Shop
nl

How far does ISO 27001 get you under NIS2?

Put NIS2 and ISO 27001 side by side and the overlap is striking. Many of the measures the directive demands already sit in Annex A of the standard. Business continuity does not, and for that The NIS2 Navigator's Handbook points to EN-ISO 22301. And a certificate proves compliance with neither.

How much of NIS2 does ISO 27001 already cover?

A substantial part, though not all of it. NIS2 deliberately aligns with existing international standards and asks for nothing that deviates from what you already apply. Recital 79 of the directive names the ISO/IEC 27000 series outright. Many NIS2 controls therefore turn up in Annex A of ISO/IEC 27001.

The handbook states it without hedging: "In relation to the NIS2 control requirements, you will find that many of the controls can be found in the ISO/IEC 27001 Annex A."

That overlap is no accident, because the standard builds an ISMS on the same risk-based reasoning. You are required to weigh every control in Annex A and then either implement it or justify leaving it out. Article 21 of NIS2 asks you to think in exactly the same way.

Where does ISO 27001 fall short of NIS2?

On business continuity. ISO/IEC 27001 approaches the subject from an information security angle, while article 21(2c) of NIS2 asks for backup management, disaster recovery and crisis management. The handbook puts it plainly: "The NIS2 part that is insufficiently covered by the ISO/IEC 27001 Annex A is the topic of business continuity."

For that gap the book points to EN-ISO 22301, which specifies the structure and requirements of a business continuity management system. It reaches beyond what NIS2 immediately requires, and that is precisely what makes it useful as guidance for building solid continuity measures. Both standards are approved by CEN and CENELEC, so you stay inside the European framework.

Explore the NIS2 standard

The standard page brings together the background, training and publications on NIS2.

More about this standard

Does an ISO 27001 certificate make you NIS2 compliant?

No. The handbook never claims it does, and the directive requires no entity to use certified products, services or processes. Member States may impose that themselves under article 24. A certificate shows your ISMS works; it says nothing about the NIS2 requirements that sit outside the standard.

What is at stake is considerable, because the competent authority can fine essential entities up to 10 million euro or 2% of global annual turnover. For important entities that ceiling drops to 7 million euro or 1.4% of turnover. Personal responsibility comes on top: article 20(1) puts approval of the programme with the management body, which is also liable for how effective it turns out to be.

Which standard should you reach for, and when?

It is not an either-or. ISO/IEC 27001 is your foundation for information security, EN-ISO 22301 covers the continuity side, and NIS2 stays more specific than either on certain points. If an ISMS is already running, start from the mapping in Annex C and close the gaps you find.

Topic ISO/IEC 27001 EN-ISO 22301
Information security (ISMS, Annex A) Core of the standard Not applicable
Business continuity (article 21(2c)) Insufficiently covered Purpose-built for it
Reporting to management (article 20(1)) Management Review usable as a basis Not applicable

Annex C of the handbook sets twelve NIS2 requirements against the standards: article 21.2 a) through j), plus article 21.3 and article 21.4. Each one appears in three columns — for ISO 27001:2022, ISO 27001:2013 and ISO 22301:2018 — so you can see at a glance where you are already covered.

If an ISO/IEC 27001 programme is running, there is one more piece of good news. The handbook notes: "Organizations running ISO/IEC 27001 programs can use the Management Review as the basis for compliance with this NIS2 requirement." That concerns the duty to report to the management body under article 20(1).

So the advice is unsatisfyingly simple: treat your ISMS as the foundation rather than the finished building. The standard carries you to the edge of information security, and continuity, reporting and the precise articles of the directive still ask for work of their own.

An ISMS is a head start, not a finish line

ISO/IEC 27001 covers a large share of the NIS2 controls, but business continuity and the reporting duty both need topping up.

Frequently asked questions

No. NIS2 encourages the use of European and international standards, but it obliges no entity to use certified products, services or processes. Member States may impose that on essential and important entities under article 24. Always check what your national law actually says.

Business continuity. The standard approaches the topic from an information security perspective, while article 21(2c) explicitly asks for backup management, disaster recovery and crisis management. The handbook calls this the part insufficiently covered by Annex A, and points to EN-ISO 22301 to fill it in.

In Annex C of The NIS2 Navigator's Handbook. It lines up twelve NIS2 requirements: article 21.2 a) through j), plus article 21.3 and article 21.4. Each requirement is shown in three columns, for ISO 27001:2022, ISO 27001:2013 and ISO 22301:2018.

The book behind this article
The NIS2 Navigator’s Handbook

The NIS2 Navigator’s Handbook

€ 59,90