Crosswalks

Compare two standards

The table exposes the left-hand requirements with no counterpart on the right. Those are exactly the ones that fail a cross-standard audit — being ISO 22301 certified does not make you DORA compliant.

Coverage

20 %

8 / 41 requirements with a match

EquivalentPartialInformative
ISO 22301:2019Règlement (UE) 2022/2554 — DORA
4Context of the organization No match
4.1Understanding the organization and its context No match
4.2Understanding the needs and expectations of interested parties No match
4.2.2Legal and regulatory requirements
  • Art. 19Reporting of major ICT-related incidentsInformativeDORA notification duties are among the legal requirements to be captured under 4.2.2.
4.3Determining the scope of the BCMS No match
4.4Business continuity management system No match
5Leadership No match
5.1Leadership and commitment
  • Art. 5Governance and organisationPartialDORA goes further: the management body is personally accountable and must be trained annually, which ISO 22301 does not explicitly require.
5.2Business continuity policy No match
5.3Roles, responsibilities and authorities No match
6Planning No match
6.1Actions to address risks and opportunities No match
6.2Business continuity objectives and planning to achieve them No match
6.3Planning of changes to the BCMS No match
7Support No match
7.1Resources No match
7.2Competence No match
7.3Awareness No match
7.4Communication No match
7.5Documented information No match
8Operation No match
8.1Operational planning and control No match
8.2Business impact analysis and risk assessment No match
8.2.2Business impact analysis
  • Art. 8IdentificationPartialArticle 8 requires asset-level mapping tied to functions, whereas the ISO BIA stops at activity level.
8.2.3Risk assessment No match
8.3Business continuity strategies and solutions No match
8.3.4Resource requirements No match
8.4Business continuity plans and procedures
  • Art. 11Response and recoveryEquivalent
8.4.2Response structure
  • Art. 17ICT-related incident management processPartial
8.4.3Warning and communication
  • Art. 14CommunicationEquivalent
8.4.4Business continuity plans No match
8.4.5Recovery No match
8.5Exercise programme
  • Art. 24General requirements for resilience testingPartialDORA mandates a broader testing programme than continuity exercises alone: technical tests, end-to-end tests and, for designated entities, TLPT.
8.6Evaluation of business continuity documentation and capabilities No match
9Performance evaluation No match
9.1Monitoring, measurement, analysis and evaluation No match
9.2Internal audit No match
9.3Management review No match
10Improvement No match
10.1Nonconformity and corrective action
  • Art. 13Learning and evolvingEquivalent
10.2Continual improvement No match