Abstract visualization of two compliance frameworks converging into a certified security structure

ISO 27001 for NIS2-Compliant Organizations: The 70-80% Head Start, and the Certification Gap It Doesn’t Close

If your organization has already built out NIS2 Article 21(2) risk-management measures — a risk analysis policy, an incident handling procedure, business continuity plans, supplier security controls — the compliance paperwork doesn’t necessarily stop there. A growing number of NIS2-compliant organizations are getting a follow-up question from a customer, an investor, an insurer, or a much larger supply-chain partner: “Are you ISO 27001 certified?” NIS2 compliance and ISO 27001 certification are not the same thing, and answering that question well starts with understanding why someone is asking it.

This article is not a technical, control-by-control mapping of NIS2 to ISO 27001 — that already exists at our full NIS2 vs ISO 27001 comparison, and readers who want the detailed clause-level table should start there. This one is a decision document: the business case for pursuing certification once you’re already NIS2-compliant, how much of your existing work genuinely transfers, what’s actually new, and a straightforward framework for deciding whether now is the right time to start.

Why a NIS2-Compliant Organization Would Still Want ISO 27001

NIS2 is a legal obligation for in-scope EU entities, enforced by national competent authorities, with real penalties attached. ISO 27001 is the opposite in one important respect: certification is entirely voluntary. [4] Nobody can fine you for not holding a certificate. So why do NIS2-compliant organizations pursue it anyway? In practice, the pressure almost always comes from outside the regulation itself.

Customer and vendor due diligence. When a prospect or a larger customer runs security due diligence on you as a supplier, an ISO 27001 certificate is one of the fastest ways to show that an information security management system (ISMS) exists and has been independently reviewed, rather than asking their security team to take your policy documents on faith. Certification only shows up in a due-diligence conversation if you can actually produce it, which is exactly why it becomes a differentiator the moment a competitor in your market has one and you don’t. [6]

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

RFP and procurement gatekeeping. Enterprise and public-sector procurement increasingly uses named security certifications as a shortlisting filter before price or features are even discussed. A certificate is something a procurement team can check off without a follow-up call; an internal policy binder usually triggers one.

Supply-chain pull-through. If part of your NIS2 exposure comes from supplying a larger essential or important entity, that customer is under its own Article 21(2)(d) duty to assess supply-chain security risk from you. [1] Larger organizations increasingly resolve that assessment burden at scale by simply requiring ISO 27001 (or an equivalent) from every supplier above a certain size or data-access level, rather than running a bespoke security questionnaire on each one individually.

Cyber insurance underwriting. Underwriters have been moving away from pure self-attestation questionnaires toward wanting verifiable evidence that a security management system is actually operating, and ISO/IEC 27102 specifically describes how an ISMS can feed into cyber-insurance underwriting. [7] A certified ISMS is not a guarantee of a lower premium or automatic coverage — underwriting decisions vary by insurer, policy, and risk profile — but it gives you a recognized, externally audited body of evidence to bring to that conversation instead of a blank questionnaire.

Multi-country and multi-market credibility. NIS2 is an EU directive with no standing outside the EU, and even inside the EU its transposition and enforcement style vary by member state. ISO 27001 is an international standard with no such boundary: the official ISO Survey recorded 96,709 valid ISO/IEC 27001 certificates worldwide in 2024, with the largest concentrations in Asia rather than the EU. [5] If your customers, investors, or expansion plans reach beyond Europe, an ISO 27001 certificate reads the same way in Singapore, the UK, or the US as it does in Germany. A NIS2 compliance statement, by contrast, means very little to a buyer outside the directive’s jurisdiction.

The 70–80% Head Start: What Your NIS2 Work Already Buys You

Here is the number that makes this decision easier than it looks from the outside: NIS2’s Article 21(2) risk-management measures and ISO 27001’s Annex A controls share roughly 70–80% foundational overlap, as our detailed technical mapping documents control by control. [1] That figure isn’t a marketing estimate — it reflects how much of the underlying process work is genuinely shared between the two frameworks, not just similarly worded headings.

In practice, that overlap shows up as work you’ve already done being extended and formalized, not redone from scratch:

  • Risk assessment. Article 21(2)(a) requires a policy on risk analysis and information system security. [1] ISO 27001’s risk assessment and risk treatment process asks the same underlying question — what are our assets, threats, and risks, and what are we doing about each one — with a more formal methodology and a Statement of Applicability built around the output. A defensible NIS2 risk register is a starting point for this, not a document you throw away.
  • Incident handling. Article 21(2)(b) incident handling procedures and ISO 27001’s incident management controls cover the same ground: detection, response roles, escalation, and lessons learned. [1] The gap here is mostly formality — ISO expects the same process tied back into documented ISMS records, not a different process.
  • Access control. NIS2’s human resources security and access control requirements under Article 21(2)(i) map closely onto ISO 27001’s identity and access management controls. [1] Role-based access and multi-factor authentication built for NIS2 transfer as evidence largely as-is.
  • Business continuity. Article 21(2)(c) business continuity, backup, and crisis-management measures line up with ISO 27001’s business continuity controls. [1] The plans, backup tests, and recovery objectives built for NIS2 are the same artifacts an ISO auditor wants to see, not a parallel set you build separately.
  • Supplier security. Article 21(2)(d) supply-chain security and ISO 27001’s supplier relationship controls both require you to assess and manage risk introduced by vendors. [1] A supplier risk process built for NIS2 needs formalizing into ISO 27001’s structure, not reinventing.

For the full control-by-control walkthrough of exactly which NIS2 measure maps to which Annex A control — including where the two frameworks genuinely diverge — see our detailed NIS2 vs ISO 27001 comparison. The short version for a decision-maker: if your NIS2 compliance program is substantively real and operating, rather than a binder that was written once and never used, you are not starting an ISO 27001 project from zero. You are formalizing and certifying work that, in large part, already exists.

The Gap: What ISO 27001 Actually Requires Beyond NIS2

The 70–80% overlap cuts the other way too: the remaining 20–30% is where the real project work sits, and it isn’t evenly distributed. Most of it is governance and documentation overhead that NIS2 simply doesn’t ask for, plus one requirement NIS2 has no equivalent of at all.

A formal ISMS scope statement. ISO 27001 requires you to explicitly define and document the boundaries of your information security management system — which business units, locations, systems, and data are in scope, and the reasoning behind that boundary. NIS2 doesn’t ask you to draw this boundary in writing; your Article 21(2) obligations simply apply to the entity as scoped by the Directive itself. [1]

A Statement of Applicability (SoA). This is the document with no NIS2 equivalent in any form. ISO 27001 requires you to work through all 93 Annex A controls, spread across four themes — Organizational (37), People (8), Physical (14), and Technological (34) — and formally record, for each one, whether it applies to you, whether it’s implemented, and why, tied back to your risk assessment. [3] NIS2 requires you to implement appropriate and proportionate measures; it does not ask for a control-by-control justification document covering a fixed, numbered control catalogue.

A management review cadence. ISO 27001 requires top management to formally review the ISMS at planned intervals, typically at least annually, covering its continuing suitability, adequacy, and effectiveness, with defined inputs and documented outputs. NIS2’s Article 21(2)(f) asks you to assess the effectiveness of your risk-management measures, but it doesn’t prescribe a specific governance ritual or cadence for doing so at the management-body level in the way ISO 27001’s management review clause does. [1]

The certification audit itself. This is the biggest structural difference, and it’s worth stating plainly: NIS2 has no third-party certification scheme. Compliance is demonstrated to a competent authority through supervision, audits, and incident reporting — not through an accredited external body issuing you a certificate. [4] ISO 27001 certification, by contrast, requires an independent, accredited certification body to run a two-stage audit: a Stage 1 documentation review confirming your ISMS is built to the standard, followed by a Stage 2 audit — typically six to eight weeks later — that tests whether the ISMS is actually operating as designed. [2] Only after both stages pass does the certification body issue a certificate, valid for three years subject to ongoing surveillance audits. [2] No amount of internal documentation, however thorough, produces a certificate on its own; that step is inherently a third-party exercise, and it’s the one part of this process a documentation toolkit cannot shortcut for you.

Should You Pursue ISO 27001 Now, or Wait?

Not every NIS2-compliant organization should start an ISO 27001 project this quarter. The honest answer depends on where the pressure is actually coming from — internal ambition is a much weaker reason to spend real budget and staff time on certification than a specific external party already asking for it.

Situation Likely right call
A customer, investor, or RFP has already named ISO 27001 as a requirement Pursue now — the demand is proven, and delay costs you deals
You supply into a much larger essential/important entity whose vendor program is standardizing on it Pursue now — this is a “when,” not an “if”
Your NIS2 Article 21(2) program is still incomplete, informal, or newly built Wait — finish and operationalize NIS2 first; certifying an ISMS built on an unfinished foundation compounds the work later
No customer or vendor has asked, and it’s being considered purely as a “nice to have” credential Wait on the audit — build the documentation foundation opportunistically, but don’t book a certification audit until demand is concrete
You operate mainly within one EU member state, with no near-term plans to sell outside the EU or into large enterprise/public-sector accounts Lower priority — NIS2 compliance alone may satisfy your actual audience for now

The middle ground most organizations land on is worth naming explicitly: build the ISO 27001 documentation now, while the NIS2 program is fresh and the overlap is easiest to exploit, but treat the certification audit itself as a separate, later decision gated on actual demand. Documentation doesn’t expire and doesn’t commit you to a certification-body contract or an audit date — it just means that when the RFP or the customer question does arrive, you’re weeks away from being ready instead of months.

FAQ

Does having ISO 27001 certification mean we’re automatically NIS2 compliant?
No. ISO 27001 certification demonstrates that your ISMS meets the standard’s requirements, but it doesn’t automatically satisfy NIS2’s specific legal obligations — reporting timelines, management-body liability, and some Article 21(2) measures have no direct Annex A equivalent. See our full comparison for exactly where the two frameworks diverge.

How long does it typically take to go from NIS2-compliant to ISO 27001 certified?
This varies significantly by organization size, scope, and how mature the existing NIS2 program already is. There’s no single reliable industry-wide timeline we can cite with confidence, so treat any specific number quoted elsewhere as an estimate for that organization’s circumstances, not a general rule.

Can a documentation toolkit get us ISO 27001 certified?
No. A documentation toolkit builds the paperwork foundation — policies, the Statement of Applicability, risk methodology, and the other artifacts an auditor expects to see — but certification itself can only be issued after a Stage 1 and Stage 2 audit performed by an independent, accredited certification body. [2]

Is ISO 27001 certification legally required for NIS2 entities?
No. ISO 27001 is voluntary in every case; NIS2 does not require certification to any standard, and no NIS2 provision names ISO 27001 as a mandatory reference. [1][4] Organizations pursue it for the business reasons covered in this article, not because NIS2 itself demands it.

What’s the fastest way to see exactly where our NIS2 documentation already satisfies ISO 27001 controls?
A structured delta or gap analysis run against the current Annex A control set is the direct way to answer that for your specific documentation, rather than relying on general overlap estimates like the 70–80% figure used throughout this article.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: