Financial entities that run a business continuity management system (BCMS) built on ISO 22301:2019 hold one of the strongest starting positions for the Digital Operational Resilience Act (DORA). Continuity is where DORA is at its most prescriptive: the ICT business continuity policy, the response and recovery plans, the yearly test and the crisis management function all sit in Article 11. This guide maps DORA to ISO 22301 clause by clause, marks precisely where the standard stops, and gives the sequence that closes the gap fastest.

It is the continuity twin of our ISO 27001 to DORA mapping guide: the same method, applied to the BCMS instead of the information security management system.

Same discipline, different perimeter

ISO 22301 is a voluntary, certifiable requirements standard covering the continuity of the whole organisation. DORA is binding EU regulation, enforced by your competent authority, and it cuts the scope differently: what it protects is the continuity of ICT services supporting critical or important functions. The engine is the same in both: impact analysis, strategies, documented plans, an exercise programme and management review. What changes is the perimeter, the vocabulary and the regulatory layers DORA adds on top: incident reporting to authorities, a supervised testing regime and a contractual framework for ICT third-party service providers that no BCMS clause anticipates.

The structure of ISO 22301:2019

Unlike ISO 27001, ISO 22301 has no Annex A: everything lives in the management-system clauses 4 to 10. The operational core is clause 8: 8.2 business impact analysis (BIA) and risk assessment, 8.3 continuity strategies and solutions, 8.4 plans and procedures, including the incident response structure and warning and communication, 8.5 the exercise programme, and 8.6 the evaluation of continuity documentation and capabilities. Around the requirements standard sit guidance documents you may already use: ISO/TS 22317 for the BIA method, ISO/TS 22318 for supplier continuity and ISO/IEC 27031 for ICT readiness.

DORA to ISO 22301: the clause-by-clause mapping

DORA requirementISO 22301:2019 anchor
Management body accountability (Art. 5)Clause 5 leadership and policy; clause 9.3 management review
Identification of functions, assets and dependencies (Art. 8)Clause 8.2 business impact analysis and risk assessment
ICT business continuity policy (Art. 11)Clause 5.2 policy, re-cut to ICT scope
Continuity arrangements, plans and mechanisms (Art. 11)Clause 8.3 strategies and solutions; clause 8.4 plans and procedures
ICT response and recovery plans (Art. 11)Clause 8.4 documented plans; clause 9.2 internal audit for the independent review
Yearly testing of the plans (Art. 11(6))Clause 8.5 exercise programme
Crisis management function and communications (Art. 11(7), Art. 14)Clause 8.4 incident response structure, warning and communication
Learning from disruptions (Art. 13)Clause 9.1 evaluation; clause 10 improvement
Backup, restoration and recovery (Art. 12)Clause 8.3 at strategy level only; the technical layer is a delta

The mapping is genuinely strong. An audited BCMS gives you the management engine Article 11 assumes: analysed impacts, chosen strategies, documented plans, an exercise habit and a review loop. Note what the table does not contain: everything in it belongs to Pillar 1. The other four pillars are where the standard runs out.

The DORA delta: what ISO 22301 does not cover

  • The scope cut. A BCMS protects prioritised activities; DORA protects critical or important functions (CIF), a legal test with consequences for contracts, testing and reporting. The two lists overlap but are not the same, and supervisors expect the designation reasoning to be recorded per function.
  • Article 12 backup specifics. DORA requires backup policies and procedures plus restoration and recovery procedures and methods, with restoration running on ICT systems segregated from the source system. A strategy paragraph in the BCMS does not satisfy a requirement written at this technical altitude.
  • Regulatory incident reporting. The clause 8.4 incident response structure manages a disruption; it does not classify it against the RTS criteria or report it to your competent authority on the DORA timelines. Pillar 2 is a net-new build, whatever your BCMS maturity.
  • The testing regime. The clause 8.5 exercise programme counts toward the yearly plan test in Article 11(6), but DORA adds a broader digital operational resilience testing programme (Art. 24-25) and threat-led penetration testing (TLPT, Art. 26-27) for designated entities.
  • Third-party risk. ISO/TS 22318 gives supplier continuity awareness; DORA demands the Register of Information (Art. 28-29), the Article 30 contractual provisions and tested exit strategies. This is the largest build for most entities.
  • Crisis standards stop at guidance. The Article 11(7) crisis management function can borrow structure from ISO 22361, but that document is guidance, not a certifiable requirements standard: no certificate exists for it.

What a 22301 certificate proves to a supervisor

DORA has no certification scheme. Your competent authority assesses compliance against the articles, not against certificates. An accredited ISO 22301 certificate is still worth presenting: it is independent, third-party-audited evidence that the continuity engine exists and runs, which is the substance behind most of Article 11. Present it as evidence supporting specific articles, never as compliance in itself, and be ready to show the deltas above handled separately.

Use the BCMS as the spine: the sequence

Quick wins that reuse what the BCMS already holds:

  • Reconcile the BIA output with the CIF list. Where a prioritised activity and a designated function diverge, write down why. Our BIA to CIF methodology covers the conversion step by step.
  • Derive the ICT business continuity policy from the corporate policy by reference, not duplication: one page cutting the scope to ICT services supporting critical or important functions.
  • Point the clause 8.5 exercise programme at Article 11(6): yearly, covering the ICT systems that support your functions, with third-party failure and cyber scenarios in rotation. Keep the exercise reports; they are supervisory evidence as they stand.
  • Write the Article 12 technical annex: backup policy, restoration procedures, segregation of the restoration environment. Small document, explicit requirement.
  • Route the clause 9.3 management review into management body reporting: the same evidence discharges part of Article 5 with no extra work.
  • Hand the supplier dependencies captured in the BIA to whoever owns the Register of Information: it is the best first draft they will get.

The document set, ready on both frameworks

If the BCMS documentation itself is the gap, the ISO 22301 BCMS Documentation Toolkit is built for exactly this dual duty: 22 documents and 3 workbooks, each carrying both the ISO 22301 clauses it satisfies and the DORA articles it evidences, plus a certification-readiness workbook that flags what would block a Stage 1 documentation review. To learn the build end to end, the DORA Business Continuity certification teaches the Article 11 and 12 workstream, and the free gap analysis tool shows where your continuity controls stand against the rest of the regulation.

Frequently asked questions

Does DORA require ISO 22301 certification?

No. DORA recognises no certification and prescribes none. Compliance is assessed by your competent authority against the articles themselves. A certificate is evidence that a continuity management system exists and is audited, and that is how to present it.

Is ISO 22301 enough to comply with DORA?

No. It covers most of the Article 11 engine and supports Articles 5, 8 and 13, but it does not deliver the Article 12 technical requirements, regulatory incident reporting, the Article 24-27 testing regime or the Article 28-30 third-party framework.

Which DORA articles does ISO 22301 map to?

Strongest on Articles 5, 8 and 11; partial on Articles 12, 13 and 14 and on the exercise side of Articles 24-25. It does not reach TLPT (Art. 26-27) or third-party risk (Art. 28-30).

Do I need ISO 22301 if I already hold ISO 27001?

They answer different questions: ISO 27001 protects information, ISO 22301 keeps functions running. DORA draws on both. If you hold ISO 27001, its continuity controls (A.5.29 and A.5.30) are a starting point, but the BIA, strategy and exercise depth DORA leans on is ISO 22301 territory. Running both on one integrated management system is the most economical structure.

Are prioritised activities the same as critical or important functions?

No. One is your own impact-ranked list; the other is a DORA legal test that pulls contracts, testing and reporting behind it. Reconcile the two lists and record the reasoning for every divergence.