
The Question Every FX Firm Is Asking
"We are already ISO 27001 certified. Does DORA add anything new?"
The short answer: yes β significantly. DORA is not a repackaging of existing cyber standards. It introduces sector-specific, legally enforceable mandates for financial entities that go well beyond what ISO 27001, NIST CSF, or even NIS2 require. Understanding exactly what is new is essential for any FX firm or licensed broker operating in or serving EU clients.
What DORA Requires That Existing Frameworks Do Not
1. Threat-Led Penetration Testing (TLPT)
DORA mandates Threat-Led Penetration Testing for significant financial entities β a specific type of advanced penetration test that simulates the tactics of real threat actors. This goes significantly beyond the penetration testing expected under ISO 27001 or NIST CSF, which leave scope and methodology largely to the organisation.
TLPT must be conducted by certified external testers, follow a TIBER-EU-aligned methodology, and involve the competent regulator directly in scoping and results review. It is not a standard pen test dressed up with a new name.
2. ICT Third-Party Risk Management at Contract Level
ISO 27001 requires you to assess third-party risks. DORA requires specific contractual provisions in every agreement with "critical" ICT third-party service providers. These include:
If your prime broker, cloud provider, or trading platform vendor's contracts do not include DORA-compliant provisions, you are non-compliant β regardless of your ISO certification status.
3. Mandatory Major Incident Classification and Reporting Timelines
DORA defines specific, binding criteria for classifying an incident as "major" β including client impact thresholds, reputational significance, and operational duration. Major incidents must be reported on a defined schedule:
NIS2 has incident reporting requirements, but DORA's thresholds and timelines are more prescriptive for financial sector entities and are sector-specifically calibrated.
4. Register of All ICT Third-Party Arrangements
DORA requires financial entities to maintain and update a register of all contractual arrangements with ICT third-party service providers β not just those deemed critical. This register must be made available to competent authorities on request. There is no equivalent requirement in ISO 27001 or NIST CSF.
5. ICT Concentration Risk at a Systemic Level
DORA addresses concentration risk at the system level β the risk that too many financial entities rely on the same critical third-party providers. Regulators will use the registers mentioned above to map concentration across the financial sector and may issue guidance or restrictions. This systemic perspective has no equivalent in existing enterprise security frameworks.
What Existing Frameworks Already Cover Well
If you have a mature ISO 27001 implementation, you are well-placed for:
These areas overlap heavily with DORA's requirements. The gap is not in these foundations β it is in the sector-specific, operationally prescriptive additions listed above.
The NIST CSF Comparison
The NIST Cybersecurity Framework provides excellent structure for a cyber programme but is US-focused and voluntary. DORA is EU law and directly enforceable. NIST does not address the financial sector's specific obligations around ICT third-party concentration risk (a major DORA focus), TLPT methodology, or the specific incident classification and reporting timelines DORA mandates.
Practical Steps for FX Brokers
If your brokerage or licensed entity operates in the EU or serves EU-regulated counterparties:
1. Gap assessment: Compare your existing controls against DORA's specific requirements β do not assume ISO 27001 or NIST alignment covers you. 2. Contract review: Audit all critical ICT third-party contracts against DORA's mandatory provisions and negotiate amendments where required. 3. Incident response: Update your incident classification and notification procedures to DORA's explicit timelines. 4. TLPT planning: Engage a certified TIBER-EU-aligned tester to understand your scope obligation and plan accordingly.
Contact Turmic LLC for a DORA gap assessment and remediation plan tailored to your FX firm's specific situation.