Glossary · Term

ISO 27001 explained

ISO/IEC 27001 is the globally recognised standard for information security. It describes how organisations build a management system that protects data and IT systems systematically – and it is a strong foundation for NIS2.

At a glance
Type
International standard (ISO/IEC)
Current version
ISO/IEC 27001:2022
Subject
information security management system (ISMS)
Benefit for NIS2
Covers many NIS2 requirements already
Updated
June 2026
Editorial team
Compliance Compass

What is ISO 27001?

ISO/IEC 27001 is the leading international standard for information security and the only one in the ISO 27000 family against which an organisation can be certified. It sets out how organisations build, run and steadily improve an information security management system (ISMS) . The aim is to protect the three security objectives of confidentiality, integrity and availability of information – whether it exists digitally, on paper or in the knowledge of staff. The standard is deliberately written to be sector- and technology-neutral, so that every organisation, from a small workshop to a corporate group, can tailor it to its own size and risk situation.

Structure: main part and Annex A

ISO 27001 consists of a normative main part (clauses 4 to 10) and Annex A. The main part sets out the requirements for the management system itself: context of the organisation, leadership, planning, Risk management, operation and continuous improvement. Annex A lists concrete security measures (Controls) – on access control, encryption, supplier management and contingency planning, for example. In the current version, ISO/IEC 27001:2022, there are 93 measures in four themes (organisational, people, physical, technological). Which of them are implemented follows from the risk assessment and is justified in the Statement of Applicability (SoA).

How does certification work?

Once the ISMS is in place, an accredited certification body examines the system in a two-stage audit (a document review and an on-site audit). The certificate is then valid for three years and is accompanied by annual surveillance audits before recertification comes round. Certification is voluntary, but it creates trust with customers, authorities and partners and is often a hard requirement in tenders.

ISO 27001 and NIS2

ISO 27001 and NIS2 pursue the same goal by different means. Where the standard describes a voluntary, certifiable framework for an ISMS, NIS2 lays down legal duties: Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover (for essential entities) and EUR 7 million or 1.4 % (for important entities), and Member States may set higher amounts. An ISMS built along ISO 27001 already covers a large part of the measures NIS2 requires – risk management, technical and organisational protective measures and Governance reaching up into the management body. Even so, certification is not mandatory.

In practice: a mid-sized mechanical engineering firm with a valid ISO 27001 certificate does not have to build a second system for NIS2. It compares its existing Controls with the NIS2 duties, adds the statutory reporting chain (early warning within 24 hours, notification within 72 hours, final report within one month) and completes the registration required in its own Member State. The registration channel and the deadline are set nationally and should not be put off.

ISO 27001 ↔ NIS2 side by side

The table below maps typical ISO 27001 building blocks to the duties in Article 21 of NIS2. It shows where an existing ISMS pays in directly – and where NIS2 goes further.

AreaISO 27001 (Annex A 2022)NIS2 Art. 21
Risk managementClause 6 + A.5.7 (risk assessment, SoA)Para. 2(a) – risk analysis & security policies
Incident handlingA.5.24–A.5.28 (incident management)Para. 2(b) + reporting chain 24 h / 72 h / 1 month (Article 23)
Business continuityA.5.29–A.5.30 (continuity, backups)Para. 2(c) – backup, recovery, crisis management
Supply chainA.5.19–A.5.23 (supplier relationships)Para. 2(d) – supply chain security
Cryptography & accessA.8.24, A.5.15–A.5.18 (encryption, access control)Para. 2(h)+(j) – cryptography, access & asset management
GovernanceClause 5 (leadership & responsibility)Art. 20 – duties & liability of the management body

One gap almost always stays open: the NIS2 reporting obligations towards the competent authority are not part of ISO 27001. They have to be set up separately.

What do you need to do?

Further reading: ISO/IEC 27001 – the official ISO standard page

Frequently asked questions

What is ISO 27001, explained simply?

ISO/IEC 27001 is the leading international standard for information security management systems (ISMS) and the only one in the ISO 27000 family against which organisations can be certified. The standard describes how an organisation builds, steers and continuously improves information security in order to protect the confidentiality, integrity and availability of information. The current version, ISO/IEC 27001:2022, lists 93 security measures in Annex A, grouped into four themes.

Is ISO 27001 mandatory for NIS2?

An ISO 27001 certification is not mandatory for NIS2 – the directive prescribes no certification at all – but it helps considerably. An ISMS built along ISO 27001 already covers many of the measures required by Article 21 of NIS2, among them risk management, technical protective measures and governance. Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

How does an ISO 27001 certification work?

An organisation first builds an ISMS, documents its processes and measures and then has the system examined by an accredited certification body in a two-stage audit consisting of a document review and an on-site audit. The ISO 27001 certificate is then valid for three years and is accompanied by annual surveillance audits before recertification comes round. Certification is voluntary, but it creates trust with customers, authorities and partners.

ISO 27001 meets NIS2

From the ISO certificate to NIS2 conformity

Compliance Compass maps your existing Annex A controls to Article 21 of NIS2 automatically, shows the open gaps and sets up the reporting chain with its 24-hour and 72-hour deadlines.