DORAISO/IEC 27001Delta
Governance & ICT risk management framework (Art. 5–6)
Clauses 4 (context), 5.1–5.3 (leadership, policy, roles), 6.1.2/6.1.3 (risk assessment and treatment), 9.2/9.3 (audit, management review), 10 (improvement)
The management body bears ultimate responsibility for ICT risk – including budget allocation and its own training obligation (Art. 5(2)–(4)). In addition, Art. 6(4) requires an independent ICT risk control function, which ISO 27001 does not provide for.
Identification, protection & detection (Art. 8–10)
A.5.9 (asset inventory), A.5.12 (classification), A.5.1 (policies), A.8.8 (vulnerabilities), A.8.15/A.8.16 (logging, monitoring), A.8.20–8.22 (network security), A.8.24 (cryptography)
The RTS in Delegated Regulation (EU) 2024/1774 prescribe, across 42 articles, minimum content far below the altitude of Annex A – for example on cryptographic key management, network segmentation and logging. What ISO 27001 leaves to the organisation is fixed here by regulation.
Response & recovery (Art. 11–12)
A.5.29 (security during disruption), A.5.30 (ICT readiness for business continuity), A.8.13 (backup), A.8.14 (redundancy)
DORA is considerably more granular: a separate backup site, recovery objectives (RTO/RPO) per function and annual testing of business continuity plans are explicitly required.
Incident management & reporting (Art. 17–23)
A.5.24–A.5.28 (incident planning, assessment, response, learning, evidence collection), A.6.8 (reporting by personnel), A.5.5 (contact with authorities)
The non-binding contact with authorities becomes a hard reporting obligation: initial notification within 4 hours of classification as major (at the latest 24 hours after becoming aware), intermediate report within 72 hours of the initial notification, final report within one month of the intermediate report – using mandatory templates, in Germany to BaFin via the MVP portal. The classification thresholds are set out bindingly in Delegated Regulation (EU) 2024/1772.
Resilience testing incl. TLPT (Art. 24–27)
Partial anchors only: A.8.8 (technical vulnerabilities), A.8.29 (security testing in development and acceptance), Clause 9.1 (monitoring, measurement)
ISO 27001 knows no mandatory, broad testing programme: DORA requires at least annual testing of all ICT systems supporting critical or important functions – and, for entities identified by the supervisory authorities, a threat-led penetration test (TLPT) on production systems every three years (Art. 26, RTS (EU) 2025/1190, aligned with the TIBER-EU framework).
ICT third-party risk (Art. 28–44)
A.5.19–A.5.23 (supplier relationships, agreements, ICT supply chain, monitoring, cloud services)
New are the register of information covering all ICT contracts in 15 standard templates (Implementing Regulation (EU) 2024/2956), the binding catalogue of contractual clauses in Art. 30, the assessment of concentration risk before contract conclusion (Art. 29) and the EU oversight of critical ICT third-party service providers.