NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
ISO 27001 vs DORA: What the Certificate Covers
Learn

ISO 27001 vs DORA: What the Certificate Covers

·Alexander Sverdlov

ISO/IEC 27001 is a voluntary standard for an information security management system, which an accredited certification body can certify. DORA, Regulation (EU) 2022/2554, is law: it has applied since 17 January 2025 to twenty types of financial entity listed in Article 2(1), from credit institutions to insurers, and to ICT third party service providers. The two overlap heavily on ICT risk management, the subject of DORA Articles 5 to 16, so an organisation with a working ISMS starts well ahead. But DORA does not mention ISO 27001 anywhere, does not require certification, and is not discharged by it. Four groups of DORA duties have no ISO 27001 counterpart at all: reporting major incidents to the competent authority on fixed clocks, the register of information on ICT contracts, the clauses Article 30 writes into those contracts, and the testing cadence up to threat led penetration testing.

This guide sets the two side by side from the text of each, shows where an ISMS already answers a DORA article and where it does not, and ends with a table you can fill in for your own programme. For the full list of DORA duties, start with DORA requirements explained.

ISO 27001DORA
What it isAn international standard, ISO/IEC 27001:2022An EU regulation, directly applicable in every Member State
Who it applies toAnyone who chooses to adopt itTwenty types of financial entity in Article 2(1)(a) to (t), and ICT third party service providers in (u)
ScopeBoundaries the organisation sets itself, clause 4.3The entity's ICT risk, as part of its overall risk management system, Article 6(1)
Who checksAn accredited certification body, by auditThe competent authority, by supervision; penalties set by each Member State under Article 50
LeadershipTop management demonstrates leadership and commitment, clause 5.1The management body bears ultimate responsibility for ICT risk and is trained in it, Article 5
IncidentsPlanning, response and learning inside the ISMS, Annex A 5.24 to 5.28Classify, then report major incidents to the authority, Articles 18 and 19
SuppliersSupplier relationship controls, Annex A 5.19 to 5.23A register of information, mandatory contract clauses and exit strategies, Articles 28 and 30
TestingEvaluation the organisation plans, clause 9Yearly tests on critical systems and, where required, TLPT every 3 years, Articles 24 and 26
ISO 27001 and DORA at a glance: ISO/IEC 27001:2022 is voluntary and certified by an accredited body, DORA is Regulation (EU) 2022/2554 applying from 17 January 2025 to twenty types of financial entity, and the text of DORA never mentions ISO 27001

What is the difference between ISO 27001 and DORA?

One is a standard you choose; the other is a regulation you are subject to. DORA Article 64 provides that the regulation "shall apply from 17 January 2025". Article 2(1) lists the entities it covers, points (a) to (t) being the financial entities, among them "(a) credit institutions", "(b) payment institutions", "(e) investment firms" and "(n) insurance and reinsurance undertakings", with "(u) ICT third-party service providers" added at the end. If you are one of those, DORA applies whether or not you hold any certificate.

ISO/IEC 27001:2022 applies to whoever adopts it, over whatever they put in scope. Clause 4.3 of the standard says: "The organization shall determine the boundaries and applicability of the information security management system to establish its scope." A certificate covers that scope and nothing else. DORA has no equivalent choice: Article 6(1) requires "a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system". A certificate scoped to one product line or one data centre leaves the rest of the entity's ICT risk outside the audit, but not outside DORA.

Does DORA require ISO 27001 certification?

No. The words ISO and 27001 do not appear in the regulation, nor in Delegated Regulation (EU) 2024/1774, the technical standard that fills in the ICT risk management framework. Recital 47 of DORA explains the approach: the regulation is "inspired by relevant international, national and industry best practices", and as long as an entity's capabilities cover identification, protection and prevention, detection, response and recovery, learning and evolving and communication, "financial entities should remain free to use ICT risk management models that are differently framed or categorised." An ISMS is one such model. It is a legitimate way to build the framework; it is not a substitute for it.

Standards come up in one other place that matters. Article 28(5) says financial entities "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards", and for critical or important functions must take due consideration of "the most up-to-date and highest quality information security standards". A supplier's ISO 27001 certificate is useful evidence in that assessment. The regulation does not say it is sufficient, and it does not name any standard.

Where does ISO 27001 overlap with DORA?

In Chapter II, the ICT risk management articles. The table pairs each DORA article with the closest ISO 27001 clause or Annex A control, using the control titles in the ISO/IEC 27002:2022 table of contents. Closest is not identical: in every row DORA adds a detail, a frequency or an addressee that the standard leaves to you.

DORA articleClosest ISO 27001 counterpartWhat DORA adds
Art. 5 Governance and organisationClause 5.1 Leadership and commitmentUltimate responsibility on the management body; members keep up to date by specific training, Art. 5(4)
Art. 6 ICT risk management frameworkClauses 6.1.2 risk assessment and 6.1.3 risk treatmentReview at least once a year and after major incidents, Art. 6(5); a digital operational resilience strategy, Art. 6(8)
Art. 6(6) internal auditClause 9.2 Internal auditAuditors with ICT risk knowledge and appropriate independence, on the entity's audit plan
Art. 8 IdentificationAsset inventory controls in Annex AAll ICT supported business functions classified, reviewed at least yearly
Art. 10 DetectionA.8.16 Monitoring activitiesMechanisms to detect anomalies and single points of failure
Art. 11 Response and recoveryA.5.29 Information security during disruption; A.5.30 ICT readiness for business continuityPlans tested at least yearly, Art. 11(6)
Art. 12 Backup and restorationA.8.13 Information backupRestoration onto systems physically and logically segregated from the source, Art. 12(3)
Art. 13 Learning and evolvingA.5.7 Threat intelligence; A.6.3 awareness, education and trainingCompulsory training for all employees and senior management staff, Art. 13(6)
Art. 17 Incident management processA.5.24 and A.5.26, incident planning and responseA process that also notifies, feeding Articles 18 and 19
Art. 28 ICT third party riskA.5.19 to A.5.23 supplier and cloud controlsRegister of information, exit strategies, Article 30 clauses

Where a row matches, an ISMS that operates as documented already produces most of the evidence a DORA review asks for. Our guide to the 93 Annex A controls shows how they are organised.

Where an ISO 27001 ISMS overlaps DORA Chapter II: Article 5 with clause 5.1, Article 6(1) with clause 6.1, Article 6(6) with clause 9.2, Article 11 with Annex A 5.29 and 5.30, Article 12 with Annex A 8.13, and Article 28 with Annex A 5.19 to 5.23
Venvera control crosswalk showing coverage by framework, including DORA and ISO, and a matrix of control domains such as encryption, key management and access control against each framework

What does DORA require that ISO 27001 does not?

Four things an ISMS will not produce on its own.

Reporting clocks. Article 18 makes you classify ICT related incidents against criteria set in Delegated Regulation (EU) 2024/1772, and Article 19(1) requires financial entities to "report major ICT-related incidents to the relevant competent authority". The deadlines are in Article 5(1) of Delegated Regulation (EU) 2025/301: the initial notification "within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware" of it; the intermediate report "at the latest within 72 hours from the submission of the initial notification"; and the final report "no later than one month" after the latest intermediate report. ISO 27001 asks you to respond to incidents, not to tell a supervisor about them on a timetable. The classification test is in our guide to DORA major incident classification.

The register of information. Article 28(3) requires "a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers", in the templates set by Implementing Regulation (EU) 2024/2956. A supplier inventory kept for Annex A 5.19 is a starting point, not the register. See the complete guide to the register of information.

Contract clauses. Article 30, "Key contractual provisions", lists what every ICT services contract must contain, with more for contracts supporting critical or important functions, and Article 28(8) requires exit strategies for those services. Annex A 5.20 asks you to address security in supplier agreements; DORA dictates the clauses.

Testing cadence. Article 24(6) requires entities other than microenterprises to ensure "at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions." Under Article 26, entities that competent authorities identify must carry out threat led penetration testing "at least every 3 years". Nothing in ISO 27001 sets either frequency. The detail is in DORA TLPT.

What DORA asks for that ISO 27001 does not: an initial notification within four hours of classifying a major incident, the Article 28(3) register of information, the Article 30 contract clauses, and threat led penetration testing every three years for entities a competent authority identifies
Venvera register of information under DORA Article 28(3), showing counts of ICT providers, contractual arrangements, business functions and risk assessments, a pre-export validation panel with warnings, and an xBRL-CSV export button

How do the leadership duties differ?

In who carries them and how far. ISO 27001 clause 5.1 says "Top management shall demonstrate leadership and commitment with respect to the information security management system". DORA Article 5(2)(a) makes the management body "bear the ultimate responsibility for managing the financial entity's ICT risk", and Article 5(4) requires its members to "actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk", "including by following specific training on a regular basis". Article 6(4) adds a control function for ICT risk with "an appropriate level of independence", under "the three lines of defence model, or an internal risk management and control model". Expect a supervisor to ask for board minutes and training records, not a leadership policy.

What the other results get wrong

Page one for this query is mostly consultancies and compliance vendors, and three errors recur. Several put a number on the overlap, from "50 to 60%" to "nearly 90% of the way to achieving DORA compliance"; none says how it was measured, and neither text contains anything to count it against. One security firm says DORA non compliance can bring "fines of up to 1% of global turnover". DORA sets no fine for financial entities: Article 50 leaves administrative penalties to each Member State. The 1% figure is from Article 35(8), a periodic penalty payment of up to 1% of average daily worldwide turnover, imposed by the Lead Overseer on critical ICT third party service providers only. And several summaries give the final incident report as "one month" with no starting point; under Delegated Regulation (EU) 2025/301 the month runs from the latest intermediate report, not from the incident.

Should you do ISO 27001 or DORA first?

If DORA applies to you, DORA, because it is not optional. But if you already run an ISMS, do not build a second framework beside it. Confirm your DORA scope under Article 2, including whether the simplified framework in Article 16 applies, then map your ISMS to Articles 5 to 16 and add what is missing: the management body record, the yearly review, the strategy. Then add the four DORA only items. Certification is a commercial decision, worth making if customers ask for the certificate; DORA does not require it. NIS2 vs ISO 27001 works through the same question for NIS2.

The order that avoids doing the work twice: confirm DORA scope under Article 2, map the ISMS to Articles 5 to 16, add incident reporting, the register and contract clauses, set the yearly tests and TLPT, and certify to ISO 27001 if customers ask
An illustrative view of one control set serving ISO 27001 and DORA: Annex A controls with current evidence, DORA Articles 5 to 16 mapped to controls, ICT contracts still missing Article 30 clauses, and days since the Article 6(5) framework review

Check your own programme

Fill in the middle column. Every blank is a gap a certificate will not close.

QuestionYour answerWhy it matters
Which point of DORA Article 2(1) are you, and does Article 16 apply?Sets which version of the duties you carry.
Does your ISMS scope cover all the entity's ICT supported business functions?Clause 4.3 lets you narrow scope; Article 6(1) does not.
When did the management body last approve the ICT risk framework and receive training?Article 5(2) and 5(4).
When was the framework last reviewed?Article 6(5): at least once a year.
Can you classify an incident and send an initial notification within four hours?Article 19 and Delegated Regulation (EU) 2025/301.
Is every ICT services contract in the register, with Article 30 clauses?Articles 28(3) and 30.
When were critical systems last tested, and has your authority named you for TLPT?Articles 24(6) and 26.

If most rows are blank, the free compliance check gives you a baseline. Venvera's DORA module and ISO 27001 module sit on one control set, so evidence collected for an Annex A control counts for the DORA article it answers, and the register of information, incident clocks and contract clauses are tracked beside it.

The bottom line on ISO 27001 vs DORA: the certificate is evidence for DORA, not compliance with it

Frequently asked questions

Is ISO 27001 mandatory under DORA?

No. DORA does not mention ISO 27001 and recital 47 leaves entities free to use ICT risk management models that are differently framed, provided the required capabilities are in place.

Does an ISO 27001 certificate make us DORA compliant?

No. It shows an audited management system over the scope you chose. DORA applies to the whole entity and adds incident reporting, the register of information, contract clauses and a testing programme that the standard does not cover.

Can we use one control set for both?

Yes, and it is the cheaper route. Map each DORA article in Chapter II to the clause or Annex A control that answers it, and add controls for the DORA only duties.

What are the DORA fines?

DORA leaves administrative penalties for financial entities to national law under Article 50, so the amount depends on your Member State. The only figure in the regulation is the periodic penalty payment for critical ICT third party service providers in Article 35(8).

Does DORA care whether our suppliers hold ISO 27001?

Indirectly. Article 28(5) requires providers to comply with appropriate information security standards. A certificate is evidence for that assessment; DORA does not say it is enough.

Primary sources

DORA articles and recitals are quoted from Regulation (EU) 2022/2554; incident deadlines from Delegated Regulation (EU) 2025/301, Article 5; classification from Delegated Regulation (EU) 2024/1772; the ICT risk framework detail from Delegated Regulation (EU) 2024/1774; register templates from Implementing Regulation (EU) 2024/2956. ISO/IEC 27001:2022 clauses 4.3 and 5.1 are from the published preview; Annex A control titles from the ISO/IEC 27002:2022 preview. Where your competent authority has issued its own guidance, it takes precedence over any general mapping.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING