Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.
ISO/IEC 27035 can organize an incident-management capability, but it cannot establish NIS2 scope or legal compliance. NIS2 is an EU directive implemented through national law. An in-scope entity must apply the controlling national rules for governance, cybersecurity risk management, supervision, and reporting, then use ISO/IEC 27035 only as supporting operational guidance.
Side-by-side comparison
ISO/IEC 27035 vs NIS2: scope, duties, evidence, and decision rule
This comparison separates ISO/IEC 27035 operating guidance from NIS2 legal scope, governance, risk-management, and reporting duties, and shows where evidence can support both.
ISO/IEC 27035 provides voluntary, adaptable guidance for building and operating an information security incident-management capability.
Second framework
NIS2
NIS2 requires Member States to establish cybersecurity risk-management, governance, supervision, and significant-incident reporting duties for covered entities. The operative requirements and procedures come from national implementation and applicable EU acts.
ISO/IEC 27035 vs NIS2: scope, duties, evidence, and decision rule
NIS2 generally reaches Annex I and II entity types that are medium-sized or larger, plus specified size-independent cases and entities identified under national criteria. Articles 2-4 contain exceptions and sector-specific interactions.
Determine the entity, service, size, Member State, essential or important classification, and any equivalent sector-specific EU regime before using ISO/IEC 27035 as an operating structure.
ISO/IEC 27035 separates management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design.
Article 20 requires management bodies of essential and important entities to approve Article 21 measures, oversee implementation, and receive training. Operational, legal, communications, service, supplier, and authority-facing roles must support those duties under national law.
Map the incident coordinator and response teams to the management body's oversight, the legal significance decision, the authority submission owner, and service-recipient communications. Document deputies and out-of-hours authority.
The ISO/IEC 27035 process begins with readiness; an observed event is then reported, assessed, and either closed or handled as an incident under organization-defined criteria.
Article 23 treats an incident as significant if it caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. National law and applicable implementing acts can add detail.
Run internal classification and the legal significance assessment in parallel. Record the facts, legal owner, controlling rule, awareness determination, and reasoning even when the result is not reportable.
ISO/IEC 27035 mainly supports incident handling. Map the remaining legal measures to their actual owners and controls, and cite the applicable law - not ISO/IEC 27035 - as the source of each duty.
ISO/IEC 27035 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
NIS2 evidence can include scope and proportionality analysis, management approvals and training, risk-treatment records, significant-incident assessments, authority submissions, acknowledgements, updates, and remediation records required by national law.
Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, requested intermediate reports, and a final report no later than one month after the incident notification. An ongoing incident instead receives a progress report then and a final report within one month after handling ends. By derogation from the 72-hour rule, a trust service provider must submit the incident notification within 24 hours of awareness when the affects the provision of its trust services.
Keep awareness evidence and statutory submissions separate from internal acknowledgement, triage, containment, and recovery targets. Apply the national route and any sector-specific rule; ISO/IEC 27035 does not change the clock.
ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.
National competent authorities supervise and enforce the transposed duties. Essential entities are subject to ex ante and ex post supervision under Article 32; important entities are generally subject to ex post supervision under Article 33 when evidence or indications of non-compliance arise.
Separate ISO adoption evidence from legal compliance. Confirm national supervisory powers, remedies, penalties, and authority practice rather than inferring them from the directive or an ISO audit.
The same incident plan, exercise, chronology, analysis, response log, communication record, and corrective action may support national NIS2 duties when it addresses the legal requirement and covered entity.
Reuse evidence only after checking the legal entity, service, jurisdiction, duty, owner, date, submission content, and authority receipt. A framework record can support a duty without proving compliance by itself.
Use national transposition, applicable EU acts, and competent-authority instructions to decide entity scope, legal significance, reporting content and timing, governance accountability, supervision, and enforcement exposure.
NIS2 generally reaches Annex I and II entity types that are medium-sized or larger, plus specified size-independent cases and entities identified under national criteria. Articles 2-4 contain exceptions and sector-specific interactions.
Determine the entity, service, size, Member State, essential or important classification, and any equivalent sector-specific EU regime before using ISO/IEC 27035 as an operating structure.
ISO/IEC 27035 separates management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design.
Article 20 requires management bodies of essential and important entities to approve Article 21 measures, oversee implementation, and receive training. Operational, legal, communications, service, supplier, and authority-facing roles must support those duties under national law.
Map the incident coordinator and response teams to the management body's oversight, the legal significance decision, the authority submission owner, and service-recipient communications. Document deputies and out-of-hours authority.
The ISO/IEC 27035 process begins with readiness; an observed event is then reported, assessed, and either closed or handled as an incident under organization-defined criteria.
Article 23 treats an incident as significant if it caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. National law and applicable implementing acts can add detail.
Run internal classification and the legal significance assessment in parallel. Record the facts, legal owner, controlling rule, awareness determination, and reasoning even when the result is not reportable.
ISO/IEC 27035 mainly supports incident handling. Map the remaining legal measures to their actual owners and controls, and cite the applicable law - not ISO/IEC 27035 - as the source of each duty.
ISO/IEC 27035 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
NIS2 evidence can include scope and proportionality analysis, management approvals and training, risk-treatment records, significant-incident assessments, authority submissions, acknowledgements, updates, and remediation records required by national law.
Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, requested intermediate reports, and a final report no later than one month after the incident notification. An ongoing incident instead receives a progress report then and a final report within one month after handling ends. By derogation from the 72-hour rule, a trust service provider must submit the incident notification within 24 hours of awareness when the affects the provision of its trust services.
Keep awareness evidence and statutory submissions separate from internal acknowledgement, triage, containment, and recovery targets. Apply the national route and any sector-specific rule; ISO/IEC 27035 does not change the clock.
ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.
National competent authorities supervise and enforce the transposed duties. Essential entities are subject to ex ante and ex post supervision under Article 32; important entities are generally subject to ex post supervision under Article 33 when evidence or indications of non-compliance arise.
Separate ISO adoption evidence from legal compliance. Confirm national supervisory powers, remedies, penalties, and authority practice rather than inferring them from the directive or an ISO audit.
The same incident plan, exercise, chronology, analysis, response log, communication record, and corrective action may support national NIS2 duties when it addresses the legal requirement and covered entity.
Reuse evidence only after checking the legal entity, service, jurisdiction, duty, owner, date, submission content, and authority receipt. A framework record can support a duty without proving compliance by itself.
Use national transposition, applicable EU acts, and competent-authority instructions to decide entity scope, legal significance, reporting content and timing, governance accountability, supervision, and enforcement exposure.
How should teams decide between ISO/IEC 27035 and NIS2 for compliance planning?
Use ISO/IEC 27035 when the work is about building or proving an incident-management process; use NIS2 when the work is about legal scope, supervision, or mandatory reporting duties.
If NIS2 applies, use ISO/IEC 27035 to organize the response process and evidence, but keep the law as the source of the obligation.
Reuse evidence only where the same owner, scope, time period, system, supplier, data type, and acceptance criteria apply.
Can ISO/IEC 27035 satisfy NIS2 incident requirements?
No. ISO/IEC 27035 can help design incident policy, teams, criteria, reporting routes, records, response operations, and lessons learned. It does not determine whether an entity falls within Annex I or II, whether a size or special-scope rule applies, whether the entity is essential or important, or which national authority and reporting channel control.
NIS2 generally covers Annex I or II entity types that qualify as medium-sized enterprises or exceed that size, but Article 2 also brings specified entities into scope regardless of size and permits some national extensions. Article 4 can displace the directive's risk-management or reporting provisions where sector-specific EU law imposes requirements at least equivalent in effect. Confirm the entity, service, establishment, size calculation, national implementation, and any sector-specific rule before mapping ISO controls.
Classify the entity as essential or important under Article 3 and national law; the distinction affects supervision, but both categories are subject to Articles 20, 21, and 23.
Map each applicable legal duty to an owner, procedure, evidence record, authority channel, and clock. Keep ISO guidance as the implementation reference, not the source of the duty.
Do not infer NIS2 compliance, scope exclusion, or a reporting exemption from ISO adoption, certification, audit evidence, or an internal severity rating.
Which records should prove ISO/IEC 27035 vs NIS2 is implemented correctly?
Keep an applicability record showing the legal entity, services, Member States, Annex sector and entity type, employee and financial size calculation where relevant, essential or important classification, competent authority or CSIRT, registration details, and any Article 4 sector-specific rule. Revisit it after acquisitions, restructurings, new services, new Member States, and national-law changes.
For operations, retain management-body approvals and training, the Article 21 risk and proportionality analysis, incident-handling procedures, exercises, significant-incident assessments, awareness timestamps, early warnings, incident notifications, requested intermediate reports, final or progress reports, authority acknowledgements, service-recipient communications where required, and corrective actions. The incident record should preserve what was known at each submission time rather than overwrite the earlier assessment.
Scope evidence: entity and service inventory, size calculation, Annex mapping, essential or important classification, jurisdiction analysis, registrations, and authority contacts.
Governance evidence: management-body approval and oversight of Article 21 measures, management training, risk decisions, resources, and tracked remediation.
Incident evidence: event chronology, significant-incident assessment, awareness time, submission content and receipts, cross-border impact analysis, recipient communications, mitigation, root cause, and closure.
What is the NIS2 significant-incident reporting workflow?
Run the ISO/IEC 27035 event assessment and the legal significance test in parallel. Under Article 23(3), an incident is significant if it caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Applicable national law and, for specified digital and trust-service entities, Commission Implementing Regulation (EU) 2024/2690 can add operational detail.
For a , Article 23 sets an early warning without undue delay and within 24 hours of awareness, followed by an incident notification without undue delay and within 72 hours. Submit an intermediate report if the CSIRT or competent authority requests one. Submit a final report no later than one month after the 72-hour incident notification; if the incident is still ongoing, submit a progress report then and a final report within one month after handling ends. By derogation from the 72-hour rule, a trust service provider must submit the incident notification without undue delay and within 24 hours of awareness when the significant incident affects the provision of its trust services.
Record when the entity became aware of facts meeting the significant-incident test; do not substitute detection time, ticket creation time, or an internal severity upgrade without analysis.
Preserve the information available at 24 hours and update it at 72 hours, including initial severity, impact, and available indicators of compromise.
Use the national reporting route and instructions. Coordinate separate GDPR, DORA, sector, law-enforcement, contractual, insurer, and customer notices where they apply.
What mistakes make ISO/IEC 27035 vs NIS2 weak or hard to audit?
Do not equate an internal incident severity with the legal significant-incident test. Internal labels can route response work, but Article 23 asks about actual or capable operational disruption, financial loss, and damage to other persons.
Another error is to cite the directive without checking national law. The directive required Member States to adopt transposition measures by 17 October 2024 and apply them from 18 October 2024, but national definitions, registration mechanisms, authorities, channels, procedures, and penalties are the operative details for an entity.
Do not start the 24-hour clock only after executive, legal, or crisis-committee confirmation if awareness occurred earlier under the controlling rule.
Do not delay the early warning until root cause, full scope, or final impact is known; the staged process allows later updates.
Do not treat ISO/IEC 27035 as certification of NIS2 compliance or as a substitute for management-body duties, the all-hazards measures in Article 21, or national supervision.
How should teams review and improve ISO/IEC 27035 vs NIS2 over time?
After an incident or exercise, compare the ISO/IEC 27035 response record with every applicable legal submission. Check awareness determination, significance analysis, escalation, authority access, submission timing, content, cross-border assessment, service-recipient communications, and preservation of evidence.
Route process and control failures into corrective actions for the Article 21 measures and management oversight. Recheck scope and national requirements when services, size, ownership, establishment, suppliers, or sector rules change. An ISO lesson learned closes only after the responsible owner implements and verifies the change; a legal reporting failure cannot be closed through framework tailoring.
Exercise the 24-hour and 72-hour submissions with incomplete facts and unavailable primary contacts.
Test supplier escalation clauses against the time the entity needs to make its own significance decision.
Report unresolved authority, scope, resource, or legal-clock risks to the management body.
Adds technical and methodological requirements and specified significance criteria for the digital infrastructure, digital provider, managed-service, social-platform, and trust-service entity types listed in the regulation.
Articles 2-4, 20-23, 32-33, and 41 support the scope, governance, risk-management, reporting, supervision, and transposition distinctions in this comparison.
"measures for a high common level of cybersecurity"