Cyvra Methodology

NIS2 and ISO 27001.
One Programme.

One programme for NIS2 compliance and ISO 27001 certification. One evidence pack, used for both.

8/10
NIS2 Article 21 requirements fully covered by ISO 27001:2022 controls
~30%
Reduction in implementation effort versus running two separate compliance projects
1
Shared evidence pack covering both frameworks, authored once for both

Most organisations treat NIS2 and ISO 27001 as two separate projects.

They gap-assess one, implement controls, write policies, build an evidence pack, pass an audit, then begin the whole process again for the other. That produces two sets of documentation describing the same security posture, written twice at roughly twice the cost.

NIS2 Article 21 was drafted with ISO 27001 as a reference point. The 10 mandatory security measures in Article 21 correspond directly to ISO 27001 Annex A control domains. A properly implemented ISO 27001 ISMS covers all 10 Article 21 requirements, with three narrow gaps that need NIS2-specific work.

We treat this overlap as the asset it is. We build controls once, then map the same evidence to both frameworks. You get full coverage of both with around 30% less effort than running two programmes.

80%
Control overlap between
NIS2 Art.21 and ISO 27001

Four phases. One integrated programme.

Every deliverable from every phase serves both frameworks. Nothing is done twice.

Phase 01
Assess

We map your current state against NIS2 Article 21 and ISO 27001:2022 in one gap assessment, producing a unified gap register and risk treatment plan.

  • Unified gap register across both frameworks
  • Control inventory and current state review
  • Risk assessment per ISO 27001 Clause 6.1
  • NIS2 scope and entity classification confirmation
  • Prioritised remediation roadmap
Phase 02
Align

We design a control architecture that satisfies both frameworks, mapping each control to its ISO 27001 clause and NIS2 Article 21 obligation before a single policy is written.

  • Dual-mapped control set
  • Statement of Applicability (SoA)
  • NIS2 reporting workflow design
  • Management accountability framework
  • Policy and procedure architecture
Phase 03
Implement

We build and deploy the controls. Policies, procedures and technical configurations are written once, structured so the same artefacts serve as evidence under both frameworks.

  • 93 ISO 27001 Annex A controls assessed and applied
  • NIS2 Article 21 specific obligations addressed
  • CSIRT reporting procedures implemented
  • Management training and sign-off (Art 20)
  • Internal audit programme established
Phase 04
Certify

We guide you through the ISO 27001 Stage 1 and Stage 2 external audit, handle NIS2 registration with your national competent authority, and hand over a complete dual-framework evidence pack.

  • ISO 27001:2022 Stage 1 and Stage 2 audit
  • NIS2 registration with NCSC-NL
  • Dual-framework evidence pack
  • Incident response runbooks
  • Ongoing surveillance support

NIS2 Article 21 requirements mapped to ISO 27001:2022

Each NIS2 Article 21 measure mapped to the ISO 27001:2022 clauses and Annex A controls that cover it. Use it as a gap assessment and implementation reference.

# NIS2 Article 21 Requirement Reference ISO 27001:2022 Controls Coverage
1 Risk analysis and information system security policies Art 21.2(a) Clauses 4.1, 4.2, 5.1, 5.2, 6.1.1–6.1.3, 6.2
A.5.1 A.5.2 A.5.36
Full
2 Incident handling Art 21.2(b) A.5.24 Planning and preparation
A.5.25 Assessment and decision
A.5.26 Response
A.5.27 Learning from incidents
A.5.28 Collection of evidence
External reporting timelines are NIS2-only (see below)
Full*
3 Business continuity, backup management and disaster recovery Art 21.2(c) A.5.29 Information security during disruption
A.5.30 ICT readiness for business continuity
A.8.13 Information backup
A.8.14 Redundancy of information processing facilities
Full
4 Supply chain security, including security aspects of relationships between entities and their direct suppliers or service providers Art 21.2(d) A.5.19 Information security in supplier relationships
A.5.20 Addressing security in supplier agreements
A.5.21 Managing security in the ICT supply chain
A.5.22 Monitoring, review and change management
A.5.23 Information security for use of cloud services
Full
5 Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure Art 21.2(e) A.8.8 Management of technical vulnerabilities
A.8.25A.8.34 Secure development lifecycle, secure coding, security testing, change management
Full
6 Policies and procedures to assess the effectiveness of cybersecurity risk-management measures Art 21.2(f) Clause 9.1 Monitoring, measurement, analysis and evaluation
Clause 9.2 Internal audit
Clause 9.3 Management review
Full
7 Basic cyber hygiene practices and cybersecurity training Art 21.2(g) A.6.3 Information security awareness, education and training
A.8.8 Management of technical vulnerabilities
NIS2 requires a more prescriptive and formally documented hygiene programme than ISO 27001 mandates
Partial
8 Policies and procedures regarding the use of cryptography and, where appropriate, encryption Art 21.2(h) A.8.24 Use of cryptography Full
9 Human resources security, access control policies and asset management Art 21.2(i) HR Security: A.6.1A.6.6
Access Control: A.5.15A.5.18 A.8.2A.8.6
Asset Management: A.5.9A.5.14
Full
10 Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems Art 21.2(j) A.8.5 Secure authentication
A.5.17 Authentication information
NIS2 explicitly mandates MFA; ISO 27001 requires appropriate controls but does not mandate a specific method
Partial

* Incident handling process is fully covered by ISO 27001. The external reporting obligations under NIS2 Article 23 (24-hour early warning; 72-hour notification to national CSIRT; one-month final report) have no ISO 27001 equivalent and require NIS2-specific procedures.  |  Coverage key: Full = ISO 27001 controls directly satisfy the NIS2 requirement and evidence maps across. Partial = ISO 27001 addresses the area but NIS2 adds prescriptive obligations requiring additional measures.

Three NIS2 obligations ISO 27001 does not close

ISO 27001 certification does not constitute NIS2 compliance. NIS2 adds three categories of obligation with no equivalent in the standard. We address all three as part of Phase 3.

Mandatory incident reporting to national CSIRT
NIS2 Article 23 requires in-scope entities to report significant incidents to their national CSIRT on a defined timeline. ISO 27001 requires incident management processes but has no external reporting obligation.
24h early warning  ·  72h notification  ·  1-month final report
Management personal accountability
NIS2 Article 20 makes senior management personally responsible for cybersecurity risk decisions. Boards must approve security measures, complete cybersecurity training, and face personal liability if the organisation fails to comply.
Board training  ·  Formal sign-off  ·  Personal liability
Registration with national competent authority
Essential and important entities must register with their national competent authority, disclosing contact details, IP ranges and entity information. In the Netherlands, that authority is NCSC-NL.
Netherlands: NCSC-NL  ·  UK: NCSC  ·  Annual review

Outcomes of the Convergence Framework

A completed engagement leaves you with NIS2 compliance and ISO 27001 certification, backed by one evidence pack.

ISO
27001:2022 certification
External certification body audit passed. Certificate issued and ready for customer and regulatory use.
NIS2
Article 21 compliance
All 10 mandatory security measures implemented and evidenced. Reporting workflows live.
1
Shared evidence pack
A single set of policies, procedures and technical records mapped to both frameworks.
Art 20
Management accountability
Board-level training delivered, responsibilities assigned, and personal sign-off documented.
CSIRT
Reporting procedures
Incident classification and notification runbooks aligned to 24h and 72h NIS2 reporting timelines.
Ongoing compliance posture
Internal audit programme, management review cadence, and surveillance cycle embedded for year-on-year compliance.
Work with Cyvra

Ready to start?

Tell us where you are with NIS2 and ISO 27001. We'll run a gap assessment against both and lay out exactly what an integrated programme requires.