[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:iso-27001-vs-nis2":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","iso-27001-vs-nis2","ISO 27001 vs NIS2: what the certificate covers and what it does not","NIS2 is law and ISO 27001 is a certifiable standard, so they are not alternatives. Here is where an existing ISMS satisfies the directive's requirements, and the two places it does not.","2026-08-20",{"who":10,"when":11,"do":12},"A company that holds or plans ISO 27001 and is, or may be, an essential or important entity under NIS2: the certificate is a choice and the directive is law, one does not stand in for the other, and the same management system answers most of what the directive asks for technically.","The moment NIS2 reaches you through a national transposition, a supervisory authority's register or a customer's contract; the incident clocks run from awareness, not from certification, and an existing management system shortens the gap analysis but does not replace it.","Keep one management system mapped to both, read the published mapping of the implementing regulation's sections against the Annex A controls, close the two gaps by adding the incident reporting procedure with its clocks and the management body's approval and training, and never present the certificate as NIS2 compliance.","\nISO 27001 and NIS2 are different kinds of thing: NIS2 is EU law that applies to you or does not, and ISO 27001 is a certification you choose to hold. Holding ISO 27001 does not make you NIS2 compliant, but it answers most of what NIS2 asks for technically: of the 13 Annex sections of Implementing Regulation (EU) 2024\u002F2690, eleven are satisfied by a conforming ISO 27001 management system and two ask for more. The mapping is published section by section.\n\n## What NIS2 actually asks for\n\nThe EU-uniform part of NIS2 is Implementing Regulation (EU) 2024\u002F2690, which lists the security measures in 13 Annex sections. That is a Regulation rather than a Directive, so it applies without national transposition and it is specific enough to check against.\n\nWe have mapped all 13 sections against the ISO 27001 controls that satisfy them. [The full mapping is here](\u002Fnis2\u002Fiso-27001-mapping), section by section.\n\n## The short version\n\nMost of it overlaps. An organisation running a certified ISMS already has policy, risk management, incident handling, business continuity, supply chain security, access control, asset management, cryptography and human resources security, because Annex A covers all of them and the clauses require them to operate.\n\n**Two places it does not.** Incident reporting deadlines are a legal obligation with clocks attached, and no ISO standard imposes them. And management-body accountability under NIS2 is personal in a way clause 5 is not.\n\n## Certification is not compliance\n\nHolding ISO 27001 does not make you NIS2 compliant, and no auditor will say it does. What it gives you is most of the evidence, already organised, plus a management system that is running rather than described. If NIS2 reaches you, an existing ISMS makes the gap analysis short.\n\nThe direction that does not work is the reverse: doing the minimum for NIS2 does not get you a certificate, because certification tests a management system operating over a period.\n\n## If both apply to you\n\nDo not run two systems. Clauses 4 to 10 are the Harmonized Structure shared across modern ISO management standards, and the same records serve both obligations. Keep one set, mapped to both, and the annual burden stops doubling.\n\nThe Cyber Resilience Act is a third thing again, with its own reporting clocks starting 11 September 2026. If you make products with digital elements, [the deadline calculator is here](\u002Fcyber-resilience-act\u002Freporting-deadlines).\n",1789383986490]