Blogs | 6clicks

Does ISO 27001 certification mean you comply with NIS2?

Written by 6clicks Editorial | Aug 17, 2026

TL;DR

  • No. ISO 27001 is a voluntary certification, NIS2 is a legal obligation. A certificate does not satisfy the law.
  • The overlap is real: six of the ten Article 21 measures are substantially covered by a working ISMS, two are partial, two are limited.
  • Three NIS2 duties have no ISO 27001 equivalent: 24 and 72 hour incident reporting, management liability under Article 20, and registration with a national authority.
  • The hardest gaps are ongoing effectiveness evidence under 21(2)(f), supply chain depth under 21(2)(d), and secured out-of-band communications under 21(2)(j).
  • Do ISO 27001 first, then confirm scope, map the ten measures, close the three structural gaps, and deepen supply chain and effectiveness evidence.

Does ISO 27001 certification mean you comply with NIS2?

No. They are different instruments doing different jobs.

 

ISO 27001 is a voluntary certifiable standard. You define a scope, run a management system inside it, and an external auditor confirms the system works. NIS2 is a legal obligation imposed by Member State law. There is no scope statement you control and no certificate that satisfies it.

 

That said, the overlap is real and substantial. Most of what Article 21 asks for is already sitting inside a functioning ISMS. The useful question is not whether ISO 27001 is enough, because it is not, but which parts of NIS2 it already answers and which parts it leaves open.

Where the overlap is strong

Six of the ten Article 21 measures map closely onto ISO 27001 clauses and Annex A controls. If your ISMS is certified and operating, this is largely evidence you already hold.

 

Article 21 measure ISO 27001 coverage Where it comes from
21(2)(a) Risk analysis and information system security policies Strong Clause 6.1 risk assessment and treatment, plus organisational policy controls in Annex A.5
21(2)(c) Business continuity, backup, disaster recovery, crisis management Strong Continuity and ICT readiness controls in A.5, backup and redundancy controls in A.8
21(2)(e) Security in acquisition, development and maintenance, vulnerability handling Strong Secure development lifecycle and vulnerability management controls in A.8
21(2)(g) Basic cyber hygiene and cybersecurity training Strong Clause 7.2 competence, clause 7.3 awareness, people controls in A.6
21(2)(h) Cryptography and, where appropriate, encryption Strong Cryptographic controls in A.8, covering use and key management
21(2)(i) HR security, access control, asset management Strong People controls in A.6, access control and asset management controls in A.5

 

Strong does not mean finished. It means the control exists, the policy exists, and the evidence trail exists in a form a regulator would recognise. What still has to happen is confirming the ISMS scope actually covers the systems NIS2 cares about, which for many organisations it does not.

Where the overlap is partial

 

21(2)(b) Incident handling. ISO 27001 covers detection, response, classification, learning from incidents and evidence collection. What it does not cover is the regulatory reporting obligation. NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Nothing in ISO 27001 forces you to build a process against those clocks or to establish a channel to a national CSIRT.

 

21(2)(f) Policies and procedures to assess effectiveness. ISO 27001 has clause 9.1 monitoring and measurement, clause 9.2 internal audit, and clause 9.3 management review. On paper, this is a direct match. In practice, most ISMS implementations satisfy it with an annual internal audit and a periodic management review, which is a point-in-time answer to what NIS2 frames as an ongoing operational requirement.

 

This is the measure that separates organisations who pass an ISO audit from organisations who can survive a NIS2 inspection. An essential entity is subject to proactive supervision, meaning a regulator can ask to see effectiveness evidence without an incident having occurred. An annual audit report is a thin answer to that question.

Where the overlap is limited

21(2)(d) Supply chain security. ISO 27001 has supplier relationship controls covering agreements, service delivery monitoring, and ICT supply chain considerations. NIS2 goes further in two ways. It requires you to account for vulnerabilities specific to each direct supplier, and it requires you to consider the results of coordinated security risk assessments of critical supply chains carried out at EU level. The practical difference is depth and cadence. A supplier register with signed security clauses satisfies ISO 27001. It does not satisfy Article 21(2)(d) on its own.

 

21(2)(j) Multi-factor authentication and secured communications. ISO 27001 covers secure authentication and information transfer as outcomes, without mandating specific mechanisms. NIS2 names multi-factor or continuous authentication explicitly, and adds secured voice, video, and text communications, plus secured emergency communication systems within the entity. That last item is the genuine gap. Most organisations have no out-of-band communication capability tested for the scenario where their primary systems are compromised.

What ISO 27001 does not cover at all

Three NIS2 obligations have no ISO 27001 equivalent. They are not gaps in coverage; they are obligations of a different kind, and they are where most organisations underestimate the work.

 

Obligation Why ISO 27001 does not address it
Incident reporting inside 24 and 72 hours ISO 27001 is a management system standard. It has no concept of a statutory reporting clock or a national competent authority.
Management liability under Article 20 Management bodies must approve the risk-management measures, oversee implementation, undergo training, and can be held personally liable. ISO 27001 requires leadership commitment under clause 5, which is a governance expectation, not personal legal exposure.
Registration and notification duties NIS2 requires in-scope entities to register with a competent authority and provide contact details. Requirements vary by Member State. Nothing in a certification scheme touches this.

So is ISO 27001 worth doing before NIS2?

Yes, and for a specific reason. Article 21(1) requires measures to be appropriate and proportionate, assessed against your exposure, size, and the societal impact of disruption. A functioning ISMS is the most efficient way to demonstrate you reached that judgement systematically rather than arbitrarily.

 

The sequencing that works:

 

  1. Confirm scope. Establish whether NIS2 applies directly, through supply chain obligations, or through a size exemption.
  2. Map what you have. Take the ten Article 21 measures against your existing Statement of Applicability and control set.
  3. Close the three structural gaps first: reporting process, management accountability, and registration. These are the fastest to fix and the most visible to a regulator.
  4. Deepen supply chain and effectiveness evidence. These are the two that take real time and cannot be documented into existence.

Common mistakes

Assuming ISMS scope equals NIS2 scope. Certification scopes are frequently narrow, sometimes covering only a product or a single business unit. NIS2 applies to the entity.

 

Treating one Member State's requirement as the requirement. NIS2 is a directive. Thresholds, registration mechanics, and reporting channels come from national transposing law, and organisations operating across several Member States face several sets of rules.

 

Reading essential and important as heavy and light. The Article 21 obligations are identical. What differs is the supervision model and penalty ceiling.

Frequently asked questions

 

How 6clicks helps

Nine of the ten Article 21 measures are answered by controls you probably already run. The tenth, Article 21(2)(f), asks whether those controls work on an ongoing basis, and Article 20 puts a named director behind the answer.

 

The gap What it takes to close How 6clicks handles it
Effectiveness evidence, not just control existence Continuous testing with retained history a regulator can inspect Automated control testing and evidence collection
Supply chain depth under 21(2)(d) Tiered assessments per direct supplier, tracked and scored Vendor risk assessments issued, tracked, and scored in one register
One control set, several Member States Test once, satisfy multiple obligations Multi-framework compliance mapping across NIS2, ISO 27001 and others
Management oversight under Article 20 Reporting a director can defend without reconstructing it Executive and board reporting views
Reporting inside 24 and 72 hours Evidence retrievable at speed, not assembled under pressure Centralized incident and evidence registers

 

Get the full Article 21 to ISO 27001 mapping, measure by measure, with the evidence each one requires. Book a 30-minute NIS2 evidence session with our team.