishing expectations, and the 2027 FCA rules will assume you have thought about it.

For the underlying control design, our guides on risk management and threat modelling cover the technical foundations, and our financial services practice covers sector-specific evidence expectations.

Frequently asked questions

Does a UK firm need to comply with NIS2?

Only where you fall in scope, typically through EU establishments or as part of an EU client’s supply chain. UK-only firms with no EU footprint usually inherit NIS2 expectations contractually rather than directly.

Is DORA mandatory for UK financial services firms?

Not directly, unless you are an EU entity. It becomes mandatory in practice through contracts with EU financial entities and through the register of information those clients must maintain.

Which is better, NIST CSF 2.0 or CIS Controls?

CIS Controls is more prescriptive and faster to implement; NIST CSF 2.0 is more strategic and better at evidencing governance. Many firms use CIS as the control spine and NIST’s Govern function as the board-level wrapper. Both map to each other.

Do NIS2 and DORA overlap with UK GDPR?

They address different things. UK GDPR and the Data Protection Act 2018 govern personal data, and the ICO expects notification within 72 hours where a breach is likely to risk people’s rights and freedoms. DORA and NIS2 govern operational resilience and incident reporting to financial and national authorities. A single incident can trigger several of these at once.

How long does a first mapping take?

For a mid-sized firm with a reasonable control set, a first pass covering the important business services and the DORA and NIS2 obligations typically takes six to ten weeks, provided the documentation already exists in some form. It is considerably longer if controls have never been documented.

Getting started

The frameworks are not four problems. They are one control set, four audiences, and a mapping exercise that gets cheaper every quarter you maintain it. Pick a spine, CIS or NIST, map once, and cover third-party risk first, because that is where the obligations converge and where UK assurance is weakest.

If you would like a second opinion on scope, or a mapping built against your existing controls, talk to our team.