Crosswalks

Compare two standards

The table exposes the left-hand requirements with no counterpart on the right. Those are exactly the ones that fail a cross-standard audit — being ISO 22301 certified does not make you DORA compliant.

Coverage

5 %

1 / 19 requirements with a match

EquivalentPartialInformative
Règlement (UE) 2022/2554 — DORAISO/TS 22318:2021
Art. 4Proportionality principle No match
Art. 5Governance and organisation No match
Art. 6ICT risk management framework No match
Art. 8Identification No match
Art. 9Protection and prevention No match
Art. 10Detection No match
Art. 11Response and recovery No match
Art. 12Backup policies and restoration procedures No match
Art. 13Learning and evolving No match
Art. 14Communication No match
Art. 17ICT-related incident management process No match
Art. 18Classification of incidents and cyber threats No match
Art. 19Reporting of major ICT-related incidents No match
Art. 24General requirements for resilience testing No match
Art. 25Testing of ICT tools and systems No match
Art. 26Threat-led penetration testing (TLPT) No match
Art. 28General principles — ICT third-party risk
  • SCPartial
Art. 29Assessment of concentration risk No match
Art. 30Key contractual provisions No match