[{"data":1,"prerenderedAt":322},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-dora-iso27001-compliance-software":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":7,"entities":266,"extension":269,"faq":270,"keywords":289,"meta":294,"navigation":295,"ogImage":296,"path":6,"persona":297,"publishedAt":296,"regulation":296,"relatedFeatures":298,"relatedPages":302,"seo":305,"shortTitle":5,"slug":306,"sources":307,"stem":318,"tldr":319,"updatedAt":320,"__hash__":321},"solutions_en\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software.md","DORA and ISO 27001 Compliance Software | CISAPP","CISAPP",{"type":108,"value":109,"toc":259},"minimark",[110,115,123,142,146,238,242,245],[111,112,114],"h2",{"id":113},"why-bring-dora-and-iso-27001-together","Why bring DORA and ISO 27001 together?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"DORA and ISO\u002FIEC 27001 rest largely on the same evidence: the same critical providers, the same technical controls, the same certificates."," Handling them in two tools artificially splits a single collection effort and lets two files describing the same reality drift apart.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,139],"ul",{},[130,131,132],"li",{},"A provider critical under DORA usually also falls under ISO 27001 controls A.5.19 to A.5.23.",[130,134,135],{},"ISO 27001 certification does not cover DORA's own obligations: register, clauses, exit, testing.",[130,137,138],{},"The SoA and the CTPP register age fast when kept apart from vendor assessments.",[130,140,141],{},"Audit reports are still produced framework by framework, on a shared evidence base.",[111,143,145],{"id":144},"what-overlaps-what-does-not","What overlaps, what does not",[147,148,150],"comparison-table",{"caption":149},"DORA and ISO\u002FIEC 27001: respective scope on third-party risk",[151,152,153,168],"table",{},[154,155,156],"thead",{},[157,158,159,163,165],"tr",{},[160,161,162],"th",{},"Topic",[160,164,42],{},[160,166,167],{},"ISO\u002FIEC 27001:2022",[169,170,171,183,194,205,216,227],"tbody",{},[157,172,173,177,180],{},[174,175,176],"td",{},"Nature",[174,178,179],{},"EU regulation, mandatory",[174,181,182],{},"Voluntary standard, certifiable",[157,184,185,188,191],{},[174,186,187],{},"Scope",[174,189,190],{},"EU financial entities",[174,192,193],{},"Any organisation",[157,195,196,199,202],{},[174,197,198],{},"Core artefact",[174,200,201],{},"Register of information (CTPP)",[174,203,204],{},"Statement of Applicability (SoA)",[157,206,207,210,213],{},[174,208,209],{},"Vendor controls",[174,211,212],{},"Minimum clauses, exit, concentration",[174,214,215],{},"Controls A.5.19 to A.5.23",[157,217,218,221,224],{},[174,219,220],{},"Testing",[174,222,223],{},"Resilience programme, TLPT for the most significant",[174,225,226],{},"Internal audits and management review",[157,228,229,232,235],{},[174,230,231],{},"Incidents",[174,233,234],{},"Major incident reporting to authorities",[174,236,237],{},"Incident management within the ISMS",[111,239,241],{"id":240},"less-duplication-more-traceability","Less duplication, more traceability",[116,243,244],{},"CISAPP attaches both frameworks to the same vendor record: the CTPP register is fed from the provider's record, the SoA updates as assessments come in, certifications are tracked with their validity dates, and the Audit module produces signable reports per framework without a fresh collection round.",[116,246,247,248,251,252,254,255,258],{},"See also the ",[249,250,42],"a",{"href":43}," and ",[249,253,50],{"href":51}," pages, and the ",[249,256,257],{"href":18},"third-party GRC platform",".",{"title":260,"searchDepth":261,"depth":261,"links":262},"",2,[263,264,265],{"id":113,"depth":261,"text":114},{"id":144,"depth":261,"text":145},{"id":240,"depth":261,"text":241},[267,268],"Digital operational resilience","Concentration risk","md",[271,274,277,280,283,286],{"q":272,"a":273},"Why handle DORA and ISO 27001 in the same software?","Both frameworks often cover the same vendors and the same technical controls. Handling them separately duplicates the evidence work: the same certificate, questionnaire and remediation plan get collected twice, with a risk of divergence between the two files.",{"q":275,"a":276},"Is ISO 27001 enough to be DORA compliant?","No. A certified ISMS covers part of DORA's expectations on ICT risk governance, but DORA adds its own obligations: the register of information, minimum contractual clauses, exit strategy, resilience testing and major incident reporting.",{"q":278,"a":279},"What is the CTPP register?","It is the register of contractual arrangements with ICT providers required by DORA. It identifies each provider, the functions supported, whether they are critical or important, data location and the subcontracting chain, and it is reported to competent authorities.",{"q":281,"a":282},"Does CISAPP produce combined audit reports?","The Audit module produces signable reports framework by framework, with common evidence reused between DORA and ISO 27001 — evidence collected once is attached to both files.",{"q":284,"a":285},"How are vendor certificates tracked?","Each certificate is recorded with its scope and validity date, and triggers an alert before expiry. To an auditor or a supervisor alike, an expired certificate is no certificate.",{"q":287,"a":288},"Which entities are in scope of DORA?","Around twenty categories of EU financial entities: credit institutions, investment firms, payment institutions, insurers, asset managers, crypto-asset service providers and market infrastructures, among others.",[290,291,292,293],"DORA ISO 27001 compliance software","DORA ISO 27001","financial regulatory compliance","DORA ISO 27001 audit",{},true,null,"entreprise",[299,300,301],"Regulatory frameworks","Certifications","Audit module",[303,304],"dora","iso-27001",{"title":105,"description":7},"dora-iso27001-compliance-software",[308,313],{"label":309,"url":310,"publisher":311,"date":312},"Regulation (EU) 2022\u002F2554 (DORA) — consolidated text","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2022\u002F2554\u002Foj","EUR-Lex","2022-12-14",{"label":314,"url":315,"publisher":316,"date":317},"ISO\u002FIEC 27001:2022 — Information security management systems","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fsolutions\u002Fdora-iso27001-compliance-software","DORA and ISO\u002FIEC 27001 share most of their evidence: the same critical vendors, the same technical controls, the same certificates. Handling them in two tools duplicates collection. CISAPP brings the register of critical ICT providers (CTPP), the Statement of Applicability (SoA) and Annex A controls onto one vendor record.","2026-08-16","r0zehDyLHCI5d-YTC-yFU2Ou7hPL7lS6axDiN1QZhiU",1791391138820]