DORA, NIS2, GDPR, PSD2, MiCA: Mapping the Overlaps EU Financial Firms Can't Afford to Miss
By Zetta Henigman
The EU has built five overlapping ICT security regimes, and left financial firms to work out the interactions themselves. Each regime was drafted separately, yet they share some requirements, including incident reporting, risk management, third-party oversight, and consumer protection.
That overlap is the real challenge for financial companies operating in the EU. Most compliance teams already know what DORA or GDPR require in isolation. What's harder is knowing where these regimes converge, where one framework already satisfies another, and where the gaps between them create exposure.
At Anove, we track the development of financial regulations on our insAIght AI-native platform, which is built to surface overlaps and produce audit-ready evidence faster than a manual mapping exercise would.
This article introduces the key EU regulations and directives with a security component that apply to financial companies, and maps the overlaps between them. For the full list of frameworks that Anove tracks, visit our our regulations page.
The Regulatory Landscape: What Financial Companies Need to Know
1. Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is a landmark EU regulation introduced to strengthen the digital resilience of financial entities.[1] It entered into force on 16 January 2023 and applies from 17 January 2025, ensuring that financial institutions can withstand, respond to, and recover from ICT (Information and Communication Technology) disruptions, such as cyberattacks or system failures.[2]
What DORA Covers
DORA establishes a comprehensive framework for managing ICT risks in the financial sector. The regulation covers the following key areas:
- ICT Risk Management: Financial entities must develop and maintain a robust ICT risk management framework, including strategies for identifying, assessing, and mitigating ICT risks.
- ICT Third-Party Risk: Financial entities must maintain a register of ICT third-party arrangements and ensure contracts with critical providers include exit strategies, audit rights and performance targets.
- Digital Operational Resilience Testing: Financial entities are required to regularly test their ICT systems to evaluate their resilience, which includes vulnerability assessments, scenario-based testing, and, for critical institutions, threat-led penetration testing (TLPT) every three years.
- ICT-Related Incident Reporting: DORA mandates that financial entities establish systems for monitoring, managing, logging, classifying, and reporting ICT-related incidents.
- Information Sharing: While not mandatory, DORA encourages financial entities to participate in voluntary threat intelligence sharing arrangements to enhance collective resilience against cyber threats.
2. Network and Information Security Directive (NIS 2)
The Network and Information Security Directive (NIS 2) is the EU’s updated cybersecurity framework, replacing the original NIS Directive.[3] Its objective is to achieve a high common level of cybersecurity across the EU by strengthening the security of network and information systems.
Member States were required to transpose NIS 2 into national law by 17 October 2024, though countries such as the Netherlands, France, Spain, and Ireland missed this deadline, creating practical uncertainty for businesses.[4]
What NIS 2 Covers
The key provisions of NIS 2 include:
- Risk Management and Reporting: The directive introduces risk management measures and incident reporting requirements for entities in critical sectors.
- Governance and Accountability: NIS 2 holds top management accountable for cybersecurity risk management, bringing cybersecurity to the attention of the boardroom.
- Cooperation and Information Sharing: The directive establishes a network of Computer Security Incident Response Teams (CSIRTs) to exchange information on cyber threats and respond to incidents. It also creates the European Cyber Crisis Liaison Organization Network (EU-CyCLONe) to support coordinated management of large-scale cybersecurity incidents or crises.
- All-Hazards Approach: NIS 2 requires organizations to prepare for a broad spectrum of risks, strengthening operational resilience and ensuring the continuity of essential and important services.
Relationship with DORA: Under Article 4 of NIS 2, where sector-specific Union legal acts (such as DORA) impose cybersecurity risk-management or incident notification requirements, the relevant NIS 2 provisions, including Articles 21 (risk management) and 23 (incident notification), as well as supervision and enforcement, do not apply.
DORA is lex specialis for financial entities, meaning banks and other financial institutions are not required to comply with both frameworks in full.
3. General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is the EU’s data privacy regulation.[5] It imposes strict requirements on how personal data is collected, processed, and stored.[6]
What GDPR Covers
GDPR establishes a comprehensive framework for data protection, ensuring that individuals have control over their personal data. Key provisions include:
- Principles of Data Processing: GDPR sets out core principles for processing personal data, including lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
- Data Breach Notification: Organizations must report personal data breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach.
- Technical and Organizational Measures: Organizations must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including pseudonymization, encryption, access controls, and regular security testing.
- Data Protection Impact Assessments (DPIAs): Organizations must conduct DPIAs for high-risk data processing activities to identify and mitigate potential privacy risks.
- Data Protection Officer (DPO): Certain organizations, particularly those involved in large-scale processing of sensitive data, are required to appoint a DPO to oversee compliance with GDPR.
- Cross-Border Data Transfers: GDPR imposes strict rules on the transfer of personal data outside the EU, requiring organizations to ensure that data transferred to third countries is protected by adequate safeguards.
4. Payment Services Directives and Regulation (PSD2, PSD3, and PSR)
PSD2 (Payment Services Directive 2) is the current EU directive governing payment services, which aims to promote competition, enhance security, and protect consumers.[7]
The PSD3 and PSR represent the next phase of EU payment services regulation.[8] Political agreement on PSD3/PSR was reached on 27 November 2025, with final texts agreed on 23 April 2026.[9] Together, they aim to further strengthen fraud prevention, expand open banking capabilities, and harmonize payment rules across the EU.
What They Cover
PSD2, PSD3, and PSR introduce key requirements for payment services, including:
- Strong Customer Authentication (SCA): Mandatory authentication using two or more elements from independent categories (knowledge, possession, inherence) for electronic transactions.
- Open Banking: Secure access for third-party providers to bank account data.
- Transparency: Clear disclosure of fees, exchange rates, and transaction details.
- Refund Rights: Customer protection for unauthorized transactions.
- Security: Requirements for confidentiality, integrity, and availability of payment data.
- Licensing: Mandatory registration and authorization for payment service providers.
- Incident Reporting: Obligation to report significant security incidents.
5. Markets in Crypto-Assets (MiCA) Regulation
The Markets in Crypto-Assets Regulation (MiCA) is the EU’s first comprehensive framework for regulating crypto-assets.[10] It establishes uniform market rules for crypto-assets, aiming to support market integrity, financial stability, and consumer protection.
What MiCA Covers
The key provisions of MiCA include:
- Transparency and Disclosure: Requires issuers of crypto-assets to provide clear and comprehensive information about their assets, including risks, to ensure consumers are well-informed.
- Technical Standards: The regulation sets data standards and formatting requirements for crypto-asset white papers and record-keeping, which include system resilience and security access protocols to protect platforms and services from cyber threats and unauthorized access.
- Market Integrity: Regulates public offers of crypto-assets to prevent market abuse and ensure financial stability.
- Authorisation and Supervision: Introduces authorization and supervision requirements for crypto-asset issuers and service providers, including those dealing with asset-referenced tokens (ARTs) and e-money tokens.
- Business Continuity Requirements: Entities must implement measures to ensure the ongoing availability and reliability of crypto-asset services, even in the event of disruptions or failures.
Where the Frameworks Actually Overlap
DORA, NIS 2, GDPR, PSD2/PSD3, and MiCA each cover some shared requirements. Where two or more overlap on the same area, firms end up with duplicate obligations. Knowing where each framework sits is what turns five compliance projects into one.
- Incident Reporting: DORA requires financial entities to classify and report ICT-related incidents; NIS 2 imposes a similar obligation for essential and important entities, but yields to DORA for financial entities under the lex specialis rule; GDPR requires breach notification within 72 hours whenever personal data is involved; and PSD2/PSD3 separately require reporting of significant payment security incidents. A single ICT incident touching customer data can trigger DORA, GDPR, and PSD2 reporting duties at once, each with its own timeline and template.
- Risk Management: DORA's ICT risk management framework and NIS 2's risk-management measures cover much of the same ground for financial entities, which is why NIS 2 steps back where DORA applies. GDPR's "appropriate technical and organizational measures" and MiCA's business continuity requirements add data- and crypto-specific risk obligations on top of that baseline.
- Third-Party Oversight: DORA's ICT third-party register and contractual requirements (exit strategies, audit rights, performance targets) are the most detailed of the five. NIS 2 expects similar supply-chain risk management for in-scope entities, and MiCA imposes its own authorisation and oversight requirements on crypto-asset service providers, meaning a single vendor relationship can fall under more than one register.
- Consumer Protection: GDPR protects personal data rights, PSD2/PSD3 protect payment customers through refund rights and transparency requirements, and MiCA protects crypto-asset holders through disclosure and market-integrity rules. These rarely conflict, but a firm offering crypto-linked payment products can find itself answering to three separate consumer-protection regimes for one customer complaint.
Summary of the Frameworks
|
Framework
|
Instrument Type |
Entered Into |
Applies From |
Supervisors |
Penalties |
|
DORA |
Regulation |
16 Jan 2023 |
17 Jan 2025 |
National competent authorities + European Supervisory Authorities (ESAs) directly oversee designated CTPPs |
Financial entities: up to 2% of global turnover (serious breaches), 1% of average daily turnover (certain breaches), or fixed fines up to €5M. CTPPs: up to €5M + periodic penalties. Individuals: up to €1M + management bans |
|
NIS 2 |
Directive |
16 Jan 2023 |
17 Oct 2024 (transposition deadline) |
National cybersecurity/competent authorities per member state, coordinated by the NIS Cooperation Group |
Essential entities: up to €10M or 2% of global turnover, whichever is higher. Important entities: up to €7M or 1.4%, whichever is higher |
|
GDPR |
Regulation |
24 May 2016 |
25 May 2018 |
National Data Protection Authorities, coordinated by the European Data Protection Board |
Up to €20M or 4% of global annual turnover, whichever is higher |
|
PSD2, PSD3, & PSR |
PSD2 & PSD3: Directives; PSR: Regulation |
PSD2: Jan 2016. PSD3/PSR: not yet in force, final texts published 23 Apr 2026 |
PSD2: 13 Jan 2018. PSD3/PSR: Publication expected in summer 2026; Application targeted for roughly Q2/Q3 2028 |
National competent authorities for payment services |
PSD2/PSD3: no EU cap, determined by member states. PSR: at least 10% of turnover for legal persons, up to €5M for individuals, plus daily penalty payments up to 3% of daily turnover |
|
MiCA |
Regulation |
29 Jun 2023 |
30 Jun 2024 (asset-referenced/e-money tokens) / 30 Dec 2024 (CASPs); national grandfathering windows for pre-existing CASPs ended by 1 Jul 2026 |
National competent authorities + European Banking Authority (significant asset-referenced/e-money tokens) + European Securities and Markets Authority (coordination) |
Natural persons: up to €700,000. Legal persons: up to 15% of annual turnover or 2x the profits gained/losses avoided, whichever is higher. Unauthorized CASP activity specifically: up to €5M or 3–5% of turnover |
What’s Coming Next
AI Act: The Artificial Intelligence Act (AI Act) is the EU's first comprehensive framework for regulating artificial intelligence.[11] It entered into force on 1 August 2024 and applies through a phased timeline: prohibitions on unacceptable-risk practices and AI literacy requirements took effect on 2 February 2025; obligations for general-purpose AI models applied from 2 August 2025; and from 2 August 2026, transparency requirements apply.[12] High-risk AI systems, including those used for credit scoring or fraud detection will apply from 2 December 2027.
AMLR/AMLD6: The Anti-Money Laundering Regulation (AMLR) and the Sixth Anti-Money Laundering Directive (AMLD6) form part of the new AML package in the EU, establishing a common rulebook for customer due diligence, beneficial ownership, and suspicious transaction reporting across Member States.[13] Both entered into force on 9 July 2024.[14] The AMLR will apply directly across all Member States from 10 July 2027,[15] while the AMLD6 must be transposed by the same date.[16]
European Digital Identity Regulation (EUDI/eIDAS 2): eIDAS 2 establishes the legal basis for the EU Digital Identity Wallet (EUDI Wallet), which allows citizens, residents, and businesses to securely store credentials and share only the specific data needed for a given transaction.[17] It entered into force on 20 May 2024.[18] Every Member State must offer at least one certified EUDI Wallet by 24 December 2026, and banks must support the wallet for strong authentication by 24 December 2027. This will affect the SCA processes under PSD2/PSD3.[19]
Cyber Resilience Act (CRA): The CRA sets mandatory cybersecurity requirements for connectable hardware and software placed on the EU market, including financial software.[20] It requires manufacturers to build security into the design, development, and maintenance of their products, and to handle vulnerabilities throughout the product lifecycle.[21] The CRA entered into force on 10 December 2024 and applies in full from 11 December 2027, with reporting obligations for actively exploited vulnerabilities and severe incidents applying earlier, from 11 September 2026.[22]
Navigating Overlaps and Intersections
Since many requirements overlap between the frameworks, financial companies often struggle to navigate the complexity of various obligations. This fragmentation can lead to duplication of efforts, missed critical obligations, or misaligned internal policies, increasing both costs and risks.
To address this, we recommend starting with a comprehensive gap analysis to identify which requirements are already covered by these overlaps. Anove’s insAIght platform helps companies go further by:
- Visualizing overlaps across all relevant frameworks, providing a clear view of how requirements intersect.
- Centralizing documentation and evidence so one control satisfies obligations under multiple regimes.
- Tracking regulatory changes in real time, ensuring updates to one regulation are automatically reflected across all related compliance activities.
With insAIght, financial companies can adopt multiple regulatory frameworks simultaneously, eliminating redundancies and streamlining compliance.
Find out more about insAIght here: https://www.anove.ai/en/product/insaight
Ready to see it in action? Book a demo with our team to find out how insAIght can help your company navigate overlapping EU regulations, close compliance gaps, prepare for audits.
[1] Regulation (EU) 2022/2554 (DORA): Retrieved from https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng.
[2] ESMA, DORA: Retrieved from https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora.
[3] Directive (EU) 2022/2555: Retrieved from https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng.
[4] ECS, NIS2 Directive Transposition Tracker: Retrieved from https://ecs-org.eu/policy/nis2-directive-transposition-tracker/.
[5] Regulation (EU) 2016/679 (GDPR): Retrieved from https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng.
[6] European Commission, Legal Framework for EU Data Protection: Retrieved from https://commission.europa.eu/law/law-topic/data-protection/legal-framework-eu-data-protection_en.
[7] Directive (EU) 2015/2366 (PSD2): Retrieved from https://eur-lex.europa.eu/eli/dir/2015/2366/oj/eng.
[8] European Parliament, Payment Services Deal: More Protection from Online Fraud and Hidden Fees: Retrieved from https://www.europarl.europa.eu/news/en/press-room/20251121IPR31540/payment-services-deal-more-protection-from-online-fraud-and-hidden-fees.
[9] European Parliament, Revision of EU Rules on Payment Services: Retrieved from https://www.europarl.europa.eu/legislative-train/theme-an-economy-that-works-for-people/file-revision-of-eu-rules-on-payment-services.
[10] Regulation (EU) 2023/1114: Retrieved from https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng.
[11] Regulation (EU) 2024/1689: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.
[12] European Commission, Timeline for Implementation of the EU AI Act: Retrieved from https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act.
[13] Signicat, AMLR vs. AMLD6: Navigating the New Anti-Money Laundering Regulation Era: Retrieved from https://www.signicat.com/blog/amlr-vs-amld6-navigating-the-new-anti-money-laundering-regulation-era.
[14] Rapidlei, EU AML Package Readiness: Retrieved from https://rapidlei.com/eu-aml-package-readiness/.
[15] Regulation (EU) 2024/1624: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng.
[16] Directive (EU) 2024/1640: Retrieved from https://eur-lex.europa.eu/eli/dir/2024/1640/oj/eng.
[17] European Commission, eUDI Regulation: Retrieved from https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation.
[18] European Digital Identity Regulation: Retrieved from https://www.european-digital-identity-regulation.com/.
[19] OneSpan, Why European Banks Must Act Now on EUDI Wallets: Retrieved from https://www.onespan.com/cybersecurity/blog/why-european-banks-must-act-now-on-EUDI-wallets.
[20] Regulation (EU) 2024/2847: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng.
[21] European Commission, Cyber Resilience Act: Retrieved from https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act.
[22] Regulation (EU) 2024/2847: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng.