ISO Compliance Governance Legal Regulations

You have ISO 27001. How much of NIS2 is already done?

Maciej Updated 23/08/2026
You have ISO 27001. How much of NIS2 is already done?
TL;DR

NIS2 article 21 is ISO 27001 shaped, and if you run a certified ISMS most of the substance is already in place: risk assessment, incident handling, business continuity and backup, supplier security, secure development and vulnerability management, effectiveness review, awareness training, cryptography, access control and asset management, and multi factor authentication all map onto existing clauses and Annex A controls. Four things do not carry over. External incident reporting on a fixed clock (24 hour early warning, 72 hour notification, one month final report) has no ISO equivalent, because ISO never asks you to tell a regulator. Registration with a national authority is a separate legal duty. Article 20 places a personal obligation on management bodies to approve the measures, oversee them and take training, which goes further than clause 5 leadership commitment. And the scope of your certificate is probably narrower than the entity NIS2 covers, which is the gap certified companies most often miss. Critically, an ISO 27001 certificate is not a presumption of conformity with NIS2. In Poland that clause sat in a draft and was removed on 3 October 2024, so it is not in the enacted law, despite plenty of pages online saying otherwise. Treat ISO as an accelerator that removes most of the work, not as an exemption.

If you hold an ISO 27001 certificate, most of NIS2 article 21 is already running in your building. Not all of it, and not automatically. The overlap is large enough that the honest job is mapping and gap filling rather than starting again, but there are four things ISO simply never asked you to do, and one scope trap that catches certified companies more often than any missing control.

Let us start with the good news, because it is most of the story.

Article 21 mapped onto ISO 27001:2022

Article 21(2) lists ten measure areas. Here is where each one already lives in a working ISMS.

NIS2 article 21(2) measureWhere it already sits in ISO 27001:2022
(a) Risk analysis and information system security policiesClauses 6.1.2 and 6.1.3 (risk assessment and treatment), A.5.1 policies for information security
(b) Incident handlingA.5.24 to A.5.28: planning and preparation, assessment and decision, response, learning from incidents, collection of evidence
(c) Business continuity, backup management, disaster recovery, crisis managementA.5.29 information security during disruption, A.5.30 ICT readiness for business continuity, A.8.13 information backup
(d) Supply chain securityA.5.19 to A.5.23: supplier relationships, security in agreements, ICT supply chain, monitoring, cloud services
(e) Security in acquisition, development and maintenance, including vulnerability handling and disclosureA.8.25 to A.8.33 (the secure development cluster), A.8.8 management of technical vulnerabilities
(f) Procedures to assess the effectiveness of the measuresClause 9.1 monitoring and measurement, 9.2 internal audit, 9.3 management review
(g) Basic cyber hygiene practices and cybersecurity trainingClauses 7.2 and 7.3 (competence and awareness), A.6.3 awareness, education and training
(h) Cryptography and, where appropriate, encryptionA.8.24 use of cryptography
(i) Human resources security, access control policies, asset managementA.6.1 to A.6.6, A.5.15 to A.5.18 access control, A.5.9 to A.5.11 asset inventory and return
(j) Multi factor authentication, secured communications, secured emergency communicationsA.8.5 secure authentication, A.5.14 information transfer

If you recognise most of that column, you are in decent shape. If the Annex A numbering looks unfamiliar because you certified against the older edition, the 2013 to 2022 control mapping is the translation table you want first.

The claim worth killing: ISO 27001 is not a presumption of conformity

You will read, on a lot of pages, that holding ISO 27001 gives you a presumption of conformity with NIS2. It does not.

NIS2 encourages the use of European and international standards, and article 24 lets member states require certified ICT products, services and processes for specific categories. Neither of those turns a certificate into compliance. The obligations still attach to you, and a regulator still assesses you against the national act.

Poland is the sharpest example, because a presumption of conformity clause genuinely existed in a draft of the Polish act and was removed on 3 October 2024. It is not in the enacted law. Any article you find asserting otherwise is either describing a draft that no longer exists or repeating something it did not check.

The practical framing: ISO 27001 is an accelerator that removes most of the work. It is not an exemption from any of it.

The four things that do not carry over

1. External incident reporting on a clock

This is the biggest genuine gap, and it is a process gap rather than a control gap. ISO 27001 requires you to detect, assess, respond to and learn from incidents. It never requires you to tell a regulator, on a deadline, in a defined format.

NIS2 does: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Your existing incident procedure almost certainly has no step that says "notify the national authority", no defined recipient, and no owner for a 24 hour clock that can start at 2am on a Sunday. That is new work, and it is the subject of the next post in this series.

2. Registration

Several categories of entity have to register with a national authority and keep that entry current. There is no ISO analogue at all. It is a filing obligation, usually with a hard date, and it is the kind of thing that is trivial to do and embarrassing to have missed.

ISO 27001 clause 5.1 requires top management to demonstrate leadership and commitment, and an auditor will interview your executives about it. Article 20 goes further. Management bodies must approve the cybersecurity risk management measures, oversee their implementation, and follow training. Member states must provide that management can be held liable for breaches of that duty.

The evidence you already keep for clause 5 gets you most of the way, but the obligation now names people rather than a function. Make sure your management review minutes actually show the approval, not just attendance.

4. The scope trap

This is the one certified companies miss most often, and it has nothing to do with controls.

ISO 27001 certifies a scope that you defined. Plenty of small companies scope their ISMS to one product, one platform or one office, entirely legitimately. NIS2 attaches to the entity. If your certificate covers your SaaS platform but not the internal corporate IT that runs your payroll and email, the uncovered part is still in scope for NIS2.

Read your Statement of Applicability and your scope statement side by side with the entity your national act names. Where they differ, that difference is your real gap list.

Ready to Streamline Your Compliance?

Discover how AuditBadger can simplify your compliance management process.

How we would run the gap analysis

In the order that wastes the least time:

  1. Confirm you are actually in scope, and under which national act. The scope test is here, including the categories that are caught at any size.
  2. Put your ISMS scope statement next to the entity definition. Resolve the delta first, because it changes everything downstream.
  3. Walk the ten measure areas against your Statement of Applicability. Most rows will be a reference, not a project.
  4. Write the reporting procedure. Named authority, named owner, the 24 and 72 hour steps, and a dry run. This is genuinely new.
  5. Check the registration duty and file it.
  6. Fix the management evidence so approval is visible, and book the training.
  7. Re-read supplier security specifically. Vendor risk for small teams is where ISO and NIS2 are closest in wording and furthest apart in how closely anyone checks.

A note on our mapping, and what it is not

We maintain an ISO 27001 to NIS2 coverage view inside AuditBadger, and the product labels it as our own mapping rather than an official correspondence. There is no ISO published crosswalk to a directive, so anyone presenting one as authoritative is presenting an opinion. Ours is a considered opinion, and it is still an opinion.

What is concrete: the Polish catalog we built runs to 30 measures and 75 sub-controls across 10 sections, authored in Polish with per control article references. 25 sub-controls in our shared library are reused across SOC 2®, ISO 27001 and the Polish regime, which is the practical shape of the overlap. Do the control once, satisfy it in three places.

NIS2 support is early access and we switch it on per account after a conversation. We went through ISO ourselves first, then certified AuditBadger with AuditBadger for SOC 2 Type II with no external consultants, which is the reason we are comfortable saying that most of article 21 is filing rather than building. It genuinely was, for us.

The ten measure areas in full, plus where the Polish transposition diverges, are on our NIS2 page. If ISO 27001 itself is still ahead of you rather than behind you, start at the ISO 27001 overview instead.

FAQ

Frequently asked questions

Does ISO 27001 certification automatically mean NIS2 compliance? +

No. ISO 27001 covers most of NIS2 article 21's technical measures, but it's not a legal exemption or presumption of conformity. You still need to map your existing ISMS controls to NIS2 requirements, fill specific gaps like mandatory incident reporting timelines, and comply with your national NIS2 act—AuditBadger helps teams organize that mapping and gap analysis in one workspace.

What are the main gaps between ISO 27001 and NIS2 compliance? +

The four key gaps are: external incident reporting to regulators on strict timelines (24/72 hours/1 month), supply chain scope that extends beyond your direct suppliers, board-level cybersecurity responsibilities documented formally, and certain member-state obligations that aren't in ISO 27001 at all. AuditBadger's incident management and vendor tracking modules help small teams organize these additional requirements without starting from scratch.

How long does it take to map ISO 27001 controls to NIS2 requirements? +

For teams with an active ISO 27001 ISMS, mapping existing controls to NIS2 article 21 typically takes 1-2 weeks, followed by gap remediation that varies by scope and missing processes. AuditBadger's AI-assisted control library and risk treatment workflows help accelerate the mapping process, especially for small teams without dedicated compliance staff.

Can AI help automate NIS2 incident reporting for ISO 27001 certified companies? +

Yes. While ISO 27001 covers incident response processes, NIS2 adds mandatory reporting timelines to national authorities. AuditBadger's AI-assisted incident management helps small teams track incidents, set deadline reminders for 24/72-hour notifications, and organize evidence collection—all in the same workspace where your ISO 27001 controls and policies already live.

What's the cost of NIS2 compliance consulting vs using AI-assisted GRC software? +

NIS2 compliance consulting typically costs €5,000-€20,000+ for gap analysis and implementation support, especially for ISO 27001 certified companies adding regulatory reporting. AuditBadger provides AI-assisted policy drafting, control mapping, incident tracking, and vendor management for $250/month with unlimited users—helping small teams handle the gap-filling work in-house while keeping everything audit-ready.

Keep reading

More implementation notes and operator context from the same topic area.

Next step

Ready to replace scattered compliance work?

See how AuditBadger turns policies, evidence, risks, and audit prep into one operating system for lean teams.

Start Subscription