TL;DR
- No. ISO 27001 is a voluntary certification, NIS2 is a legal obligation. A certificate does not satisfy the law.
- The overlap is real: six of the ten Article 21 measures are substantially covered by a working ISMS, two are partial, two are limited.
- Three NIS2 duties have no ISO 27001 equivalent: 24 and 72 hour incident reporting, management liability under Article 20, and registration with a national authority.
- The hardest gaps are ongoing effectiveness evidence under 21(2)(f), supply chain depth under 21(2)(d), and secured out-of-band communications under 21(2)(j).
- Do ISO 27001 first, then confirm scope, map the ten measures, close the three structural gaps, and deepen supply chain and effectiveness evidence.
Does ISO 27001 certification mean you comply with NIS2?
No. They are different instruments doing different jobs.
ISO 27001 is a voluntary certifiable standard. You define a scope, run a management system inside it, and an external auditor confirms the system works. NIS2 is a legal obligation imposed by Member State law. There is no scope statement you control and no certificate that satisfies it.
That said, the overlap is real and substantial. Most of what Article 21 asks for is already sitting inside a functioning ISMS. The useful question is not whether ISO 27001 is enough, because it is not, but which parts of NIS2 it already answers and which parts it leaves open.
Where the overlap is strong
Six of the ten Article 21 measures map closely onto ISO 27001 clauses and Annex A controls. If your ISMS is certified and operating, this is largely evidence you already hold.
| Article 21 measure | ISO 27001 coverage | Where it comes from |
|---|---|---|
| 21(2)(a) Risk analysis and information system security policies | Strong | Clause 6.1 risk assessment and treatment, plus organisational policy controls in Annex A.5 |
| 21(2)(c) Business continuity, backup, disaster recovery, crisis management | Strong | Continuity and ICT readiness controls in A.5, backup and redundancy controls in A.8 |
| 21(2)(e) Security in acquisition, development and maintenance, vulnerability handling | Strong | Secure development lifecycle and vulnerability management controls in A.8 |
| 21(2)(g) Basic cyber hygiene and cybersecurity training | Strong | Clause 7.2 competence, clause 7.3 awareness, people controls in A.6 |
| 21(2)(h) Cryptography and, where appropriate, encryption | Strong | Cryptographic controls in A.8, covering use and key management |
| 21(2)(i) HR security, access control, asset management | Strong | People controls in A.6, access control and asset management controls in A.5 |
Strong does not mean finished. It means the control exists, the policy exists, and the evidence trail exists in a form a regulator would recognise. What still has to happen is confirming the ISMS scope actually covers the systems NIS2 cares about, which for many organisations it does not.
Where the overlap is partial
21(2)(b) Incident handling. ISO 27001 covers detection, response, classification, learning from incidents and evidence collection. What it does not cover is the regulatory reporting obligation. NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Nothing in ISO 27001 forces you to build a process against those clocks or to establish a channel to a national CSIRT.
21(2)(f) Policies and procedures to assess effectiveness. ISO 27001 has clause 9.1 monitoring and measurement, clause 9.2 internal audit, and clause 9.3 management review. On paper, this is a direct match. In practice, most ISMS implementations satisfy it with an annual internal audit and a periodic management review, which is a point-in-time answer to what NIS2 frames as an ongoing operational requirement.
This is the measure that separates organisations who pass an ISO audit from organisations who can survive a NIS2 inspection. An essential entity is subject to proactive supervision, meaning a regulator can ask to see effectiveness evidence without an incident having occurred. An annual audit report is a thin answer to that question.
Where the overlap is limited
21(2)(d) Supply chain security. ISO 27001 has supplier relationship controls covering agreements, service delivery monitoring, and ICT supply chain considerations. NIS2 goes further in two ways. It requires you to account for vulnerabilities specific to each direct supplier, and it requires you to consider the results of coordinated security risk assessments of critical supply chains carried out at EU level. The practical difference is depth and cadence. A supplier register with signed security clauses satisfies ISO 27001. It does not satisfy Article 21(2)(d) on its own.
21(2)(j) Multi-factor authentication and secured communications. ISO 27001 covers secure authentication and information transfer as outcomes, without mandating specific mechanisms. NIS2 names multi-factor or continuous authentication explicitly, and adds secured voice, video, and text communications, plus secured emergency communication systems within the entity. That last item is the genuine gap. Most organisations have no out-of-band communication capability tested for the scenario where their primary systems are compromised.
What ISO 27001 does not cover at all
Three NIS2 obligations have no ISO 27001 equivalent. They are not gaps in coverage; they are obligations of a different kind, and they are where most organisations underestimate the work.
| Obligation | Why ISO 27001 does not address it |
|---|---|
| Incident reporting inside 24 and 72 hours | ISO 27001 is a management system standard. It has no concept of a statutory reporting clock or a national competent authority. |
| Management liability under Article 20 | Management bodies must approve the risk-management measures, oversee implementation, undergo training, and can be held personally liable. ISO 27001 requires leadership commitment under clause 5, which is a governance expectation, not personal legal exposure. |
| Registration and notification duties | NIS2 requires in-scope entities to register with a competent authority and provide contact details. Requirements vary by Member State. Nothing in a certification scheme touches this. |
So is ISO 27001 worth doing before NIS2?
Yes, and for a specific reason. Article 21(1) requires measures to be appropriate and proportionate, assessed against your exposure, size, and the societal impact of disruption. A functioning ISMS is the most efficient way to demonstrate you reached that judgement systematically rather than arbitrarily.
The sequencing that works:
- Confirm scope. Establish whether NIS2 applies directly, through supply chain obligations, or through a size exemption.
- Map what you have. Take the ten Article 21 measures against your existing Statement of Applicability and control set.
- Close the three structural gaps first: reporting process, management accountability, and registration. These are the fastest to fix and the most visible to a regulator.
- Deepen supply chain and effectiveness evidence. These are the two that take real time and cannot be documented into existence.
Common mistakes
Assuming ISMS scope equals NIS2 scope. Certification scopes are frequently narrow, sometimes covering only a product or a single business unit. NIS2 applies to the entity.
Treating one Member State's requirement as the requirement. NIS2 is a directive. Thresholds, registration mechanics, and reporting channels come from national transposing law, and organisations operating across several Member States face several sets of rules.
Reading essential and important as heavy and light. The Article 21 obligations are identical. What differs is the supervision model and penalty ceiling.
Frequently asked questions
No. NIS2 does not require any certification. Article 21(2) allows entities to use European or international standards, and Member States may encourage specific ones, but certification is not the obligation.
Six of the ten are substantially covered. Two are partially covered, and two are covered only in limited form. Actual coverage depends on ISMS scope and maturity.
No. ISO 27001 covers incident management as an internal process. The statutory reporting timeline and communication to a national CSIRT are NIS2-specific and must be implemented separately.
No. Both are subject to the same ten Article 21 measures. The difference is supervision and maximum penalties.
Partially. Supplier relationship controls provide a foundation, but Article 21(2)(d) requires assessment of vulnerabilities specific to each direct supplier, which typically goes deeper than a standard supplier register.
How 6clicks helps
Nine of the ten Article 21 measures are answered by controls you probably already run. The tenth, Article 21(2)(f), asks whether those controls work on an ongoing basis, and Article 20 puts a named director behind the answer.
| The gap | What it takes to close | How 6clicks handles it |
|---|---|---|
| Effectiveness evidence, not just control existence | Continuous testing with retained history a regulator can inspect | Automated control testing and evidence collection |
| Supply chain depth under 21(2)(d) | Tiered assessments per direct supplier, tracked and scored | Vendor risk assessments issued, tracked, and scored in one register |
| One control set, several Member States | Test once, satisfy multiple obligations | Multi-framework compliance mapping across NIS2, ISO 27001 and others |
| Management oversight under Article 20 | Reporting a director can defend without reconstructing it | Executive and board reporting views |
| Reporting inside 24 and 72 hours | Evidence retrievable at speed, not assembled under pressure | Centralized incident and evidence registers |
Get the full Article 21 to ISO 27001 mapping, measure by measure, with the evidence each one requires. Book a 30-minute NIS2 evidence session with our team.