NIS2 knowledge base

ISO 27001 and NIS2: overlap, differences and board relevance

ISO 27001 provides a structured information-security management system. NIS2 and the Dutch Cybersecurity Act add statutory scope, executive responsibility, specific duty-of-care expectations, incident reporting and regulatory supervision.

Where ISO 27001 and NIS2 overlap

Both approaches expect risk-based management, clear roles, policies, controls, monitoring, internal review and continual improvement. A well-operated ISO 27001 management system can therefore provide valuable structure and evidence for NIS2 readiness.

The strongest value lies in operation: current risk assessments, ownership, testing, corrective actions and management review. A certificate is useful evidence, while the underlying management process creates resilience.

Where the difference arises

NIS2 is a legal framework with entity scope, registration, significant-incident reporting, executive duties and regulatory enforcement. ISO 27001 is a voluntary certifiable standard unless a contract or policy makes it mandatory.

The scope of an ISO certificate may also be narrower than the legal entity or services covered by the Act. Compare both scopes explicitly.

What directors should understand

Ask how the ISO 27001 scope maps to statutory scope, which NIS2 obligations require additional processes and which evidence supports the effectiveness of measures. Pay particular attention to incident-reporting timelines, suppliers, all-hazards risks, continuity and board approvals.

  • Does the certified scope cover all relevant services and entities?
  • Are risks linked to critical services and protected interests?
  • Do reporting and crisis processes meet the Dutch legal timeline?
  • Which supplier and continuity requirements need additional work?
  • How are exceptions and residual risks reported to the board?

When ISO 27001 adds the most value

ISO 27001 adds value when the organisation uses it as a living management system and integrates it with governance, enterprise risk, continuity, procurement and incident management. Existing processes can then be extended rather than rebuilt.

A gap assessment between the certified system and the Dutch Cybersecurity Act provides a focused implementation route.

Frequently asked questions

Does an ISO 27001 certificate prove NIS2 compliance?

No. It provides useful evidence and structure, while statutory scope, incident reporting, executive duties and other requirements still need a separate assessment.

Do we need ISO 27001 for NIS2?

NIS2 does not generally require certification. The standard can be a strong method for structuring and evidencing information-security management.

What should the board compare first?

Compare the ISO scope with statutory scope and identify additional legal, reporting, supplier and governance requirements.

Assess how ISO 27001 supports your NIS2 roadmap

Training helps the board recognise useful ISMS evidence and identify the statutory duties and governance choices that require separate attention.

Discuss the appropriate training route