NIS2 and ISO/IEC 27001 are not alternatives. NIS2 is an EU directive implemented and enforced through Member-State law for in-scope entities; ISO/IEC 27001:2022 is an international standard for an information security management system that any organisation can implement and may choose to certify. An ISO certificate can support evidence, but it does not establish NIS2 scope or legal compliance.
The practical differences
| Question | NIS2 | ISO/IEC 27001:2022 |
|---|---|---|
| What is it? | EU cybersecurity directive transposed into national law | International ISMS requirements standard |
| Who is covered? | Entity types and size or exception rules in the Directive and national law | Any organisation choosing to implement it |
| Is it mandatory? | Yes for entities within applicable national scope | Usually voluntary unless a contract or other rule requires it |
| Who assesses it? | National competent authorities under the applicable regime | Organisation; optionally an external certification body for certification |
| Main focus | Cyber risk measures, reporting, governance, supervision and enforcement | Establishing, operating, evaluating and improving an ISMS |
| Certificate? | NIS2 itself does not create an ISO-style organisational certificate | Optional third-party certification to a defined ISMS scope |
| Incident reporting? | Staged reporting for significant incidents under Article 23 | The standard supports incident management but does not replace legal notification |
| Management duties? | Article 20 approval, oversight and training duties | Leadership and management-system responsibilities within the ISMS |
Where ISO 27001 helps
A functioning ISMS can provide useful foundations:
- defined scope, interested parties and accountability;
- repeatable risk assessment and treatment;
- controlled policies and operational evidence;
- incident, continuity, access, supplier and vulnerability processes;
- effectiveness monitoring, internal audit and management review; and
- corrective action and continual improvement.
Annex A offers 93 reference controls in organisational, people, physical and technological groups. The organisation selects necessary controls through risk treatment and records its decisions in the Statement of Applicability.
Gaps that require explicit NIS2 work
Even a mature certified ISMS needs a legal and operational NIS2 review:
- Scope and jurisdiction. Determine entity types, size rules, regardless-of-size cases, essential or important classification, Member States and national transposition.
- Article 20 governance. Evidence the management body's approval and oversight of NIS2 measures and required training.
- Article 21 mapping. Demonstrate that measures are appropriate and proportionate and cover every minimum area in the applicable regime.
- Article 23 reporting. Build significant-incident assessment, 24-hour early warning, 72-hour incident notification, intermediate and final-report processes with applicable qualifications.
- Authority processes. Address registration, contact, information requests, supervision and national evidence expectations.
- Legal enforcement. Track national powers, remedies and penalties rather than treating certification findings as the only consequence.
Do not use an overlap percentage
Statements such as “ISO covers 70% of NIS2” are not meaningful without a defined scope, mapping method, implementation evidence, national law and weighting. One missing incident-reporting workflow can be more significant than several fully implemented administrative controls.
Use a traceable crosswalk instead:
| NIS2 requirement | National provision | ISMS process / control | Evidence | Gap / action / owner |
|---|---|---|---|---|
| [ARTICLE / RULE] | [CITATION] | [PROCESS] | [RECORD] | [ENTRY] |
Rate design and operation separately. A policy can map to a requirement while the control still fails in practice.
Recommended sequence
- Complete NIS2 entity and national-law analysis.
- Freeze the relevant obligations and authority instructions in a register.
- Map the existing ISMS and evidence to each obligation.
- Prioritise gaps by legal timing, service impact and risk.
- Implement management, incident, supplier and effectiveness gaps.
- Exercise reporting and crisis governance.
- Provide management with evidence and residual-risk decisions.
- Maintain the map when services, law, suppliers or ISMS scope change.
If you are certified, verify the certificate's legal entity, sites, services, edition, validity and ISMS scope before citing it as evidence. ISO notes that it does not issue certificates; external certification bodies do.
For a scoped crosswalk and implementation programme, see our NIS2 compliance services.
Sources and review
This comparison was substantively reviewed on 8 August 2026. It removes unsupported overlap percentages and clearly separates law, implementation, conformity and certification.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.