ISO 27001 is a voluntary international standard you certify against; NIS2 is binding EU law you must comply with. ISO 27001 builds the security management system, NIS2 adds legal duties on top: 24-hour incident reporting, management liability, sector supervision and fines up to €10M or 2% of turnover.
How they fit together
- An ISO 27001 ISMS satisfies most of NIS2 Article 21 risk-management measures
- NIS2 reporting deadlines (24h/72h/1 month) exceed anything ISO requires
- ISO certification is evidence, not exemption — regulators supervise NIS2 directly
- Doing both in one programme costs far less than sequential projects
We map every control once and reuse it for both — see NIS2 services and compliance readiness consulting.