GAISSF to DORA Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to DORA, with scope, method, limitations and traceability.
Executive Summary
CRO-028 maps all 59 GAISSF v1.0 controls to all 64 DORA articles through 236 outcome-based records. It supports readiness planning, evidence reuse and gap analysis, but does not establish legal compliance or supervisory acceptance.
1. Purpose and Intended Use
The crosswalk supports financial entities, ICT third-party providers, security teams, risk functions and assessors in relating GAISSF controls to DORA requirements. Applicability must be determined for the relevant entity type, exemption, proportionality category, service arrangement and competent authority.
2. Source Baseline
| Source | Identifier | Status | Use |
|---|---|---|---|
| GAISSF Framework Standard | GAISSF-NOR-001 v1.0 | Normative | Framework baseline |
| GAISSF Control Catalogue | GAISSF-NOR-004 v1.0 | Normative | 59-control source |
| Digital Operational Resilience Act | Regulation (EU) 2022/2554 | Binding regulation | Primary legal source |
| DORA Level 2 acts | Delegated and implementing acts | Binding where adopted | Detailed implementation layer |
3. Scope and Interpretation
DORA applies from 17 January 2025. The article mapping is distinct from Level 2 technical standards, supervisory expectations, contractual negotiations and evidence of operating effectiveness. Similar terminology does not establish equivalence.
4. Mapping Methodology
Mappings compare intended outcomes, lifecycle scope, governance, technical controls, evidence and accountable actors. Relationship and confidence are recorded separately. Composite mappings are expected because DORA obligations usually require several controls and additional legal or operational measures.
5. Article Coverage Summary
| Art. | Title | Chapter | Controls | Coverage |
|---|---|---|---|---|
| 1 | Subject matter | General provisions | 0 | Not Addressed |
| 2 | Scope | General provisions | 0 | Not Addressed |
| 3 | Definitions | General provisions | 0 | Not Addressed |
| 4 | Principle of proportionality | General provisions | 0 | Not Addressed |
| 5 | Governance and organisation | ICT risk management | 10 | Substantially Addressed |
| 6 | ICT risk management framework | ICT risk management | 42 | Substantially Addressed |
| 7 | ICT systems, protocols and tools | ICT risk management | 5 | Partially Addressed |
| 8 | Identification | ICT risk management | 3 | Partially Addressed |
| 9 | Protection and prevention | ICT risk management | 26 | Substantially Addressed |
| 10 | Detection | ICT risk management | 16 | Substantially Addressed |
| 11 | Response and recovery | ICT risk management | 20 | Substantially Addressed |
| 12 | Backup policies and procedures, restoration and recovery procedures and methods | ICT risk management | 1 | Indirectly Supported |
| 13 | Learning and evolving | ICT risk management | 9 | Substantially Addressed |
| 14 | Communication | ICT risk management | 10 | Substantially Addressed |
| 15 | Further harmonisation of ICT risk management tools, methods, processes and policies | ICT risk management | 2 | Indirectly Supported |
| 16 | Simplified ICT risk management framework | ICT risk management | 0 | Not Addressed |
| 17 | ICT-related incident management process | ICT-related incident management, classification and reporting | 11 | Substantially Addressed |
| 18 | Classification of ICT-related incidents and cyber threats | ICT-related incident management, classification and reporting | 7 | Partially Addressed |
| 19 | Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | ICT-related incident management, classification and reporting | 1 | Indirectly Supported |
| 20 | Harmonisation of reporting content and templates | ICT-related incident management, classification and reporting | 1 | Indirectly Supported |
| 21 | Centralisation of reporting of major ICT-related incidents | ICT-related incident management, classification and reporting | 0 | Not Addressed |
| 22 | Supervisory feedback | ICT-related incident management, classification and reporting | 0 | Not Addressed |
| 23 | Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions | ICT-related incident management, classification and reporting | 0 | Not Addressed |
| 24 | General requirements for the performance of digital operational resilience testing | Digital operational resilience testing | 30 | Substantially Addressed |
| 25 | Testing of ICT tools and systems | Digital operational resilience testing | 7 | Partially Addressed |
| 26 | Advanced testing of ICT tools, systems and processes based on TLPT | Digital operational resilience testing | 2 | Indirectly Supported |
| 27 | Requirements for testers for the carrying out of TLPT | Digital operational resilience testing | 2 | Indirectly Supported |
| 28 | General principles for the sound management of ICT third-party risk | Managing ICT third-party risk and oversight | 11 | Substantially Addressed |
| 29 | Preliminary assessment of ICT concentration risk at entity level | Managing ICT third-party risk and oversight | 8 | Substantially Addressed |
| 30 | Key contractual provisions | Managing ICT third-party risk and oversight | 8 | Substantially Addressed |
| 31 | Designation of critical ICT third-party service providers | Managing ICT third-party risk and oversight | 2 | Indirectly Supported |
| 32 | Structure of the Oversight Framework | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 33 | Tasks of the Lead Overseer | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 34 | Operational coordination between Lead Overseers | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 35 | Powers of the Lead Overseer | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 36 | Exercise of the powers of the Lead Overseer outside the Union | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 37 | Requests for information | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 38 | General investigations | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 39 | Inspections | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 40 | Ongoing oversight | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 41 | Harmonisation of conditions enabling the conduct of oversight activities | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 42 | Follow-up by competent authorities | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 43 | Oversight fees | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 44 | International cooperation | Managing ICT third-party risk and oversight | 0 | Not Addressed |
| 45 | Information-sharing arrangements on cyber threat information and intelligence | Information-sharing arrangements | 0 | Not Addressed |
| 46 | Competent authorities | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 47 | Cooperation with structures and authorities established by Directive (EU) 2022/2555 | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 48 | Cooperation between authorities | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 49 | Financial cross-sector exercises, communication and cooperation | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 50 | Administrative penalties and remedial measures | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 51 | Exercise of the power to impose administrative penalties and remedial measures | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 52 | Criminal penalties | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 53 | Notification duties | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 54 | Publication of administrative penalties | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 55 | Professional secrecy | Competent authorities, cooperation and enforcement | 1 | Indirectly Supported |
| 56 | Data protection | Competent authorities, cooperation and enforcement | 1 | Indirectly Supported |
| 57 | Processing of personal data outside the Union | Competent authorities, cooperation and enforcement | 0 | Not Addressed |
| 58 | Review clause | Transitional and final provisions | 0 | Not Addressed |
| 59 | Amendments to Regulation (EC) No 1060/2009 | Transitional and final provisions | 0 | Not Addressed |
| 60 | Amendments to Regulation (EU) No 648/2012 | Transitional and final provisions | 0 | Not Addressed |
| 61 | Amendments to Regulation (EU) No 909/2014 | Transitional and final provisions | 0 | Not Addressed |
| 62 | Amendments to Regulation (EU) No 600/2014 | Transitional and final provisions | 0 | Not Addressed |
| 63 | Amendments to Regulation (EU) 2016/1011 | Transitional and final provisions | 0 | Not Addressed |
| 64 | Entry into force and date of application | Transitional and final provisions | 0 | Not Addressed |
6. GAISSF-to-DORA Mapping Register
| Record | GAISSF | Article | Provision | Rel. | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|---|
| CRO-028-0001 | D1-CTL-01 | 6 | ICT risk management framework | P | Medium-High | GAISSF D1-CTL-01 supports part of DORA Article 6 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. | Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
| CRO-028-0002 | D1-CTL-01 | 9 | Protection and prevention | P | Medium-High | GAISSF D1-CTL-01 supports part of DORA Article 9 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. | Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
| CRO-028-0003 | D1-CTL-01 | 10 | Detection | P | Medium-High | GAISSF D1-CTL-01 supports part of DORA Article 10 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. | Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
| CRO-028-0004 | D1-CTL-01 | 24 | General requirements for the performance of digital operational resilience testing | P | Medium-High | GAISSF D1-CTL-01 supports part of DORA Article 24 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance. | Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
| CRO-028-0005 | D1-CTL-02 | 10 | Detection | SP | High | GAISSF D1-CTL-02 supports part of DORA Article 10 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance. | Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
| CRO-028-0006 | D1-CTL-02 | 6 | ICT risk management framework | SP | High | GAISSF D1-CTL-02 supports part of DORA Article 6 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance. | Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone. |
7. Implementation and Evidence Reuse
Potentially reusable evidence includes ICT risk frameworks, asset and dependency inventories, protection standards, monitoring records, incident classification and reports, continuity and recovery plans, testing programmes, TLPT records, third-party registers, contracts, concentration-risk assessments, exit plans, threat-intelligence sharing records and management-body approvals. Reuse remains conditional on scope, currency, integrity and DORA-specific sufficiency.
8. Limitations
Mapping does not establish DORA compliance or supervisory acceptance.
Level 2 delegated and implementing acts must be assessed separately.
Applicability depends on entity type, exemptions, proportionality and service arrangements.
Operating effectiveness must be independently tested.
9. Notably Absent
The source review did not identify any basis for treating GAISSF certification as DORA compliance, using this mapping as a substitute for the register of information, assuming all financial entities have identical obligations, or treating all ICT third-party providers as critical providers subject to direct oversight.
10. Approval and Revalidation
Independent EU financial-regulatory, ICT-risk, legal and supervisory review is required before public reliance. Revalidate after amendments, new Level 2 acts, supervisory guidance, material GAISSF changes or significant enforcement developments.