NIS2 vs ISO 27001: differences and overlap

ISO 27001 and NIS2

Cybersecurity regulations are changing rapidly. Many organizations are therefore concerned about NIS2, the new European directive that will become mandatory from the end of 2024. Especially for organizations already working according to ISO 27001, it is important to have a clear understanding of the differences and similarities. Both systems have the same goal: better information protection. But while ISO 27001 is voluntary and applied internationally, NIS2 is a mandatory European directive for specific sectors. Therefore, it is important to fully understand where any gaps may exist. Based on an analysis of top Dutch and British sources, we clearly outline what you need to know.

Need help with NIS2 or ISO 27001?

Our consultants are happy to help you.

Contact us

What is NIS2?

NIS2 is a European regulation that will take effect from the end of 2024 and imposes stricter cybersecurity requirements on essential sectors such as energy, healthcare, transport, and financial services. Medium-sized and large organizations in these sectors are obligated to comply. The consequences of non-compliance can be significant, with fines of up to 10 million euros or 2% of the annual turnover. NIS2 requires, for example, that incidents be reported within 24 hours, that cybersecurity in the supply chain be addressed, and that top managers can be held personally liable in case of negligence.

What is ISO 27001?

ISO 27001 is an international standard for information security management, also known as an Information Security Management System (ISMS). Organizations voluntarily implement ISO 27001 to better secure their information. The standard emphasizes continuous risk assessment, implementation of security measures, and ongoing improvement of security. ISO 27001 certification is often requested by clients or partners, but it is not a legal requirement.

Scope and obligation

The scope of NIS2 is limited to specific sectors within the EU, with clearly defined criteria such as the number of employees or revenue. ISO 27001, on the other hand, can be applied by all organizations worldwide, regardless of size or sector. The key difference is that NIS2 is legally mandatory and subject to supervision by authorities, while ISO 27001 is voluntary and involves audits by certifying bodies. This means, in practice, that organizations cannot evade NIS2 once they fall within its criteria.

Management Responsibility & Reporting

A significant difference lies in management responsibility. Under NIS2, top managers can be held personally liable if requirements are not met. NIS2 also obliges organizations to report cybersecurity incidents to supervisors within 24 hours. ISO 27001 does not have this rapid reporting obligation or personal liability. While ISO 27001 does expect management involvement and regular internal audits, it does so without the external pressure of legal sanctions.

AspectISO 27001NIS2
Legal statusVoluntary standardMandatory EU law
Incident reportNot mandatoryRequired within 24 hours
Management liabilityIndirect via ISMSExplicitly recorded
OversightCertification auditGovernment oversight

Focus and approach of both

NIS2 focuses primarily on practical cybersecurity measures that help organizations respond quickly to incidents and keep their processes running. This includes things like contingency plans and vendor security. ISO 27001, on the other hand, uses a management approach and focuses on how risks can be structurally managed through policies, procedures, and evaluations. While NIS2 indicates what needs to be achieved, ISO 27001 provides practical controls and processes to actually accomplish this.

Agreements and overlap

Despite differences, we have NIS2 en ISO 27001 many points of overlap. Both focus on risk management and concrete security measures to reduce cyber risks. In addition, they both require top management involvement and continuous improvement. Research shows that approximately 70 to 80 percent of NIS2 is already covered by ISO 27001. Think of measures related to access, incident response, and employee awareness. Therefore, those who are already ISO 27001-certified are in a good starting position for NIS2.

Additional NIS2 requirements

However, there are important points where NIS2 goes further:

  • Incident report within 24 hoursISO 27001 encourages incident management but does not require prompt notification to authorities.
  • Supplier risks: NIS2 requires that supplier cybersecurity risks be contractually defined.
  • Administrative liabilityUnder NIS2, directors can be held directly liable for negligence, with significant sanctions as a result.
  • Government oversightUnlike ISO 27001, NIS2 features external oversight and audits by the government.

Organizations with ISO 27001 must be aware of these additional requirements to fully comply with NIS2.

ISO 27001 as a tool for NIS2

ISO 27001 is just useful as a starting point for NIS2. Experts state that organizations with ISO 27001 are already about 70% compliant with NIS2. Existing procedures, such as risk assessments and incident management plans, align well with NIS2. The European directive itself recommends the use of standards like ISO 27001, making it easier for organizations to take the final steps toward full compliance.

Practical approach to integration

The best approach is to start with a gap analysis between ISO 27001 and the additional requirements of NIS2. Then, create a plan for the extra steps, such as formally arranging rapid incident notifications and contractual agreements with suppliers. It is important that management is actively involved, and that all employees are regularly trained. By starting in a timely manner and potentially seeking external support, organizations can comply with NIS2 smoothly and efficiently.

Getting started – ready for the future

Don't wait until the last moment to adjust your security measures. By combining ISO 27001 and NIS2, you can prevent incidents and fines. Start improving your information security today and be ready for tomorrow.

    Want to know more about the difference and overlap between NIS2 and ISO 27001? Follow our socials.