Book an Appointment
Integrated compliance for the financial sector

DORA & ISO 27001 implemented in synergy

An ISMS in accordance with ISO/IEC 27001 is the foundation; you add the DORA deltas as an overlay – with one risk methodology, one control framework and shared evidence. VamiSec supports you from gap analysis to integrated operations.

17 Jan 2025DORA (Regulation (EU) 2022/2554) directly applicable
5 pillarsfrom ICT risk management to information sharing (Art. 5–45)
93 controlsISO 27001:2022 Annex A as the foundation for the DORA overlay

Two frameworks, one management system

With DORA (Regulation (EU) 2022/2554), a directly applicable legal framework for digital operational resilience in the financial sector has been in force since 17 January 2025 – covering banks, insurers and investment firms as well as payment institutions and crypto-asset service providers. The regulation bundles its requirements into five pillars: ICT risk management (Art. 5–16), incident management and reporting (Art. 17–23), resilience testing (Art. 24–27), ICT third-party risk (Art. 28–44) and information sharing (Art. 45). Supplementary regulatory and implementing technical standards specify the obligations down to the operational level.

The good news: the European Supervisory Authorities (ESAs) explicitly developed the technical standards with the ISO 27000 family in mind and use its terminology. An ISMS in accordance with ISO/IEC 27001:2022 thus provides the governance, risk methodology, control framework and audit cycle on which the DORA implementation builds. Running both frameworks in parallel produces duplicate policies, duplicate risk assessments and duplicate audits. Implemented in an integrated way, a single management system remains – and you add the DORA-specific requirements as an overlay.

The mapping: DORA building blocks anchored in ISO 27001

The overview shows our mapping of the DORA building blocks to ISO/IEC 27001:2022 at control level – and what DORA requires beyond it.

Governance & ICT risk management framework (Art. 5–6)
Clauses 4 (context), 5.1–5.3 (leadership, policy, roles), 6.1.2/6.1.3 (risk assessment and treatment), 9.2/9.3 (audit, management review), 10 (improvement)
The management body bears ultimate responsibility for ICT risk – including budget allocation and its own training obligation (Art. 5(2)–(4)). In addition, Art. 6(4) requires an independent ICT risk control function, which ISO 27001 does not provide for.
Identification, protection & detection (Art. 8–10)
A.5.9 (asset inventory), A.5.12 (classification), A.5.1 (policies), A.8.8 (vulnerabilities), A.8.15/A.8.16 (logging, monitoring), A.8.20–8.22 (network security), A.8.24 (cryptography)
The RTS in Delegated Regulation (EU) 2024/1774 prescribe, across 42 articles, minimum content far below the altitude of Annex A – for example on cryptographic key management, network segmentation and logging. What ISO 27001 leaves to the organisation is fixed here by regulation.
Response & recovery (Art. 11–12)
A.5.29 (security during disruption), A.5.30 (ICT readiness for business continuity), A.8.13 (backup), A.8.14 (redundancy)
DORA is considerably more granular: a separate backup site, recovery objectives (RTO/RPO) per function and annual testing of business continuity plans are explicitly required.
Incident management & reporting (Art. 17–23)
A.5.24–A.5.28 (incident planning, assessment, response, learning, evidence collection), A.6.8 (reporting by personnel), A.5.5 (contact with authorities)
The non-binding contact with authorities becomes a hard reporting obligation: initial notification within 4 hours of classification as major (at the latest 24 hours after becoming aware), intermediate report within 72 hours of the initial notification, final report within one month of the intermediate report – using mandatory templates, in Germany to BaFin via the MVP portal. The classification thresholds are set out bindingly in Delegated Regulation (EU) 2024/1772.
Resilience testing incl. TLPT (Art. 24–27)
Partial anchors only: A.8.8 (technical vulnerabilities), A.8.29 (security testing in development and acceptance), Clause 9.1 (monitoring, measurement)
ISO 27001 knows no mandatory, broad testing programme: DORA requires at least annual testing of all ICT systems supporting critical or important functions – and, for entities identified by the supervisory authorities, a threat-led penetration test (TLPT) on production systems every three years (Art. 26, RTS (EU) 2025/1190, aligned with the TIBER-EU framework).
ICT third-party risk (Art. 28–44)
A.5.19–A.5.23 (supplier relationships, agreements, ICT supply chain, monitoring, cloud services)
New are the register of information covering all ICT contracts in 15 standard templates (Implementing Regulation (EU) 2024/2956), the binding catalogue of contractual clauses in Art. 30, the assessment of concentration risk before contract conclusion (Art. 29) and the EU oversight of critical ICT third-party service providers.

Integrated instead of parallel: your synergies

Six reasons to build DORA on top of your ISMS instead of alongside it.

01

Compatible by design

By their own account, the ESAs took the ISO 27000 family into account when drafting the technical standards on ICT risk management and deliberately use its terminology. Anyone operating an ISMS in accordance with ISO 27001 is already working within DORA's conceptual and control logic.

02

One risk methodology

The risk assessment under Clauses 6.1.2/6.1.3 is extended to cover ICT-supported functions, assets and dependencies under Art. 6 and 8. You assess once – and serve both frameworks.

03

One document control

Policies, the SoA and records remain within a single controlled document set. DORA-specific documents such as the digital operational resilience strategy or the register of information follow the same document control – instead of ageing in a parallel repository.

04

One control framework

The 93 controls of Annex A form the basis; DORA and RTS requirements are mapped as an overlay onto existing controls. Every measure is implemented only once and operated only once.

05

Shared audits & evidence

Internal audits under Clause 9.2 and the management review under Clause 9.3 cover both frameworks in a single cycle. Every piece of evidence serves multiple assurance contexts – from the certification audit to supervisory requests.

06

Focus on the real deltas

Instead of building DORA on a greenfield, you concentrate budget and team on what ISO 27001 does not cover: reporting deadlines and formats, the register of information, the testing programme and TLPT, contractual clauses and management body accountability.

Your path to integrated implementation

Five steps from gap analysis to integrated operations.

01

Scope and gap analysis

We check your ISMS scope against the scope of DORA – a certified ISMS with a limited scope does not automatically cover DORA for the entire financial entity. We then determine your deltas against Art. 5–45 and the relevant RTS and ITS.

02

Mapping and SoA extension

The DORA and RTS requirements are mapped onto your Annex A controls, the Statement of Applicability is extended and the overlay controls are defined. The result is a single control framework for both regimes.

03

Implementing the deltas as an overlay

We add what DORA additionally requires: reporting processes with deadlines and mandatory templates, the register of information, contract adjustments under Art. 30, the assessment of concentration risk, the independent ICT risk control function and training for the management body.

04

Testing and demonstrating

You establish a testing programme for all ICT systems supporting critical or important functions and assess your TLPT readiness. The internal audit and the management review are extended to include the DORA perspective – one audit cycle, two regimes.

05

Operating in an integrated way

In operations, the cycles interlock: annual review of the ICT risk management framework under Art. 6, maintenance of the register of information, lessons learned from incidents under Art. 13. Findings feed into the improvement process under Clause 10 – for ISO and DORA alike.

VamiGRC: one platform for both regimes

VamiSec's AI-native, agentic GRC platform operationalises the integrated implementation.

VamiGRC models DORA and ISO 27001:2022 together in an OSCAL-based framework engine – alongside a total of 22 tier-1 regulations and more than 50 standards and frameworks. The five-stage applicability pipeline leads from regulatory drivers via scope and mapping through to evidence and the SoA; 63% of controls are reused across three or more frameworks – implement once, comply many times. Risks, controls, evidence and suppliers live in a queryable GRC graph instead of separate silos. The platform runs on the Open Telekom Cloud – exclusively in German data centres.

Multi-framework mapping

The OSCAL-based engine maps requirements across frameworks and automates cross-mapping – the basis for your DORA overlay on the ISO control framework.

Evidence with an audit trail

The IMS Repository controls documents in 12 canonical categories – from policies via the SoA to audits. Every action is recorded in an immutable audit log; evidence is cryptographically chained.

Consolidated risk view

A Risk Dashboard unifies all risks in a 5×5 heatmap (inherent/residual) with monetised exposure per business unit and FAIR-based Monte Carlo modelling.

Reporting deadlines in view

Incident Management runs regulatory deadline clocks, including for DORA, detects reporting obligations automatically and ships with more than 15 playbook templates.

Third parties under control

The Third-Party Risk module derives criticality automatically from processes and data and monitors suppliers continuously; the Supplier Contract Wizard maps more than 220 master clauses to controls.

Frequently asked questions

Answers to the questions we are asked most often about DORA and ISO 27001.

Does ISO 27001 certification replace DORA compliance?

No. DORA is a directly applicable EU regulation; there is no official recognition of ISO 27001 certification as proof of DORA compliance. However, the ESAs explicitly developed the technical standards with the ISO 27000 family in mind – your ISMS therefore carries the load as the foundation, while you must additionally implement deltas such as reporting deadlines, the register of information or TLPT.

Who does DORA apply to – and since when?

DORA (Regulation (EU) 2022/2554) has been directly applicable since 17 January 2025. It applies to financial entities such as banks, insurers, investment firms, payment and e-money institutions as well as crypto-asset service providers. The requirements are structured in five pillars: ICT risk management, incident management and reporting, resilience testing, ICT third-party risk and information sharing.

Which reporting deadlines apply to major ICT-related incidents?

Delegated Regulation (EU) 2025/301 stipulates: initial notification within 4 hours of classification as major, at the latest 24 hours after becoming aware; intermediate report within 72 hours of submitting the initial notification; final report within one month of the (most recently updated) intermediate report. Implementing Regulation (EU) 2025/302 prescribes the standard forms. In Germany, you report to BaFin via the MVP portal.

What is TLPT – and does it affect us?

Under Art. 26, financial entities identified by the supervisory authorities must carry out a threat-led penetration test (TLPT) on live production systems supporting critical or important functions at least every three years. The corresponding RTS (Delegated Regulation (EU) 2025/1190) are aligned with the TIBER-EU framework and govern scope, methodology and requirements for testers. Whether your institution is identified is decided by the supervisor on a case-by-case basis – an early readiness assessment is therefore advisable.

What does DORA require for ICT service providers beyond ISO 27001?

A register of information covering all contractual arrangements with ICT third-party service providers in 15 standard templates (Implementing Regulation (EU) 2024/2956), the binding catalogue of contractual clauses in Art. 30, an assessment of concentration risk before contract conclusion (Art. 29) and exit strategies for critical functions. Added to this is the EU oversight of critical ICT third-party service providers: in November 2025 the ESAs designated the first 19 providers, including AWS, Microsoft and Google Cloud – a status you must take into account in your third-party risk management.

Are there simplifications for smaller institutions?

Yes. Art. 4 enshrines the principle of proportionality according to size, risk profile and complexity; Art. 16 defines a simplified ICT risk management framework for certain small institutions, specified by the RTS (EU) 2024/1774 and a BaFin supervisory notice of 21 August 2025. Unlike with an ISMS, however, the scope cannot be tailored freely – DORA sets regulatory minimum requirements.

Ready for the integrated implementation?

Talk to our team about your DORA status and your ISMS – we will show you where your synergies lie and which deltas really drive effort.