Case: the institution that "already had everything"
The situation
A 280-person payment institution, ISO/IEC 27001 certified for four years, aligned with EBA/GL/2019/04, with an annually tested continuity plan. The executive committee considers that DORA "does not change much".
The article-by-article gap analysis produces a more nuanced result.
What was already covered
| Article | Status | Existing source |
|---|---|---|
| 9 Protection | Covered | ISO/IEC 27001 Annex A |
| 10 Detection | Covered | Existing monitoring and SOC |
| 12 Backups | Partially | Existing policy, with no immutability requirement |
| 13 Learning | Covered | ISMS improvement process |
| 17 Incident management | Covered | Existing ITIL procedure |
| 24–25 Testing | Partially | Annual technical tests, no formalised programme |
That is roughly 60% of requirements, already met by operational arrangements.
The four real gaps
Article 5 — board accountability. The framework existed but had never been formally approved by the board, and no director had received ICT risk training. Treatment: a resolution and a three-hour training session. Cost: low. Stakes: the first point examined in a review.
Article 8 — function / asset / third-party chain. The asset inventory existed, the process map too, but nothing linked them. Treatment: eight weeks of workshops. The costliest gap in time.
Article 19 — notification deadlines. The incident procedure existed, with no role empowered to classify alone out of hours and no report templates. Treatment: two weeks.
Article 28 — register of information. Non-existent. Procurement held a supplier list with no link to functions, no legal entity identifiers, no sub-outsourcing chain. Treatment: four months, two of them waiting for supplier responses.
What the case generalises
A mature security framework covers DORA's technical requirements well. It almost never covers the three requirements of a different nature: the board's personal governance, the chaining between business and technology, and the contractual inventory of third parties.
None of those can be derived from a prior standard. That is where effort must be concentrated from the outset.
Key takeaways
- A mature ISO 27001 system covers roughly 60% of DORA
- Gaps concentrate on the register, notification deadlines and board accountability
- An article-by-article gap analysis saves six months of pointless work