# ISO 27001 vs NIS2: what each one is, and how they differ

> ISO 27001 is a voluntary standard you can be certified against. NIS2 is EU law with mandatory duties, reporting clocks and fines. They overlap in content, not in consequence.

Source: https://fmcybersecurity.com/en/insights/compliance/iso-27001-vs-nis2-what-is-the-difference/
Locale: English
Other locale: https://fmcybersecurity.com/insights/compliance/iso-27001-vs-nis2-forskjellen/

## Metadata

- Date: 2026-10-04
- Author: maximilian-sharoyan
- Topic: compliance
- Format: article

**In brief:** ISO 27001 is an international standard for how an organisation manages information security. Choosing it is voluntary, and an accredited body can certify that you follow it. NIS2 is an EU directive that makes security measures, incident reporting and management accountability a legal duty for organisations in listed sectors. The two ask for much of the same work, but a certificate does not make you NIS2-compliant, and being covered by NIS2 does not give you a certificate.

Both terms tend to appear in the same meeting. A customer asks for ISO 27001 in a tender. A board member has read that NIS2 means personal liability. Someone suggests that doing one will take care of the other. This article explains what each one actually is, where they overlap, and where they part ways.

## What ISO 27001 is

[ISO/IEC 27001](https://www.iso.org/standard/27001) is a standard published by the International Organization for Standardization. The current edition is from 2022. It describes how to build and run an information security management system, usually shortened to ISMS: a structured way of deciding what needs protecting, assessing the risks, choosing controls, and checking that the controls work.

The standard has two parts. Clauses 4 to 10 are the management requirements: understand your context, get leadership commitment, plan around risk, provide resources, operate the controls, measure the result, and improve. Annex A is a reference list of 93 security controls grouped into four themes: organisational, people, physical and technological. You do not implement all 93 by default. You pick the ones your risk assessment justifies and document that choice in a Statement of Applicability.

Nobody is required to follow ISO 27001. An organisation adopts it because it wants a recognised structure, or because customers ask for proof. That proof is a certificate from an accredited certification body, issued after an audit and kept valid through annual surveillance audits and a full recertification every three years. The certificate covers a defined scope, which can be the whole company or one service, and that scope is written on the certificate.

## What NIS2 is

[NIS2](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng) is Directive (EU) 2022/2555 on cybersecurity across the Union. It replaces the first NIS directive from 2016 and widens it considerably. EU member states had to transpose it into national law by 17 October 2024.

NIS2 does not ask whether an organisation wants to participate. It lists sectors in two annexes, from energy, transport, health and banking to digital infrastructure, ICT service management, public administration, postal services, food production and manufacturing of certain goods. Medium-sized and larger organisations in those sectors are covered automatically, with some entities covered regardless of size. Covered organisations are classed as either essential or important, which determines how closely they are supervised and how large the fines can be.

Three sets of duties follow. Article 21 requires an all-hazards approach to risk management with ten minimum measures, including incident handling, business continuity, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication. Article 23 sets reporting deadlines for significant incidents: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month. Article 20 makes the management body responsible for approving and overseeing the measures, requires managers to attend training, and allows them to be held personally liable for breaches.

Supervision and penalties are real. According to the [European Commission's NIS2 FAQ](https://digital-strategy.ec.europa.eu/en/faqs/directive-measures-high-common-level-cybersecurity-across-union-nis2-directive-faqs), essential entities face fines of up to at least EUR 10 million or 2 percent of worldwide annual turnover, whichever is higher. For important entities the ceiling is at least EUR 7 million or 1.4 percent. Essential entities can be inspected proactively; important entities are supervised after the fact, typically when there is evidence of a problem.

## Side by side

| | ISO 27001 | NIS2 |
|---|---|---|
| What it is | International management standard | EU directive, transposed into national law |
| Who decides it applies | You do, or a customer asks for it | The law, based on sector and size |
| Scope | Chosen by you and written on the certificate | Set by the directive and national implementation |
| What it demands | A working ISMS with risk-based controls | Ten minimum security measures, incident reporting, management duties |
| Incident reporting | Internal process; no fixed deadlines to authorities | 24 hours, 72 hours, one month |
| Management | Leadership commitment is a requirement | Management body approves, oversees, trains, and can be held liable |
| Proof | Certificate from an accredited body after audit | Supervision by national authorities; no certificate |
| Consequence of failing | Lost or suspended certificate, lost tenders | Fines, orders, in serious cases temporary bans on management |
| Status in Norway | Available and widely used | Not yet in force; the current law implements NIS1 |

## Where they overlap

The content overlaps more than the labels suggest. Each of the ten NIS2 measures has a counterpart in the ISO 27001 structure or in Annex A. Risk analysis and security policies map to the standard's planning clauses. Incident handling, business continuity and backup, supply chain security, secure development and vulnerability handling, cryptography, access control, asset management and security awareness are all Annex A control areas. Even the NIS2 requirement to assess whether the measures are effective matches the standard's clauses on performance evaluation and internal audit.

This is why an organisation with a functioning ISMS is usually well placed for NIS2. The risk register, the incident procedure, the supplier assessments and the access reviews already exist. The work is to check that they meet the specific NIS2 wording, and to add what is missing rather than to build a parallel system.

## Where they differ

**Certification is not compliance.** An ISO 27001 certificate shows that an auditor found your management system consistent with the standard, inside the scope you chose. It says nothing about whether you have met the legal duties NIS2 imposes, and a supervisory authority is not bound by it. NIS2 does encourage the use of European or international standards, and the directive allows member states to require certification under specific schemes, but no national authority treats an ISO certificate as a substitute for its own supervision.

**Scope is chosen in one and imposed in the other.** An organisation can certify a single data centre or one SaaS product and leave the rest out. NIS2 covers the legal entity and the services that put it in scope, and the organisation cannot narrow that by choice.

**The reporting clocks are different in kind.** ISO 27001 requires an incident management process, with the timing set by the organisation's own policy. NIS2 fixes the deadlines in law, names the recipients, and sets the content of each report.

**Accountability sits in different places.** The standard expects top management to commit to the ISMS and to review it. NIS2 goes further by placing a legal duty on the management body, mandating training, and allowing personal liability.

**The proof is different.** ISO 27001 gives you a document you can send to a customer. NIS2 gives you an obligation you must be ready to demonstrate when a supervisory authority asks, with no certificate at the end.

## Where Norway stands

Norway is not an EU member, so NIS2 reaches Norwegian law through the EEA agreement and a national act. That has not happened yet. [Norway's Digital Security Act and its regulation entered into force on 1 October 2025](https://nsm.no/aktuelt/ny-digitalsikkerhetslov-i-norge) and implement the first NIS directive, not NIS2. According to NSM, NIS2 will in due course be introduced into Norwegian law together with the CER directive on the resilience of critical entities. No date has been confirmed.

The current act already covers providers of essential services in energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure, plus certain digital service providers, and already includes a 24-hour initial notification for significant incidents. [Norway's Digital Security Act: scope and reporting](/en/insights/compliance/what-norways-digital-security-act-is/) covers those duties in more detail.

Norwegian organisations can still be subject to NIS2 today in two ways: through a subsidiary or establishment in an EU member state, or through contracts with EU customers who are covered and pass security requirements down the supply chain. [What NIS2 means for Norwegian businesses](/en/insights/compliance/what-nis2-is-and-who-it-covers-in-norway/) explains how to assess that.

## How the two fit together

ISO 27001 answers the question "how do we run information security in a way we can prove?" NIS2 answers "what does the law require of us, by when, and who is accountable?" One is a method, the other is an obligation. An organisation that is covered by NIS2 can use ISO 27001 as the structure for meeting it, and will find that most of the required measures already have a home in the standard. An organisation that is certified still has to check its legal scope, add the reporting procedures and the management duties, and keep evidence that a supervisory authority will accept.

If you are deciding which to start with, [ISO 27001 or NIS2 first?](/en/insights/compliance/iso-27001-or-nis2-first/) covers that decision. [What ISO 27001 is, and why buyers ask for it](/en/insights/compliance/what-iso-27001-is-and-why-tenders-require-it/) goes deeper on the certification side.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
