Short answer: ISO 27001 certification gives you a significant head start on NIS2, but doesn't cover everything. The gaps are mainly around incident notification timelines, supply chain security specifics, and board-level training obligations. Plan for roughly 30–40% additional work if you're already ISO 27001 certified.

Why the question matters

Many mid-sized EU companies in manufacturing, logistics, and digital services pursued ISO 27001 certification in the years before NIS2 took effect, either because clients required it or because it provided a framework for their ISMS. When NIS2 became enforceable in October 2024, these companies found themselves asking whether their existing certification covered the new obligations.

The short answer is: partially. ISO 27001 and NIS2 are designed around similar concerns — information security management, risk assessment, incident handling — but they're different in scope, specificity, and enforcement mechanism.

What ISO 27001 and NIS2 share

The overlap is real and significant. An ISO 27001-certified ISMS will already address most of the Article 21 security areas if implemented properly:

  • Risk management: ISO 27001 Clause 6 requires a formal risk assessment process. This directly satisfies the NIS2 Article 21(2)(a) requirement for risk analysis and information security policies.
  • Access control: Annex A controls 5.15–5.18 cover identity and access management. NIS2's access control requirements (Article 21(2)(i)) are consistent with this.
  • Cryptography: Annex A 8.24 covers cryptographic controls. NIS2 Article 21(2)(h) requires documented cryptography policies.
  • Asset management: Annex A 5.9–5.10 cover asset inventory and classification. NIS2's network and information system security requirements are partly addressed here.
  • HR security and training: Annex A 6.3 covers awareness training. NIS2 Article 20 requires management training specifically (see below).
  • Business continuity: Annex A 5.29–5.30 cover business continuity. NIS2 Article 21(2)(c) addresses backup and recovery.

Where NIS2 goes further

Incident notification timelines

This is the biggest practical difference. ISO 27001 doesn't specify external notification timelines for security incidents. NIS2 Article 23 requires a 24-hour early warning to the national authority for significant incidents, followed by a formal notification within 72 hours, and a final report within one month.

Your ISO 27001 incident management procedures (Annex A 5.24–5.28) won't automatically satisfy this unless you've explicitly incorporated NIS2 notification triggers and timelines. This requires amending your incident response procedure and identifying who has authority to make notification decisions — which in turn requires board-level awareness.

Supply chain security specifics

ISO 27001 Annex A 5.19–5.22 covers supplier relationships, but the implementation varies widely. NIS2 Article 21(2)(d) is more specific: it requires policies addressing security in supplier and service provider relationships, including ICT supply chain security. Many ISO 27001 certifications treat supplier security as a documentation exercise without genuinely assessing what access or risk those suppliers carry. NIS2 enforcement is likely to scrutinise this more carefully.

Board-level training obligation

ISO 27001 requires security awareness training for all staff and specialist training for those with security responsibilities. NIS2 Article 20 goes further, explicitly requiring that management bodies of in-scope entities receive cybersecurity training on risk management and that they be able to assess cybersecurity risks and their impact.

This is frequently unaddressed in ISO 27001 implementations, where board members sign off the policy but have no documented training on what it means. NIS2 makes this explicit, and national supervisory authorities are likely to test for it during inspections.

Supervisory accountability

ISO 27001 is a voluntary certification. If you fail to maintain it, you lose the certificate, but there are no fines or enforcement actions from regulatory bodies. NIS2 is a legal obligation with enforceable fines (up to €10M or 2% of global turnover for essential entities) and — specifically — personal liability provisions for management bodies. This is a different category of obligation.

Practical implications for ISO 27001 certified companies

If you're ISO 27001 certified and in scope for NIS2, the realistic gap-closing work is:

  • Amend incident response procedures to include NIS2 notification timelines and triggers
  • Conduct a genuine supply chain security review — not just contract review, but actual assessment of what access suppliers have and what your contract requires of them
  • Run a management-level security training session that satisfies Article 20 and document it
  • Confirm that your ISMS scope covers the systems and services relevant to your NIS2 classification (the ISMS scope and the NIS2 in-scope systems may not be identical)
  • Identify your national competent authority and confirm the notification procedures with them

This is substantive work, but it's bounded. Companies without any existing ISMS face a significantly larger compliance journey.