INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeSectorsBanking
Annex I / Sector guidance

Banking and NIS2

Credit institutions appear in the banking category. Sector-specific EU acts, including DORA, can affect the applicable cybersecurity framework.

Applicability starts with the service

Compare the precise entity and service category in Annex I with the organisation’s actual activity. Review size-related rules, exceptions and the law of the relevant Member State before concluding that an entity is in or out of scope.

Implementation considerations

  • Determine interaction with sector-specific rules
  • Align governance and evidence ownership
  • Map service and third-party dependencies

Obligations to review

For in-scope entities, examine cybersecurity risk-management measures, management oversight and the reporting of significant incidents, including the national rules and any sector-specific EU measures.

A sector listing is not a determination of legal status or an exhaustive description of covered entities.

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.