Comparison
DORA vs ISO 27001 — regulation or management system?
Published Reviewed
DORA is binding sector law. ISO 27001 is a certifiable management-system standard. They overlap in control practice, not legal status.
Side by side
Dimension DORA ISO 27001
Who decides scope The regulation and financial-sector classification. The organisation defines an ISMS scope that an accredited body audits.
Third parties Detailed ICT register, clauses, concentration and oversight. Supplier controls selected through risk treatment and the Statement of Applicability.
Incidents Regulatory classification and reporting duties. Management and improvement process; no regulator report clock by itself.
Outcome Supervisory compliance. A certificate over the defined ISMS scope.
How they combine
Use an ISO 27001 ISMS as part of the operating system behind DORA. The certificate is useful evidence, but supervisors still expect DORA-specific governance, registers, reporting, testing, and contracts.
A quick self-check
Are you ready?
- Does the ISMS scope cover every DORA-critical function?
- Are DORA-specific duties mapped beyond Annex A controls?
- Can regulatory evidence be produced independently of the certificate?