Crosswalks

Compare two standards

The table exposes the left-hand requirements with no counterpart on the right. Those are exactly the ones that fail a cross-standard audit — being ISO 22301 certified does not make you DORA compliant.

Coverage

42 %

8 / 19 requirements with a match

EquivalentPartialInformative
Règlement (UE) 2022/2554 — DORAISO 22301:2019
Art. 4Proportionality principle No match
Art. 5Governance and organisation
  • 5.1Leadership and commitmentPartialDORA goes further: the management body is personally accountable and must be trained annually, which ISO 22301 does not explicitly require.
Art. 6ICT risk management framework No match
Art. 8Identification
  • 8.2.2Business impact analysisPartialArticle 8 requires asset-level mapping tied to functions, whereas the ISO BIA stops at activity level.
Art. 9Protection and prevention No match
Art. 10Detection No match
Art. 11Response and recovery
  • 8.4Business continuity plans and proceduresEquivalent
Art. 12Backup policies and restoration procedures No match
Art. 13Learning and evolving
  • 10.1Nonconformity and corrective actionEquivalent
Art. 14Communication
  • 8.4.3Warning and communicationEquivalent
Art. 17ICT-related incident management process
  • 8.4.2Response structurePartial
Art. 18Classification of incidents and cyber threats No match
Art. 19Reporting of major ICT-related incidents
  • 4.2.2Legal and regulatory requirementsInformativeDORA notification duties are among the legal requirements to be captured under 4.2.2.
Art. 24General requirements for resilience testing
  • 8.5Exercise programmePartialDORA mandates a broader testing programme than continuity exercises alone: technical tests, end-to-end tests and, for designated entities, TLPT.
Art. 25Testing of ICT tools and systems No match
Art. 26Threat-led penetration testing (TLPT) No match
Art. 28General principles — ICT third-party risk No match
Art. 29Assessment of concentration risk No match
Art. 30Key contractual provisions No match