Glossary · Cross-regulation

ISO 27001

The international standard for information security management systems, widely used as a framework for implementing NIS2's requirements.

Explained in depth: The 10 NIS2 security requirements

ISO/IEC 27001 specifies how to establish, operate, and continually improve an information security management system (ISMS): risk assessment, a catalogue of controls (detailed in ISO 27002), management commitment, internal audits, and continual improvement. It is the most widely adopted security certification globally, and its structure maps well onto NIS2's Article 21: risk analysis, incident handling, continuity, supplier security, access control, and cryptography all have direct counterparts. The mapping is good but not complete. ISO 27001 certification does not equal NIS2 compliance: NIS2 adds specific obligations the standard does not impose, notably the three-stage incident reporting to authorities, registration duties, management-body training and liability, and any national additions. ENISA and several national authorities publish mappings between Article 21 and ISO 27001 controls.

Why it matters

For organisations starting from zero, building an ISO 27001-aligned ISMS is the most defensible route to Article 21 compliance, and certification provides third-party evidence auditors and customers recognise. "NIS2 vs ISO 27001" is also one of the highest-volume searches in this space, making this page a strong traffic entry.

Used in

See also

← All glossary terms