Home › DORA › DORA vs ISO 27001

DORA Compliance

DORA vs ISO 27001: Does Your Cert Cover DORA?

Key takeaway

ISO 27001 is a strong foundation and covers much of DORA’s ICT risk-management expectations — but it does not make you DORA compliant. DORA adds obligations ISO does not, including threat-led penetration testing, the register of information, specific incident-reporting timelines and management-body accountability.

Holding ISO 27001 is genuinely valuable for DORA — but it is a head start, not a finish line.

Where they align

Venn-style diagram showing where DORA, NIS2 and ISO 27001 overlap and differ, including DORA's lex specialis status for financial entities
Where DORA, NIS2 and ISO 27001 overlap — and where each stands alone.

ISO 27001’s information security management system maps well onto much of DORA’s ICT risk-management framework: governance, risk assessment, controls, and continual improvement. If you hold ISO 27001, you have a strong base.

What DORA adds

  • Threat-led penetration testing for identified entities — not an ISO requirement.

  • The register of information and prescribed third-party contract clauses.

  • Specific incident-reporting timelines and channels.

  • Management-body accountability as an explicit legal duty.

  • Proportionate, at-least-annual testing of CIF-supporting systems.

Closing the gaps

A gap analysis maps your ISO-based controls against DORA and shows what remains. Often the delta is smaller than firms fear — but it is real. See DORA readiness assessment.

Next step

Hold ISO 27001 and want to know your DORA gap? Book a gap assessment.