CROSSWALKS

GAISSF to DORA Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to DORA, with scope, method, limitations and traceability.

Executive Summary

CRO-028 maps all 59 GAISSF v1.0 controls to all 64 DORA articles through 236 outcome-based records. It supports readiness planning, evidence reuse and gap analysis, but does not establish legal compliance or supervisory acceptance.

1. Purpose and Intended Use

The crosswalk supports financial entities, ICT third-party providers, security teams, risk functions and assessors in relating GAISSF controls to DORA requirements. Applicability must be determined for the relevant entity type, exemption, proportionality category, service arrangement and competent authority.

2. Source Baseline

Source Identifier Status Use
GAISSF Framework Standard GAISSF-NOR-001 v1.0 Normative Framework baseline
GAISSF Control Catalogue GAISSF-NOR-004 v1.0 Normative 59-control source
Digital Operational Resilience Act Regulation (EU) 2022/2554 Binding regulation Primary legal source
DORA Level 2 acts Delegated and implementing acts Binding where adopted Detailed implementation layer

3. Scope and Interpretation

DORA applies from 17 January 2025. The article mapping is distinct from Level 2 technical standards, supervisory expectations, contractual negotiations and evidence of operating effectiveness. Similar terminology does not establish equivalence.

4. Mapping Methodology

Mappings compare intended outcomes, lifecycle scope, governance, technical controls, evidence and accountable actors. Relationship and confidence are recorded separately. Composite mappings are expected because DORA obligations usually require several controls and additional legal or operational measures.

5. Article Coverage Summary

Art. Title Chapter Controls Coverage
1 Subject matter General provisions 0 Not Addressed
2 Scope General provisions 0 Not Addressed
3 Definitions General provisions 0 Not Addressed
4 Principle of proportionality General provisions 0 Not Addressed
5 Governance and organisation ICT risk management 10 Substantially Addressed
6 ICT risk management framework ICT risk management 42 Substantially Addressed
7 ICT systems, protocols and tools ICT risk management 5 Partially Addressed
8 Identification ICT risk management 3 Partially Addressed
9 Protection and prevention ICT risk management 26 Substantially Addressed
10 Detection ICT risk management 16 Substantially Addressed
11 Response and recovery ICT risk management 20 Substantially Addressed
12 Backup policies and procedures, restoration and recovery procedures and methods ICT risk management 1 Indirectly Supported
13 Learning and evolving ICT risk management 9 Substantially Addressed
14 Communication ICT risk management 10 Substantially Addressed
15 Further harmonisation of ICT risk management tools, methods, processes and policies ICT risk management 2 Indirectly Supported
16 Simplified ICT risk management framework ICT risk management 0 Not Addressed
17 ICT-related incident management process ICT-related incident management, classification and reporting 11 Substantially Addressed
18 Classification of ICT-related incidents and cyber threats ICT-related incident management, classification and reporting 7 Partially Addressed
19 Reporting of major ICT-related incidents and voluntary notification of significant cyber threats ICT-related incident management, classification and reporting 1 Indirectly Supported
20 Harmonisation of reporting content and templates ICT-related incident management, classification and reporting 1 Indirectly Supported
21 Centralisation of reporting of major ICT-related incidents ICT-related incident management, classification and reporting 0 Not Addressed
22 Supervisory feedback ICT-related incident management, classification and reporting 0 Not Addressed
23 Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions ICT-related incident management, classification and reporting 0 Not Addressed
24 General requirements for the performance of digital operational resilience testing Digital operational resilience testing 30 Substantially Addressed
25 Testing of ICT tools and systems Digital operational resilience testing 7 Partially Addressed
26 Advanced testing of ICT tools, systems and processes based on TLPT Digital operational resilience testing 2 Indirectly Supported
27 Requirements for testers for the carrying out of TLPT Digital operational resilience testing 2 Indirectly Supported
28 General principles for the sound management of ICT third-party risk Managing ICT third-party risk and oversight 11 Substantially Addressed
29 Preliminary assessment of ICT concentration risk at entity level Managing ICT third-party risk and oversight 8 Substantially Addressed
30 Key contractual provisions Managing ICT third-party risk and oversight 8 Substantially Addressed
31 Designation of critical ICT third-party service providers Managing ICT third-party risk and oversight 2 Indirectly Supported
32 Structure of the Oversight Framework Managing ICT third-party risk and oversight 0 Not Addressed
33 Tasks of the Lead Overseer Managing ICT third-party risk and oversight 0 Not Addressed
34 Operational coordination between Lead Overseers Managing ICT third-party risk and oversight 0 Not Addressed
35 Powers of the Lead Overseer Managing ICT third-party risk and oversight 0 Not Addressed
36 Exercise of the powers of the Lead Overseer outside the Union Managing ICT third-party risk and oversight 0 Not Addressed
37 Requests for information Managing ICT third-party risk and oversight 0 Not Addressed
38 General investigations Managing ICT third-party risk and oversight 0 Not Addressed
39 Inspections Managing ICT third-party risk and oversight 0 Not Addressed
40 Ongoing oversight Managing ICT third-party risk and oversight 0 Not Addressed
41 Harmonisation of conditions enabling the conduct of oversight activities Managing ICT third-party risk and oversight 0 Not Addressed
42 Follow-up by competent authorities Managing ICT third-party risk and oversight 0 Not Addressed
43 Oversight fees Managing ICT third-party risk and oversight 0 Not Addressed
44 International cooperation Managing ICT third-party risk and oversight 0 Not Addressed
45 Information-sharing arrangements on cyber threat information and intelligence Information-sharing arrangements 0 Not Addressed
46 Competent authorities Competent authorities, cooperation and enforcement 0 Not Addressed
47 Cooperation with structures and authorities established by Directive (EU) 2022/2555 Competent authorities, cooperation and enforcement 0 Not Addressed
48 Cooperation between authorities Competent authorities, cooperation and enforcement 0 Not Addressed
49 Financial cross-sector exercises, communication and cooperation Competent authorities, cooperation and enforcement 0 Not Addressed
50 Administrative penalties and remedial measures Competent authorities, cooperation and enforcement 0 Not Addressed
51 Exercise of the power to impose administrative penalties and remedial measures Competent authorities, cooperation and enforcement 0 Not Addressed
52 Criminal penalties Competent authorities, cooperation and enforcement 0 Not Addressed
53 Notification duties Competent authorities, cooperation and enforcement 0 Not Addressed
54 Publication of administrative penalties Competent authorities, cooperation and enforcement 0 Not Addressed
55 Professional secrecy Competent authorities, cooperation and enforcement 1 Indirectly Supported
56 Data protection Competent authorities, cooperation and enforcement 1 Indirectly Supported
57 Processing of personal data outside the Union Competent authorities, cooperation and enforcement 0 Not Addressed
58 Review clause Transitional and final provisions 0 Not Addressed
59 Amendments to Regulation (EC) No 1060/2009 Transitional and final provisions 0 Not Addressed
60 Amendments to Regulation (EU) No 648/2012 Transitional and final provisions 0 Not Addressed
61 Amendments to Regulation (EU) No 909/2014 Transitional and final provisions 0 Not Addressed
62 Amendments to Regulation (EU) No 600/2014 Transitional and final provisions 0 Not Addressed
63 Amendments to Regulation (EU) 2016/1011 Transitional and final provisions 0 Not Addressed
64 Entry into force and date of application Transitional and final provisions 0 Not Addressed

6. GAISSF-to-DORA Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 236 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF Article Provision Rel. Confidence Rationale Residual gap
CRO-028-0001 D1-CTL-01 6 ICT risk management framework P Medium-High GAISSF D1-CTL-01 supports part of DORA Article 6 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.
CRO-028-0002 D1-CTL-01 9 Protection and prevention P Medium-High GAISSF D1-CTL-01 supports part of DORA Article 9 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.
CRO-028-0003 D1-CTL-01 10 Detection P Medium-High GAISSF D1-CTL-01 supports part of DORA Article 10 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.
CRO-028-0004 D1-CTL-01 24 General requirements for the performance of digital operational resilience testing P Medium-High GAISSF D1-CTL-01 supports part of DORA Article 24 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.
CRO-028-0005 D1-CTL-02 10 Detection SP High GAISSF D1-CTL-02 supports part of DORA Article 10 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance. Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.
CRO-028-0006 D1-CTL-02 6 ICT risk management framework SP High GAISSF D1-CTL-02 supports part of DORA Article 6 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance. Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.

7. Implementation and Evidence Reuse

Potentially reusable evidence includes ICT risk frameworks, asset and dependency inventories, protection standards, monitoring records, incident classification and reports, continuity and recovery plans, testing programmes, TLPT records, third-party registers, contracts, concentration-risk assessments, exit plans, threat-intelligence sharing records and management-body approvals. Reuse remains conditional on scope, currency, integrity and DORA-specific sufficiency.

8. Limitations

  • Mapping does not establish DORA compliance or supervisory acceptance.

  • Level 2 delegated and implementing acts must be assessed separately.

  • Applicability depends on entity type, exemptions, proportionality and service arrangements.

  • Operating effectiveness must be independently tested.

9. Notably Absent

The source review did not identify any basis for treating GAISSF certification as DORA compliance, using this mapping as a substitute for the register of information, assuming all financial entities have identical obligations, or treating all ICT third-party providers as critical providers subject to direct oversight.

10. Approval and Revalidation

Independent EU financial-regulatory, ICT-risk, legal and supervisory review is required before public reliance. Revalidate after amendments, new Level 2 acts, supervisory guidance, material GAISSF changes or significant enforcement developments.