NIS2: all pages and articles

Implementing Regulation (EU) 2024/2690 · Annex

NIS2, mapped to ISO 27001

Most of what NIS2 asks for technically is the same in every member state, because that part is a Regulation rather than a Directive, and it was written from ISO 27001. If you run a conforming ISMS you have already built most of this. Here is the whole Annex, section by section, and the two places it asks for more.

Two different instruments, and only one of them is portable

The controls are a Regulation. Implementing Regulation (EU) 2024/2690 applies directly in all 27 member states: the same text, no national version. Everything around them is a Directive. Registration, which authority supervises you, the filing portal and the penalties all come from 27 separate national laws that differ in substance. This page covers the first and deliberately says nothing about the second.

The national laws themselves, as each state communicated them to the Commission, are on their own page: NIS2 transposition by member state.

Recital 3 of the Regulation is explicit about where its requirements come from. They are “based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401”. That is what makes a crosswalk possible rather than approximate.

The Annex, section by section

1. Policy on the security of network and information systems

Art. 21(2)(a) NIS2

Satisfied by

2. Risk management policy

Art. 21(2)(a) NIS2

Satisfied by

3. Incident handling

Art. 21(2)(b) NIS2

Satisfied by

Not covered by ISO 27001: The statutory clock. ISO 27001 requires an incident process; it does not require a 24-hour early warning, a 72-hour notification, dual filing to a CSIRT and a competent authority, or a significance test. IR Arts. 3–14 make those mechanical and EU-uniform. Art. 3(1)(a) is €500,000 or 5% of turnover, whichever is lower, and none of it falls out of an ISMS by itself.

4. Business continuity and crisis management

Art. 21(2)(c) NIS2

Satisfied by

5. Supply chain security

Art. 21(2)(d) NIS2

Satisfied by

6. Security in network and information systems acquisition, development and maintenance

Art. 21(2)(e) NIS2

Satisfied by

7. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures

Art. 21(2)(f) NIS2

Satisfied by

  • Clause 9.1
  • Clause 9.2
  • Clause 9.3
  • Clause 10.1
  • Clause 10.2

8. Basic cyber hygiene practices and security training

Art. 21(2)(g) NIS2

Satisfied by

Not covered by ISO 27001: Training the management body. Art. 20(2) NIS2 requires members of the management body themselves to follow training, and Art. 20(1) makes them personally liable for approving and overseeing the measures. ISO 27001 asks for leadership commitment and competence; it does not put the board in the training register or attach liability to the signature.

9. Cryptography

Art. 21(2)(h) NIS2

Satisfied by

10. Human resources security

Art. 21(2)(i) NIS2

Satisfied by

11. Access control

Art. 21(2)(j) NIS2

Satisfied by

12. Asset management

Art. 21(2)(j) NIS2

Satisfied by

13. Physical and environmental security

Art. 21(2)(j) NIS2

Satisfied by

Where an ISMS stops, in 2 places

Everything else in that Annex falls out of a conforming ISO 27001 management system. These do not, and no amount of ISO conformity produces them:

  • 3. Incident handling

    The statutory clock. ISO 27001 requires an incident process; it does not require a 24-hour early warning, a 72-hour notification, dual filing to a CSIRT and a competent authority, or a significance test. IR Arts. 3–14 make those mechanical and EU-uniform. Art. 3(1)(a) is €500,000 or 5% of turnover, whichever is lower, and none of it falls out of an ISMS by itself.

  • 8. Basic cyber hygiene practices and security training

    Training the management body. Art. 20(2) NIS2 requires members of the management body themselves to follow training, and Art. 20(1) makes them personally liable for approving and overseeing the measures. ISO 27001 asks for leadership commitment and competence; it does not put the board in the training register or attach liability to the signature.

What this page is not

It is not a coverage score. A single percentage for how much of NIS2 ISO 27001 covers gets quoted in a lot of places. Every version of it is a structural judgement rather than a measurement, and we are not going to repeat a number we cannot show the working for. ENISA published a machine-readable crosswalk in its Technical Implementation Guidance (v1.0, June 2025); the mapping above is ours, from the two documents, and you should check it against theirs rather than trust either of us.

It is not a NIS2 product. StandardOS does not register you with a national authority, does not file your incident reports, and does not track 27 national transpositions. If you need those, you need something else, and the honest version of our position is that the control set is the part worth building once, because it is the only part that is the same everywhere.

It is not a scope determination. NIS2 binds essential and important entities above the size thresholds in Article 2. Below roughly 50 people and €10m you are very likely outside it entirely, with sector exceptions. That determination is yours to make and record, and we will not make it for you on a marketing page.

Further reading

The overlap is the point

If a customer's questionnaire is really asking whether you manage security the way the Regulation describes, an ISO 27001 ISMS is the answer to eleven of these thirteen sections. StandardOS builds that ISMS: the Statement of Applicability, the risk register and the evidence trail. The export is organised by Annex A reference, which is the same vocabulary the table above uses.

Section titles are quoted from the Annex to Implementing Regulation (EU) 2024/2690 as published on EUR-Lex, read on August 10, 2026. The mapping to ISO/IEC 27001 is our own and is not ENISA's. This is not legal advice, and the Regulation is short enough to read yourself: Implementing Regulation (EU) 2024/2690.