TL;DR
- No. ISO 27001 is a voluntary certification, NIS2 is a legal obligation. A certificate does not satisfy the law.
- The overlap is real: six of the ten Article 21 measures are substantially covered by a working ISMS, two are partial, two are limited.
- Three NIS2 duties have no ISO 27001 equivalent: 24 and 72 hour incident reporting, management liability under Article 20, and registration with a national authority.
- The hardest gaps are ongoing effectiveness evidence under 21(2)(f), supply chain depth under 21(2)(d), and secured out-of-band communications under 21(2)(j).
- Do ISO 27001 first, then confirm scope, map the ten measures, close the three structural gaps, and deepen supply chain and effectiveness evidence.
No. They are different instruments doing different jobs.
ISO 27001 is a voluntary certifiable standard. You define a scope, run a management system inside it, and an external auditor confirms the system works. NIS2 is a legal obligation imposed by Member State law. There is no scope statement you control and no certificate that satisfies it.
That said, the overlap is real and substantial. Most of what Article 21 asks for is already sitting inside a functioning ISMS. The useful question is not whether ISO 27001 is enough, because it is not, but which parts of NIS2 it already answers and which parts it leaves open.
Six of the ten Article 21 measures map closely onto ISO 27001 clauses and Annex A controls. If your ISMS is certified and operating, this is largely evidence you already hold.
| Article 21 measure | ISO 27001 coverage | Where it comes from |
|---|---|---|
| 21(2)(a) Risk analysis and information system security policies | Strong | Clause 6.1 risk assessment and treatment, plus organisational policy controls in Annex A.5 |
| 21(2)(c) Business continuity, backup, disaster recovery, crisis management | Strong | Continuity and ICT readiness controls in A.5, backup and redundancy controls in A.8 |
| 21(2)(e) Security in acquisition, development and maintenance, vulnerability handling | Strong | Secure development lifecycle and vulnerability management controls in A.8 |
| 21(2)(g) Basic cyber hygiene and cybersecurity training | Strong | Clause 7.2 competence, clause 7.3 awareness, people controls in A.6 |
| 21(2)(h) Cryptography and, where appropriate, encryption | Strong | Cryptographic controls in A.8, covering use and key management |
| 21(2)(i) HR security, access control, asset management | Strong | People controls in A.6, access control and asset management controls in A.5 |
Strong does not mean finished. It means the control exists, the policy exists, and the evidence trail exists in a form a regulator would recognise. What still has to happen is confirming the ISMS scope actually covers the systems NIS2 cares about, which for many organisations it does not.
21(2)(b) Incident handling. ISO 27001 covers detection, response, classification, learning from incidents and evidence collection. What it does not cover is the regulatory reporting obligation. NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Nothing in ISO 27001 forces you to build a process against those clocks or to establish a channel to a national CSIRT.
21(2)(f) Policies and procedures to assess effectiveness. ISO 27001 has clause 9.1 monitoring and measurement, clause 9.2 internal audit, and clause 9.3 management review. On paper, this is a direct match. In practice, most ISMS implementations satisfy it with an annual internal audit and a periodic management review, which is a point-in-time answer to what NIS2 frames as an ongoing operational requirement.
This is the measure that separates organisations who pass an ISO audit from organisations who can survive a NIS2 inspection. An essential entity is subject to proactive supervision, meaning a regulator can ask to see effectiveness evidence without an incident having occurred. An annual audit report is a thin answer to that question.
21(2)(d) Supply chain security. ISO 27001 has supplier relationship controls covering agreements, service delivery monitoring, and ICT supply chain considerations. NIS2 goes further in two ways. It requires you to account for vulnerabilities specific to each direct supplier, and it requires you to consider the results of coordinated security risk assessments of critical supply chains carried out at EU level. The practical difference is depth and cadence. A supplier register with signed security clauses satisfies ISO 27001. It does not satisfy Article 21(2)(d) on its own.
21(2)(j) Multi-factor authentication and secured communications. ISO 27001 covers secure authentication and information transfer as outcomes, without mandating specific mechanisms. NIS2 names multi-factor or continuous authentication explicitly, and adds secured voice, video, and text communications, plus secured emergency communication systems within the entity. That last item is the genuine gap. Most organisations have no out-of-band communication capability tested for the scenario where their primary systems are compromised.
Three NIS2 obligations have no ISO 27001 equivalent. They are not gaps in coverage; they are obligations of a different kind, and they are where most organisations underestimate the work.
| Obligation | Why ISO 27001 does not address it |
|---|---|
| Incident reporting inside 24 and 72 hours | ISO 27001 is a management system standard. It has no concept of a statutory reporting clock or a national competent authority. |
| Management liability under Article 20 | Management bodies must approve the risk-management measures, oversee implementation, undergo training, and can be held personally liable. ISO 27001 requires leadership commitment under clause 5, which is a governance expectation, not personal legal exposure. |
| Registration and notification duties | NIS2 requires in-scope entities to register with a competent authority and provide contact details. Requirements vary by Member State. Nothing in a certification scheme touches this. |
Yes, and for a specific reason. Article 21(1) requires measures to be appropriate and proportionate, assessed against your exposure, size, and the societal impact of disruption. A functioning ISMS is the most efficient way to demonstrate you reached that judgement systematically rather than arbitrarily.
The sequencing that works:
Assuming ISMS scope equals NIS2 scope. Certification scopes are frequently narrow, sometimes covering only a product or a single business unit. NIS2 applies to the entity.
Treating one Member State's requirement as the requirement. NIS2 is a directive. Thresholds, registration mechanics, and reporting channels come from national transposing law, and organisations operating across several Member States face several sets of rules.
Reading essential and important as heavy and light. The Article 21 obligations are identical. What differs is the supervision model and penalty ceiling.
Nine of the ten Article 21 measures are answered by controls you probably already run. The tenth, Article 21(2)(f), asks whether those controls work on an ongoing basis, and Article 20 puts a named director behind the answer.
| The gap | What it takes to close | How 6clicks handles it |
|---|---|---|
| Effectiveness evidence, not just control existence | Continuous testing with retained history a regulator can inspect | Automated control testing and evidence collection |
| Supply chain depth under 21(2)(d) | Tiered assessments per direct supplier, tracked and scored | Vendor risk assessments issued, tracked, and scored in one register |
| One control set, several Member States | Test once, satisfy multiple obligations | Multi-framework compliance mapping across NIS2, ISO 27001 and others |
| Management oversight under Article 20 | Reporting a director can defend without reconstructing it | Executive and board reporting views |
| Reporting inside 24 and 72 hours | Evidence retrievable at speed, not assembled under pressure | Centralized incident and evidence registers |
Get the full Article 21 to ISO 27001 mapping, measure by measure, with the evidence each one requires. Book a 30-minute NIS2 evidence session with our team.