- Type
- International standard (ISO/IEC)
- Current version
- ISO/IEC 27001:2022
- Subject
- information security management system (ISMS)
- Benefit for NIS2
- Covers many NIS2 requirements already
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is ISO 27001?
ISO/IEC 27001 is the leading international standard for information security and the only one in the ISO 27000 family against which an organisation can be certified. It sets out how organisations build, run and steadily improve an information security management system (ISMS) . The aim is to protect the three security objectives of confidentiality, integrity and availability of information – whether it exists digitally, on paper or in the knowledge of staff. The standard is deliberately written to be sector- and technology-neutral, so that every organisation, from a small workshop to a corporate group, can tailor it to its own size and risk situation.
Structure: main part and Annex A
ISO 27001 consists of a normative main part (clauses 4 to 10) and Annex A. The main part sets out the requirements for the management system itself: context of the organisation, leadership, planning, Risk management, operation and continuous improvement. Annex A lists concrete security measures (Controls) – on access control, encryption, supplier management and contingency planning, for example. In the current version, ISO/IEC 27001:2022, there are 93 measures in four themes (organisational, people, physical, technological). Which of them are implemented follows from the risk assessment and is justified in the Statement of Applicability (SoA).
How does certification work?
Once the ISMS is in place, an accredited certification body examines the system in a two-stage audit (a document review and an on-site audit). The certificate is then valid for three years and is accompanied by annual surveillance audits before recertification comes round. Certification is voluntary, but it creates trust with customers, authorities and partners and is often a hard requirement in tenders.
ISO 27001 and NIS2
ISO 27001 and NIS2 pursue the same goal by different means. Where the standard describes a voluntary, certifiable framework for an ISMS, NIS2 lays down legal duties: Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover (for essential entities) and EUR 7 million or 1.4 % (for important entities), and Member States may set higher amounts. An ISMS built along ISO 27001 already covers a large part of the measures NIS2 requires – risk management, technical and organisational protective measures and Governance reaching up into the management body. Even so, certification is not mandatory.
In practice: a mid-sized mechanical engineering firm with a valid ISO 27001 certificate does not have to build a second system for NIS2. It compares its existing Controls with the NIS2 duties, adds the statutory reporting chain (early warning within 24 hours, notification within 72 hours, final report within one month) and completes the registration required in its own Member State. The registration channel and the deadline are set nationally and should not be put off.
ISO 27001 ↔ NIS2 side by side
The table below maps typical ISO 27001 building blocks to the duties in Article 21 of NIS2. It shows where an existing ISMS pays in directly – and where NIS2 goes further.
| Area | ISO 27001 (Annex A 2022) | NIS2 Art. 21 |
|---|---|---|
| Risk management | Clause 6 + A.5.7 (risk assessment, SoA) | Para. 2(a) – risk analysis & security policies |
| Incident handling | A.5.24–A.5.28 (incident management) | Para. 2(b) + reporting chain 24 h / 72 h / 1 month (Article 23) |
| Business continuity | A.5.29–A.5.30 (continuity, backups) | Para. 2(c) – backup, recovery, crisis management |
| Supply chain | A.5.19–A.5.23 (supplier relationships) | Para. 2(d) – supply chain security |
| Cryptography & access | A.8.24, A.5.15–A.5.18 (encryption, access control) | Para. 2(h)+(j) – cryptography, access & asset management |
| Governance | Clause 5 (leadership & responsibility) | Art. 20 – duties & liability of the management body |
One gap almost always stays open: the NIS2 reporting obligations towards the competent authority are not part of ISO 27001. They have to be set up separately.
What do you need to do?
- Align the scope: Check whether the ISMS scope of your certificate really covers all the services and facilities that are relevant for NIS2 – it is often drawn more narrowly.
- Run a gap analysis: Compare your Statement of Applicability (SoA) with the ten categories of measures in Article 21 of NIS2 and document the deviations.
- Set up the reporting chain: Define who is responsible and how escalation runs for the 24-hour, 72-hour and one-month deadlines towards your competent authority – this part is missing from the ISMS.
- Sort out registration: Registration runs through the national channel of your Member State. Ask the authority responsible for you which form and which deadline apply, and do not put it off.
- Bring the management body on board: Have the management formally approve the risk measures and take part in training – under Article 20 of NIS2 the members of the management body can be held liable for infringements.
Further reading: ISO/IEC 27001 – the official ISO standard page
Frequently asked questions
What is ISO 27001, explained simply?
ISO/IEC 27001 is the leading international standard for information security management systems (ISMS) and the only one in the ISO 27000 family against which organisations can be certified. The standard describes how an organisation builds, steers and continuously improves information security in order to protect the confidentiality, integrity and availability of information. The current version, ISO/IEC 27001:2022, lists 93 security measures in Annex A, grouped into four themes.
Is ISO 27001 mandatory for NIS2?
An ISO 27001 certification is not mandatory for NIS2 – the directive prescribes no certification at all – but it helps considerably. An ISMS built along ISO 27001 already covers many of the measures required by Article 21 of NIS2, among them risk management, technical protective measures and governance. Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
How does an ISO 27001 certification work?
An organisation first builds an ISMS, documents its processes and measures and then has the system examined by an accredited certification body in a two-stage audit consisting of a document review and an on-site audit. The ISO 27001 certificate is then valid for three years and is accompanied by annual surveillance audits before recertification comes round. Certification is voluntary, but it creates trust with customers, authorities and partners.