ISO 27019 and NIS2 cybersecurity compliance for energy sector OT operators

Does Your ISO 27019 Certification Cover NIS2? The 4 Critical Gaps Energy Sector OT Operators Must Close

Energy utilities, gas networks, and district heating operators entering NIS2 compliance often begin from the same position: an existing ISO 27019 certification that documents information security controls across their process control environment. The natural question is whether that certification does meaningful work toward NIS2 compliance — and exactly where it falls short.

The answer is more structured than it might appear. ISO 27019 certification provides genuine, audited evidence for at least five of NIS2’s ten Article 21(2) risk management measures, and Article 21(1) explicitly requires that measures take into account “relevant European and international standards” — a test regulators apply when assessing proportionality. But four obligations in the NIS2 framework sit entirely outside what ISO 27019 was designed to address, and those four gaps remain open regardless of how thorough your OT security controls are.

This guide maps where ISO 27019 earns you credit, identifies the four gaps, and outlines a practical sequence for closing them. For the broader energy sector NIS2 picture — essential entity thresholds, supervisory tiers, and sector-specific obligations — see the energy sector NIS2 guide.

What ISO 27019 Covers — and Why It Matters for Energy OT

ISO/IEC 27019:2024 extends the ISO 27001 information security management framework with requirements specific to energy utility process control environments. Where ISO 27001 establishes the ISMS structure and risk methodology, and ISO 27002 provides generalised security controls, ISO 27019 prescribes the measures needed for operational technology running electricity generation and transmission, gas distribution, district heating and cooling networks, and oil and heat infrastructure.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The standard covers the full range of energy OT assets: programmable logic controllers (PLCs), SCADA systems, advanced metering infrastructure (AMI), distributed energy resources (DER) management systems, smart grid environments, remote substations, human-machine interfaces (HMIs), and associated telemetry and communication networks. Nuclear facilities are explicitly out of scope and are addressed separately under IEC 63096:2020.

The 2024 edition adds 12 supplementary sector-specific controls beyond the restructured ISO 27002:2022 baseline, according to iso27001security.com’s review of the standard:

Domain Controls added Focus areas
Organisational 2 External business partner risk identification; customer data security protocols
Physical 4 Control centre protection; technical room safeguards; remote facility security; communication link protection
Technological 6 Legacy system risk mitigation; safety function availability; anomaly detection; configuration management; threat intelligence collection; data protection

The critical structural point for NIS2 purposes: ISO 27019 requires an ISO 27001-based ISMS as its foundation rather than replacing it. Organisations holding an ISO 27019 certification have already implemented risk-based information security management with independently audited OT-specific controls — a foundation that carries real weight when proportionality is assessed.

Where ISO 27019 and NIS2 Article 21 Align

NIS2 Article 21(2) lists ten mandatory cybersecurity risk management measures for essential and important entities. For energy operators with ISO 27019 certification, at least five measures have strong coverage and several more have partial coverage — a more substantial head start than organisations with ISO 27001 alone.

Strong coverage:

NIS2 Art. 21(2) measure ISO 27019 coverage mechanism
(a) Risk analysis and security policies ISO 27001 risk assessment process with ISO 27019’s OT-adapted risk scope covering process control assets, specific threat actors, and safety-critical scenarios
(e) System acquisition, development, maintenance ISO 27019 patch management for OT systems, configuration management procedures, and change controls adapted for offline maintenance windows on live plant
(f) Effectiveness assessment ISO 27001 monitoring, measurement, and internal audit framework — no OT-specific gap at this layer
(h) Cryptography ISO 27019 communication security and encryption controls for process system communications and remote access sessions
(i) HR security, access control, asset management ISO 27001 Annex A controls extended by ISO 27019’s role-based access requirements for OT environments and remote maintenance governance

Partial coverage:

NIS2 Art. 21(2) measure What ISO 27019 provides What remains open
(b) Incident handling Internal detection, analysis, containment, and recovery procedures for OT environments Regulatory notification to CSIRTs and competent authorities under Art. 23
(c) Business continuity Safety function availability requirements and minimum service levels Formal crisis management plan with documented, tested recovery procedures
(d) Supply chain security Third-party connection risk management and vendor access controls at the OT perimeter Contractual cascading obligations and Tier 2 supplier assessment requirements
(g) Cyber hygiene and training OT security awareness for operational staff Personal training obligation for management body members under Art. 20(2)
(j) MFA and secure communications OT communication security and session encryption Explicit multi-factor authentication as a named control requirement

This overlap is why Article 21(1) of NIS2 specifically requires that measures take into account “relevant European and international standards” when assessing proportionality. EN ISO/IEC 27019:2025 — adopted by CEN, the European Committee for Standardisation — qualifies as exactly such a standard, and national competent authorities are expected to credit independently audited certification against it when evaluating whether an energy entity’s OT controls are appropriate to its risk exposure.

An ISO 27019 certification creates evidence, not equivalence. It demonstrates state-of-the-art OT security for the measures it covers, and that evidence carries genuine regulatory weight. The four obligations below sit entirely outside what any ISO standard — 27001, 27002, or 27019 — was designed to address.

Gap 1 — Article 23 Incident Reporting: The 24/72/1-Month Cascade

ISO 27019 establishes comprehensive internal incident handling for energy OT environments: detection, analysis, containment, and recovery. What it does not specify is any obligation to notify a national competent authority or CSIRT within defined regulatory timeframes. That obligation comes from NIS2 Article 23.

Essential energy entities — those listed under Annex I of the Directive, including transmission system operators (TSOs), distribution system operators (DSOs), generators above defined capacity thresholds, and large suppliers — must submit three structured notifications following any incident with a significant impact on their services:

  • Within 24 hours of awareness: an early warning to the national CSIRT or competent authority, noting whether the incident involves unlawful or malicious acts and whether cross-border impact is likely.
  • Within 72 hours: a detailed incident notification including initial severity assessment, preliminary impact analysis, and indicators of compromise where available.
  • Within one month: a final report covering the detailed description, type of threat likely involved, applied and ongoing mitigation measures, and cross-border impact if relevant.

An incident is significant under Article 23 if it causes severe operational disruption of services or is capable of causing material or non-material damage to affected persons. CIR 2024/2690 adds specific financial thresholds for the digital infrastructure providers it directly governs — losses above EUR 500,000 or 5% of turnover — and energy entities can use these benchmarks alongside national transposition criteria when calibrating their own significance thresholds.

The operational gap this creates is specific: your ISO 27019 incident response procedure needs a regulatory notification layer. That means designating who holds national authority contact details, who authors the 24-hour early warning, who has authority to submit the 72-hour notification, and — critically — how clock management works from the first moment of awareness rather than after severity is confirmed. For a step-by-step notification workflow built for energy OT environments, the energy incident response guide covers each stage of the Article 23 cascade.

Gap 2 — Article 20 Board Liability: Personal Accountability That No ISO Standard Addresses

ISO 27001 and ISO 27019 address the management system and its controls. Neither standard creates personal liability for individual members of a management body. NIS2 Article 20 does.

Article 20(1) requires management bodies of essential and important entities to approve the cybersecurity risk management measures implemented under Article 21 and to oversee their implementation. Article 20(2) requires member states to ensure that management body members receive regular cybersecurity training — sufficient to identify risks, assess cybersecurity practices, and understand their impact on services provided. The liability consequence follows directly: if a cybersecurity incident results from inadequate measures under Article 21, accountability traces back to the management body that approved — or failed to ensure — those measures.

Some national transpositions have made this explicit with personal sanctions. Under Spain’s draft transposition law, directors face fines up to EUR 500,000 and temporary disqualification from office in cases of serious non-compliance, according to Privalex’s NIS2 energy sector analysis. The principle — that delegating all cybersecurity to the CISO without board approval and oversight is no longer sufficient — is consistent across member state transpositions.

What this gap requires in practice is documentation that sits entirely outside any ISO standard’s scope:

  • A formal board resolution approving the NIS2 cybersecurity risk management programme under Article 20(1)
  • Evidence that the management body has reviewed and approved risk treatment decisions
  • A training record showing when board members received cybersecurity training and what it covered
  • A mechanism to bring significant incidents to board attention with a documented oversight response

The ISO 27019 ISMS provides the controls the board approves. It does not produce the governance documentation above the controls layer — and that documentation is what Article 20 enforcement looks for first.

Gap 3 — Supply Chain Depth: Cascading Obligations Beyond Vendor Management

ISO 27019’s approach to third-party risk is designed for OT operational reality: vendor access management, remote maintenance controls, third-party connection security, and data diodes where appropriate. These are the supply chain risks most dangerous to process control environments, and ISO 27019 addresses them at the technical layer.

NIS2 Article 21(2)(d) requires entities to address supply chain security “taking into account the vulnerabilities specific to each direct supplier or service provider.” CIR 2024/2690 elaborates the required structure: a documented supply chain security policy, contractual security requirements for direct suppliers, and an ongoing supplier directory reviewed throughout the relationship lifecycle. The gap between ISO 27019 and Article 21(2)(d) opens in two places.

Contractual formalisation: ISO 27019 enforces vendor security at the network perimeter — access policies, technical controls, monitoring. NIS2 requires that security obligations flow contractually into supplier agreements. The approach mirrors GDPR’s Article 28 Data Processing Agreements: a standard cybersecurity addendum that suppliers sign, covering the technical and organisational measures they commit to, incident notification timelines, and sub-contractor obligations. An access control policy on your side does not substitute for a signed commitment on theirs.

Tier 2 exposure: ISO 27019’s vendor scope covers your direct relationships with entities accessing your OT environment. NIS2 supply chain security requires you to assess the vulnerabilities introduced by your direct suppliers’ own supply chains. If your SCADA integrator relies on firmware from a sub-supplier you have never assessed, that dependency is material under Article 21(2)(d) even though the sub-supplier has no direct access to your environment.

Closing this gap means building a supplier classification register by criticality tier, introducing a standard contractual security addendum for new and renewing supplier agreements, and identifying the highest-criticality Tier 2 dependencies for assessment. Start with suppliers holding remote OT access or delivering safety-critical components — these are the relationships where an Article 21(2)(d) audit will begin.

Gap 4 — Supervisory Obligations and National Registration

NIS2 creates a proactive supervisory regime for essential entities — meaning competent authorities can conduct on-site inspections, targeted security audits, and documentation requests without an incident having occurred. Essential energy entities must be known to their national competent authority: most member state transpositions require operators to notify or register with the designated authority, providing sector, sub-sector, and organisational contact details. Without that registration, an entity sits outside the regulatory visibility of the authority responsible for oversight.

ISO 27019 has no equivalent. The standard is adopted voluntarily or mandated by sector regulation; certification is issued by accredited conformity assessment bodies and involves no notification to any national cybersecurity authority. The standard was never designed to interface with a regulatory supervisory regime.

The evidence package expected during a supervisory inspection includes compliance records for all Article 21 measures, incident reporting records, and board governance documentation. ISO 27019 certification records are relevant supporting evidence within that package — but the registration itself and the compliance evidence for the three preceding gaps must all be built independently. Registration requirements vary by member state; the energy sector NIS2 guide lists the national competent authorities for major EU jurisdictions and links to registration mechanisms where they have been published.

Using ISO 27019 Certification as NIS2 Proportionality Evidence

Article 21(1)’s reference to “relevant European and international standards” is an explicit mechanism for presenting existing certification as structured credit toward NIS2 compliance. EN ISO/IEC 27019:2025 — the European adoption of the standard published by CEN — sits squarely within what Article 21(1) means by “relevant European standards,” making it directly relevant when a national competent authority assesses proportionality for an energy entity. The most defensible approach is to structure the evidence explicitly rather than presenting the certificate and expecting the connection to be obvious.

Build a dual-direction mapping document. Map your ISO 27019 controls to the Article 21(2)(a–j) measures they satisfy, and show which ISO controls correspond to each NIS2 measure. This is the format an auditor expects and the structure ENISA’s technical implementation guidance uses for ISO 27001 controls — energy entities extend this with their ISO 27019 sector-specific layer. For the ISO 27001 baseline mapping, the NIS2 vs ISO 27001 guide provides the full control-by-control comparison that ISO 27019 organisations can use as a starting point.

Acknowledge gaps explicitly in the same document. An honest gap analysis that identifies the four areas above and documents a remediation timeline strengthens credibility with a competent authority. A gap disclosed with a closure plan is a much better supervisory position than a gap discovered during an inspection.

Maintain active certification. A lapsed ISO 27019 certification provides no proportionality credit. Annual surveillance audit records and the current certification scope document should sit within your NIS2 compliance evidence portfolio and be reviewed before any supervisory contact.

Closing the 4 Gaps — A Practical Sequence

The four gaps do not carry equal remediation effort. Sequencing by complexity:

Gap NIS2 Article Effort First action
Supervisory registration National transposition Low Identify national competent authority and complete registration
Incident reporting notification layer Art. 23 Medium Draft regulatory notification annex; designate 24h/72h roles
Supply chain contracts and Tier 2 assessment Art. 21(2)(d) Medium–High Classify critical suppliers; introduce contractual security addendum
Board governance documentation Art. 20 High Schedule board cybersecurity briefing; issue formal approval resolution

Registration (lowest effort): This is an administrative task with a defined regulatory destination. Identify your national competent authority, complete the registration, and confirm your organisational point of contact. Most member states that have transposed NIS2 have published registration mechanisms on their authority’s website.

Incident reporting (medium effort): The ISO 27019 detection and response framework is the foundation — the task is adding the regulatory notification layer on top. Draft the three notification templates (24h/72h/1-month), designate roles with authority to submit each, and run a tabletop exercise to verify your team can work within Article 23 timescales. The energy sector NIS2 checklist includes the incident notification workflow as a step-by-step sequence with role assignments.

Supply chain contracts (medium–high effort): Start with your highest-criticality direct suppliers — those with remote OT access or delivering safety-related components. Introduce a standard contractual security addendum to new agreements immediately, and retrofit it to critical supplier contracts at the next renewal window. Build the supplier classification register from that highest-risk subset outward.

Board governance (sustained programme): This takes longest because it requires behaviour change at executive level, not just documentation. The starting point is a board resolution formally adopting the NIS2 compliance programme, a scheduled cybersecurity briefing in the board calendar, and a training record from the initial session. These are discrete, manageable steps — but they require a sponsor above the CISO level to land.

Key Takeaways

  • ISO 27019 certification provides audited evidence for at least five NIS2 Article 21(2) measures and partial evidence for five more. It is a substantial head start, not a compliance shortcut.
  • Four obligations sit entirely outside ISO 27019’s scope: Article 23 incident reporting timelines (24h/72h/1-month), Article 20 board liability and governance documentation, Article 21(2)(d) supply chain contractual depth, and the supervisory registration requirement under national NIS2 transposition law.
  • EN ISO/IEC 27019:2025, the CEN-adopted European standard, qualifies as a “relevant European standard” under Article 21(1)’s proportionality test. Present your certification as structured, mapped evidence — not as a compliance claim.
  • Registration is the lowest-effort gap to close; board governance is the highest. Sequence accordingly.

Frequently Asked Questions

Does ISO 27019 certification mean we are partially NIS2 compliant?

In practice, ISO 27019 certification creates audited evidence for several Article 21(2) measures that a national competent authority must consider under the proportionality test. However, NIS2 does not provide a formal “partial compliance” status — entities either satisfy all Article 21 measures or they do not. The certification strengthens your position for the controls it covers; the four gaps above remain open obligations regardless.

Which energy entities are classified as essential entities under NIS2?

Annex I of NIS2 covers electricity, natural gas, oil, hydrogen, and district heating and cooling infrastructure. TSOs, DSOs, generators meeting defined capacity thresholds, and large suppliers (generally 250+ employees or EUR 50M+ turnover) are classified as essential entities subject to stricter supervision and higher penalty ceilings. Check your national transposition law for the exact thresholds applicable in your jurisdiction — some member states have set lower thresholds than the Directive’s defaults.

Does ISO 27001 certification also need to sit alongside ISO 27019?

Yes — ISO 27019 is a sector supplement that requires ISO 27001 as the foundation ISMS. Organisations holding ISO 27019 certification have, by definition, implemented ISO 27001 as well. Some hold a combined ISO 27001/27019 certification; others certify against both separately. Either approach is valid for NIS2 proportionality purposes.

Is the Network Code on Cybersecurity separate from NIS2?

Yes. Commission Delegated Regulation (EU) 2024/1366 — the Network Code on Cybersecurity (NCCS) — applies specifically to the electricity sector, covering TSOs, DSOs, generators, and suppliers. Its application deadline was 2 July 2025. The NCCS adds electricity-specific requirements alongside NIS2 obligations rather than substituting for them. Energy entities subject to both must satisfy the more demanding requirement where the two overlap and maintain separate evidence where they diverge.

Sources

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: