Industry

NIS2 vs ISO 27001: How the Requirements Map

Equip IgeraSolutions
September 27, 2026
9 min read
NIS2 vs ISO 27001: How the Requirements Map
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

NIS2's 10 security measures and ISO 27001's Annex A controls overlap heavily. See how they map — and where certification alone falls short.

✓ Citing current regulationsSee detailed guide below ↓

NIS2 vs ISO 27001: How the Requirements Map

NIS2's Article 21 sets out ten categories of cybersecurity measures, and ISO/IEC 27001:2022's Annex A organises 93 controls under four themes — Organizational, People, Physical, and Technological. The two frameworks were built independently, but their subject matter overlaps closely: most of what Article 21 asks for is already addressed, in substance, by a well-implemented Annex A control set. That overlap makes ISO 27001 certification a strong head start for NIS2 readiness — but not, on its own, a substitute for it.

Two different kinds of document, one overlapping subject

It helps to be clear about what each framework actually is. NIS2 (Directive (EU) 2022/2555) is EU law, transposed into national statute by each member state, and it applies to organisations that fall within its scope — including a wide range of manufacturers and industrial operators once national thresholds and sector criteria are met. ISO/IEC 27001 is a voluntary, internationally recognised standard for an information security management system (ISMS), and certification against it is issued by an accredited certification body, not a regulator.

Because NIS2 is law and ISO 27001 is a management-system standard, they don't map to each other clause-by-clause. No regulator or standards body has published — or is likely to publish — an official, numbered, one-to-one correspondence table between NIS2's measures and ISO 27001's controls. What exists, and what genuinely helps a compliance team, is a conceptual mapping: matching each category of NIS2 measure to the Annex A control theme (or themes) that address the same subject matter.

Where the two frameworks line up conceptually

Article 21 requires organisations to implement measures across ten broad categories: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition/development/maintenance of systems, policies to assess the effectiveness of measures, basic cyber hygiene and training, cryptography and encryption, human resources security and access control, and the use of multi-factor authentication or continuous authentication solutions along with secured communications.

ISO 27001's Annex A groups its 93 controls under four themes: Organizational controls (governance, policies, supplier relationships, incident management), People controls (screening, training, responsibilities), Physical controls (secure areas, equipment, media handling), and Technological controls (access control, cryptography, network security, secure development).

At the category level, the correspondence is genuinely close:

  • Risk analysis and security policies — addressed by Annex A's organizational controls on policies for information security, roles and responsibilities, and the risk assessment process that underpins the whole ISMS.
  • Incident handling — mirrored by the organizational controls covering incident management planning, assessment, and response.
  • Business continuity and crisis management — mirrored by the organizational controls on ICT readiness for business continuity and the broader continuity planning requirements built into the ISMS.
  • Supply chain security — this is the closest single match: Article 21's supply chain requirement corresponds directly to Annex A's supplier relationship controls, including security in supplier agreements and monitoring supplier performance.
  • Security in acquisition, development and maintenance of systems — addressed by the technological controls on secure development lifecycle, secure coding, and system change management.
  • Policies to assess the effectiveness of measures — reflected in the ISMS's own internal audit and management review cycle, which is a core structural requirement of ISO 27001 itself, not just an Annex A control.
  • Basic cyber hygiene and training — covered by the People controls theme, particularly security awareness, education and training requirements.
  • Cryptography and encryption — corresponds directly to Annex A's cryptography controls theme within Technological controls.
  • Human resources security and access control — covered jointly by People controls (screening, terms of employment, disciplinary process) and the access control group within Technological controls.
  • Multi-factor authentication and secured communications — addressed by the technological controls on authentication information and network security.

This is a category-to-theme correspondence, not a numbered article-to-control table. Several Article 21 measures map to more than one Annex A theme at once, and several Annex A controls support more than one NIS2 measure. Treat any resource that presents this relationship as a precise, exhaustive 1:1 table with scepticism — the frameworks simply aren't structured to produce one.

The practical business case

For a manufacturer or industrial operator that is already ISO 27001 certified, this overlap is genuinely useful. The risk assessment methodology, the supplier due-diligence process, the incident response procedure, the access control framework, the training programme, and the internal audit cycle required to maintain certification all produce artefacts — policies, records, logs, evidence — that directly support a NIS2 compliance file. Very little of that groundwork needs to be built from scratch. In practice, this is one of the strongest arguments for pursuing or maintaining ISO 27001 certification even where it isn't itself a legal requirement: it converts a large part of NIS2 readiness into evidence you already hold.

What it does not do is close the gap entirely. NIS2 imposes obligations that are legal in character and sit outside what any ISMS certification covers:

  • Statutory incident reporting timelines. NIS2 requires notifying the competent national authority within specific, legally binding deadlines after becoming aware of a significant incident. ISO 27001 requires an incident management process exists and works — it does not require reporting to a government authority on a statutory clock. An organisation can have an exemplary ISO 27001 incident process and still be in breach of NIS2 if it doesn't meet the regulatory reporting deadline.
  • Governance liability. NIS2 places direct accountability on management bodies for approving and overseeing cybersecurity risk-management measures, with the possibility of personal liability for non-compliance in some member states' transposing legislation. ISO 27001 requires top management commitment as a certification criterion, but it does not carry the same statutory liability exposure — that liability arises from national law implementing the Directive, not from a management-system standard.
  • Registration and scope determination under national law. Whether an organisation falls within NIS2's scope at all, and which specific national authority it must register and report to, is determined by each member state's transposing legislation — something no international standard addresses.

The honest summary: ISO 27001 certification gives you most of the technical and organisational substance NIS2 asks for, and it gives you an audited, evidenced management system to build on. It does not, by itself, satisfy NIS2's legal obligations. The two need to be treated as connected but distinct compliance tracks.

Common mistakes

  • Assuming certification equals compliance. Teams sometimes tell auditors or leadership "we're ISO 27001 certified, so we're covered for NIS2." Certification demonstrates a management system exists and is audited; it does not by itself demonstrate that statutory reporting timelines, governance accountability structures, or national registration obligations have been met.
  • Skipping the gap analysis. Even with strong Annex A coverage, someone needs to formally check which NIS2-specific legal obligations — reporting workflows, designated contact points, governance sign-off procedures — are not yet in place, rather than assuming the ISMS covers everything.
  • Treating supply chain security as a checkbox. Both frameworks treat supplier risk seriously, but NIS2's supply chain expectations for critical or important entities can go beyond what a standard Annex A supplier control implementation covers, particularly for assessing subcontractors several tiers down.
  • Waiting for a final, official mapping document to appear. Because NIS2 is still being transposed and interpreted differently across member states, and formal guidance continues to evolve, organisations that wait for a definitive cross-reference before acting risk missing deadlines that are already fixed in law.

A note on regulatory uncertainty

NIS2's national transposition is not uniform: member states have implemented the Directive on different timelines and with some variation in scope thresholds, sector definitions, and enforcement detail. Guidance from national cybersecurity authorities on exactly how NIS2 obligations interact with existing certifications is also still developing in several jurisdictions. Any specific figures — turnover thresholds, headcount thresholds, exact reporting deadlines in hours, penalty amounts — should be confirmed against the current transposing legislation in your own member state and sector, not assumed from general summaries, including this one.

Where IgeraIndustria fits

Once a manufacturer has mapped its ISO 27001 documentation against its NIS2 obligations, the harder ongoing problem is usually keeping staff and auditors able to find the right answer in the right document, fast — which policy covers supplier onboarding, which procedure governs incident escalation, which control owns a given clause. IgeraIndustria is built for exactly that: it answers questions directly from an organisation's own compliance and quality documents — ISMS policies, procedures, risk registers, supplier contracts — and cites the exact source paragraph, rather than producing a generic answer. For a compliance team juggling ISO 27001 evidence and NIS2 obligations side by side, that traceability is often the difference between an audit that runs smoothly and one that doesn't.

Frequently asked questions

Does ISO 27001 certification automatically make us NIS2 compliant?

No. It gives you substantial groundwork — Annex A's control themes cover most of what Article 21 asks for in substance — but NIS2-specific legal obligations, such as statutory incident reporting timelines and management-body liability, are not certification requirements and must be addressed separately.

Is there an official table mapping NIS2 articles to ISO 27001 controls?

No official, numbered one-to-one correspondence table exists from any regulator or standards body. What's genuinely useful, and what this article presents, is a conceptual mapping at the level of measure category to control theme.

Which NIS2 measure maps most directly to a single ISO 27001 control area?

Supply chain security is the closest match — it corresponds fairly directly to Annex A's supplier relationship controls. Most other NIS2 measure categories draw on two or more Annex A themes at once, so a clean one-to-one match is the exception rather than the rule.

If we're not yet ISO 27001 certified, should we get certified before addressing NIS2?

Not necessarily in that order. NIS2 obligations carry their own legal deadlines that don't wait for a certification cycle. Many organisations run both efforts in parallel, using ISO 27001's structure to organise the technical and organisational work while addressing NIS2's specific legal obligations, such as reporting procedures and governance sign-off, directly.

Does NIS2 apply to our manufacturing site specifically?

That depends on your sector classification, size, and the transposing legislation in your specific EU member state, since thresholds and scope details vary by country. This determination should be confirmed against current national law rather than assumed.

What's the single biggest gap between an ISO 27001 ISMS and NIS2 obligations?

Statutory incident reporting to a national authority within a legally defined timeframe. ISO 27001 requires an incident management process to exist and function; it does not require reporting to a regulator on a fixed legal clock, which is where most certified organisations still need dedicated NIS2 work.

Can a tool like IgeraIndustria replace legal or compliance advice on NIS2?

No. It helps teams find and cite the relevant passage in their own existing documents quickly and accurately, which supports audit readiness and internal consistency — but it does not interpret law or certify compliance, and it is not a substitute for qualified advice.

Disclaimer: This article is provided for general informational purposes only and does not constitute legal or certification advice. NIS2 transposition and enforcement practice vary by EU member state and continue to evolve, and ISO/IEC 27001 requirements are set by the applicable standard and your certification body. Before making compliance decisions, consult a qualified compliance consultant, certification body, or lawyer familiar with your specific sector, jurisdiction, and organisational scope.

#NIS2 ISO 27001 mapping#NIS2 compliance manufacturing#ISO 27001 Annex A controls#NIS2 Article 21 requirements#NIS2 vs ISO 27001#cybersecurity compliance industrial sector#IgeraIndustria#NIS2 gap analysis

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

🛡️IgeraRegTech2026 Diagnostic Matrix
GUÍA DESCARGABLE (TXT)

NIS2 & DORA 2026 Statutory Compliance Gap Assessment Matrix

Diagnostic tool for DPOs and CISOs: essential vs important entity classifier, 10 mandatory risk management measures under NIS2 Art. 21, and DORA ICT third-party rules.

  • Automatic entity classification based on revenue and sector thresholds
  • Real-time compliance scoring with automated remediation action roadmap
  • Mandatory 24h/72h cybersecurity incident alert templates for authorities

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network