Abstract blue and amber network node clusters linked by light trails, representing the overlap between NIS2 security obligations and privacy information management

ISO 27701 and NIS2: The Privacy Standard the Directive Never Names — and the One Article Where Your Certificate Still Counts

NIS2 does not require ISO 27701. The Directive never names it. Neither does Commission Implementing Regulation (EU) 2024/2690, and neither does ENISA’s 170-page technical implementation guidance — the most detailed document the EU has published on how to build Article 21 measures. Searched as plain text, the string “27701” appears zero times in all three [1][2][4].

That settles the compliance question and opens a more useful one. Privacy law and NIS2 meet in three specific places in the legal text, and one of them decides whether a regulator can fine you twice for the same incident.

Does this question actually apply to you?

Almost everyone asking it sits in one of four positions, and the honest answer differs for each.

Your position What you are usually being sold What the legal text actually asks of you
DPO or compliance officer in a NIS2 entity A PIMS to “cover GDPR and NIS2 in one system” Two separate duties. NIS2 Article 21(2) lists ten security measures, none of them a privacy programme. GDPR accountability is unchanged and unaffected by NIS2.
CISO with ISO 27001 already certified 27701 as the “privacy extension” that finishes the job Nothing in NIS2 asks for the extension. Your gap is between ISO 27001 and Article 21(2), not between ISO 27001 and privacy.
SME owner, no management system yet A bundle of both standards before the supervisor arrives Article 21(1) requires measures proportionate to your exposure, size and risk. Building two management systems at once is rarely the proportionate answer.
Board member or managing director Certification as liability cover Article 32(7)(g) makes certification one of eight factors a supervisor weighs. It is a mitigating factor, never a shield.

What NIS2 actually says — and does not say

In plain terms: NIS2 tells you which security outcomes to achieve, deliberately avoids telling you which standard to use, and never mentions privacy management as one of the outcomes.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Article 21(2) sets the floor: risk analysis and information system security policies (a), incident handling (b), business continuity and crisis management (c), supply chain security (d), security in acquisition, development and maintenance (e), policies to assess the effectiveness of the measures (f), basic cyber hygiene and training (g), cryptography and, where appropriate, encryption (h), human resources security, access control and asset management (i), and multi-factor or continuous authentication and secured communications (j) [1]. Point (h) is the closest the list comes to data protection, and it is a cryptography obligation, not a privacy governance one.

The Directive is also deliberate about standards. Article 21(1) requires an appropriate level of security “taking into account the state-of-the-art and, where applicable, relevant European and international standards” — a conditional, not a mandate. Article 25 goes further: Member States shall encourage the use of standards “without imposing or discriminating in favour of the use of a particular type of technology” [1].

Here is the absence test in full, run on the official text of each document:

Document “27701” “27001” “GDPR” / “2016/679”
NIS2 Directive (EU) 2022/2555, full OJ text 0 0 24 references to Regulation (EU) 2016/679
CIR (EU) 2024/2690 (the eleven digital-service categories) 0 1 — Recital 3 only, non-binding 0
ENISA Technical Implementation Guidance v1.0, 170 pp 0 5 9 mentions of GDPR

The contrast in the last two columns is the finding to carry forward. Privacy law is all over NIS2 — as a neighbouring regime the Directive keeps deferring to, never as a management system it asks you to build.

Where privacy law does bind your NIS2 build

ENISA’s guidance mentions GDPR nine times. Not one of them adds a privacy control to build. Seven set conditions on how a security control may be implemented; the other two name GDPR as a risk category to prioritise and as knowledge your reviewer should hold. That distinction is the practical heart of this question, and it is where a privacy programme earns its keep if you have one.

NIS2 measure The constraint ENISA names What a PIMS would already hold
Event detection and log correlation, under incident handling — Article 21(2)(b) Minimise what you collect, avoid retaining unnecessary personal data, anonymise or pseudonymise “when possible”, and apply retention “in alignment with GDPR requirements” with regular purging [4] Retention schedule, lawful-basis record and a pseudonymisation standard for the SIEM — documents most SOC build-outs write from scratch
Background verification of staff — Article 21(2)(i) Criminal-record checks and candidate screening must “align with legal and regulatory requirements (e.g. national (labour) laws and the GDPR)” Screening lawfulness assessment and the candidate privacy notice
Disciplinary process — Article 21(2)(i) The process must take account of legal and contractual requirements, involve HR, and protect the identity of those subject to it “where possible” Employee-monitoring and internal-investigation procedures
Multi-factor authentication — Article 21(2)(j) “Ensure that MFA implementation meets legal requirements (e.g. the GDPR)”. In practice this bites hardest on biometric factors, which GDPR Article 9(1) prohibits by default where used to identify a person uniquely The lawfulness assessment for a biometric factor, done before it is rolled out rather than after

Physical security adds a fifth: ENISA tells entities to retain video surveillance recordings for a defined period “in accordance with the GDPR”. Read the pattern and the real relationship becomes clear. NIS2 pushes you to collect more telemetry about people, screen staff harder, watch premises longer and authenticate more intrusively. Privacy law sets the ceiling on every one of those. An organisation with a functioning privacy programme clears these items in days. An organisation without one meets them mid-implementation, usually when the works council asks who authorised six months of full-payload log retention.

ENISA’s own advice on frameworks is to extend what you already run: entities “may build upon their current usage of standards or frameworks, if available”, and the guidance “does not aim to establish a new standard or to duplicate existing ones” [4]. It is also explicit that the document “is not legally binding and is only of an advisory character”.

Article 32(7)(g): the one place your certificate counts

Summary first: a certificate cannot make you compliant, but it can lower a fine — and the Directive contains one sentence that says so.

When a competent authority takes any enforcement measure against an essential entity, Article 32(7) obliges it to “take due account of” eight factors as a minimum. Point (g) is “any adherence to approved codes of conduct or approved certification mechanisms”. Article 34(3) routes that same list into the money: “When deciding whether to impose an administrative fine and deciding on its amount in each individual case, due regard shall be given, as a minimum, to the elements provided for in Article 32(7)” [1]. The obligation on the authority is binding. What it is obliged to weigh is not defined.

Set the two texts side by side and the gap is visible. GDPR Article 83(2)(j) reads “adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42[3]. NIS2 reproduces the wording and drops both cross-references. GDPR tells you exactly what “approved” means; NIS2 does not, and it has no approval machinery of its own for management-system certificates. Its certification article, Article 24(1), points elsewhere — to European cybersecurity certification schemes adopted under Article 49 of Regulation (EU) 2019/881, and only where a Member State chooses to require them.

Under GDPR, “approved” has a hard meaning: criteria approved by a supervisory authority under Article 58(3) or by the Board under Article 63, per Article 42(5). The EDPB register lists 17 entries — the European Data Protection Seals are Europrivacy, BC 5701:2024 in the Netherlands and EuroPriSe, alongside national criteria in France, Austria and three German Länder [5], most recently reapproved for Europrivacy on 16 April 2026 [6]. ISO/IEC 27701 is not in that register, and an ISO certificate is not issued on Board-approved criteria.

Whether a NIS2 supervisor reads its own undefined “approved certification mechanisms” narrowly or broadly is genuinely unsettled, and no case law resolves it. The evidential route is stronger anyway. Article 32(2)(g) lets authorities request “evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence” [1]. An accredited certification audit and its working papers fit that description without needing to win the “approved” argument — but note the sting: the power reaches past the certificate to what the auditor looked at. GDPR Article 42(4) says the rest outright — certification “does not reduce the responsibility of the controller or the processor”.

The exposure being mitigated is worth stating precisely:

Entity class Maximum administrative fine for infringing Article 21 or 23 Legal basis
Essential entity At least EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher Article 34(4)
Important entity At least EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher Article 34(5)

Article 35: when a GDPR fine blocks the NIS2 fine

This is the provision that changes real exposure, and it appears in no ISO 27701 explainer we could find.

Article 35(1) obliges a NIS2 competent authority that finds an Article 21 or 23 infringement capable of entailing a personal data breach — as defined in GDPR Article 4(12) and notifiable under GDPR Article 33 — to inform the data protection supervisory authority without undue delay. Your NIS2 supervisor is, in that moment, a referral channel into your privacy regulator. Our analysis of dual breach notification covers when a GDPR breach starts the 24-hour CSIRT clock at all.

Article 35(2) then does something unusual in EU law. Where the data protection authority imposes an administrative fine under GDPR Article 58(2)(i), the NIS2 authority “shall not impose an administrative fine pursuant to Article 34 of this Directive for an infringement referred to in paragraph 1 of this Article arising from the same conduct” [1]. One set of facts, one fine.

Read the rest of the sentence before relaxing. The same paragraph preserves everything except the fine: authorities “may, however, impose the enforcement measures provided for in Article 32(4), points (a) to (h), Article 32(5) and Article 33(4), points (a) to (g)”.

Barred by Article 35(2) Expressly preserved
The NIS2 administrative fine under Article 34, for the same conduct already fined under GDPR Article 58(2)(i) Warnings; binding instructions with deadlines; cease-and-desist orders; orders to bring Article 21 measures into compliance within a set period; orders to notify affected customers of a cyber threat; orders to implement audit recommendations; a monitoring officer appointed to oversee your Article 21 and 23 compliance; orders to make the infringement public. For essential entities, Article 32(5) also preserves temporary suspension of an authorisation and a temporary ban on named executives exercising managerial functions.

For a board, that is the sharper reading of the whole privacy overlap. Paying a GDPR fine removes the second fine and leaves the monitoring officer, the publication order and the management ban entirely intact. The DPO’s decision tree for the 24-hour and 72-hour clocks and the full NIS2/GDPR dual-notification playbook handle the operational half of this.

What changed on 14 October 2025

ISO/IEC 27701 was republished on 14 October 2025 as a standalone management system standard, retitled Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance. In BSI’s words, it “has now become a fully standalone Privacy Information Management System (PIMS), no longer requiring ISO/IEC 27001 certification as a prerequisite for implementation or audit” [7]. It uses the harmonised Clause 4–10 structure shared with ISO/IEC 27001:2022 and ISO/IEC 42001, and splits its annex controls into 34 for PII controllers, 21 for processors and 31 shared. Organisations with an existing ISMS can integrate the two rather than run them separately [8].

Decoupling cuts both ways. It removes the old argument that 27701 was a cheap add-on once you had 27001 — it is now a management system with its own clauses, audit and maintenance cost. A second standard published the same day, ISO/IEC 27706:2025, sets the requirements for the bodies that certify a PIMS, and in practice a certification body must be accredited against it before it may audit you at all. On the transition timeline published by UKAS, accreditation assessments of certification bodies began in May 2026 and all certified organisations must have transitioned by 31 October 2028 [9]. Published dates for the certification-body deadline itself vary between 2026 and 2027 by source, so confirm your own body’s accreditation status rather than assuming availability [10].

The two clocks run in opposite directions. NIS2 supervision is live now; a 27701:2025 certificate sits behind an accreditation queue that only started moving in 2026. Treating certification as your NIS2 answer means arriving late by design.

So do you need one? A decision by role

Work down this list and stop at the first row that describes you.

  1. You process personal data at scale or as a core service (processor, cloud, MSP, health, HR tech). A PIMS is worth building — for GDPR accountability and because customers increasingly ask for it in procurement. Build it as a privacy decision, not against your NIS2 budget.
  2. You hold ISO 27001 and are being sold 27701 to “finish” NIS2. Decline, and spend the money on a gap analysis between your Annex A controls and Article 21(2)(a)–(j) — or, if you fall in one of the eleven digital-service categories, against the more specific CIR 2024/2690 annex.
  3. You are an SME with no management system and a supervisor deadline. Build Article 21(2) coverage first. Every measure there is mandatory; nothing in the PIMS is.
  4. You are a DPO who has been handed NIS2 as well. Your highest-value move is not a new certificate. It is claiming the control points in the table above — log retention, background screening, disciplinary process, MFA factors, CCTV retention — before the security team implements them without you.
  5. You are on the board. The question is not “are we certified” but “what survives if we pay the GDPR fine”. Article 35(2) answers it, and the answer is not comforting.

Frequently asked questions

Does ISO 27701 certification prove GDPR compliance?
No. It is not an approved certification mechanism under GDPR Article 42, and Article 42(4) states that certification “does not reduce the responsibility of the controller or the processor” in any case. It is credible evidence of a managed privacy programme, not proof of compliance.

Will a supervisor accept ISO 27701 as evidence for NIS2?
Plausibly as evidence — Article 32(2)(g) invites audit results and their underlying evidence, and nothing restricts which audits. As a mitigating factor under Article 32(7)(g) the position is unsettled, because NIS2 never defines “approved”. Neither route substitutes for showing your Article 21(2) measures exist and work.

Which standard does NIS2 actually point to?
None, by design. Article 21(1) makes standards a “where applicable” consideration and Article 25 forbids discriminating in favour of a particular type of technology. The only certification NIS2 singles out is in Article 24 — European cybersecurity certification schemes under Regulation (EU) 2019/881, and only where a Member State requires them. Our guide to NIS2 certification schemes covers that route, and NIS2 versus ISO 27001 covers the mapping most entities actually need.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Official Journal — Articles 21, 24, 25, 32, 34 and 35. EUR-Lex
  2. Commission Implementing Regulation (EU) 2024/2690, Official Journal. EUR-Lex
  3. Regulation (EU) 2016/679 (GDPR), Official Journal — Articles 42 and 83(2). EUR-Lex
  4. ENISA, Technical Implementation Guidance on Cybersecurity Risk Management Measures, version 1.0, June 2025. ENISA (PDF)
  5. European Data Protection Board, register of certification mechanisms, seals and marks. EDPB
  6. European Data Protection Board, Opinion 14/2026 on the Europrivacy certification criteria, adopted 16 April 2026. EDPB
  7. BSI Group, ISO/IEC 27701:2025 — Key Changes and Guidance. BSI
  8. IAPP, ISO updates standard on managing privacy compliance programs. IAPP
  9. Certification Bodies, ISO/IEC 27701:2025 Transition, reporting the UKAS transition guidance of 18 March 2026. certbodies.co.uk
  10. Schellman, ISO 27701:2025 FAQs. Schellman
  11. ISO/IEC 27701:2025 and ISO/IEC 27706:2025, published 14 October 2025. Cited as text; iso.org blocks automated access, so publication details are carried by sources 7 to 10.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: