Implementing Regulation (EU) 2024/2690 · Annex
NIS2, mapped to ISO 27001
Most of what NIS2 asks for technically is the same in every member state, because that part is a Regulation rather than a Directive, and it was written from ISO 27001. If you run a conforming ISMS you have already built most of this. Here is the whole Annex, section by section, and the two places it asks for more.
Two different instruments, and only one of them is portable
The controls are a Regulation. Implementing Regulation (EU) 2024/2690 applies directly in all 27 member states: the same text, no national version. Everything around them is a Directive. Registration, which authority supervises you, the filing portal and the penalties all come from 27 separate national laws that differ in substance. This page covers the first and deliberately says nothing about the second.
The national laws themselves, as each state communicated them to the Commission, are on their own page: NIS2 transposition by member state.
Recital 3 of the Regulation is explicit about where its requirements come from. They are “based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401”. That is what makes a crosswalk possible rather than approximate.
The Annex, section by section
1. Policy on the security of network and information systems
Art. 21(2)(a) NIS2
Satisfied by
2. Risk management policy
Art. 21(2)(a) NIS2
Satisfied by
3. Incident handling
Art. 21(2)(b) NIS2
Satisfied by
Not covered by ISO 27001: The statutory clock. ISO 27001 requires an incident process; it does not require a 24-hour early warning, a 72-hour notification, dual filing to a CSIRT and a competent authority, or a significance test. IR Arts. 3–14 make those mechanical and EU-uniform. Art. 3(1)(a) is €500,000 or 5% of turnover, whichever is lower, and none of it falls out of an ISMS by itself.
6. Security in network and information systems acquisition, development and maintenance
Art. 21(2)(e) NIS2
Satisfied by
7. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
Art. 21(2)(f) NIS2
Satisfied by
- Clause 9.1
- Clause 9.2
- Clause 9.3
- Clause 10.1
- Clause 10.2
8. Basic cyber hygiene practices and security training
Art. 21(2)(g) NIS2
Satisfied by
Not covered by ISO 27001: Training the management body. Art. 20(2) NIS2 requires members of the management body themselves to follow training, and Art. 20(1) makes them personally liable for approving and overseeing the measures. ISO 27001 asks for leadership commitment and competence; it does not put the board in the training register or attach liability to the signature.
12. Asset management
Art. 21(2)(j) NIS2
Satisfied by
Where an ISMS stops, in 2 places
Everything else in that Annex falls out of a conforming ISO 27001 management system. These do not, and no amount of ISO conformity produces them:
3. Incident handling
The statutory clock. ISO 27001 requires an incident process; it does not require a 24-hour early warning, a 72-hour notification, dual filing to a CSIRT and a competent authority, or a significance test. IR Arts. 3–14 make those mechanical and EU-uniform. Art. 3(1)(a) is €500,000 or 5% of turnover, whichever is lower, and none of it falls out of an ISMS by itself.
8. Basic cyber hygiene practices and security training
Training the management body. Art. 20(2) NIS2 requires members of the management body themselves to follow training, and Art. 20(1) makes them personally liable for approving and overseeing the measures. ISO 27001 asks for leadership commitment and competence; it does not put the board in the training register or attach liability to the signature.
What this page is not
It is not a coverage score. A single percentage for how much of NIS2 ISO 27001 covers gets quoted in a lot of places. Every version of it is a structural judgement rather than a measurement, and we are not going to repeat a number we cannot show the working for. ENISA published a machine-readable crosswalk in its Technical Implementation Guidance (v1.0, June 2025); the mapping above is ours, from the two documents, and you should check it against theirs rather than trust either of us.
It is not a NIS2 product. StandardOS does not register you with a national authority, does not file your incident reports, and does not track 27 national transpositions. If you need those, you need something else, and the honest version of our position is that the control set is the part worth building once, because it is the only part that is the same everywhere.
It is not a scope determination. NIS2 binds essential and important entities above the size thresholds in Article 2. Below roughly 50 people and €10m you are very likely outside it entirely, with sector exceptions. That determination is yours to make and record, and we will not make it for you on a marketing page.
Further reading
The ten measures of NIS2 Article 21(2), as a checklist: each point quoted, the Regulation sections behind it, and the ISO 27001 controls that already produce it
Article 21(2) lists ten measures every essential and important entity must take, from risk analysis policies to multi-factor authentication. For cloud, managed service and the other digital providers, Implementing Regulation 2024/2690 details each in 13 sections written from ISO/IEC 27001 and 27002. One table: the ten points as the Directive words them, the sections that detail each, and the ISO 27001 clauses and Annex A controls that produce the evidence, with the two places an ISMS does not reach.
NIS2 Article 20 for the board: what the management body must approve, oversee and learn, the twelve places the Implementing Regulation names it, and what liability means
Article 20 of NIS2 makes the management body of an essential or important entity approve the cybersecurity risk-management measures, oversee their implementation, be liable for the entity's infringements of Article 21, and follow training. Implementing Regulation 2024/2690 then names the management body in twelve places of its Annex: a dated approval of the policy, an annual review, a direct reporting line, acceptance of residual risk, compliance reporting, an awareness programme. Each of the twelve as a record, the ISO 27001 clause that already produces it, and what Article 32 and Article 34 say liability looks like.
NIS2 for a SaaS company: you are a cloud computing service provider, and this is what follows
Recital 33 of the Directive names Software as a Service as a cloud service model, so a SaaS company of medium size or larger is an entity of NIS2 as a cloud computing service provider: important below the medium ceilings, essential above them. What follows, in the order it arrives: the state of your main establishment, the registry you had to be in by 17 January 2025, the measures of Implementing Regulation 2024/2690, the four incident thresholds of its Article 7 and the Article 23 clocks, and the line between this and the CRA.
NIS2 for managed service providers and MSSPs: an Annex I entity by definition, and the supplier every customer's due diligence lands on
Article 6(39) makes anyone who installs, manages, operates or maintains ICT for customers, on site or remotely, a managed service provider, and Article 6(40) makes the ones who help with cybersecurity risk management MSSPs. Both are Annex I types: important at medium size, essential above the ceilings, under the law of the main establishment, in ENISA's registry, under Implementing Regulation 2024/2690 directly, with Article 10's four incident thresholds. And recital 86 tells every essential and important customer to exercise increased diligence in choosing you.
NIS2 or CRA: which incident clock runs for a software company, and what makes an incident 'significant'
Both laws give you 24 hours, 72 hours and a month, and both start the clock when you 'become aware'. Almost everything else differs: what triggers it, who receives it, on which platform, and what counts. NIS2 Article 23 and Implementing Regulation 2024/2690 for the company that runs a cloud service; CRA Article 14 for the company that ships a product; both for the company that does both. The thresholds, criterion by criterion, and one procedure that satisfies the two.
ISO 27001 vs NIS2: what the certificate covers and what it does not
NIS2 is law and ISO 27001 is a certifiable standard, so they are not alternatives. Here is where an existing ISMS satisfies the directive's requirements, and the two places it does not.
NIS2 transposition, state by state: what the Commission's own register shows
Not a law firm's tracker: the national measures the member states have communicated to the Commission as transposing Directive (EU) 2022/2555, read from the Publications Office on 12 September 2026. 25 of the 27 states have communicated at least one, 303 measures in all; Spain and Ireland none; France 15 texts, all older than the Directive. The act each state calls its NIS2 law, when it entered into force, and what a software company does with the answer.
CRA or NIS2: which one applies to a software company, and can it be both?
The Cyber Resilience Act regulates products placed on the market; NIS2 regulates entities that provide services. A software company can be under one, the other, both or neither, and the answer turns on two questions: do you place a product on the market, and are you a medium-sized or larger entity in a listed sector. The dates, the reporting clocks, the fines and the decision table, from the two texts.
Which EU countries name ISO 27001 in public tenders: 1,548 German notices, 829 Polish, and Greece has the highest share
Over 365 days, ISO 27001 appears in 3,415 TED notices. Germany and Poland account for 70% of them, Greece names it in 2% of everything it buys, and France, Spain and Italy barely name it at all. The numbers by country, and the query to re-run them.
The overlap is the point
If a customer's questionnaire is really asking whether you manage security the way the Regulation describes, an ISO 27001 ISMS is the answer to eleven of these thirteen sections. StandardOS builds that ISMS: the Statement of Applicability, the risk register and the evidence trail. The export is organised by Annex A reference, which is the same vocabulary the table above uses.
Section titles are quoted from the Annex to Implementing Regulation (EU) 2024/2690 as published on EUR-Lex, read on August 10, 2026. The mapping to ISO/IEC 27001 is our own and is not ENISA's. This is not legal advice, and the Regulation is short enough to read yourself: Implementing Regulation (EU) 2024/2690.