DORA vs ISO 28000
DORA
EU regulation for digital operational resilience in financial sector
ISO 28000
International standard for supply chain security management systems.
Quick Verdict
DORA mandates digital resilience for EU finance against ICT risks via testing and reporting, while ISO 28000 offers voluntary supply chain security frameworks globally. Firms adopt DORA for regulatory compliance; ISO 28000 for resilience, certification, and market advantage.
DORA
Regulation (EU) 2022/2554
ISO 28000
ISO 28000:2022 Security management systems Requirements
Key Features
- Risk-based supply chain security assessment and treatment
- PDCA cycle for continual SMS improvement
- Supplier and third-party security governance
- Integration with ISO 22301 and 27001 standards
- Incident response and recovery planning
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
DORA Details
What It Is
Digital Operational Resilience Act (DORA), formally Regulation (EU) 2022/2554, is a transformative EU regulation. It mandates digital operational resilience for the financial sector against ICT disruptions like cyberattacks and third-party failures. Applicable to 20 financial entity types and critical ICT third-party providers (CTPPs) across 27 member states, it uses a risk-based, proportional approach focusing on proactive strategies over reactive measures.
Key Components
Core pillars include ICT risk management frameworks for identifying and mitigating risks; standardized incident reporting with 4-hour notifications; resilience testing via annual scans and triennial threat-led penetration testing (TLPT); and third-party oversight with due diligence and ESAs supervision of CTPPs. Proportionality tailors requirements to entity size and risk profile, with no formal certification but strict compliance enforcement.
Why Organizations Use It
Financial entities comply to meet legal obligations enforced since the January 2025 deadline, avoiding fines up to 2% of global turnover. It mitigates systemic cyber risks (74% perceive as top threat), enhances resilience post-incidents like CrowdStrike outage, builds stakeholder trust, and drives cybersecurity innovation amid €10-15B EU spend.
Implementation Overview
Involves gap analyses against RTS/ITS, framework development, testing programs, and vendor monitoring. Targets ~22,000 entities; larger firms leverage existing setups, SMEs face challenges. Ongoing ESAs oversight with Batch 1/2 standards guides compliance following the 2025 rollout.
ISO 28000 Details
What It Is
ISO 28000:2022 is an international management system standard specifying requirements for establishing, implementing, maintaining, and improving a security management system (SMS) focused on supply chain security and resilience. It adopts a risk-based approach using the PDCA cycle, aligned with ISO High Level Structure.
Key Components
- Clauses cover context, leadership, planning, support, operation, performance evaluation, and improvement.
- Emphasizes risk assessment, security strategies, incident response, supplier controls, and continual improvement.
- Built on ISO 31000 risk principles and integrates with ISO 22301, ISO 27001.
- Optional third-party certification via accredited bodies per ISO 28003.
Why Organizations Use It
- Mitigates supply chain risks like theft, sabotage, disruptions.
- Meets contractual, regulatory, trade facilitation needs.
- Reduces incidents, insurance costs; enhances market access, reputation.
- Builds stakeholder trust through auditable governance.
Implementation Overview
- Phased: scoping, gap analysis, risk assessment, controls deployment, audits, certification.
- Scalable for all sizes/industries (logistics, manufacturing, pharma).
- Global applicability; involves training, supplier engagement, KPIs monitoring.
Key Differences
| Aspect | DORA | ISO 28000 |
|---|---|---|
| Scope | Digital operational resilience in finance | Supply chain security management systems |
| Industry | EU financial entities and ICT providers | All industries worldwide, supply chain focused |
| Nature | Mandatory EU regulation with enforcement | Voluntary international certification standard |
| Testing | Annual basic tests, triennial TLPT | Internal audits, management reviews, certification audits |
| Penalties | Up to 2% global turnover fines | Loss of certification, no legal penalties |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about DORA and ISO 28000
DORA FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

Top 5 Reasons NIST SP 800-53 Rev 5 Overlays Unlock AI Risk Management for Private Sector Enterprises in 2025
Top 5 reasons NIST SP 800-53 Rev 5 AI overlays unlock risk management for private enterprises. Tailorable controls combat model poisoning & data leakage. CISO i

Thailand PDPA Enforcement Trends 2025: Analyzing 1,048 Complaints, Breach Volumes, and Hidden Lessons for Proactive Compliance
Decode PDPC Thailand's 1,048 complaints & 610 breaches. Uncover consent/security violations, project 2025 enforcement. Risk heatmap, self-assessment & playbook

NIST CSF 2.0 Plain English Decoder: Translating Govern, Supply Chain, and Core Functions from Jargon to Actionable Insights
Demystify NIST CSF 2.0 jargon with plain English tables for Govern, Supply Chain & Core Functions. Actionable steps for risk oversight & vendor management. Empo
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how DORA and ISO 28000 compare against other standards