Side-by-sideGlobalISO/IEC 27035

ISO/IEC 27035 ISO/IEC 27035 vs NIS2

Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27035 can organize an incident-management capability, but it cannot establish NIS2 scope or legal compliance. NIS2 is an EU directive implemented through national law. An in-scope entity must apply the controlling national rules for governance, cybersecurity risk management, supervision, and reporting, then use ISO/IEC 27035 only as supporting operational guidance.

Side-by-side comparison

ISO/IEC 27035 vs NIS2: scope, duties, evidence, and decision rule

This comparison separates ISO/IEC 27035 operating guidance from NIS2 legal scope, governance, risk-management, and reporting duties, and shows where evidence can support both.

Review all sources
First framework
ISO/IEC 27035

ISO/IEC 27035 provides voluntary, adaptable guidance for building and operating an information security incident-management capability.

Second framework
NIS2

NIS2 requires Member States to establish cybersecurity risk-management, governance, supervision, and significant-incident reporting duties for covered entities. The operative requirements and procedures come from national implementation and applicable EU acts.

Comparison row 1

Scope and covered activity

ISO/IEC 27035

ISO/IEC 27035 structures information security incident management from preparation and detection through response and lessons learned.

NIS2

NIS2 generally reaches Annex I and II entity types that are medium-sized or larger, plus specified size-independent cases and entities identified under national criteria. Articles 2-4 contain exceptions and sector-specific interactions.

Operational implication

Determine the entity, service, size, Member State, essential or important classification, and any equivalent sector-specific EU regime before using ISO/IEC 27035 as an operating structure.

Comparison row 2

Who must act

ISO/IEC 27035

ISO/IEC 27035 separates management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design.

NIS2

Article 20 requires management bodies of essential and important entities to approve Article 21 measures, oversee implementation, and receive training. Operational, legal, communications, service, supplier, and authority-facing roles must support those duties under national law.

Operational implication

Map the incident coordinator and response teams to the management body's oversight, the legal significance decision, the authority submission owner, and service-recipient communications. Document deputies and out-of-hours authority.

Comparison row 3

Trigger or threshold

ISO/IEC 27035

The ISO/IEC 27035 process begins with readiness; an observed event is then reported, assessed, and either closed or handled as an incident under organization-defined criteria.

NIS2

Article 23 treats an incident as significant if it caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. National law and applicable implementing acts can add detail.

Operational implication

Run internal classification and the legal significance assessment in parallel. Record the facts, legal owner, controlling rule, awareness determination, and reasoning even when the result is not reportable.

Comparison row 4

Core obligations

ISO/IEC 27035

ISO/IEC 27035 guides policy, planning, roles, detection, triage, analysis, response, communications, records, and lessons learned.

NIS2

Articles 20 and 21 cover management approval, oversight and training, plus appropriate and proportionate all-hazards measures for risk analysis, incident handling, continuity, supply chains, secure development, effectiveness checks, cyber hygiene, cryptography, personnel, access, assets, and secure communications.

Operational implication

ISO/IEC 27035 mainly supports incident handling. Map the remaining legal measures to their actual owners and controls, and cite the applicable law - not ISO/IEC 27035 - as the source of each duty.

Comparison row 5

Evidence and records

ISO/IEC 27035

ISO/IEC 27035 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.

NIS2

NIS2 evidence can include scope and proportionality analysis, management approvals and training, risk-treatment records, significant-incident assessments, authority submissions, acknowledgements, updates, and remediation records required by national law.

Operational implication

Build an evidence matrix with one row per claim and columns for source, owner, artifact, date, review trigger, and reuse permission.

Comparison row 6

Timing and cadence

ISO/IEC 27035

ISO/IEC 27035 timing follows implementation, exercise, review, supplier, incident, or change cycles rather than a single universal deadline.

NIS2

Article 23 sets an early warning within 24 hours of awareness, an incident notification within 72 hours, requested intermediate reports, and a final report no later than one month after the incident notification. An ongoing incident instead receives a progress report then and a final report within one month after handling ends. By derogation from the 72-hour rule, a trust service provider must submit the incident notification within 24 hours of awareness when the affects the provision of its trust services.

Operational implication

Keep awareness evidence and statutory submissions separate from internal acknowledgement, triage, containment, and recovery targets. Apply the national route and any sector-specific rule; ISO/IEC 27035 does not change the clock.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27035

ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.

NIS2

National competent authorities supervise and enforce the transposed duties. Essential entities are subject to ex ante and ex post supervision under Article 32; important entities are generally subject to ex post supervision under Article 33 when evidence or indications of non-compliance arise.

Operational implication

Separate ISO adoption evidence from legal compliance. Confirm national supervisory powers, remedies, penalties, and authority practice rather than inferring them from the directive or an ISO audit.

Comparison row 8

Overlap and reuse

ISO/IEC 27035

ISO/IEC 27035 can supply reusable management-system evidence, control operation records, risk decisions, and review outputs.

NIS2

The same incident plan, exercise, chronology, analysis, response log, communication record, and corrective action may support national NIS2 duties when it addresses the legal requirement and covered entity.

Operational implication

Reuse evidence only after checking the legal entity, service, jurisdiction, duty, owner, date, submission content, and authority receipt. A framework record can support a duty without proving compliance by itself.

Comparison row 9

Practical decision rule

ISO/IEC 27035

Use ISO/IEC 27035 to design and improve how the organization handles information security events and incidents.

NIS2

Use national transposition, applicable EU acts, and competent-authority instructions to decide entity scope, legal significance, reporting content and timing, governance accountability, supervision, and enforcement exposure.

Operational implication

If both apply, let law determine the obligation and ISO/IEC 27035 organize the people, process, evidence, and improvement loop used to meet it.

Practical decision rule

How should teams decide between ISO/IEC 27035 and NIS2 for compliance planning?

  • Use ISO/IEC 27035 when the work is about building or proving an incident-management process; use NIS2 when the work is about legal scope, supervision, or mandatory reporting duties.
  • If NIS2 applies, use ISO/IEC 27035 to organize the response process and evidence, but keep the law as the source of the obligation.
  • Reuse evidence only where the same owner, scope, time period, system, supplier, data type, and acceptance criteria apply.
Section 1

Can ISO/IEC 27035 satisfy NIS2 incident requirements?

No. ISO/IEC 27035 can help design incident policy, teams, criteria, reporting routes, records, response operations, and lessons learned. It does not determine whether an entity falls within Annex I or II, whether a size or special-scope rule applies, whether the entity is essential or important, or which national authority and reporting channel control.

NIS2 generally covers Annex I or II entity types that qualify as medium-sized enterprises or exceed that size, but Article 2 also brings specified entities into scope regardless of size and permits some national extensions. Article 4 can displace the directive's risk-management or reporting provisions where sector-specific EU law imposes requirements at least equivalent in effect. Confirm the entity, service, establishment, size calculation, national implementation, and any sector-specific rule before mapping ISO controls.

  • Classify the entity as essential or important under Article 3 and national law; the distinction affects supervision, but both categories are subject to Articles 20, 21, and 23.
  • Map each applicable legal duty to an owner, procedure, evidence record, authority channel, and clock. Keep ISO guidance as the implementation reference, not the source of the duty.
  • Do not infer NIS2 compliance, scope exclusion, or a reporting exemption from ISO adoption, certification, audit evidence, or an internal severity rating.
Section 2

Which records should prove ISO/IEC 27035 vs NIS2 is implemented correctly?

Keep an applicability record showing the legal entity, services, Member States, Annex sector and entity type, employee and financial size calculation where relevant, essential or important classification, competent authority or CSIRT, registration details, and any Article 4 sector-specific rule. Revisit it after acquisitions, restructurings, new services, new Member States, and national-law changes.

For operations, retain management-body approvals and training, the Article 21 risk and proportionality analysis, incident-handling procedures, exercises, significant-incident assessments, awareness timestamps, early warnings, incident notifications, requested intermediate reports, final or progress reports, authority acknowledgements, service-recipient communications where required, and corrective actions. The incident record should preserve what was known at each submission time rather than overwrite the earlier assessment.

  • Scope evidence: entity and service inventory, size calculation, Annex mapping, essential or important classification, jurisdiction analysis, registrations, and authority contacts.
  • Governance evidence: management-body approval and oversight of Article 21 measures, management training, risk decisions, resources, and tracked remediation.
  • Incident evidence: event chronology, significant-incident assessment, awareness time, submission content and receipts, cross-border impact analysis, recipient communications, mitigation, root cause, and closure.
Section 3

What is the NIS2 significant-incident reporting workflow?

Run the ISO/IEC 27035 event assessment and the legal significance test in parallel. Under Article 23(3), an incident is significant if it caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Applicable national law and, for specified digital and trust-service entities, Commission Implementing Regulation (EU) 2024/2690 can add operational detail.

For a , Article 23 sets an early warning without undue delay and within 24 hours of awareness, followed by an incident notification without undue delay and within 72 hours. Submit an intermediate report if the CSIRT or competent authority requests one. Submit a final report no later than one month after the 72-hour incident notification; if the incident is still ongoing, submit a progress report then and a final report within one month after handling ends. By derogation from the 72-hour rule, a trust service provider must submit the incident notification without undue delay and within 24 hours of awareness when the significant incident affects the provision of its trust services.

  • Record when the entity became aware of facts meeting the significant-incident test; do not substitute detection time, ticket creation time, or an internal severity upgrade without analysis.
  • Preserve the information available at 24 hours and update it at 72 hours, including initial severity, impact, and available indicators of compromise.
  • Use the national reporting route and instructions. Coordinate separate GDPR, DORA, sector, law-enforcement, contractual, insurer, and customer notices where they apply.
Section 4

What mistakes make ISO/IEC 27035 vs NIS2 weak or hard to audit?

Do not equate an internal incident severity with the legal significant-incident test. Internal labels can route response work, but Article 23 asks about actual or capable operational disruption, financial loss, and damage to other persons.

Another error is to cite the directive without checking national law. The directive required Member States to adopt transposition measures by 17 October 2024 and apply them from 18 October 2024, but national definitions, registration mechanisms, authorities, channels, procedures, and penalties are the operative details for an entity.

  • Do not start the 24-hour clock only after executive, legal, or crisis-committee confirmation if awareness occurred earlier under the controlling rule.
  • Do not delay the early warning until root cause, full scope, or final impact is known; the staged process allows later updates.
  • Do not treat ISO/IEC 27035 as certification of NIS2 compliance or as a substitute for management-body duties, the all-hazards measures in Article 21, or national supervision.
Section 5

How should teams review and improve ISO/IEC 27035 vs NIS2 over time?

After an incident or exercise, compare the ISO/IEC 27035 response record with every applicable legal submission. Check awareness determination, significance analysis, escalation, authority access, submission timing, content, cross-border assessment, service-recipient communications, and preservation of evidence.

Route process and control failures into corrective actions for the Article 21 measures and management oversight. Recheck scope and national requirements when services, size, ownership, establishment, suppliers, or sector rules change. An ISO lesson learned closes only after the responsible owner implements and verifies the change; a legal reporting failure cannot be closed through framework tailoring.

  • Exercise the 24-hour and 72-hour submissions with incomplete facts and unavailable primary contacts.
  • Test supplier escalation clauses against the time the entity needs to make its own significance decision.
  • Report unresolved authority, scope, resource, or legal-clock risks to the management body.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Adds technical and methodological requirements and specified significance criteria for the digital infrastructure, digital provider, managed-service, social-platform, and trust-service entity types listed in the regulation.
eur-lex.europa.eu
Referenced sections
  • Articles 2-4, 20-23, 32-33, and 41 support the scope, governance, risk-management, reporting, supervision, and transposition distinctions in this comparison.
"measures for a high common level of cybersecurity"
iso.org
Referenced sections
  • Primary ISO listing for incident management principles and process.
"preparing for, detecting, reporting, assessing, and responding to incidents"
iso.org
Referenced sections
  • Primary ISO listing for planning, preparing, and lessons-learned guidance.
"plan and prepare for incident response and to learn lessons"
iso.org
Referenced sections
  • Primary ISO listing for ICT incident response operations guidance.
"information security incident response in ICT security operations"
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.