Key takeaways
- An ISO 27001 ISMS covers roughly 70% of NIS2's Article 21 security requirements — a rule of thumb, not a guarantee, and it varies by scope and sector.
- NIS2 adds three things ISO 27001 doesn't fully cover: strict incident reporting (24-hour, 72-hour and one-month deadlines), management accountability (Article 20), and deeper business continuity (toward ISO 22301).
- ISO 27001 is not mandatory for NIS2, but a certified ISMS is the fastest route to compliance and the strongest evidence of it.
- Extending an existing ISMS is faster and cheaper than building a separate NIS2 programme.
- In Germany, NIS2 is already in force (NIS2UmsuCG, since 6 December 2025), covering around 29,500 companies, with fines up to 10 million euro or 2% of global turnover.
How much of NIS2 does ISO 27001 actually cover?
An ISO 27001-conformant ISMS is commonly estimated to satisfy around 70% of NIS2's technical and organizational security requirements under Article 21, because both frameworks rest on the same risk-based controls. Treat 70% as a widely-cited rule of thumb, not a certified figure: the exact coverage depends on your scope and sector. The remaining portion — strict incident-reporting timelines, management accountability, and deeper business-continuity requirements — needs NIS2-specific additions layered on top of the ISMS.
ISO 27001 to NIS2 mapping: what carries over and what doesn't
NIS2 Article 21(2) lists ten security measures. Most map directly onto ISO 27001 Annex A controls; a few need additions. This is the practical view of the overlap.
The pattern is clear: ISO 27001 gives you the ISMS backbone, and NIS2 adds three things on top — strict incident-reporting deadlines, explicit management accountability, and business-continuity depth. Build the ISMS once, then layer those on rather than starting a separate NIS2 programme.
Where NIS2 stands now (and why it's urgent in Germany)
NIS2 is no longer a future directive — it is being enforced through national law. In Germany, the NIS2 Implementation Act (NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz, NIS2UmsuCG) has been in force since 6 December 2025, and the initial BSI registration window closed on 6 March 2026. It brings roughly 29,500 companies into scope (up from about 4,500), with fines up to 10 million euro or 2% of global turnover, personal liability for management, and no transition period. If your organization is in scope and already holds ISO 27001, you are in the best possible starting position — your ISMS already covers most of what the law requires. See the German government's overview of the NIS2 implementation. (Status verified 15 July 2026.)
Frequently asked questions
Does ISO 27001 certification make me NIS2 compliant?
No, but it gets you most of the way. An ISO 27001-conformant ISMS satisfies the majority of NIS2's Article 21 security measures. It does not, on its own, cover NIS2's strict incident-reporting timelines, management-accountability duties, or the deeper business-continuity requirements for essential entities, which must be added on top.
How much of NIS2 does ISO 27001 cover?
Commonly estimated at around 70% of the technical and organizational requirements, because both frameworks share the same risk-based control foundation. The exact figure depends on your scope and sector, so treat 70% as a rule of thumb rather than a guarantee.
Where does NIS2 go beyond ISO 27001?
Three areas mainly: incident reporting (NIS2 requires an early warning within 24 hours, a notification within 72 hours, and a final report within one month); management accountability (Article 20 makes leadership personally responsible); and business continuity, where NIS2 often expects ISO 22301-level depth that ISO 27001 alone does not prescribe.
Do I need ISO 27001 to comply with NIS2?
No. ISO 27001 is not mandatory under NIS2. But because NIS2 tells you what to achieve and ISO 27001 provides the how, a certified ISMS is the most efficient route to compliance and the strongest evidence of it.
Can I reuse my existing ISMS for NIS2?
Yes, and you should. Extending an existing ISO 27001 ISMS to cover NIS2 is faster and cheaper than building a separate programme, because the controls, evidence, and governance largely overlap. You add the NIS2-specific reporting, accountability, and continuity elements rather than starting over.
Is NIS2 mandatory in Germany now?
Yes. The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025, with around 29,500 companies in scope, fines up to 10 million euro or 2% of global turnover, and no transition period. The initial BSI registration deadline was 6 March 2026.
What is the fastest route to NIS2 readiness if I already have ISO 27001?
Map your existing Annex A controls to NIS2 Article 21, then close the three usual gaps: implement the 24h/72h/one-month incident-reporting process, document management accountability under Article 20, and strengthen business continuity toward ISO 22301 where you are an essential entity. Most of the ISMS work is already done.
Want to learn more? Book a personal demo with our team.







