InfoSec

NIS2 and ISO 27001: Where They Overlap

Most often, NIS2 and ISO 27001 are intertwined together. ISO 27001 touches NIS2 at many key points that facilitate compliance with the latter if the former is achieved.

Author
Dr. Kilian Schmidt
Date
23.4.2026
Updated on
20.7.2026
NIS2 and ISO 27001: Where They Overlap

Key takeaways

  • An ISO 27001 ISMS covers roughly 70% of NIS2's Article 21 security requirements — a rule of thumb, not a guarantee, and it varies by scope and sector.
  • NIS2 adds three things ISO 27001 doesn't fully cover: strict incident reporting (24-hour, 72-hour and one-month deadlines), management accountability (Article 20), and deeper business continuity (toward ISO 22301).
  • ISO 27001 is not mandatory for NIS2, but a certified ISMS is the fastest route to compliance and the strongest evidence of it.
  • Extending an existing ISMS is faster and cheaper than building a separate NIS2 programme.
  • In Germany, NIS2 is already in force (NIS2UmsuCG, since 6 December 2025), covering around 29,500 companies, with fines up to 10 million euro or 2% of global turnover.

How much of NIS2 does ISO 27001 actually cover?

An ISO 27001-conformant ISMS is commonly estimated to satisfy around 70% of NIS2's technical and organizational security requirements under Article 21, because both frameworks rest on the same risk-based controls. Treat 70% as a widely-cited rule of thumb, not a certified figure: the exact coverage depends on your scope and sector. The remaining portion — strict incident-reporting timelines, management accountability, and deeper business-continuity requirements — needs NIS2-specific additions layered on top of the ISMS.

ISO 27001 to NIS2 mapping: what carries over and what doesn't

NIS2 Article 21(2) lists ten security measures. Most map directly onto ISO 27001 Annex A controls; a few need additions. This is the practical view of the overlap.

NIS2 Article 21 measure ISO 27001 coverage Gap to close
Risk analysis and information security policiesClause 6 risk assessment; Annex A 5.1 policiesNone — fully covered
Incident handlingAnnex A 5.24–5.28NIS2's 24h / 72h / one-month reporting timelines to the authority
Business continuity, backup, crisis managementAnnex A 5.29, 5.30, 8.13Often needs ISO 22301-level continuity depth for essential entities
Supply chain securityAnnex A 5.19–5.22Largely covered; NIS2 expects active supplier monitoring
Security in acquisition, development and maintenanceAnnex A 8.25–8.31None — fully covered
Measuring the effectiveness of controlsClause 9 monitoring, internal audit, management reviewNone — fully covered
Cyber hygiene and trainingAnnex A 6.3None — fully covered
Cryptography and encryptionAnnex A 8.24None — fully covered
HR security, access control, asset managementAnnex A 6.1–6.6, 5.9–5.11, 8.1–8.5None — fully covered
Multi-factor authentication and secure communicationsAnnex A 8.5, 8.20–8.21None — fully covered

The pattern is clear: ISO 27001 gives you the ISMS backbone, and NIS2 adds three things on top — strict incident-reporting deadlines, explicit management accountability, and business-continuity depth. Build the ISMS once, then layer those on rather than starting a separate NIS2 programme.

Where NIS2 stands now (and why it's urgent in Germany)

NIS2 is no longer a future directive — it is being enforced through national law. In Germany, the NIS2 Implementation Act (NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz, NIS2UmsuCG) has been in force since 6 December 2025, and the initial BSI registration window closed on 6 March 2026. It brings roughly 29,500 companies into scope (up from about 4,500), with fines up to 10 million euro or 2% of global turnover, personal liability for management, and no transition period. If your organization is in scope and already holds ISO 27001, you are in the best possible starting position — your ISMS already covers most of what the law requires. See the German government's overview of the NIS2 implementation. (Status verified 15 July 2026.)

Frequently asked questions

Does ISO 27001 certification make me NIS2 compliant?

No, but it gets you most of the way. An ISO 27001-conformant ISMS satisfies the majority of NIS2's Article 21 security measures. It does not, on its own, cover NIS2's strict incident-reporting timelines, management-accountability duties, or the deeper business-continuity requirements for essential entities, which must be added on top.

How much of NIS2 does ISO 27001 cover?

Commonly estimated at around 70% of the technical and organizational requirements, because both frameworks share the same risk-based control foundation. The exact figure depends on your scope and sector, so treat 70% as a rule of thumb rather than a guarantee.

Where does NIS2 go beyond ISO 27001?

Three areas mainly: incident reporting (NIS2 requires an early warning within 24 hours, a notification within 72 hours, and a final report within one month); management accountability (Article 20 makes leadership personally responsible); and business continuity, where NIS2 often expects ISO 22301-level depth that ISO 27001 alone does not prescribe.

Do I need ISO 27001 to comply with NIS2?

No. ISO 27001 is not mandatory under NIS2. But because NIS2 tells you what to achieve and ISO 27001 provides the how, a certified ISMS is the most efficient route to compliance and the strongest evidence of it.

Can I reuse my existing ISMS for NIS2?

Yes, and you should. Extending an existing ISO 27001 ISMS to cover NIS2 is faster and cheaper than building a separate programme, because the controls, evidence, and governance largely overlap. You add the NIS2-specific reporting, accountability, and continuity elements rather than starting over.

Is NIS2 mandatory in Germany now?

Yes. The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025, with around 29,500 companies in scope, fines up to 10 million euro or 2% of global turnover, and no transition period. The initial BSI registration deadline was 6 March 2026.

What is the fastest route to NIS2 readiness if I already have ISO 27001?

Map your existing Annex A controls to NIS2 Article 21, then close the three usual gaps: implement the 24h/72h/one-month incident-reporting process, document management accountability under Article 20, and strengthen business continuity toward ISO 22301 where you are an essential entity. Most of the ISMS work is already done.

Want to learn more? Book a personal demo with our team.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

NIS2 and ISO 27001: Where They Overlap
Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder, Kertos GmbH

Dr. Kilian Schmidt developed a strong interest in legal processes early on. After studying law, he began his career as Senior Legal Counsel and Data Protection Officer at the Home24 Group. After working at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where, as General Counsel, he was significantly involved in expanding the legal and public policy department - and grew the company from one to 65 cities and from 50 to 800 employees. Motivated by limited technological advances in the legal sector and inspired by his consulting work at Gorillas Technologies, he co-founded Kertos to develop the next generation of European data protection technology.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check