Side-by-sideGlobalISO/IEC 27001

ISO/IEC 27001 ISO/IEC 27001 vs NIS2

ISO/IEC 27001 is a voluntary certifiable management-system standard; NIS2 is an EU directive implemented through national law for covered essential and important entities.

An ISMS can organize risk management and evidence, but certification does not determine NIS2 scope or automatically satisfy governance, reporting, supervision, or national-law duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use ISO/IEC 27001 as an evidence and governance foundation where it fits, then maintain a separate legal applicability and obligation map. Compare the actual certified ISMS boundary with the legal entity, services, establishments, supply chain, and national transposition rules that determine NIS2 coverage.

Side-by-side comparison

ISO/IEC 27001 vs NIS2: scope, duties, evidence, and decision rule

This comparison shows where ISO/IEC 27001 can organize implementation, where and national law determine the duty, and when evidence can be reused.

Review all sources
First framework
ISO/IEC 27001

Use ISO/IEC 27001 to build and audit an ISMS for a defined organizational scope. Certification is optional and covers the stated ISMS boundary.

Second framework
NIS2

Use and the applicable national transposition to decide which legal entities and services are covered and which governance, security, reporting, supervision, and enforcement rules apply.

Comparison row 1

Scope and covered activity

ISO/IEC 27001

ISO/IEC 27001 is a certifiable ISMS requirements standard that organizes information security governance, risk treatment, controls, evidence, audit, and continual improvement.

NIS2

applies primarily to entity types in Annex I or II that qualify as medium-sized enterprises or exceed the medium-enterprise ceilings and provide services or activities in the EU. Article 2 also brings specified entities into scope regardless of size, excludes certain public-administration security activities, and permits specified exemptions and Member State identification. Article 4 can displace corresponding NIS2 provisions where sector-specific EU requirements are at least equivalent in effect.

Operational implication

Perform the entity, sector, size, establishment, exclusion, sector-rule, and national-law analysis first. Compare that legal boundary with the certificate holder and ISMS scope; neither boundary proves the other.

Comparison row 2

Who must act

ISO/IEC 27001

Top management must establish the ISMS policy and roles, integrate ISMS requirements into business processes, provide resources, and review the system. Risk owners approve treatment and accept residual information-security risks.

NIS2

The covered essential or important entity carries the duties. Its management body must approve Article 21 measures, oversee implementation, and receive training; Member States must encourage comparable training for employees. Operational teams still need named roles for risk, suppliers, incidents, and authority contact.

Operational implication

Map ISO roles to duties, but keep the legal entity and management-body accountability explicit. Suppliers may support controls; they do not inherit the covered entity's statutory responsibility merely because they operate a service.

Comparison row 3

Trigger or threshold

ISO/IEC 27001

An organization chooses to implement ISO/IEC 27001, often for risk governance, customer assurance, or certification. The standard then requires it to define the ISMS scope and apply the clauses within that boundary.

NIS2

applicability follows Article 2, the Annex I and II entity types, the size-cap rule and exceptions, EU establishment or service rules, and national transposition. Article 3 then classifies in-scope entities as essential or important.

Operational implication

Do not wait for a customer request or incident to test scope. Record the facts behind the size calculation, sector and service classification, establishment, exception, and essential-or-important result.

Comparison row 4

Core obligations

ISO/IEC 27001

Clauses 4 to 10 require an ISMS covering context, leadership, planning, support, operation, performance evaluation, and improvement. Risk treatment includes determining necessary controls, checking them against Annex A, and maintaining a Statement of Applicability.

NIS2

Article 21 requires appropriate and proportionate technical, operational, and organizational measures using an all-hazards approach. Its minimum topics include risk analysis, incident handling, continuity and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access security, asset management, and multi-factor or continuous authentication where appropriate.

Operational implication

Map each measure to the national provision, responsible owner, implementation, and evidence. An Annex A label alone does not show that the legal measure is proportionate or effective for the covered service.

Comparison row 5

Evidence and records

ISO/IEC 27001

ISO/IEC 27001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.

NIS2

evidence should show the applicability decision, management-body approval and oversight, Article 21 risk measures and effectiveness checks, supplier-security decisions, significant-incident assessments and notifications, and information supplied to competent authorities.

Operational implication

Build an evidence matrix with one row per national duty and columns for legal source, entity and service, owner, measure, artifact, date, review trigger, and any linked ISO clause or control.

Comparison row 6

Timing and cadence

ISO/IEC 27001

ISO/IEC 27001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.

NIS2

Member States were required to transpose by 17 October 2024 and apply those measures from 18 October 2024. For a significant incident, Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and ordinarily a final report within one month after that notification, with special branches for ongoing incidents and trust service providers.

Operational implication

Use the applicable national reporting route and definitions. ISO review and audit dates do not pause or replace a statutory incident clock.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27001

ISO/IEC 27001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.

NIS2

requires Member States to supervise and enforce national duties. Essential entities are subject to ex ante and ex post supervision; important entities are generally subject to ex post supervision when authorities receive evidence or indications of non-compliance. Article 34 sets minimum maximum-fine levels for Article 21 or 23 infringements: the higher of EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities.

Operational implication

An ISO certification audit is not supervision. Track authority requests, audits, orders, remediation, and possible penalties under the applicable national law separately from certification findings.

Comparison row 8

Overlap and reuse

ISO/IEC 27001

ISO/IEC 27001 can supply reusable management-system evidence, control operation records, risk decisions, and review outputs.

NIS2

can reuse ISMS evidence where it demonstrates the covered entity's applicable risk measure or governance process, but legal scope decisions, management-body duties, incident notifications, authority interactions, and national registration records remain NIS2-specific.

Operational implication

Reuse evidence only after checking the legal entity, covered service, system, supplier, owner, period, national provision, and acceptance criteria. Record partial coverage instead of calling a control equivalent.

Comparison row 9

Practical decision rule

ISO/IEC 27001

Use ISO/IEC 27001 when the main work is building, operating, reviewing, or proving a management-system or standards-based control process.

NIS2

Use when deciding legal coverage or implementing management-body governance, Article 21 measures, Article 23 reporting, registration, supervision, or enforcement duties under national law.

Operational implication

If both apply, use the ISMS to operate controls and evidence, while the register preserves the legal actor, provision, deadline, authority, and national variation.

Practical decision rule

How should teams decide between ISO/IEC 27001 and NIS2 for compliance planning?

  • If you need a certifiable management system for information security governance, risk treatment, controls, audit, and continual improvement, start with ISO/IEC 27001. Its clauses 4 to 10 and Annex A give you the operating structure.
  • If you need to determine whether an entity is covered, classify it as essential or important, or implement governance, Article 21 measures, Article 23 reporting, supervision, and enforcement duties, start with and the applicable national transposition.
  • When both apply, keep the legal obligation, the ISMS decision, and the evidence set distinct; reuse records only where the same owner, scope, time period, system, supplier, data type, and acceptance criteria apply.
Section 1

Are ISO/IEC 27001 and NIS2 the same kind of requirement?

No. ISO/IEC 27001 is a voluntary, certifiable management-system requirements standard. is an EU directive whose binding duties depend on legal scope, Member State transposition, the covered entity and services, and the competent authority.

ISO/IEC 27001 can organize scope, risk management, controls, evidence, internal audit, management review, and improvement. A certificate does not decide whether an entity is essential or important, satisfy statutory incident-reporting timelines by itself, or replace national-law supervision and enforcement.

  • Use ISO/IEC 27001 when you need a management-system structure for scope, risk assessment, Annex A controls, internal audit, and management review, as set out in the standard's clauses 4 to 10.
  • Use when the question is a legal one: whether a covered entity must meet EU cybersecurity obligations, incident-reporting deadlines, or national supervision and enforcement requirements.
  • If both apply, keep the legal duty and the management-system evidence separate, then reuse only the records that match the same owner, scope, date, and acceptance criteria.
Section 2

Which ISO/IEC 27001 evidence can support NIS2, and what remains separate?

Reusable evidence can include governance roles, risk methodology and results, treatment plans, supplier-security records, incident processes, continuity evidence, vulnerability handling, access controls, cryptography, logging, internal audits, management reviews, and corrective actions, but only when the evidence covers the same legal entity, service, system, date, and obligation.

Keep separate records for legal applicability, management-body duties, national registration or notification, significant-incident classification and deadlines, competent-authority interactions, and any national measures or enforcement requirements not represented by the ISMS certificate.

  • Map each reused artifact to the article or national requirement it supports; do not use 'ISO certified' as the mapping.
  • Record scope differences between the certified ISMS and the regulated entity, service, network and information systems, establishments, and supply chain.
  • Add legal owners and statutory deadlines separately from ISO process owners and internal review dates.
  • Treat gaps as legal implementation work even when the ISO audit raised no finding.
Recommended next step

Operationalize ISO/IEC 27001 vs NIS2

Assign owners to the NIS2 applicability decision and each mapped measure, request evidence, record scope differences, and track legal and ISMS review dates.

Section 4

Which equivalence assumptions create compliance gaps?

Do not treat a certification decision as a legal opinion. A certification body evaluates conformity of a stated ISMS scope; it does not determine applicability, interpret every national transposition, or certify compliance with statutory reporting and enforcement duties unless a separate scheme expressly says so.

Control-name matching can also hide gaps. An Annex A control can support a measure, but the responsible entity must still show that the implementation, scope, proportionality, governance, and timing satisfy the applicable legal rule.

  • Do not state that ISO/IEC 27001 certification equals compliance.
  • Do not use the certificate scope as the legal-entity applicability analysis.
  • Do not replace statutory incident decisions and deadlines with the ISMS incident procedure's internal timetable.
Section 5

When should the ISO/NIS2 mapping be reviewed?

Review the mapping at planned ISMS intervals and whenever the legal entity, covered service, national law, authority guidance, supplier chain, system boundary, or incident process changes. duties come from the applicable national transposition, so a group operating in several Member States may need separate jurisdiction records.

After a change, update the applicability decision, Article 21 measure mapping, Article 23 reporting workflow, evidence owners, and management-body reporting. Keep the original legal source visible even when one control record supports both and ISO/IEC 27001.

  • Set a review date and triggers for acquisitions, new services, new establishments, material suppliers, major incidents, and national-law changes.
  • Test the significant-incident escalation path against the 24-hour early warning, 72-hour incident notification, and one-month final-report sequence in Article 23, subject to the Directive's specific conditions and national process.
  • Escalate gaps in Article 21 measures and incident readiness to the management body, which Article 20 requires to approve the measures and oversee implementation.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU cybersecurity directive used for regulatory comparison.
"measures for a high common level of cybersecurity"
iso.org
Referenced sections
  • This source is the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
"Information security management systems - Requirements"
iso.org
Referenced sections
  • This source supports control implementation guidance and control-implementation expectations supporting ISO/IEC 27001 governance.
"Information security controls"
iso.org
Referenced sections
  • This source supports risk treatment and monitoring context that informs control decisions and residual risk handling.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.