DORA vs ISO 22301 ICT resilience and business continuity
DORA and ISO 22301 overlap around resilience, disruption response, testing, suppliers, and evidence, but they are not substitutes.
This comparison separates DORA's legal ICT operational resilience obligations for financial entities from ISO 22301's business continuity management system requirements and optional certification.
DORA has applied since 17 January 2025 to the financial entities in its scope. ISO 22301:2019, together with Amendment 1:2024, remains the current published international standard for a business continuity management system (). ISO/CD 22301 is an Edition 3 committee draft under development, not a published replacement. A financial entity can reuse ISO 22301 evidence, but certification does not replace DORA's ICT risk, incident reporting, resilience testing, third-party risk, register, contract, or supervisory requirements.
Side-by-side comparison
DORA vs ISO 22301: practical differences
Use these rows to decide what is a DORA legal obligation, what is ISO 22301 continuity management evidence, and where the same record can support both without blurring the distinction.
Binding EU digital operational resilience regime for covered financial entities, focused on ICT risk, incidents, testing, ICT third-party risk, registers, and supervision.
Second framework
ISO 22301
International business continuity management system standard for organizations that need a documented, maintained, reviewed, and improved continuity capability.
DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.
ISO 22301:2019 targets business continuity management systems. The organization sets and documents the scope after considering its context, interested parties, products, services, activities, and dependencies.
An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.
DORA work includes ICT risk governance, ICT-related incident management and classification, operational resilience testing, ICT third-party risk management, register-of-information maintenance, and management accountability.
ISO 22301 work includes context and scope, leadership, policy, objectives, resources, documented information, business impact analysis and risk assessment, continuity strategies, plans, exercises, internal audit, management review, and improvement.
Map requirements rather than framework headings. A continuity plan can support both, but DORA also needs ICT-specific governance, incident, testing, provider, contract, and register evidence.
ISO 22301 focuses on disruption to products and services through response structures, warning and communication, business continuity plans, recovery, exercises, evaluation, and improvement. It does not define DORA's major ICT-related incident threshold or regulator report.
A major ICT-related incident record should include DORA classification and reporting evidence. The same event may also create ISO 22301 evidence for plan activation, recovery performance, lessons learned, and corrective action.
DORA requires digital operational resilience testing and includes a specific threat-led penetration testing track for financial entities that meet the applicable criteria.
ISO 22301 requires an exercise programme and evaluation of business continuity documentation and capabilities. Exercise objectives, scenarios, reports, outcomes, recommendations, and corrective actions belong in the evidence.
Use ISO 22301 exercises for continuity capability, but do not treat them as DORA TLPT or ICT resilience testing unless the DORA criteria, scope, evidence, and governance are also met.
DORA evidence should show ICT risk decisions, incident classification, testing scope and results, ICT service registers, third-party contract controls, remediation, and management oversight.
ISO 22301 evidence should show the scope, policy, objectives, BIA, risk assessment, continuity strategies, plans, exercises, internal audits, management reviews, and improvement actions.
Build one evidence index with two labels per record: the DORA obligation supported and the ISO 22301 requirement supported. Leave blanks where a record supports only one side.
DORA treats ICT third-party risk as a dedicated obligation, including policies for ICT services supporting critical or important functions and register evidence for ICT service arrangements.
ISO 22301 addresses suppliers through continuity dependencies, interested-party requirements, resources, strategies and solutions, and continuity procedures. It does not create DORA's ICT contract clauses or register fields.
Supplier continuity assessments can be reused, but DORA needs ICT-provider classification, critical or important function linkage, contractual evidence, subcontracting awareness where relevant, and register-ready data.
DORA assurance is supervisory and legal. Covered entities need evidence that can be reviewed through financial-sector governance and supervisory channels.
ISO 22301 requires internal audit and management review. Third-party certification is optional and applies to the stated scope; it does not certify compliance with DORA.
ISO 22301 certification may help demonstrate continuity discipline. Its assurance covers the stated scope, so present separate evidence for each applicable DORA obligation.
Use DORA when the question is whether a financial entity has met ICT operational resilience, incident, testing, ICT third-party, register, or supervisory evidence duties.
Use ISO 22301 when the question is whether the organization has a functioning for disruption preparedness, continuity response, recovery, exercise, audit, review, and improvement.
For every shared control, write the DORA purpose and ISO 22301 purpose separately. If you cannot name both, the control is probably reusable evidence for only one side.
DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.
ISO 22301:2019, with Amendment 1:2024, sets requirements for organizations of any size. Use the edition and amendment named in the organization's scope or certificate, and check transition requirements when ISO publishes the next revision.
An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.
DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.
ISO 22301:2019 targets business continuity management systems. The organization sets and documents the scope after considering its context, interested parties, products, services, activities, and dependencies.
An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.
DORA work includes ICT risk governance, ICT-related incident management and classification, operational resilience testing, ICT third-party risk management, register-of-information maintenance, and management accountability.
ISO 22301 work includes context and scope, leadership, policy, objectives, resources, documented information, business impact analysis and risk assessment, continuity strategies, plans, exercises, internal audit, management review, and improvement.
Map requirements rather than framework headings. A continuity plan can support both, but DORA also needs ICT-specific governance, incident, testing, provider, contract, and register evidence.
ISO 22301 focuses on disruption to products and services through response structures, warning and communication, business continuity plans, recovery, exercises, evaluation, and improvement. It does not define DORA's major ICT-related incident threshold or regulator report.
A major ICT-related incident record should include DORA classification and reporting evidence. The same event may also create ISO 22301 evidence for plan activation, recovery performance, lessons learned, and corrective action.
DORA requires digital operational resilience testing and includes a specific threat-led penetration testing track for financial entities that meet the applicable criteria.
ISO 22301 requires an exercise programme and evaluation of business continuity documentation and capabilities. Exercise objectives, scenarios, reports, outcomes, recommendations, and corrective actions belong in the evidence.
Use ISO 22301 exercises for continuity capability, but do not treat them as DORA TLPT or ICT resilience testing unless the DORA criteria, scope, evidence, and governance are also met.
DORA evidence should show ICT risk decisions, incident classification, testing scope and results, ICT service registers, third-party contract controls, remediation, and management oversight.
ISO 22301 evidence should show the scope, policy, objectives, BIA, risk assessment, continuity strategies, plans, exercises, internal audits, management reviews, and improvement actions.
Build one evidence index with two labels per record: the DORA obligation supported and the ISO 22301 requirement supported. Leave blanks where a record supports only one side.
DORA treats ICT third-party risk as a dedicated obligation, including policies for ICT services supporting critical or important functions and register evidence for ICT service arrangements.
ISO 22301 addresses suppliers through continuity dependencies, interested-party requirements, resources, strategies and solutions, and continuity procedures. It does not create DORA's ICT contract clauses or register fields.
Supplier continuity assessments can be reused, but DORA needs ICT-provider classification, critical or important function linkage, contractual evidence, subcontracting awareness where relevant, and register-ready data.
DORA assurance is supervisory and legal. Covered entities need evidence that can be reviewed through financial-sector governance and supervisory channels.
ISO 22301 requires internal audit and management review. Third-party certification is optional and applies to the stated scope; it does not certify compliance with DORA.
ISO 22301 certification may help demonstrate continuity discipline. Its assurance covers the stated scope, so present separate evidence for each applicable DORA obligation.
Use DORA when the question is whether a financial entity has met ICT operational resilience, incident, testing, ICT third-party, register, or supervisory evidence duties.
Use ISO 22301 when the question is whether the organization has a functioning for disruption preparedness, continuity response, recovery, exercise, audit, review, and improvement.
For every shared control, write the DORA purpose and ISO 22301 purpose separately. If you cannot name both, the control is probably reusable evidence for only one side.
DORA targets digital operational resilience in the financial sector. Its scope is tied to financial entities, ICT risk, ICT-supported functions, major ICT-related incidents, resilience testing, and ICT third-party services.
ISO 22301:2019, with Amendment 1:2024, sets requirements for organizations of any size. Use the edition and amendment named in the organization's scope or certificate, and check transition requirements when ISO publishes the next revision.
An ISO 22301 can support DORA continuity evidence, but it does not decide whether a financial entity is in DORA scope or whether a DORA ICT obligation applies.
If the issue concerns a covered financial entity's ICT risk, ICT incident, ICT provider, register, testing, or supervisory evidence, start with DORA.
If the issue concerns organization-wide continuity capability, business impact analysis, recovery strategy, continuity plans, exercises, internal audit, management review, or continual improvement, start with ISO 22301.
If both apply, reuse facts and evidence but keep separate requirement labels, owners, approvals, and review triggers.
If ISO 22301 certification is being used in a DORA programme, document exactly which DORA controls it supports and which DORA controls still need separate evidence.
Use DORA to determine the legal ICT resilience duties of a covered financial entity. Use ISO 22301 to design and operate a business continuity management system () for disruptive incidents across the scope chosen by the organization.
The strongest overlap is in business impact analysis, continuity and recovery arrangements, exercises, lessons learned, supplier dependencies, management review, and documented evidence. DORA adds financial-sector ICT governance, regulatory reporting, prescribed testing, ICT third-party records, and supervision. ISO 22301 adds a management-system structure for context, leadership, objectives, competence, internal audit, management review, and continual improvement.
Use ISO 22301:2019 together with Amendment 1:2024 for current claims about the published standard. ISO now identifies ISO/CD 22301 as an Edition 3 committee draft that will replace the 2019 edition only after the ISO development and publication process is complete. Do not treat the draft as a certification requirement or as an effective transition date.
Use DORA to decide what the financial entity must do for ICT systems, major ICT-related incidents, resilience testing, ICT third-party providers, and the register of information.
Use ISO 22301:2019 and Amendment 1:2024 to structure the : scope, leadership, planning, support, business impact analysis, continuity strategies, plans, exercises, audits, management review, and improvement.
Reuse continuity evidence only after tagging which DORA obligation and which ISO 22301 requirement it supports.
An ISO 22301 programme does not by itself cover DORA. DORA uses continuity evidence, but it also requires financial entities to govern ICT risk, classify and report major ICT-related incidents, test digital operational resilience, control ICT third-party risk, and keep prescribed ICT service information.
DORA is also not the whole continuity programme. ISO 22301 covers a broader that includes organizational context, interested-party needs, continuity objectives, business impact analysis, continuity strategies and solutions, plans and procedures, exercises, internal audit, management review, and continual improvement.
Do not label a business impact analysis as DORA-complete unless it also maps ICT-supported critical or important functions and DORA evidence needs.
Do not label an ICT incident playbook as ISO 22301-complete unless it also connects to continuity plans, recovery, exercise results, management review, and corrective action.
Do not treat certification, customer questionnaires, or internal audits as a substitute for a DORA supervisory record.
Some records can serve both programmes when they describe service dependencies, recovery needs, exercises, incidents, lessons learned, and management decisions. Reuse works only when the record covers the scope, actor, objective, approval, and result required on each side.
For example, a payment-service recovery exercise can support the ISO 22301 exercise programme and DORA resilience testing. The DORA record must still identify the ICT systems and applications tested, the critical or important functions they support, the weaknesses found, remediation and validation, tester independence, and management accountability. An ordinary continuity exercise is not automatically DORA threat-led penetration testing (TLPT).
Start from the service. Identify the business service, ICT assets, data flows, suppliers, outsourced services, continuity dependencies, impact over time, recovery priorities, and recovery expectations. Then mark which facts create a DORA obligation and which belong in the ISO 22301 .
The output should be a comparison record that is usable by ICT risk, business continuity, security operations, procurement, legal, audit, and accountable management. It should show the source, owner, evidence, review trigger, and unresolved gaps for each side.
For DORA: map ICT-supported business functions, critical or important functions, ICT third-party services, incident classification, testing coverage, register entries, contract obligations, and management approvals.
For ISO 22301: map scope, interested parties, continuity objectives, BIA outputs, continuity strategies, plans, exercises, audit findings, management review, and improvement actions.
For overlap: decide which continuity records can be reused, which need DORA-specific fields, and which cannot be reused because they answer different assurance questions.
Turn this comparison into a DORA and BCMS evidence map
Sorena can help separate DORA ICT operational resilience duties from ISO 22301 continuity evidence, identify reusable records, and flag gaps that need legal, audit, or operational review.