NIS2

Already ISO 27001 Certified? You're Well on Your Way to NIS2

Samuel Mihalcik

Samuel Mihalcik

Senior Consultant

NIS2 ISO 27001 Mapping
NIS2 ISO 27001 Mapping
NIS2 ISO 27001 Mapping

If you're the compliance officer at a company with ISO 27001 certification, you already know the question that's coming from your board: "Are we NIS2 compliant, or not?

For a fast, hassle-free comparison, feel free to download this practical toolkit with a NIS2 ISO 27001 mapping Excel and documentation right here:

Is ISO 27001 Certification Enough for NIS2? The Short Answer

If your board is asking whether ISO 27001 certification means you're NIS2 compliant, the honest answer is no, not automatically. The two aren't really the same kind of thing: one is a voluntary standard you get audited against, the other is a legal obligation. That said, if you've been running an ISMS for a while, you're not starting from zero. Most of the cybersecurity risk-management measures NIS2 asks for overlap heavily with controls you've already built and had audited under ISO 27001. In practice that makes the sensible path a NIS2 ISO 27001 mapping exercise followed by a targeted gap analysis and remediation, rather than standing up a second, parallel security management system next to the one you already have.


NIS2 vs ISO 27001: What's the Difference?

The ISO 27001 vs NIS2 question usually gets framed as two competing frameworks, and the terms are often used interchangeably in boardrooms, but they're fundamentally different types of things.

ISO 27001 is an information security management standard.

It's a voluntary, certifiable framework for running an ISMS: risk assessment, controls, continual improvement, and independent audit.


In the Netherlands, NIS2 is transposed into national law as the Cyberbeveiligingswet (Cbw). It's not something you get "certified" against. It's a statutory obligation with cybersecurity requirements, incident reporting duties, and management accountability, enforced by a regulator rather than an audit body.



ISO 27001

NIS2 / Cyberbeveiligingswet

Type

International standard

Legislation

Primary focus

ISMS

Cybersecurity risk and resilience

Certification

Possible (accredited audit)

No ISO-style certification

Applicability

Voluntary / contractual

Determined by legal scope (entity size, sector)

Incident reporting

Internal security process

Statutory reporting requirements and deadlines

Supplier risk

Required (A.5.19, A.5.23)

Required (supply-chain security measure)

Risk management

Core requirement

Core requirement

In short, ISO 27001 certification tells a customer you manage information security well. NIS2/Cbw compliance tells a regulator you meet a legal minimum bar for cybersecurity risk management, and it applies whether or not you're certified against anything.

Infographic comparing ISO 27001 as a voluntary certifiable standard versus NIS2 as mandatory cybersecurity legislation.

How much does ISO 27001 certification cost?

There is no fixed price for ISO 27001 certification. The total cost depends largely on the size and complexity of the organisation, the scope of the ISMS, and how much of the required work is already in place.

Direct certification costs

One cost is the internal audit. This can be performed by a trained employee, a suitably qualified hire, or an external consultant. Each option comes with its own cost, whether that is employee training, hiring additional expertise, or paying an external company to perform the audit.

You also need to pay the certification body to perform the external audit. The cost depends on the number of audit days required, which is determined by the size of the organisation expressed in the number of employees within the certification scope.

Certification is also not a one-time cost. Maintaining it requires ongoing surveillance audits and periodic recertification.

The cost of building the ISMS

The audit fees are only part of the total investment. You also need to account for the work required to build and maintain the ISMS, including:

  • Developing policies and procedures.

  • Performing risk assessments.

  • Implementing security controls.

  • Training employees.

  • Purchasing the necessary security and compliance tooling.

  • Collecting evidence and maintaining documentation.

  • Remediating gaps before the audit.

For an organisation that already has mature security processes, these costs may be relatively low. For an organisation starting from scratch, the cost of building the ISMS can be significantly greater than the certification audit itself.

Ultimately, the cost of ISO 27001 certification depends not just on the size of your company, but also on how much of the required ISMS you already have in place.

NIS2 ISO 27001 Mapping: How Does ISO 27001 Map to NIS2?

NIS2 (and the Cyberbeveiligingswet) organises its cybersecurity risk-management requirements into ten measures. The nis2 vs iso 27001 mapping below covers all ten. Nearly all of them map to something you already cover under ISO 27001:2022 Annex A, but "high overlap" doesn't mean "fully covered." Here's where to verify.

NIS2 Measure

Relevant ISO 27001:2022 areas

Typical overlap

What you still need to verify

1. Cybersecurity risk analysis

Clauses 5–8; Annex A.5.1–A.5.8, A.6.3

Very high

Frequency and formality of NIS2 risk assessment versus your ISMS review cycle, and whether residual risk and treatment decisions carry NIS2-specific justification

2. Incident response

A.5.24, A.5.25, A.5.26, A.5.27, A.5.28

High

Statutory NIS2/Cbw notification timelines (24h early warning, 72h notification), and whether your escalation path can actually meet them

3. Business continuity & outage preparedness

A.5.29, A.5.30, A.8.13, A.8.14

Very high

Crisis-management processes and the recovery evidence a regulator expects, not just what an ISO auditor expects

4. Supply-chain security

A.5.19, A.5.20, A.5.21, A.5.22, A.5.23

High

Supplier monitoring depth and NIS2-specific supplier expectations, especially reassessment frequency for critical suppliers

5. Cyber hygiene & security awareness

A.6.3, A.8.19

High

Coverage of NIS2-specific awareness topics, not just general security training

6. Secure network & information systems

A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.31, A.8.32, A.8.33, A.8.34

High

Secure development lifecycle documentation and whether patch/vulnerability evidence is retained in a form NIS2 reporting can use

7. Personnel, access & asset management

A.5.9–A.5.18, A.8.1–A.8.10

Very high

Joiner/mover/leaver process completeness and frequency of privileged access reviews

8. Strong authentication, MFA & passkeys

A.5.17, A.5.18, A.8.5

High

MFA or passkey coverage across privileged accounts, remote access and cloud services, and how exceptions are approved and reviewed

9. Cryptography & encryption

A.8.24

High

Alignment with sector-specific cryptography guidance, if any applies, and how often the cryptography policy itself is reviewed

10. Effectiveness of security measures

Clause 9 (internal audit, management review)

High

Whether your review cycle and reassessment frequency match what NIS2 expects as risks change

That "verify" column is the actual work of NIS2 compliance. Overlap tells you where to look first, it doesn't tell you you're done.

Download the NIS2 to ISO 27001 mapping (Excel) - nis2 iso27001 mapping
All ten NIS2 measures mapped to ISO 27001:2022 Annex A controls, with a coverage column (Covered / Partially / Not covered) and an owner field you can fill in as you work through the gap analysis below.


Start With Your ISO 27001 Statement of Applicability

RiskRhino NIS2 ISO27001 Compliance


Why the SoA is the natural starting point

If you already run an ISMS, your Statement of Applicability is the best starting point for a NIS2 gap analysis, and a much better one than starting from a blank NIS2 requirements checklist. It already tells you which controls apply to your organisation, which ones you've excluded and why, how far implementation actually got, and who owns the evidence behind each control. That's most of the groundwork a gap analysis needs, already sitting in a document you update every year anyway. Instead of assembling that inventory from scratch under time pressure, you're just putting it to a second use.


Map existing controls instead of recreating them

The approach that works is to map existing controls rather than invent new ones. For each NIS2 or Cbw requirement, trace it back to the ISO 27001 control that already covers it, check what evidence supports that control, judge how well it actually covers the requirement, and note whatever gap is left. Do that consistently and you end up extending a control environment you already run, not building a new one next to it. That distinction matters more than it sounds: a NIS2 program built as a parallel structure tends to drift out of sync with the ISMS within a year, while one built as an extension of it stays current by default, because updating the control updates both.


How to Perform an ISO 27001 to NIS2 Gap Analysis

This is the core, repeatable process that turns a NIS2 to ISO 27001 mapping into an actual compliance assessment. The same approach can be used whenever you need to layer another framework or regulation on top of ISO 27001, whether that is NIS2, DORA, the EU AI Act, or future legislation.

Step-by-step workflow showing how to conduct an ISO 27001 to NIS2 gap analysis and ISMS integration.

Step 1: Determine Applicable Requirements

First, establish whether NIS2 and the Cyberbeveiligingswet (Cbw) actually apply to your organisation. NIS2 scope is determined by factors such as sector and organisation size, so this is a legal and regulatory question before it becomes a security exercise.

Confirm whether your organisation falls within scope and whether it is classified as an Essential or Important Entity.


Step 2: Map Existing Controls

Work through the ten NIS2 measures one by one and map them to the ISO 27001 controls you already have in place. Mapping NIS2 to ISO 27001 at requirement level rather than topic level is what makes the remaining steps worth anything. Your Statement of Applicability (SoA) is a useful starting point, rather than creating a completely new control inventory.

You can use the mapping table above as a starting point.

By the end of this exercise of mapping nis2 iso 27001 controls, every NIS2 measure should be linked to a specific ISO 27001 control. Avoid relying on a general assumption that a requirement is "probably covered somewhere."


Step 3: Assess Coverage

For each mapped requirement, assess how much of the NIS2 requirement your existing control actually covers.

Classify each requirement as: Covered, Partially covered, Not covered, Not yet assessed

This is where gap analyses are often too optimistic. A mapping may show significant overlap on paper while still leaving important requirements unaddressed in practice.

For example, an incident management process may already exist under ISO 27001 but may not have been tested against the specific NIS2 reporting timelines. Assess coverage against the actual requirement, not just the general topic.


Step 4: Identify and Document Gaps

For anything that is not fully covered, document exactly what is missing.

The gap could be a missing process, additional documentation, a control that has not been implemented, or evidence that is insufficient to demonstrate compliance.

Avoid vague findings such as "supply chain security needs improvement." A finding such as "critical suppliers are assessed during onboarding but are not reassessed periodically" is much more actionable.


Step 5: Assign Owners

Every gap should have a named owner, not simply a department or team.

NIS2 places accountability at management level, while individual activities may sit with different functions. Depending on the requirement, ownership may sit with the CISO or risk function for risk management and control effectiveness, security or the CISO for incident response, IT or business continuity for recovery planning, procurement for supplier security, and HR together with security for training and awareness.

Assigning ownership early makes it much easier to keep gaps moving through remediation.


Step 6: Create Remediation Actions

Turn every identified gap into a specific remediation action with a clear owner and deadline.

For example:

"Introduce annual reassessment of critical suppliers, owned by Procurement, due by the end of Q2."

is a useful remediation action.

"Improve supplier oversight."

is not.

Where possible, integrate these actions into your existing ISMS improvement cycle rather than creating a separate NIS2 action plan. This keeps both programmes aligned and visible in the same process.


Step 7: Verify Evidence

Before closing a gap, collect the evidence that demonstrates the requirement has actually been addressed.

A completed action without supporting evidence is not a closed gap. It is an unverified claim.

Also check whether the evidence is sufficient to demonstrate compliance, particularly where NIS2 introduces specific requirements around reporting, documentation or ongoing control effectiveness.


Step 8: Integrate NIS2 into the ISMS

The final step is to make NIS2 part of your existing ISMS rather than managing it as a separate compliance programme.

Your existing risk register, control owners, evidence collection and management review processes can all be used to manage NIS2 requirements.

The same risk register should include NIS2-relevant risks, existing control owners should remain responsible for their applicable controls, and management reviews should include NIS2 status alongside the wider ISMS.

Don't build a second security management system. Extend the one you already have.


What ISO 27001 Already Covers Well for NIS2

If your ISMS is reasonably mature, there's a long list of areas where you're probably already in decent shape. Cybersecurity risk management sits at the core of both frameworks, so your existing risk assessment and treatment process carries over directly. The same goes for incident management: detection, response and lessons-learned are things you've been doing since your first audit cycle, and NIS2 mostly just adds reporting deadlines on top of a process you already run. Business continuity and backup planning under A.5.29, A.5.30, A.8.13 and A.8.14 map almost one-to-one, and your supplier due diligence work gives you a real starting point for the supply-chain security requirement, even if it needs to go further.

Secure development and vulnerability management, covered under A.8.25 through A.8.34, is another area where the substance is already there. Your Clause 9 internal audits and management reviews satisfy a good part of the effectiveness-assessment requirement, and whatever security awareness training you already run covers most of what NIS2 expects on cyber hygiene. Cryptography policy under A.8.24, access control and asset management, and multi-factor authentication and secure communications round out the list. These tend to be some of the more mature parts of an ISO 27001 ISMS, and NIS2 doesn't ask for much beyond what's already there.

None of this means an ISO 27001-certified organisation is automatically NIS2 compliant. It means you're genuinely ahead of most organisations starting this process from nothing.


What ISO 27001 Does Not Automatically Give You for NIS2

This is where the difference between a management-system standard and legislation becomes important.

ISO 27001 is an international standard for establishing and maintaining an information security management system. NIS2 is an EU directive implemented through national legislation. In the Netherlands, those legal requirements are implemented through the Cyberbeveiligingswet.

That means some NIS2 obligations sit outside the normal scope of an ISO 27001 audit.


Your ISMS can tell you how cybersecurity risks are managed. It cannot, by itself, determine all of your legal obligations under Dutch law.

For NIS2, you first need to establish whether your organisation is within scope, whether you are an Essential or Important Entity, which supervisory authority applies to you and which obligations follow from that classification.

This is not something an ISO 27001 certificate automatically establishes.

You therefore need to assess your organisation against the Cyberbeveiligingswet rather than assuming that certification equals compliance.


Incident reporting

ISO 27001 can give you a mature incident-management process.

What it does not automatically give you is a process built around statutory reporting deadlines.

For organisations covered by the Cyberbeveiligingswet, significant incidents follow a phased reporting process, including an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month.

That means your incident-response process needs to connect operational decision-making with legal reporting requirements.

Someone needs to know:

  • When an incident becomes reportable.

  • Who decides whether it is significant.

  • Who is responsible for the notification.

  • Which authority needs to be contacted.

  • What information needs to be provided.

  • How the reporting deadlines are tracked.

  • Who communicates with management, customers and other relevant parties.

Your ISO 27001 incident process may already cover much of the operational side. The NIS2 gap is often the legal reporting layer.


Management accountability

ISO 27001 already requires leadership involvement, management commitment and regular management review.

NIS2 goes further by placing specific cybersecurity responsibilities on management bodies.

This means the board or relevant management body cannot simply delegate cybersecurity to IT and consider the matter finished.

Management needs appropriate oversight of cybersecurity risk management, understand the risks facing the organisation and ensure that appropriate measures are implemented.

For an ISO 27001 organisation, this may require relatively little change to existing governance processes.

But it should be explicitly documented.

Management review should not only ask whether the ISMS remains effective. It should also provide appropriate oversight of the organisation's NIS2 and Cyberbeveiligingswet obligations.


Registration and regulatory requirements

ISO 27001 does not require you to register as an organisation subject to Dutch cybersecurity legislation.

Where the Cyberbeveiligingswet requires registration or other interaction with the relevant authorities, those obligations need to be handled separately from your ISO certification.

This is one of the clearest examples of why "we have ISO 27001" is not the same answer as "we comply with NIS2."

A management-system certificate cannot replace a statutory registration requirement.


Evidence and sector-specific requirements

Your ISO auditor may be satisfied with evidence showing that a control is defined, implemented and periodically reviewed.

A regulator may have different expectations.

NIS2 requirements can also interact with sector-specific legislation, regulatory guidance and the particular circumstances of your organisation.

This means your gap analysis should not stop at:

ISO control → NIS2 requirement → Covered

Instead, ask:

What exactly does the law require?

What control do we have?

What evidence demonstrates that it operates?

Is there anything the legal requirement adds that ISO 27001 does not cover?

That level of detail is what turns a framework mapping exercise into a useful compliance assessment.


NIS2 Mapping to ISO 27001: A Worked Example

Consider supply-chain security.

An organisation with ISO 27001 certification may already have supplier security controls covering supplier selection, security requirements, contractual obligations and supplier monitoring.

On paper, the NIS2 mapping may look straightforward.

ISO 27001: Supplier security controls in A.5.19, A.5.20, A.5.21, A.5.22, A.5.23.

NIS2: Supply-chain security.

Initial assessment: High overlap.

But now look at how the control actually operates.

The organisation has 300 suppliers. Critical suppliers are assessed during onboarding, security requirements are included in contracts and suppliers provide ISO certificates or security questionnaires.

That sounds good.

Then the gap analysis asks a more difficult question:

What happens after the supplier has been onboarded?

You discover that critical suppliers are not systematically reassessed. Some contracts are five years old. Several suppliers have changed their subcontractors without a formal security review. There is no consistent process for tracking supplier remediation actions.

The control is therefore not completely missing.

It is partially covered.

The remediation could be straightforward:

  • Reassess critical suppliers annually

  • Define reassessment criteria.

  • Review relevant contractual requirements.

  • Track supplier findings and remediation.

  • Assign an owner.

  • Set deadlines.

  • Retain evidence of completed reviews.

This is what a useful gap analysis looks like.

"High overlap" tells you where to look.

A named gap, owner, action and deadline tells you how to close it.


Can You Reuse ISO 27001 Evidence for NIS2?

In most cases, yes.

There is no reason to recreate evidence simply because the framework name has changed.

If you already maintain a risk register, that same risk register can support your NIS2 risk-management activities.

Your existing access reviews can support access-management requirements.

Supplier assessments can support supply-chain security.

Business continuity tests, backup restoration tests, penetration tests, vulnerability scans, training records, incident-response exercises and management reviews can all provide useful evidence.

The key is to establish traceability.


For example:

Risk → Control → Evidence → Finding → Remediation → Owner

If the same control supports ISO 27001 and NIS2, there is usually no benefit in maintaining two separate versions of that control or collecting the same evidence twice.

What you do need to check is whether the evidence actually demonstrates the full NIS2 requirement.

A document existing in an ISO folder does not automatically make it sufficient evidence for NIS2.

The useful question is:

Does this evidence demonstrate that the requirement is implemented, operating and appropriately governed?

If yes, reuse it.

If it only demonstrates part of the requirement, identify the missing evidence rather than starting again.


Manage ISO 27001 and NIS2 as One Control Environment

Once the initial mapping is complete, the next challenge is keeping everything aligned.

This is where organisations often make the wrong decision.

They create:

  • One ISO 27001 control register.

  • One NIS2 spreadsheet.

  • One evidence folder.

  • One remediation tracker.

  • One audit plan.

Then six months later, the two systems no longer agree.

A control has changed in one place but not the other. An owner has left the organisation. Evidence has been updated for ISO but not NIS2. A remediation action is closed in one spreadsheet and still open in another.

The better approach is to manage ISO 27001 and NIS2 as one control environment.


Map one control to multiple frameworks

27001 and NIS2/CbW control-to-risk traceability diagram — Control, Evidence, Owner, Risk — RiskRhino GRC

A single control can support multiple frameworks.

For example:

Control: Privileged accounts must use MFA.

That control may map to:

  • ISO 27001

  • NIS2

  • Cyberbeveiligingswet

  • DORA

  • Other internal security requirements

You do not need five different controls.

You need one properly defined control with the relevant framework mappings.


Reuse evidence

The same MFA coverage report can support multiple requirements.

The same access review can support multiple controls.

The same supplier assessment can provide evidence for several frameworks.

The same risk assessment can be referenced by multiple compliance requirements.

This reduces duplicate work and makes evidence management much easier.


Track remediation actions

When a gap is identified, it should have:

  • A clear description.

  • A responsible owner.

  • A deadline.

  • A priority.

  • Supporting evidence.

  • A remediation status.

The action should then be linked back to the control and requirement that created it.

This gives management a much clearer picture of what actually remains open.


Maintain one source of truth

The objective is simple:

One risk → one control → one owner → one evidence set → multiple framework mappings.

This is much easier to maintain than separate compliance programmes for every framework.

This is also where a GRC platform such as RiskRhino can help.

The same risk, control, evidence, owner and remediation action can be connected across ISO 27001, NIS2 and other frameworks, rather than being maintained manually across multiple spreadsheets.


ISO 27001 and NIS2 FAQ


Is ISO 27001 enough for NIS2?

No.

ISO 27001 provides a strong foundation for many of the cybersecurity risk-management requirements, but it does not automatically satisfy every NIS2 or Cyberbeveiligingswet obligation.

Legal scope, incident reporting, management accountability, registration and other regulatory requirements still need to be addressed.


Does ISO 27001 cover NIS2?

ISO 27001 covers a significant amount of the underlying cybersecurity control environment required by NIS2.

However, control overlap is not the same as legal compliance.

You should map the applicable NIS2 and Cyberbeveiligingswet requirements against your existing ISMS and identify any gaps.


What is the difference between ISO 27001 and NIS2?

ISO 27001 is an international standard for establishing and maintaining an information security management system.

NIS2 is European legislation implemented through national law.

ISO 27001 provides a management framework and can be certified against.

NIS2 creates legal obligations for organisations that fall within its scope.

In the Netherlands, those obligations are implemented through the Cyberbeveiligingswet.


Can ISO 27001 controls be reused for NIS2?

Yes.

This is one of the main benefits of already having an ISO 27001 ISMS.

Many existing controls, processes and evidence can be reused for NIS2.

The important part is to verify that the existing control fully addresses the NIS2 requirement and to document any additional legal or sector-specific requirements.


Do I need a separate NIS2 management system?

No.

In most cases, creating a completely separate NIS2 management system would create unnecessary duplication.

A better approach is to extend your existing ISMS and connect the relevant NIS2 and Cyberbeveiligingswet requirements to your existing risks, controls, owners and evidence.


Is there a NIS2 certification?

No.

NIS2 is not an ISO-style certifiable management-system standard.

Organisations within scope need to meet the applicable legal requirements and be able to demonstrate appropriate cybersecurity measures. The relevant authorities can exercise supervisory and enforcement powers under the national implementation framework.


Is ISO 27001 the same as NIST?

The iso 27001 nist comparison comes up often, but they're not really substitutes for each other. ISO 27001 vs NIST is a similar comparison to ISO 27001 vs NIS2: NIST is a US framework, not a legal requirement in the EU, and organisations aren't certified against it the way they are against ISO 27001. If you operate in the EU or Netherlands, ISO 27001 and NIS2/Cyberbeveiligingswet are the two frameworks that actually matter for certification and legal compliance.


How does ISO 27001 relate to GDPR?

ISO 27001 and GDPR overlap on data protection controls, access management, encryption, breach handling, but they're not interchangeable. ISO 27001 certification demonstrates that you manage information security well; it doesn't by itself demonstrate GDPR compliance, in the same way GDPR doesn't automatically demonstrate NIS2 compliance.


What is NIS, and how is it different from NIS2?

NIS (Network and Information Security) is the original EU directive that NIS2 replaces and expands. NIS2 broadens the scope to more sectors, tightens incident-reporting deadlines, and adds direct management accountability. In the Netherlands, NIS2 is transposed into national law as the Cyberbeveiligingswet (Cbw).


Is ISO 27001 and NIS2 certification worthwhile for SMEs (mkb)?

Whether NIS2 applies depends on sector and organisation size, not on whether you're an SME, so the first step for any mkb is confirming legal scope. If you're already ISO 27001 certified, the incremental cost of closing NIS2 gaps is usually far lower than starting a compliance programme from nothing, since most of the underlying controls already exist.


Is there an ISO 27001 checklist for NIS2 readiness?

The NIS2-to-ISO 27001 mapping table above functions as a working checklist: go measure by measure, mark each as Covered, Partially covered, or Not covered, and assign an owner to anything that isn't fully covered. The downloadable Excel version includes these columns pre-built so you can track it directly.


How does NIS2 relate to NEN 7510 for healthcare organisations?

NEN 7510 is the Dutch information security standard for healthcare, and it's built on the same structure as ISO 27001. For healthcare providers, that means the NIS2-to-ISO 27001 mapping approach in this guide largely carries over to NEN 7510 as well, the same risk, control and evidence chain can usually support all three.


Do I need outside help (begeleiding) with ISO 27001 and NIS2 certification?

It depends on how mature your existing ISMS is and how much internal capacity you have to run a structured gap analysis. Many organisations bring in support (begeleiding) for the initial mapping and legal-scope questions, then manage the ongoing NIS2 work themselves as an extension of their existing ISO 27001 processes , which is where a platform like RiskRhino can reduce the need for repeated outside consulting.