ISO/IEC 27001 is a voluntary certifiable management-system standard; NIS2 is an EU directive implemented through national law for covered essential and important entities.
An ISMS can organize risk management and evidence, but certification does not determine NIS2 scope or automatically satisfy governance, reporting, supervision, or national-law duties.
Use ISO/IEC 27001 as an evidence and governance foundation where it fits, then maintain a separate legal applicability and obligation map. Compare the actual certified ISMS boundary with the legal entity, services, establishments, supply chain, and national transposition rules that determine NIS2 coverage.
Side-by-side comparison
ISO/IEC 27001 vs NIS2: scope, duties, evidence, and decision rule
This comparison shows where ISO/IEC 27001 can organize implementation, where and national law determine the duty, and when evidence can be reused.
Use ISO/IEC 27001 to build and audit an ISMS for a defined organizational scope. Certification is optional and covers the stated ISMS boundary.
Second framework
NIS2
Use and the applicable national transposition to decide which legal entities and services are covered and which governance, security, reporting, supervision, and enforcement rules apply.
ISO/IEC 27001 vs NIS2: scope, duties, evidence, and decision rule
ISO/IEC 27001 is a certifiable ISMS requirements standard that organizes information security governance, risk treatment, controls, evidence, audit, and continual improvement.
applies primarily to entity types in Annex I or II that qualify as medium-sized enterprises or exceed the medium-enterprise ceilings and provide services or activities in the EU. Article 2 also brings specified entities into scope regardless of size, excludes certain public-administration security activities, and permits specified exemptions and Member State identification. Article 4 can displace corresponding NIS2 provisions where sector-specific EU requirements are at least equivalent in effect.
Perform the entity, sector, size, establishment, exclusion, sector-rule, and national-law analysis first. Compare that legal boundary with the certificate holder and ISMS scope; neither boundary proves the other.
Top management must establish the ISMS policy and roles, integrate ISMS requirements into business processes, provide resources, and review the system. Risk owners approve treatment and accept residual information-security risks.
The covered essential or important entity carries the duties. Its management body must approve Article 21 measures, oversee implementation, and receive training; Member States must encourage comparable training for employees. Operational teams still need named roles for risk, suppliers, incidents, and authority contact.
Map ISO roles to duties, but keep the legal entity and management-body accountability explicit. Suppliers may support controls; they do not inherit the covered entity's statutory responsibility merely because they operate a service.
An organization chooses to implement ISO/IEC 27001, often for risk governance, customer assurance, or certification. The standard then requires it to define the ISMS scope and apply the clauses within that boundary.
applicability follows Article 2, the Annex I and II entity types, the size-cap rule and exceptions, EU establishment or service rules, and national transposition. Article 3 then classifies in-scope entities as essential or important.
Do not wait for a customer request or incident to test scope. Record the facts behind the size calculation, sector and service classification, establishment, exception, and essential-or-important result.
Clauses 4 to 10 require an ISMS covering context, leadership, planning, support, operation, performance evaluation, and improvement. Risk treatment includes determining necessary controls, checking them against Annex A, and maintaining a Statement of Applicability.
Article 21 requires appropriate and proportionate technical, operational, and organizational measures using an all-hazards approach. Its minimum topics include risk analysis, incident handling, continuity and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access security, asset management, and multi-factor or continuous authentication where appropriate.
Map each measure to the national provision, responsible owner, implementation, and evidence. An Annex A label alone does not show that the legal measure is proportionate or effective for the covered service.
ISO/IEC 27001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
evidence should show the applicability decision, management-body approval and oversight, Article 21 risk measures and effectiveness checks, supplier-security decisions, significant-incident assessments and notifications, and information supplied to competent authorities.
Build an evidence matrix with one row per national duty and columns for legal source, entity and service, owner, measure, artifact, date, review trigger, and any linked ISO clause or control.
ISO/IEC 27001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
Member States were required to transpose by 17 October 2024 and apply those measures from 18 October 2024. For a significant incident, Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and ordinarily a final report within one month after that notification, with special branches for ongoing incidents and trust service providers.
ISO/IEC 27001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
requires Member States to supervise and enforce national duties. Essential entities are subject to ex ante and ex post supervision; important entities are generally subject to ex post supervision when authorities receive evidence or indications of non-compliance. Article 34 sets minimum maximum-fine levels for Article 21 or 23 infringements: the higher of EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities.
An ISO certification audit is not supervision. Track authority requests, audits, orders, remediation, and possible penalties under the applicable national law separately from certification findings.
can reuse ISMS evidence where it demonstrates the covered entity's applicable risk measure or governance process, but legal scope decisions, management-body duties, incident notifications, authority interactions, and national registration records remain NIS2-specific.
Reuse evidence only after checking the legal entity, covered service, system, supplier, owner, period, national provision, and acceptance criteria. Record partial coverage instead of calling a control equivalent.
Use when deciding legal coverage or implementing management-body governance, Article 21 measures, Article 23 reporting, registration, supervision, or enforcement duties under national law.
If both apply, use the ISMS to operate controls and evidence, while the register preserves the legal actor, provision, deadline, authority, and national variation.
ISO/IEC 27001 is a certifiable ISMS requirements standard that organizes information security governance, risk treatment, controls, evidence, audit, and continual improvement.
applies primarily to entity types in Annex I or II that qualify as medium-sized enterprises or exceed the medium-enterprise ceilings and provide services or activities in the EU. Article 2 also brings specified entities into scope regardless of size, excludes certain public-administration security activities, and permits specified exemptions and Member State identification. Article 4 can displace corresponding NIS2 provisions where sector-specific EU requirements are at least equivalent in effect.
Perform the entity, sector, size, establishment, exclusion, sector-rule, and national-law analysis first. Compare that legal boundary with the certificate holder and ISMS scope; neither boundary proves the other.
Top management must establish the ISMS policy and roles, integrate ISMS requirements into business processes, provide resources, and review the system. Risk owners approve treatment and accept residual information-security risks.
The covered essential or important entity carries the duties. Its management body must approve Article 21 measures, oversee implementation, and receive training; Member States must encourage comparable training for employees. Operational teams still need named roles for risk, suppliers, incidents, and authority contact.
Map ISO roles to duties, but keep the legal entity and management-body accountability explicit. Suppliers may support controls; they do not inherit the covered entity's statutory responsibility merely because they operate a service.
An organization chooses to implement ISO/IEC 27001, often for risk governance, customer assurance, or certification. The standard then requires it to define the ISMS scope and apply the clauses within that boundary.
applicability follows Article 2, the Annex I and II entity types, the size-cap rule and exceptions, EU establishment or service rules, and national transposition. Article 3 then classifies in-scope entities as essential or important.
Do not wait for a customer request or incident to test scope. Record the facts behind the size calculation, sector and service classification, establishment, exception, and essential-or-important result.
Clauses 4 to 10 require an ISMS covering context, leadership, planning, support, operation, performance evaluation, and improvement. Risk treatment includes determining necessary controls, checking them against Annex A, and maintaining a Statement of Applicability.
Article 21 requires appropriate and proportionate technical, operational, and organizational measures using an all-hazards approach. Its minimum topics include risk analysis, incident handling, continuity and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access security, asset management, and multi-factor or continuous authentication where appropriate.
Map each measure to the national provision, responsible owner, implementation, and evidence. An Annex A label alone does not show that the legal measure is proportionate or effective for the covered service.
ISO/IEC 27001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
evidence should show the applicability decision, management-body approval and oversight, Article 21 risk measures and effectiveness checks, supplier-security decisions, significant-incident assessments and notifications, and information supplied to competent authorities.
Build an evidence matrix with one row per national duty and columns for legal source, entity and service, owner, measure, artifact, date, review trigger, and any linked ISO clause or control.
ISO/IEC 27001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
Member States were required to transpose by 17 October 2024 and apply those measures from 18 October 2024. For a significant incident, Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and ordinarily a final report within one month after that notification, with special branches for ongoing incidents and trust service providers.
ISO/IEC 27001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
requires Member States to supervise and enforce national duties. Essential entities are subject to ex ante and ex post supervision; important entities are generally subject to ex post supervision when authorities receive evidence or indications of non-compliance. Article 34 sets minimum maximum-fine levels for Article 21 or 23 infringements: the higher of EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities.
An ISO certification audit is not supervision. Track authority requests, audits, orders, remediation, and possible penalties under the applicable national law separately from certification findings.
can reuse ISMS evidence where it demonstrates the covered entity's applicable risk measure or governance process, but legal scope decisions, management-body duties, incident notifications, authority interactions, and national registration records remain NIS2-specific.
Reuse evidence only after checking the legal entity, covered service, system, supplier, owner, period, national provision, and acceptance criteria. Record partial coverage instead of calling a control equivalent.
Use when deciding legal coverage or implementing management-body governance, Article 21 measures, Article 23 reporting, registration, supervision, or enforcement duties under national law.
If both apply, use the ISMS to operate controls and evidence, while the register preserves the legal actor, provision, deadline, authority, and national variation.
How should teams decide between ISO/IEC 27001 and NIS2 for compliance planning?
If you need a certifiable management system for information security governance, risk treatment, controls, audit, and continual improvement, start with ISO/IEC 27001. Its clauses 4 to 10 and Annex A give you the operating structure.
If you need to determine whether an entity is covered, classify it as essential or important, or implement governance, Article 21 measures, Article 23 reporting, supervision, and enforcement duties, start with and the applicable national transposition.
When both apply, keep the legal obligation, the ISMS decision, and the evidence set distinct; reuse records only where the same owner, scope, time period, system, supplier, data type, and acceptance criteria apply.
Are ISO/IEC 27001 and NIS2 the same kind of requirement?
No. ISO/IEC 27001 is a voluntary, certifiable management-system requirements standard. is an EU directive whose binding duties depend on legal scope, Member State transposition, the covered entity and services, and the competent authority.
ISO/IEC 27001 can organize scope, risk management, controls, evidence, internal audit, management review, and improvement. A certificate does not decide whether an entity is essential or important, satisfy statutory incident-reporting timelines by itself, or replace national-law supervision and enforcement.
Use ISO/IEC 27001 when you need a management-system structure for scope, risk assessment, Annex A controls, internal audit, and management review, as set out in the standard's clauses 4 to 10.
Use when the question is a legal one: whether a covered entity must meet EU cybersecurity obligations, incident-reporting deadlines, or national supervision and enforcement requirements.
If both apply, keep the legal duty and the management-system evidence separate, then reuse only the records that match the same owner, scope, date, and acceptance criteria.
Which ISO/IEC 27001 evidence can support NIS2, and what remains separate?
Reusable evidence can include governance roles, risk methodology and results, treatment plans, supplier-security records, incident processes, continuity evidence, vulnerability handling, access controls, cryptography, logging, internal audits, management reviews, and corrective actions, but only when the evidence covers the same legal entity, service, system, date, and obligation.
Keep separate records for legal applicability, management-body duties, national registration or notification, significant-incident classification and deadlines, competent-authority interactions, and any national measures or enforcement requirements not represented by the ISMS certificate.
Map each reused artifact to the article or national requirement it supports; do not use 'ISO certified' as the mapping.
Record scope differences between the certified ISMS and the regulated entity, service, network and information systems, establishments, and supply chain.
Add legal owners and statutory deadlines separately from ISO process owners and internal review dates.
Treat gaps as legal implementation work even when the ISO audit raised no finding.
Assign owners to the NIS2 applicability decision and each mapped measure, request evidence, record scope differences, and track legal and ISMS review dates.
How should teams map ISMS scope to NIS2 legal scope?
Start with a legal entity-and-service map under and the applicable national transposition. Separately extract the certified ISMS scope statement, sites, products, services, systems, outsourced processes, and interfaces.
The default size-cap rule covers Annex I or II entity types that qualify as medium-sized enterprises or exceed those ceilings. Under Recommendation 2003/361/EC, a medium-sized enterprise has fewer than 250 staff and annual turnover of no more than EUR 50 million or an annual balance-sheet total of no more than EUR 43 million; its partner and linked enterprises can affect the calculation. Article 2 also covers specified entity types regardless of size and allows Member States to identify certain additional entities, so sector, service, size, establishment, and national rules all need checking.
Check exclusions and special regimes before finalizing the result. does not apply to public administration entities acting in national security, public security, defence, or law enforcement, and Member States may exempt specified entities or services tied to those activities from Articles 21 or 23. Under Article 4, equivalent sector-specific EU cybersecurity and incident-reporting requirements can displace the corresponding NIS2 provisions. Record the exact exclusion, exemption, or sector rule rather than treating an entire corporate group as outside scope.
Compare those two boundaries explicitly. Where the legal scope is broader, extend governance and evidence or maintain a separate legal control record; where the ISMS is broader, do not imply that every certified activity is regulated by .
List regulated entities, covered services, establishments, critical systems, and competent authorities.
List the certificate holder, certified scope, locations, services, exclusions, and material dependencies.
Create a gap register for people, services, systems, suppliers, incident duties, and governance outside the ISMS boundary.
Which equivalence assumptions create compliance gaps?
Do not treat a certification decision as a legal opinion. A certification body evaluates conformity of a stated ISMS scope; it does not determine applicability, interpret every national transposition, or certify compliance with statutory reporting and enforcement duties unless a separate scheme expressly says so.
Control-name matching can also hide gaps. An Annex A control can support a measure, but the responsible entity must still show that the implementation, scope, proportionality, governance, and timing satisfy the applicable legal rule.
Do not state that ISO/IEC 27001 certification equals compliance.
Do not use the certificate scope as the legal-entity applicability analysis.
Do not replace statutory incident decisions and deadlines with the ISMS incident procedure's internal timetable.
Review the mapping at planned ISMS intervals and whenever the legal entity, covered service, national law, authority guidance, supplier chain, system boundary, or incident process changes. duties come from the applicable national transposition, so a group operating in several Member States may need separate jurisdiction records.
After a change, update the applicability decision, Article 21 measure mapping, Article 23 reporting workflow, evidence owners, and management-body reporting. Keep the original legal source visible even when one control record supports both and ISO/IEC 27001.
Set a review date and triggers for acquisitions, new services, new establishments, material suppliers, major incidents, and national-law changes.
Test the significant-incident escalation path against the 24-hour early warning, 72-hour incident notification, and one-month final-report sequence in Article 23, subject to the Directive's specific conditions and national process.
Escalate gaps in Article 21 measures and incident readiness to the management body, which Article 20 requires to approve the measures and oversee implementation.