ISO/IEC 27001 is a voluntary standard for an information security management system, which an accredited certification body can certify. DORA, Regulation (EU) 2022/2554, is law: it has applied since 17 January 2025 to twenty types of financial entity listed in Article 2(1), from credit institutions to insurers, and to ICT third party service providers. The two overlap heavily on ICT risk management, the subject of DORA Articles 5 to 16, so an organisation with a working ISMS starts well ahead. But DORA does not mention ISO 27001 anywhere, does not require certification, and is not discharged by it. Four groups of DORA duties have no ISO 27001 counterpart at all: reporting major incidents to the competent authority on fixed clocks, the register of information on ICT contracts, the clauses Article 30 writes into those contracts, and the testing cadence up to threat led penetration testing.
This guide sets the two side by side from the text of each, shows where an ISMS already answers a DORA article and where it does not, and ends with a table you can fill in for your own programme. For the full list of DORA duties, start with DORA requirements explained.
| ISO 27001 | DORA | |
|---|---|---|
| What it is | An international standard, ISO/IEC 27001:2022 | An EU regulation, directly applicable in every Member State |
| Who it applies to | Anyone who chooses to adopt it | Twenty types of financial entity in Article 2(1)(a) to (t), and ICT third party service providers in (u) |
| Scope | Boundaries the organisation sets itself, clause 4.3 | The entity's ICT risk, as part of its overall risk management system, Article 6(1) |
| Who checks | An accredited certification body, by audit | The competent authority, by supervision; penalties set by each Member State under Article 50 |
| Leadership | Top management demonstrates leadership and commitment, clause 5.1 | The management body bears ultimate responsibility for ICT risk and is trained in it, Article 5 |
| Incidents | Planning, response and learning inside the ISMS, Annex A 5.24 to 5.28 | Classify, then report major incidents to the authority, Articles 18 and 19 |
| Suppliers | Supplier relationship controls, Annex A 5.19 to 5.23 | A register of information, mandatory contract clauses and exit strategies, Articles 28 and 30 |
| Testing | Evaluation the organisation plans, clause 9 | Yearly tests on critical systems and, where required, TLPT every 3 years, Articles 24 and 26 |
What is the difference between ISO 27001 and DORA?
One is a standard you choose; the other is a regulation you are subject to. DORA Article 64 provides that the regulation "shall apply from 17 January 2025". Article 2(1) lists the entities it covers, points (a) to (t) being the financial entities, among them "(a) credit institutions", "(b) payment institutions", "(e) investment firms" and "(n) insurance and reinsurance undertakings", with "(u) ICT third-party service providers" added at the end. If you are one of those, DORA applies whether or not you hold any certificate.
ISO/IEC 27001:2022 applies to whoever adopts it, over whatever they put in scope. Clause 4.3 of the standard says: "The organization shall determine the boundaries and applicability of the information security management system to establish its scope." A certificate covers that scope and nothing else. DORA has no equivalent choice: Article 6(1) requires "a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system". A certificate scoped to one product line or one data centre leaves the rest of the entity's ICT risk outside the audit, but not outside DORA.
Does DORA require ISO 27001 certification?
No. The words ISO and 27001 do not appear in the regulation, nor in Delegated Regulation (EU) 2024/1774, the technical standard that fills in the ICT risk management framework. Recital 47 of DORA explains the approach: the regulation is "inspired by relevant international, national and industry best practices", and as long as an entity's capabilities cover identification, protection and prevention, detection, response and recovery, learning and evolving and communication, "financial entities should remain free to use ICT risk management models that are differently framed or categorised." An ISMS is one such model. It is a legitimate way to build the framework; it is not a substitute for it.
Standards come up in one other place that matters. Article 28(5) says financial entities "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards", and for critical or important functions must take due consideration of "the most up-to-date and highest quality information security standards". A supplier's ISO 27001 certificate is useful evidence in that assessment. The regulation does not say it is sufficient, and it does not name any standard.
Where does ISO 27001 overlap with DORA?
In Chapter II, the ICT risk management articles. The table pairs each DORA article with the closest ISO 27001 clause or Annex A control, using the control titles in the ISO/IEC 27002:2022 table of contents. Closest is not identical: in every row DORA adds a detail, a frequency or an addressee that the standard leaves to you.
| DORA article | Closest ISO 27001 counterpart | What DORA adds |
|---|---|---|
| Art. 5 Governance and organisation | Clause 5.1 Leadership and commitment | Ultimate responsibility on the management body; members keep up to date by specific training, Art. 5(4) |
| Art. 6 ICT risk management framework | Clauses 6.1.2 risk assessment and 6.1.3 risk treatment | Review at least once a year and after major incidents, Art. 6(5); a digital operational resilience strategy, Art. 6(8) |
| Art. 6(6) internal audit | Clause 9.2 Internal audit | Auditors with ICT risk knowledge and appropriate independence, on the entity's audit plan |
| Art. 8 Identification | Asset inventory controls in Annex A | All ICT supported business functions classified, reviewed at least yearly |
| Art. 10 Detection | A.8.16 Monitoring activities | Mechanisms to detect anomalies and single points of failure |
| Art. 11 Response and recovery | A.5.29 Information security during disruption; A.5.30 ICT readiness for business continuity | Plans tested at least yearly, Art. 11(6) |
| Art. 12 Backup and restoration | A.8.13 Information backup | Restoration onto systems physically and logically segregated from the source, Art. 12(3) |
| Art. 13 Learning and evolving | A.5.7 Threat intelligence; A.6.3 awareness, education and training | Compulsory training for all employees and senior management staff, Art. 13(6) |
| Art. 17 Incident management process | A.5.24 and A.5.26, incident planning and response | A process that also notifies, feeding Articles 18 and 19 |
| Art. 28 ICT third party risk | A.5.19 to A.5.23 supplier and cloud controls | Register of information, exit strategies, Article 30 clauses |
Where a row matches, an ISMS that operates as documented already produces most of the evidence a DORA review asks for. Our guide to the 93 Annex A controls shows how they are organised.

What does DORA require that ISO 27001 does not?
Four things an ISMS will not produce on its own.
Reporting clocks. Article 18 makes you classify ICT related incidents against criteria set in Delegated Regulation (EU) 2024/1772, and Article 19(1) requires financial entities to "report major ICT-related incidents to the relevant competent authority". The deadlines are in Article 5(1) of Delegated Regulation (EU) 2025/301: the initial notification "within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware" of it; the intermediate report "at the latest within 72 hours from the submission of the initial notification"; and the final report "no later than one month" after the latest intermediate report. ISO 27001 asks you to respond to incidents, not to tell a supervisor about them on a timetable. The classification test is in our guide to DORA major incident classification.
The register of information. Article 28(3) requires "a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers", in the templates set by Implementing Regulation (EU) 2024/2956. A supplier inventory kept for Annex A 5.19 is a starting point, not the register. See the complete guide to the register of information.
Contract clauses. Article 30, "Key contractual provisions", lists what every ICT services contract must contain, with more for contracts supporting critical or important functions, and Article 28(8) requires exit strategies for those services. Annex A 5.20 asks you to address security in supplier agreements; DORA dictates the clauses.
Testing cadence. Article 24(6) requires entities other than microenterprises to ensure "at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions." Under Article 26, entities that competent authorities identify must carry out threat led penetration testing "at least every 3 years". Nothing in ISO 27001 sets either frequency. The detail is in DORA TLPT.

How do the leadership duties differ?
In who carries them and how far. ISO 27001 clause 5.1 says "Top management shall demonstrate leadership and commitment with respect to the information security management system". DORA Article 5(2)(a) makes the management body "bear the ultimate responsibility for managing the financial entity's ICT risk", and Article 5(4) requires its members to "actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk", "including by following specific training on a regular basis". Article 6(4) adds a control function for ICT risk with "an appropriate level of independence", under "the three lines of defence model, or an internal risk management and control model". Expect a supervisor to ask for board minutes and training records, not a leadership policy.
What the other results get wrong
Page one for this query is mostly consultancies and compliance vendors, and three errors recur. Several put a number on the overlap, from "50 to 60%" to "nearly 90% of the way to achieving DORA compliance"; none says how it was measured, and neither text contains anything to count it against. One security firm says DORA non compliance can bring "fines of up to 1% of global turnover". DORA sets no fine for financial entities: Article 50 leaves administrative penalties to each Member State. The 1% figure is from Article 35(8), a periodic penalty payment of up to 1% of average daily worldwide turnover, imposed by the Lead Overseer on critical ICT third party service providers only. And several summaries give the final incident report as "one month" with no starting point; under Delegated Regulation (EU) 2025/301 the month runs from the latest intermediate report, not from the incident.
Should you do ISO 27001 or DORA first?
If DORA applies to you, DORA, because it is not optional. But if you already run an ISMS, do not build a second framework beside it. Confirm your DORA scope under Article 2, including whether the simplified framework in Article 16 applies, then map your ISMS to Articles 5 to 16 and add what is missing: the management body record, the yearly review, the strategy. Then add the four DORA only items. Certification is a commercial decision, worth making if customers ask for the certificate; DORA does not require it. NIS2 vs ISO 27001 works through the same question for NIS2.
Check your own programme
Fill in the middle column. Every blank is a gap a certificate will not close.
| Question | Your answer | Why it matters |
|---|---|---|
| Which point of DORA Article 2(1) are you, and does Article 16 apply? | Sets which version of the duties you carry. | |
| Does your ISMS scope cover all the entity's ICT supported business functions? | Clause 4.3 lets you narrow scope; Article 6(1) does not. | |
| When did the management body last approve the ICT risk framework and receive training? | Article 5(2) and 5(4). | |
| When was the framework last reviewed? | Article 6(5): at least once a year. | |
| Can you classify an incident and send an initial notification within four hours? | Article 19 and Delegated Regulation (EU) 2025/301. | |
| Is every ICT services contract in the register, with Article 30 clauses? | Articles 28(3) and 30. | |
| When were critical systems last tested, and has your authority named you for TLPT? | Articles 24(6) and 26. |
If most rows are blank, the free compliance check gives you a baseline. Venvera's DORA module and ISO 27001 module sit on one control set, so evidence collected for an Annex A control counts for the DORA article it answers, and the register of information, incident clocks and contract clauses are tracked beside it.
Frequently asked questions
Is ISO 27001 mandatory under DORA?
No. DORA does not mention ISO 27001 and recital 47 leaves entities free to use ICT risk management models that are differently framed, provided the required capabilities are in place.
Does an ISO 27001 certificate make us DORA compliant?
No. It shows an audited management system over the scope you chose. DORA applies to the whole entity and adds incident reporting, the register of information, contract clauses and a testing programme that the standard does not cover.
Can we use one control set for both?
Yes, and it is the cheaper route. Map each DORA article in Chapter II to the clause or Annex A control that answers it, and add controls for the DORA only duties.
What are the DORA fines?
DORA leaves administrative penalties for financial entities to national law under Article 50, so the amount depends on your Member State. The only figure in the regulation is the periodic penalty payment for critical ICT third party service providers in Article 35(8).
Does DORA care whether our suppliers hold ISO 27001?
Indirectly. Article 28(5) requires providers to comply with appropriate information security standards. A certificate is evidence for that assessment; DORA does not say it is enough.
Primary sources
DORA articles and recitals are quoted from Regulation (EU) 2022/2554; incident deadlines from Delegated Regulation (EU) 2025/301, Article 5; classification from Delegated Regulation (EU) 2024/1772; the ICT risk framework detail from Delegated Regulation (EU) 2024/1774; register templates from Implementing Regulation (EU) 2024/2956. ISO/IEC 27001:2022 clauses 4.3 and 5.1 are from the published preview; Annex A control titles from the ISO/IEC 27002:2022 preview. Where your competent authority has issued its own guidance, it takes precedence over any general mapping.




