NIS2 and ISO 27001.
One Programme.
One programme for NIS2 compliance and ISO 27001 certification. One evidence pack, used for both.
Most organisations treat NIS2 and ISO 27001 as two separate projects.
They gap-assess one, implement controls, write policies, build an evidence pack, pass an audit, then begin the whole process again for the other. That produces two sets of documentation describing the same security posture, written twice at roughly twice the cost.
NIS2 Article 21 was drafted with ISO 27001 as a reference point. The 10 mandatory security measures in Article 21 correspond directly to ISO 27001 Annex A control domains. A properly implemented ISO 27001 ISMS covers all 10 Article 21 requirements, with three narrow gaps that need NIS2-specific work.
We treat this overlap as the asset it is. We build controls once, then map the same evidence to both frameworks. You get full coverage of both with around 30% less effort than running two programmes.
NIS2 Art.21 and ISO 27001
Four phases. One integrated programme.
Every deliverable from every phase serves both frameworks. Nothing is done twice.
We map your current state against NIS2 Article 21 and ISO 27001:2022 in one gap assessment, producing a unified gap register and risk treatment plan.
- Unified gap register across both frameworks
- Control inventory and current state review
- Risk assessment per ISO 27001 Clause 6.1
- NIS2 scope and entity classification confirmation
- Prioritised remediation roadmap
We design a control architecture that satisfies both frameworks, mapping each control to its ISO 27001 clause and NIS2 Article 21 obligation before a single policy is written.
- Dual-mapped control set
- Statement of Applicability (SoA)
- NIS2 reporting workflow design
- Management accountability framework
- Policy and procedure architecture
We build and deploy the controls. Policies, procedures and technical configurations are written once, structured so the same artefacts serve as evidence under both frameworks.
- 93 ISO 27001 Annex A controls assessed and applied
- NIS2 Article 21 specific obligations addressed
- CSIRT reporting procedures implemented
- Management training and sign-off (Art 20)
- Internal audit programme established
We guide you through the ISO 27001 Stage 1 and Stage 2 external audit, handle NIS2 registration with your national competent authority, and hand over a complete dual-framework evidence pack.
- ISO 27001:2022 Stage 1 and Stage 2 audit
- NIS2 registration with NCSC-NL
- Dual-framework evidence pack
- Incident response runbooks
- Ongoing surveillance support
NIS2 Article 21 requirements mapped to ISO 27001:2022
Each NIS2 Article 21 measure mapped to the ISO 27001:2022 clauses and Annex A controls that cover it. Use it as a gap assessment and implementation reference.
| # | NIS2 Article 21 Requirement | Reference | ISO 27001:2022 Controls | Coverage |
|---|---|---|---|---|
| 1 | Risk analysis and information system security policies | Art 21.2(a) | Clauses 4.1, 4.2, 5.1, 5.2, 6.1.1–6.1.3, 6.2A.5.1 A.5.2 A.5.36 |
Full |
| 2 | Incident handling | Art 21.2(b) | A.5.24 Planning and preparationA.5.25 Assessment and decisionA.5.26 ResponseA.5.27 Learning from incidentsA.5.28 Collection of evidenceExternal reporting timelines are NIS2-only (see below) |
Full* |
| 3 | Business continuity, backup management and disaster recovery | Art 21.2(c) | A.5.29 Information security during disruptionA.5.30 ICT readiness for business continuityA.8.13 Information backupA.8.14 Redundancy of information processing facilities |
Full |
| 4 | Supply chain security, including security aspects of relationships between entities and their direct suppliers or service providers | Art 21.2(d) | A.5.19 Information security in supplier relationshipsA.5.20 Addressing security in supplier agreementsA.5.21 Managing security in the ICT supply chainA.5.22 Monitoring, review and change managementA.5.23 Information security for use of cloud services |
Full |
| 5 | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | Art 21.2(e) | A.8.8 Management of technical vulnerabilitiesA.8.25–A.8.34 Secure development lifecycle, secure coding, security testing, change management |
Full |
| 6 | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | Art 21.2(f) | Clause 9.1 Monitoring, measurement, analysis and evaluation Clause 9.2 Internal audit Clause 9.3 Management review |
Full |
| 7 | Basic cyber hygiene practices and cybersecurity training | Art 21.2(g) | A.6.3 Information security awareness, education and trainingA.8.8 Management of technical vulnerabilitiesNIS2 requires a more prescriptive and formally documented hygiene programme than ISO 27001 mandates |
Partial |
| 8 | Policies and procedures regarding the use of cryptography and, where appropriate, encryption | Art 21.2(h) | A.8.24 Use of cryptography |
Full |
| 9 | Human resources security, access control policies and asset management | Art 21.2(i) | HR Security: A.6.1–A.6.6Access Control: A.5.15–A.5.18 A.8.2–A.8.6Asset Management: A.5.9–A.5.14 |
Full |
| 10 | Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems | Art 21.2(j) | A.8.5 Secure authenticationA.5.17 Authentication informationNIS2 explicitly mandates MFA; ISO 27001 requires appropriate controls but does not mandate a specific method |
Partial |
* Incident handling process is fully covered by ISO 27001. The external reporting obligations under NIS2 Article 23 (24-hour early warning; 72-hour notification to national CSIRT; one-month final report) have no ISO 27001 equivalent and require NIS2-specific procedures. | Coverage key: Full = ISO 27001 controls directly satisfy the NIS2 requirement and evidence maps across. Partial = ISO 27001 addresses the area but NIS2 adds prescriptive obligations requiring additional measures.
Three NIS2 obligations ISO 27001 does not close
ISO 27001 certification does not constitute NIS2 compliance. NIS2 adds three categories of obligation with no equivalent in the standard. We address all three as part of Phase 3.
Outcomes of the Convergence Framework
A completed engagement leaves you with NIS2 compliance and ISO 27001 certification, backed by one evidence pack.
Ready to start?
Tell us where you are with NIS2 and ISO 27001. We'll run a gap assessment against both and lay out exactly what an integrated programme requires.