
Many organisations that are beginning to grapple with the requirements of NIS2 immediately look to ISO 27001 as a ‘ready-made solution’. This is a natural association, as both approaches concern information security and risk management. The problem arises when they are treated as one and the same, or when one is expected to automatically replace the other.
In reality, NIS2 and ISO 27001 are interrelated but fulfil different roles. One is a legal regulation, the other a security management standard. Understanding this difference is crucial to how an organisation builds compliance.
NIS2 is an EU directive, i.e. a legal act that imposes obligations on specific groups of organisations. Its aim is to ensure a minimum level of cybersecurity in sectors deemed critical or important to the functioning of the state and the economy. It covers, amongst other things, obligations regarding incident reporting, risk management, supply chain security and management responsibility.
ISO 27001, on the other hand, is an international standard that describes how to establish and maintain an information security management system (ISMS). It is not legally binding but voluntary. Organisations implement it to streamline their security processes and obtain certification confirming compliance with the standard.
The key difference, therefore, is that NIS2 specifies what needs to be achieved, whilst ISO 27001 describes how this can be done. The Directive sets out legal obligations, whilst the standard provides methodologies for fulfilling them.

Despite their differences, the two approaches share many common elements. Both NIS2 and ISO 27001 are based on a risk-based approach, which means that threats must be identified, their impact assessed and appropriate safeguards implemented. In both cases, issues such as access control, incident management, business continuity and supply chain security are also important. ISO 27001 organises these areas within a management system that can significantly facilitate compliance with NIS2 requirements.
Organisations holding ISO 27001 certification usually already have basic security processes in place, which gives them an advantage when it comes to complying with NIS2. However, this does not mean automatic compliance, as the directive introduces additional obligations that the standard does not explicitly cover.
Holding ISO 27001 certification can be a significant help in meeting the requirements of NIS2, but it does not fully replace them. The Directive imposes additional obligations that go beyond the scope of the standard. Above all, NIS2 introduces formal accountability of the board for cybersecurity and a requirement to report serious incidents within strictly defined timeframes. It also includes more detailed requirements regarding the supervision of suppliers and the obligation to implement specific organisational and technical measures.
ISO 27001 does not legally impose such obligations. It is a flexible standard that can be adapted to an organisation, whereas NIS2 is a regulation that must be complied with if a company falls within its scope.
For this reason, ISO 27001 can provide a solid foundation for meeting the requirements of NIS2, but it does not exempt organisations from the need to analyse compliance with the directive and address any gaps. In many cases, certified organisations still need to introduce additional procedures, particularly in the areas of incident reporting and risk management at board level.
NIS2 and ISO 27001 are not competing approaches, but rather solutions of a different nature. The NIS2 Directive sets out legal requirements, whilst ISO 27001 provides a proven methodology for establishing an information security management system.
For organisations, this means that ISO 27001 can significantly facilitate compliance with NIS2 requirements, but it does not replace a regulatory compliance assessment. The most effective approach is to use the standard as a foundation and supplement it with elements derived directly from the directive.