NIS2 vs ISO 27001: the difference and the overlap
NIS2 and ISO 27001 are often confused. In this article you read the difference, where they overlap and whether an ISO certification helps you to comply with NIS2.
By Max HoltropNIS2 and ISO 27001 both come from the world of information security, and that is exactly why they are often confused. Yet they are two different things. In this article we explain the difference and show how they relate. For the basics of the legislation we refer you to NIS2 for SMEs.
What is the most important difference?
NIS2 is a law, ISO 27001 is a standard. NIS2 is European legislation that obliges you to have your digital security in order; you cannot choose whether it applies to you. ISO 27001 is an international standard for information security that you can follow voluntarily and for which you can be certified. So one is an obligation, the other a choice and a hallmark.
Where do they overlap?
In the measures. Both revolve around managing risks: access, protection, backup and incident handling. Whoever has set up ISO 27001 well already has much of what NIS2 asks for in place. Conversely, with the NIS2 measures you build a solid foundation that is close to the ISO approach. The underlying logic, knowing and managing risks, is the same.
Does an ISO 27001 certification help to comply with NIS2?
Yes, it gives a considerable head start, but it is not an automatic exemption. An ISO certification shows that you have approached security in a structured way, and that aligns well with what NIS2 expects. Still, NIS2 remains a law of its own with its own obligations, such as the duty to report incidents. So a certificate helps, but does not relieve you of the question of whether you comply with NIS2.
What does this mean for SMEs?
For most SMEs a full ISO 27001 certification is too heavy, and that is not necessary either. Focus on the NIS2 measures themselves: they make you demonstrably safer without the full certification process. A concrete start can be found in the NIS2 checklist for SMEs.
How IT-gemak helps
With our approach to IT security and NIS2 we lay the technical foundation and help you get it demonstrably in order, whether you are working towards NIS2 or considering an ISO process.
Want to know what suits your organisation? Schedule a no-obligation consultation. We think along honestly with you.
Good to know
What is the difference between NIS2 and ISO 27001?
NIS2 is European legislation that obliges you to have your security in order. ISO 27001 is a voluntary standard for information security for which you can be certified. One is an obligation, the other a choice and hallmark.
Do I automatically comply with NIS2 with ISO 27001?
Not automatically, but it gives a considerable head start. An ISO certification aligns well with what NIS2 asks, but NIS2 remains a law of its own with its own obligations such as the duty to report incidents.
Does an SME need an ISO 27001 certification for NIS2?
Usually not. A full certification process is too heavy for many SMEs. Focus on the NIS2 measures themselves; they make you demonstrably safer without the full certification.
Do the measures of NIS2 and ISO 27001 overlap?
Yes, strongly. Both revolve around managing risks: access, protection, backup and incident handling. Whoever has set up one well already has much of the other in place.
Related services
ICT Security & NIS2
Control over your business information and demonstrable compliance, for the law and for your clients.
Read more →Keeper Password Security
Secure password management for your entire organisation: strong passwords, shared and under control.
Read more →Microsoft 365 security licenses
The right Microsoft security licenses for your organization: advice, setup and management.
Read more →Related articles
NIS2 for accountants: what to look out for
Does your accountancy firm fall under NIS2, and what do your clients expect from you? In this article you read how NIS2 affects accountants, often via the chain, and what you can arrange now.
Read more →Backup requirements under NIS2: why Microsoft 365 alone is not enough
Does NIS2 require a backup, and does Microsoft 365 not make one itself? In this article you read what the backup requirements mean for SMEs and why you need a separate backup of your Microsoft 365 environment.
Read more →Does my company fall under NIS2? The decision tree
Does my company fall under NIS2? Work through the decision tree based on your sector, your size and your role in the chain, and know where you stand by the end.
Read more →Want to spar with a specialist?
Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.
