Comparison GuideEU

DORA vs ISO 22301 ICT resilience and business continuity

DORA and ISO 22301 overlap around resilience, disruption response, testing, suppliers, and evidence, but they are not substitutes.

This comparison separates DORA's legal ICT operational resilience obligations for financial entities from ISO 22301's business continuity management system requirements and optional certification.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

DORA has applied since 17 January 2025 to the financial entities in its scope. ISO 22301:2019, together with Amendment 1:2024, remains the current published international standard for a business continuity management system (). ISO/CD 22301 is an Edition 3 committee draft under development, not a published replacement. A financial entity can reuse ISO 22301 evidence, but certification does not replace DORA's ICT risk, incident reporting, resilience testing, third-party risk, register, contract, or supervisory requirements.

Side-by-side comparison

DORA vs ISO 22301: practical differences

Use these rows to decide what is a DORA legal obligation, what is ISO 22301 continuity management evidence, and where the same record can support both without blurring the distinction.

Review all sources
First framework
DORA

Binding EU digital operational resilience regime for covered financial entities, focused on ICT risk, incidents, testing, ICT third-party risk, registers, and supervision.

Second framework
ISO 22301

International business continuity management system standard for organizations that need a documented, maintained, reviewed, and improved continuity capability.

Comparison row 1

Scope boundary

DORA

DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.

ISO 22301

ISO 22301:2019 targets business continuity management systems. The organization sets and documents the scope after considering its context, interested parties, products, services, activities, and dependencies.

Operational implication

An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.

Comparison row 2

Covered actors

DORA

DORA work includes ICT risk governance, ICT-related incident management and classification, operational resilience testing, ICT third-party risk management, register-of-information maintenance, and management accountability.

ISO 22301

ISO 22301 work includes context and scope, leadership, policy, objectives, resources, documented information, business impact analysis and risk assessment, continuity strategies, plans, exercises, internal audit, management review, and improvement.

Operational implication

Map requirements rather than framework headings. A continuity plan can support both, but DORA also needs ICT-specific governance, incident, testing, provider, contract, and register evidence.

Comparison row 3

Trigger

DORA

DORA focuses on ICT-related incidents, including classification of major incidents and cyber threats under DORA technical standards.

ISO 22301

ISO 22301 focuses on disruption to products and services through response structures, warning and communication, business continuity plans, recovery, exercises, evaluation, and improvement. It does not define DORA's major ICT-related incident threshold or regulator report.

Operational implication

A major ICT-related incident record should include DORA classification and reporting evidence. The same event may also create ISO 22301 evidence for plan activation, recovery performance, lessons learned, and corrective action.

Comparison row 4

Core obligations

DORA

DORA requires digital operational resilience testing and includes a specific threat-led penetration testing track for financial entities that meet the applicable criteria.

ISO 22301

ISO 22301 requires an exercise programme and evaluation of business continuity documentation and capabilities. Exercise objectives, scenarios, reports, outcomes, recommendations, and corrective actions belong in the evidence.

Operational implication

Use ISO 22301 exercises for continuity capability, but do not treat them as DORA TLPT or ICT resilience testing unless the DORA criteria, scope, evidence, and governance are also met.

Comparison row 5

Evidence record

DORA

DORA evidence should show ICT risk decisions, incident classification, testing scope and results, ICT service registers, third-party contract controls, remediation, and management oversight.

ISO 22301

ISO 22301 evidence should show the scope, policy, objectives, BIA, risk assessment, continuity strategies, plans, exercises, internal audits, management reviews, and improvement actions.

Operational implication

Build one evidence index with two labels per record: the DORA obligation supported and the ISO 22301 requirement supported. Leave blanks where a record supports only one side.

Comparison row 6

Supplier and third-party risk

DORA

DORA treats ICT third-party risk as a dedicated obligation, including policies for ICT services supporting critical or important functions and register evidence for ICT service arrangements.

ISO 22301

ISO 22301 addresses suppliers through continuity dependencies, interested-party requirements, resources, strategies and solutions, and continuity procedures. It does not create DORA's ICT contract clauses or register fields.

Operational implication

Supplier continuity assessments can be reused, but DORA needs ICT-provider classification, critical or important function linkage, contractual evidence, subcontracting awareness where relevant, and register-ready data.

Comparison row 7

Enforcement

DORA

DORA assurance is supervisory and legal. Covered entities need evidence that can be reviewed through financial-sector governance and supervisory channels.

ISO 22301

ISO 22301 requires internal audit and management review. Third-party certification is optional and applies to the stated scope; it does not certify compliance with DORA.

Operational implication

ISO 22301 certification may help demonstrate continuity discipline. Its assurance covers the stated scope, so present separate evidence for each applicable DORA obligation.

Comparison row 8

Overlap and reuse

DORA

Use DORA when the question is whether a financial entity has met ICT operational resilience, incident, testing, ICT third-party, register, or supervisory evidence duties.

ISO 22301

Use ISO 22301 when the question is whether the organization has a functioning for disruption preparedness, continuity response, recovery, exercise, audit, review, and improvement.

Operational implication

For every shared control, write the DORA purpose and ISO 22301 purpose separately. If you cannot name both, the control is probably reusable evidence for only one side.

Comparison row 9

Practical decision rule

DORA

DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.

ISO 22301

ISO 22301:2019, with Amendment 1:2024, sets requirements for organizations of any size. Use the edition and amendment named in the organization's scope or certificate, and check transition requirements when ISO publishes the next revision.

Operational implication

An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.

Practical decision rule

How should teams decide what to implement?

  • If the issue concerns a covered financial entity's ICT risk, ICT incident, ICT provider, register, testing, or supervisory evidence, start with DORA.
  • If the issue concerns organization-wide continuity capability, business impact analysis, recovery strategy, continuity plans, exercises, internal audit, management review, or continual improvement, start with ISO 22301.
  • If both apply, reuse facts and evidence but keep separate requirement labels, owners, approvals, and review triggers.
  • If ISO 22301 certification is being used in a DORA programme, document exactly which DORA controls it supports and which DORA controls still need separate evidence.
Section 1

The practical takeaway

Use DORA to determine the legal ICT resilience duties of a covered financial entity. Use ISO 22301 to design and operate a business continuity management system () for disruptive incidents across the scope chosen by the organization.

The strongest overlap is in business impact analysis, continuity and recovery arrangements, exercises, lessons learned, supplier dependencies, management review, and documented evidence. DORA adds financial-sector ICT governance, regulatory reporting, prescribed testing, ICT third-party records, and supervision. ISO 22301 adds a management-system structure for context, leadership, objectives, competence, internal audit, management review, and continual improvement.

Use ISO 22301:2019 together with Amendment 1:2024 for current claims about the published standard. ISO now identifies ISO/CD 22301 as an Edition 3 committee draft that will replace the 2019 edition only after the ISO development and publication process is complete. Do not treat the draft as a certification requirement or as an effective transition date.

  • Use DORA to decide what the financial entity must do for ICT systems, major ICT-related incidents, resilience testing, ICT third-party providers, and the register of information.
  • Use ISO 22301:2019 and Amendment 1:2024 to structure the : scope, leadership, planning, support, business impact analysis, continuity strategies, plans, exercises, audits, management review, and improvement.
  • Reuse continuity evidence only after tagging which DORA obligation and which ISO 22301 requirement it supports.
Section 2

Where teams usually confuse the two

An ISO 22301 programme does not by itself cover DORA. DORA uses continuity evidence, but it also requires financial entities to govern ICT risk, classify and report major ICT-related incidents, test digital operational resilience, control ICT third-party risk, and keep prescribed ICT service information.

DORA is also not the whole continuity programme. ISO 22301 covers a broader that includes organizational context, interested-party needs, continuity objectives, business impact analysis, continuity strategies and solutions, plans and procedures, exercises, internal audit, management review, and continual improvement.

  • Do not label a business impact analysis as DORA-complete unless it also maps ICT-supported critical or important functions and DORA evidence needs.
  • Do not label an ICT incident playbook as ISO 22301-complete unless it also connects to continuity plans, recovery, exercise results, management review, and corrective action.
  • Do not treat certification, customer questionnaires, or internal audits as a substitute for a DORA supervisory record.
Section 3

Evidence that can be reused

Some records can serve both programmes when they describe service dependencies, recovery needs, exercises, incidents, lessons learned, and management decisions. Reuse works only when the record covers the scope, actor, objective, approval, and result required on each side.

For example, a payment-service recovery exercise can support the ISO 22301 exercise programme and DORA resilience testing. The DORA record must still identify the ICT systems and applications tested, the critical or important functions they support, the weaknesses found, remediation and validation, tester independence, and management accountability. An ordinary continuity exercise is not automatically DORA threat-led penetration testing (TLPT).

  • Reusable records: business impact analyses, recovery objectives, continuity strategies, exercise reports, incident lessons learned, management review minutes, supplier continuity assessments, and corrective-action logs.
  • DORA-specific records: ICT risk management policies, major ICT-related incident classification records, register-of-information templates, ICT provider contract evidence, TLPT scoping where applicable, and supervisory communications.
  • ISO 22301-specific records: scope, continuity policy, continuity objectives, competence and awareness records, documented-information controls, internal audit programme, and management review outputs.
Section 4

How to run the comparison in practice

Start from the service. Identify the business service, ICT assets, data flows, suppliers, outsourced services, continuity dependencies, impact over time, recovery priorities, and recovery expectations. Then mark which facts create a DORA obligation and which belong in the ISO 22301 .

The output should be a comparison record that is usable by ICT risk, business continuity, security operations, procurement, legal, audit, and accountable management. It should show the source, owner, evidence, review trigger, and unresolved gaps for each side.

  • For DORA: map ICT-supported business functions, critical or important functions, ICT third-party services, incident classification, testing coverage, register entries, contract obligations, and management approvals.
  • For ISO 22301: map scope, interested parties, continuity objectives, BIA outputs, continuity strategies, plans, exercises, audit findings, management review, and improvement actions.
  • For overlap: decide which continuity records can be reused, which need DORA-specific fields, and which cannot be reused because they answer different assurance questions.
Recommended next step

Turn this comparison into a DORA and BCMS evidence map

Sorena can help separate DORA ICT operational resilience duties from ISO 22301 continuity evidence, identify reusable records, and flag gaps that need legal, audit, or operational review.

Primary sources

References and citations

iso.org
Referenced sections
  • Current ISO source showing that the proposed Edition 3 replacement is a committee draft under development, not the published standard.
eur-lex.europa.eu
Referenced sections
  • Primary source for DORA's ICT operational resilience obligations.
"digital operational resilience"
Related guides

Explore more topics

DORA Critical or Important Functions: mapping ICT dependencies and evidence
How DORA critical or important functions affect ICT service mapping, third-party contracts, register-of-information records, incidents, testing, and evidence.
DORA deadlines and compliance calendar for financial entities
Track DORA dates and recurring evidence: 17 January 2025 application, incident reporting clocks, register updates, annual reporting, TLPT cadence, and critical-provider oversight milestones.
DORA ICT Third-Party Contract Remediation Workflow
A DORA workflow for remediating ICT third-party contracts covering critical or important functions, subcontracting, audit rights, exits, register updates, and evidence.
DORA ICT Third-Party Contracts FAQ
What DORA requires in ICT third-party contracts, including critical or important functions, audit and access rights, termination, exit, subcontracting, register updates, and evidence.
DORA ICT third-party risk and contract clauses guide
Official source DORA guide for financial entities in scope, ICT third-party risk, contract clauses, subcontracting controls, register evidence, audit rights, exit planning, and oversight.
DORA incident classification forms: criteria, fields, and reporting clocks
Official source guide to DORA ICT incident classification forms: major-incident criteria, significant cyber-threat notifications, report fields, time limits, evidence, and reclassification records.
DORA incident clock workflow: classification, reports, deadlines, and evidence
Official source DORA workflow for starting the major-incident reporting clock, classifying ICT incidents, submitting initial, intermediate, and final reports, and preserving authority evidence.
DORA major ICT incident reporting: classification, reports, and timing
Official source DORA guide to major ICT-related incident classification, initial notifications, intermediate and final reports, competent authority routing, and significant cyber threat notifications.
DORA major ICT incident thresholds: what triggers reporting?
FAQ on DORA major ICT-related incident classification thresholds, recurring incidents, reporting triggers, and evidence inputs based on EU DORA RTS and ITS texts.
DORA Register of Information FAQ: ICT Third-Party Arrangements
FAQ on the DORA register of information: who maintains it, which ICT third-party arrangements it covers, template fields, critical functions, reporting, data quality, and evidence.
DORA Register of Information Import and Build Workflow
Build a DORA register of information from procurement, vendor, contract, service, function, and subcontractor data using the official register templates and validation checks.
DORA Register of Information Template: ICT Provider Fields and Evidence
An official source DORA register of information template for ICT third-party contracts, provider hierarchy, critical functions, dates, statuses, reporting, and evidence.
DORA TLPT selection: who can be required to test?
FAQ on DORA threat-led penetration testing selection: who identifies financial entities, what criteria are used, what the TLPT authority validates, and what evidence to keep.
DORA vs EBA outsourcing guidelines: ICT third-party risk comparison
Compare binding DORA ICT third-party risk duties with the EBA/ESA outsourcing baseline for registers, critical functions, contracts, subcontracting, exit, incident reporting, and evidence.
DORA vs ISO/IEC 27001: legal ICT resilience obligations and ISMS controls
Compare EU DORA and ISO/IEC 27001 across scope, governance, incident reporting, testing, ICT third-party risk, certification, evidence, overlap, and gaps.
DORA vs NIS2: financial-sector obligations, overlap, and evidence
Compare DORA and NIS2 for financial entities, ICT providers, incident reporting, management accountability, third-party risk, supervisory routes, and reusable evidence.
DORA vs PSD2 incident reporting: major ICT and payment incidents
Compare DORA major ICT-related incident reporting with PSD2 major operational or security payment incident reporting, including scope, triggers, report stages, recipients, and evidence.
EU DORA Applicability Test for Financial Entities and ICT Providers
An official source DORA applicability test for financial-entity scope, ICT third-party services, critical or important functions, exclusions, proportionality, and evidence.
EU DORA Compliance Checklist for Financial Entities
An official source DORA checklist covering ICT risk governance, major incident reporting, resilience testing, TLPT, ICT third-party contracts, register-of-information records, and audit evidence.
EU DORA Compliance Obligations and Evidence Guide
An official source DORA compliance guide covering ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, registers, governance, oversight, and evidence.
EU DORA FAQ: scope, incidents, ICT contracts, testing, and evidence
Concise DORA FAQ covering who is in scope, proportionality, ICT third-party contracts, register-of-information records, major ICT incident thresholds and reporting, TLPT, testing, enforcement, and evidence.
EU DORA ICT risk management control baseline
An official source DORA control baseline for ICT risk governance, asset and dependency mapping, protection, detection, response, recovery, testing, third-party risk, and evidence.
EU DORA ICT subcontracting chain controls for critical functions
DORA guide to ICT subcontracting chains for critical or important functions: prior assessment, contract conditions, register fields, monitoring, exit rights, and evidence.
EU DORA penalties and fines: enforcement powers and limits
Official source guide to DORA enforcement: competent-authority powers, administrative penalties, remedial measures, publication rules, and Lead Overseer penalty payments for critical ICT third-party providers.
EU DORA Register of Information Data Model: templates, fields, and evidence
Field-level guide to the EU DORA register of information data model: templates B_01 to B_07, provider identifiers, contract links, subcontracting chains, critical-function assessments, dates, and export evidence.
EU DORA Requirements Overview: ICT risk, incidents, testing, and third-party risk
An official source overview of the main EU DORA requirements for financial entities: governance, ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, register of information, oversight, proportionality, and evidence.
EU DORA Scope and Covered Entities: financial entities and ICT providers
Classify whether DORA applies to a financial entity, ICT third-party provider, group arrangement, branch, or critical ICT service dependency.
EU DORA Scope and Proportionality Workflow
Classify DORA covered entities, simplified-framework status, critical or important functions, ICT dependencies, evidence records, and governance approvals.
EU DORA testing and TLPT readiness guide
An official source DORA guide for resilience testing, TLPT eligibility, authority interaction, test evidence, remediation plans, and avoiding unsupported testing cadence.
EU DORA TLPT eligibility workflow for financial entities
Check how DORA TLPT authorities identify financial entities for threat-led penetration testing and what evidence supports scope, readiness, providers, and governance.
EU DORA TLPT Runbook: scope, providers, reports, and remediation
Build a DORA threat-led penetration testing runbook around authority coordination, scope validation, provider controls, active testing, closure reports, remediation, and attestation.
How does proportionality work under EU DORA?
An official source FAQ on DORA proportionality: what can be scaled, who may use the simplified ICT risk framework, what evidence supports the decision, and which duties cannot be waived.
How to build a DORA register of information
Build a DORA register of information from contracts, ICT services, providers, functions, subcontractors, risk assessments, audit evidence, exit plans, and export checks.