Difference, mapping & the fastest route to compliance

NIS2 vs ISO 27001

NIS2 is mandatory — ISO/IEC 27001 is your accelerator. We show how EU Directive 2022/2555 and the international ISMS standard overlap, where the decisive gaps lie and how an existing ISO 27001 system shortens your NIS2 implementation by months. With a concrete article-to-Annex mapping and a clear recommendation for mid-sized businesses.

NIS2 and ISO 27001 in direct comparison

Same goal, different obligation: both aim at information security — but NIS2 is EU law with liability, ISO 27001 a certifiable standard

Regulation vs. standard

NIS2 (EU Directive 2022/2555) is mandatory EU law with fines of up to €10 million or 2% of annual turnover. ISO/IEC 27001 is a voluntary, certifiable standard. Both target information security — but with a different level of obligation.

Scope of application

NIS2 applies, depending on the sector, to around 30,000 companies in Germany (BSI estimate) across 18 sectors. ISO 27001 can be adopted voluntarily by any organisation. NIS2 dictates WHAT must be protected; ISO 27001 provides the HOW.

Shared risk core

Both require a risk-based approach, a management system that is actually practised and the anchoring of security at management level. Article 21 NIS2 and Annex A of ISO 27001 overlap to a large extent in terms of content.

Compliance accelerator

According to the BSI guidance, an existing ISMS based on ISO 27001 already covers a large part of the NIS2 minimum measures. Certified companies typically shorten their NIS2 project by several months.

The NIS2 gaps

ISO 27001 alone is not enough: NIS2 requires statutory reporting obligations (24h/72h), registration with the BSI, personal liability of management and supply chain security — points that go beyond the ISO scope.

Recommendation for SMEs

For mid-sized businesses, ISO 27001 is the pragmatic entry point: structured, recognised and eligible for funding. We combine a lean ISMS with a targeted NIS2 delta assessment — without duplicated effort.

AnyonewhotrulylivesISO27001hasalreadyimplementedupto80%oftheNIS2measurestherestisatargeteddelta.

The NIS2 → ISO 27001 mapping in detail

This is how the minimum measures from Article 21 NIS2 map to the controls in Annex A of ISO/IEC 27001:2022 — the foundation of every efficient NIS2 project

Governance & responsibility

Art. 21 (2) NIS2 requires security governance at management level — congruent with ISO 27001 Clause 5 (Leadership). Here ISO delivers the documented role and responsibility structure that NIS2 demands.

Risk management

The risk-based approach from Art. 21 (1) NIS2 corresponds to ISO 27001 Clauses 6 & 8 (risk assessment and treatment) as well as Annex A 5.7 (threat intelligence). An ISO risk process directly fulfils the NIS2 core requirement.

Incident management & reporting obligation

Art. 23 NIS2 mandates an initial report within 24h and a full report within 72h to the BSI. ISO 27001 Annex A 5.24–5.28 governs incident management — we add the statutory NIS2 reporting channels as a NIS2 delta.

Business continuity

Backup, emergency and crisis management under Art. 21 (2c) NIS2 are mirrored in ISO 27001 Annex A 5.29–5.30 and in ISO 22301. This is how you demonstrably safeguard the operational continuity required by NIS2.

Supply chain security

Art. 21 (2d) NIS2 requires security in the supply chain — mapped via ISO 27001 Annex A 5.19–5.23 (supplier relationships, cloud services). An often underestimated NIS2 focus that is relevant in audits.

Cryptography & access control

Encryption and MFA under Art. 21 (2h/j) NIS2 correspond to ISO 27001 Annex A 8.24 (cryptography) as well as A 5.15–5.18 & 8.5 (access control, secure authentication). Largely congruent from a technical perspective.

Awareness & cyber hygiene

Art. 21 (2g) NIS2 requires basic cyber hygiene and training — covered by ISO 27001 Annex A 6.3 (awareness) and Clause 7.2/7.3 (competence and awareness). On this basis we build a NIS2-compliant training programme.

Effectiveness measurement

Art. 21 (2f) NIS2 requires concepts for assessing effectiveness. ISO 27001 Clause 9 (performance evaluation: internal audits, management review) and 10 (continual improvement) provide the PDCA evidence that auditors and the BSI want to see.

Ready for the next step?

Let's discuss in a free initial consultation how we can move your business forward.