ISO 27001 and NIS2 are different kinds of thing: NIS2 is EU law that applies to you or does not, and ISO 27001 is a certification you choose to hold. Holding ISO 27001 does not make you NIS2 compliant, but it answers most of what NIS2 asks for technically: of the 13 Annex sections of Implementing Regulation (EU) 2024/2690, eleven are satisfied by a conforming ISO 27001 management system and two ask for more. The mapping is published section by section.
What NIS2 actually asks for
The EU-uniform part of NIS2 is Implementing Regulation (EU) 2024/2690, which lists the security measures in 13 Annex sections. That is a Regulation rather than a Directive, so it applies without national transposition and it is specific enough to check against.
We have mapped all 13 sections against the ISO 27001 controls that satisfy them. The full mapping is here, section by section.
The short version
Most of it overlaps. An organisation running a certified ISMS already has policy, risk management, incident handling, business continuity, supply chain security, access control, asset management, cryptography and human resources security, because Annex A covers all of them and the clauses require them to operate.
Two places it does not. Incident reporting deadlines are a legal obligation with clocks attached, and no ISO standard imposes them. And management-body accountability under NIS2 is personal in a way clause 5 is not.
Certification is not compliance
Holding ISO 27001 does not make you NIS2 compliant, and no auditor will say it does. What it gives you is most of the evidence, already organised, plus a management system that is running rather than described. If NIS2 reaches you, an existing ISMS makes the gap analysis short.
The direction that does not work is the reverse: doing the minimum for NIS2 does not get you a certificate, because certification tests a management system operating over a period.
If both apply to you
Do not run two systems. Clauses 4 to 10 are the Harmonized Structure shared across modern ISO management standards, and the same records serve both obligations. Keep one set, mapped to both, and the annual burden stops doubling.
The Cyber Resilience Act is a third thing again, with its own reporting clocks starting 11 September 2026. If you make products with digital elements, the deadline calculator is here.