NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 vs ISO 27001: How They Overlap
Learn

NIS2 vs ISO 27001: How They Overlap

·Alexander Sverdlov
The short answer
ISO 27001 is a voluntary certification. NIS2 is law. Holding the certificate does not discharge the legal duty, and no supervisor accepts it as a substitute. What it does is cover a large share of the Article 21 measures already, so a certified organisation is usually most of the way there. The four things certification leaves open are national registration, the Article 23 reporting clocks, the management body's personal duty, and per-country variation.
On this page
  1. The core difference: law against certification
  2. Where the overlap is genuinely large
  3. The four gaps ISO 27001 leaves
  4. Does ISO 27001 help with a NIS2 inspection?
  5. The efficient order to do them in
  6. Frequently asked questions

The core difference: law against certification

NIS2 as binding law compared with ISO 27001 as a voluntary certification, and the large overlap between them
One is enforceable against you. The other is a certificate you choose to hold.

NIS2 is Directive (EU) 2022/2555, transposed into national law in each Member State. It applies to you by virtue of your sector and size, it is supervised, and non-compliance carries administrative fines and other sanctions, covered in NIS2 fines and penalties. Access control is one of the measures both regimes share; user access review software covers how to evidence it once for both. Supply chain security is one of the shared measures, worked through in how to perform a third-party risk assessment.

ISO 27001 is a standard you can be certified against by an accredited body. Nobody compels it. Its value is that it is recognised, it structures the work, and customers understand it.

The category error to avoid: treating the certificate as compliance. A supervisor examining you under national NIS2 law will ask whether your measures are appropriate and proportionate and whether you can evidence them. A certificate is useful supporting evidence in that conversation and it is not the answer to it.

Where the overlap is genuinely large

Article 21 lists ten areas of cybersecurity risk-management measures. Most map closely onto ISO 27001 Annex A.

NIS2 Article 21 measureCovered by an ISO 27001 ISMS?
Risk analysis and information system security policiesYes, this is the core of the management system
Incident handlingYes, Annex A covers incident management
Business continuity, backup management, crisis managementLargely, though NIS2 emphasises crisis management explicitly
Supply chain securityYes, supplier relationship controls
Security in acquisition, development and maintenanceYes
Policies to assess effectiveness of measuresYes, internal audit and management review
Basic cyber hygiene and security trainingYes, awareness controls
Cryptography and encryptionYes
Human resources security, access control, asset managementYes
Multi-factor authentication and secured communicationsLargely, though NIS2 names MFA explicitly

If you hold a current certificate with a scope that covers the relevant services, most of this is evidencing work rather than building work. That is the good news and it is real.

NIS2 gap assessment scoring the Article 21 measures
Most Article 21 measures map to Annex A. The assessment shows which ones your ISMS already answers.

The four gaps ISO 27001 leaves

  1. Registration. NIS2 requires in-scope entities to register with the competent authority, per country. No certification does this for you.
  2. The Article 23 reporting clocks. An early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month, filed into a national route. An ISMS incident process is a good starting point and it is not the same obligation.
  3. The management body's duty. Under NIS2 the management body approves the risk-management measures, oversees implementation, can be held liable, and must undertake training. ISO 27001 requires leadership commitment; it does not create personal exposure.
  4. Per-country variation. NIS2 binds you through national transposition, so thresholds, registration duties and reporting routes differ by Member State. A single certificate does not track twenty-seven implementations.
NIS2 requirements tracked per Member State with national deviations
The gap a certificate cannot close: obligations arrive through twenty-seven national laws.
NIS2 and ISO 27001 compared on legal force, scope, measures, certification, reporting and management duty
Six axes. The overlap is on measures; the divergence is everywhere else.

Does ISO 27001 help with a NIS2 inspection?

Yes, materially, in three ways. It gives you a documented management system a supervisor can follow. It gives you evidence that measures are tested for effectiveness, which Article 21 requires explicitly. And it gives you an external opinion that your controls operate, which is worth more than self-assertion.

What it will not do is answer the question of whether you registered, whether you met the reporting deadlines, or whether your management body approved the measures and can show it. Those are the questions that produce findings.

The efficient order to do them in

For an organisation facing both, doing them separately is the expensive path.

  1. Scope NIS2 first. Determine whether you are essential or important, in which countries. This sets everything else. Start with what NIS2 is and who must comply.
  2. Build one control set. Map the Article 21 measures and Annex A to shared controls so one piece of evidence answers both.
  3. Add the NIS2-only items. Registration, the reporting clocks, and the management body record.
  4. Certify if it earns its keep commercially. Certification is a customer-facing asset; treat the decision as a commercial one rather than a compliance one.
One control mapped across NIS2 and ISO 27001 with shared evidence
One control, one piece of evidence, counted by both. Running two separate programmes is the expensive way to reach the same place.

Do this in Venvera

Venvera maintains NIS2 and ISO 27001 as separate control sets that share evidence, so an artefact collected once answers both wherever the requirements overlap, and the NIS2-only items are tracked explicitly. Per-country transposition differences are modelled rather than averaged. See the NIS2 workspace and the ISO 27001 workspace, or start with the free NIS2 compliance checklist.

Frequently asked questions

Does ISO 27001 make you NIS2 compliant?

No. ISO 27001 is a voluntary certification and NIS2 is law, so the certificate cannot discharge the legal duty. It does cover a large share of the Article 21 measures, so a certified organisation is usually most of the way there on the technical and organisational side.

What does NIS2 require that ISO 27001 does not?

Registration with a national competent authority, the Article 23 reporting deadlines of 24 hours, 72 hours and one month, the management body's duty to approve and oversee the measures with personal liability attached, and tracking of per-country transposition differences.

Should we get certified if we are already doing NIS2?

Treat it as a commercial decision. Certification is a recognised signal to customers and it makes a supervisory conversation easier, but it is not required by the Directive.

Can one control set serve both?

Yes, and it is the main saving available. Most Article 21 measures map onto Annex A controls, so shared evidence answers both. The NIS2-only obligations then sit on top as a smaller, separate list.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING