ISO 27001 is a strong foundation and covers much of DORA’s ICT risk-management expectations — but it does not make you DORA compliant. DORA adds obligations ISO does not, including threat-led penetration testing, the register of information, specific incident-reporting timelines and management-body accountability.
Holding ISO 27001 is genuinely valuable for DORA — but it is a head start, not a finish line.
Where they align
ISO 27001’s information security management system maps well onto much of DORA’s ICT risk-management framework: governance, risk assessment, controls, and continual improvement. If you hold ISO 27001, you have a strong base.
What DORA adds
Threat-led penetration testing for identified entities — not an ISO requirement.
The register of information and prescribed third-party contract clauses.
Specific incident-reporting timelines and channels.
Management-body accountability as an explicit legal duty.
Proportionate, at-least-annual testing of CIF-supporting systems.
Closing the gaps
A gap analysis maps your ISO-based controls against DORA and shows what remains. Often the delta is smaller than firms fear — but it is real. See DORA readiness assessment.
Hold ISO 27001 and want to know your DORA gap? Book a gap assessment.