The Most Common NIS2 Misconception in the Market
The most common question ROOTKey's enterprise team hears from compliance professionals is this: 'We have ISO 27001. Does that cover NIS2?'
The short answer: no. ISO 27001 certification is a significant asset in a NIS2 compliance programme, and it demonstrates a mature approach to information security management. But it does not cover NIS2's regulatory obligations, and organisations that assume it does will face gaps - some of them material.
This is not a criticism of ISO 27001 - it remains the most rigorous internationally recognised framework for information security management. It is a clarification of what NIS2 requires that ISO 27001 does not.
Understanding the differences will save compliance teams significant time by focusing effort on genuine gaps rather than duplicating work already done.
What ISO 27001 and NIS2 Share
The substantial overlap between the two frameworks means that ISO 27001-certified organisations have a significant head start on NIS2 compliance:
Risk management. Both require systematic risk identification, assessment, and treatment. ISO 27001's risk treatment plans map closely to NIS2's Article 21 security measures.
Technical controls. ISO 27001 Annex A controls cover access control, cryptography, physical security, operations security, and communications security - all of which are required by NIS2.
Documentation. ISO 27001's documentation requirements (policies, procedures, records) align with NIS2's requirement to demonstrate that appropriate measures are in place.
Business continuity. ISO 27001 includes business continuity planning (Annex A.17), which maps to NIS2's requirement for business continuity and crisis management measures.
Supplier relationships. ISO 27001 Annex A.15 covers supplier security, which aligns with NIS2's supply chain security requirements.
For organisations with a mature ISO 27001 programme, these areas require documentation updates and gap mapping rather than building from scratch.
What NIS2 Requires That ISO 27001 Does Not
The genuine NIS2 gaps for ISO 27001-certified organisations fall into three main areas:
1. Incident notification to authorities. NIS2 requires mandatory notification to national competent authorities within specific timeframes (24 hours initial alert, 72 hours detailed notification, 30 days final report) for significant incidents. ISO 27001 has incident management requirements but no mandatory regulatory notification timeline. This is an operational process that must be built specifically for NIS2.
2. Management body accountability (Article 20). NIS2 explicitly makes the management body of an entity responsible for approving cybersecurity risk management measures. Management members can be held personally liable for infringements and must undergo regular cybersecurity training. ISO 27001 requires management commitment but does not specify personal liability for management body members.
3. Registration with national competent authorities. NIS2 requires in-scope entities to register with their national authority. ISO 27001 certification involves a third-party auditor but no registration with a regulatory body.
4. Supply chain specifics. While ISO 27001 covers supplier security, NIS2 Article 21(2)(d) requires entities to address 'vulnerabilities specific to each direct supplier and service provider' and consider 'the overall quality of products and cybersecurity practices of their suppliers.' This is more specific than ISO 27001's supplier relationship management.
For organisations in Portugal, our guide to NIS2 Portugal and Decreto-Lei 125/2025 covers the national-level specifics that apply on top of these base requirements.
The Fastest Path to NIS2 Compliance from an ISO 27001 Baseline
For ISO 27001-certified organisations, the most efficient NIS2 compliance journey focuses on the genuine gaps:
Priority 1: Incident notification procedure. Build and test the 24/72/30-day notification workflow. Identify who in the organisation triggers the notification, who approves it, and which national authority receives it.
Priority 2: Management training and accountability documentation. Ensure the management body has received formal cybersecurity training. Document this. Ensure the management body has formally approved the risk management measures and that this approval is recorded.
Priority 3: Register with the national competent authority. Complete registration within the required timeframe after determining entity status.
Priority 4: Supply chain audit update. Review existing supplier assessments against the NIS2 Article 21(2)(d) specifics. Update supplier contracts to include NIS2-aligned security requirements.
The NIS2 compliance readiness assessment takes about 15 minutes and maps your current state against all four priority areas. Our NIS2 enterprise guide covers the full compliance framework. Start your assessment today.
Erhalten Sie Einblicke zur Cyber-Resilienz per E-Mail
Praktische, auditfähige Hinweise zu Datenintegrität, Compliance und Kontinuität – sobald wir veröffentlichen.





