Glossary · Term

ISMS explained

An ISMS (information security management system) is the structured framework with which an organisation steers its information security – plannable, traceable and verifiable instead of accidental.

At a glance
Meaning
Information Security Management System
Common standard
ISO/IEC 27001
Core principle
PDCA cycle (Plan – Do – Check – Act)
Benefit for NIS2
The central tool for implementing the requirements
Updated
June 2026
Editorial team
Compliance Compass

What is an ISMS?

An ISMS (information security management system) is not a single product or tool but a management framework: a collection of policies, processes, roles and measures that together make sure information is protected. It is not a purchase, it is a method. It bundles responsibilities and turns information security into a steerable, verifiable process instead of a pile of individual protective measures. While a standard such as ISO 27001 describes which requirements a good ISMS has to meet, the ISMS itself is those requirements in daily operation – it can be built on a standard or designed in-house.

What does an ISMS consist of?

The PDCA cycle

An ISMS lives on continuous improvement following the PDCA cycle: Plan (assess risks and plan measures), Do (implement them), Check (test effectiveness with audits and metrics) and Act (improve). This cycle keeps security from decaying into a one-off project and keeps it current when new threats, new systems or organisational changes appear.

ISMS roadmap: six steps to a running system

The PDCA cycle sounds abstract. The order below makes it practical. It shows the sequence most implementation projects follow – from the first scoping to the point at which the ISMS carries itself. Steps one to three are the one-off build-up work; from step four the cycle becomes routine.

  1. Clarify context & scope (Plan). Which sites, systems and processes fall under the ISMS? Set the scope out in writing and define the role of the management body . Without a clear boundary the project has no end.
  2. Carry out the risk analysis (Plan). Record your values (data, applications, infrastructure), assess threats and vulnerabilities and decide for each risk whether to avoid, reduce, transfer or accept it – the core of risk management.
  3. Define measures and document the SoA (Plan). Derive concrete TOMs and Security policies from the risks and set out in a Statement of Applicability which controls apply and which do not.
  4. Implement measures and go live (Do). Configure the technology, introduce the processes, train staff and put reporting routes and responsibilities into productive use.
  5. Test effectiveness (Check). Use internal audits, metrics and management reviews to measure whether the measures actually work – not only whether they exist on paper.
  6. Improve and restart the cycle (Act). Correct deviations, work in the lessons from incidents and go back to step two with the updated risk picture – annually or whenever something material changes.

ISMS, ISO 27001 and NIS2

Most often an ISMS is built along ISO 27001 . For NIS2 an ISMS is the ideal foundation: it provides the systematic approach the directive demands of Risk management and of security measures, and at the same time it produces the evidence competent authorities ask for. NIS2 has applied since 18 October 2024, but the duties reach an entity through the national law of its Member State, so the registration channel and the deadline differ from country to country. Whether your entity has to register is a question for the authority responsible for you, and it is not one to put off.

An example: an IT service provider classified as an important entity first carries out an ISMS risk analysis, derives measures and policies from it and puts clear reporting routes in place. If a significant security incident occurs later, the ISMS process is already defined, so the statutory reporting chain runs without panic: the early warning goes to the competent authority within 24 hours, the incident notification with a first assessment follows after 72 hours and the final report after one month at the latest. Without an ISMS all of that would have to be improvised under time pressure. That gets expensive: Article 34 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

What do you need to do?

Further reading: ISO/IEC 27001 – the official ISO standard page

Frequently asked questions

What is an ISMS, explained simply?

An ISMS (information security management system) is a structured management framework of policies, processes, roles and measures with which an organisation steers its information security in a plannable and demonstrable way. It is not a single product and not a purchase, but a method that is lived: it turns information security into a steerable, verifiable process instead of a pile of individual protective measures. An ISMS is frequently built along ISO/IEC 27001.

What is the PDCA cycle in an ISMS?

PDCA stands for Plan, Do, Check, Act and is the heart of an ISMS. The cycle of continuous improvement has four steps: Plan (assess risks and plan measures), Do (implement them), Check (test effectiveness with audits and metrics) and Act (improve). That keeps security current when new threats, new systems or organisational changes appear, instead of letting it become a one-off project.

Do you need an ISMS for NIS2?

NIS2 prescribes no particular ISMS and requires no certification, but it does require systematic risk management and appropriate security measures. An ISMS is the central tool for meeting those requirements in a structured way and for producing the evidence a competent authority asks for. The directive has applied since 18 October 2024; the registration duty and its deadline follow the national law of the Member State in which your entity is established.

Information security

From the scope to the management review

Compliance Compass takes your ISMS through all six roadmap steps: assess risks, maintain the SoA, evidence measures and keep the PDCA cycle running – without a jungle of spreadsheets.