If you are certified to ISO 27001:2022 and now find yourself in NIS2 scope, most of the security substance is already done. The ten minimum measures map cleanly onto Annex A. What does not map is the part organisations underestimate: NIS2 imposes duties that are administrative and legal rather than technical, and no certificate discharges them.
This is a crosswalk, and every crosswalk is interpretive. Use it to find gaps quickly, then confirm the detail against your national transposition, which is the law that actually binds you.
The ten measures, mapped
- Risk analysis and information security policies — ISO 27001 clauses 6.1 and 5.2 plus A.5.1. Direct match; the ISMS is built on it.
- Incident handling — A.5.24 to A.5.28. The process carries over; the reporting timelines do not, see below.
- Business continuity, backup and crisis management — A.5.29, A.5.30 and A.8.13. Direct match, provided your restoration testing is real.
- Supply chain security — A.5.19 to A.5.22, plus A.5.23 for cloud services. Match on structure, but NIS2 expects attention to direct suppliers' own security posture, which is often deeper than a certified ISMS actually goes.
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure — A.8.25 to A.8.31 and A.8.8. Note the disclosure half: a coordinated vulnerability disclosure route is thinner in most ISMS implementations than NIS2 anticipates.
- Policies to assess effectiveness of measures — clause 9.1, plus 9.2 and 9.3. This is a genuine strength of ISO, not a gap: monitoring, measurement and management review are mandatory clauses.
- Basic cyber hygiene and training — A.6.3 and clause 7.2 and 7.3. Direct match for staff; see the governance gap for management.
- Cryptography and encryption policy — A.8.24 and A.5.31. Direct match.
- HR security, access control and asset management — A.6.1 to A.6.6, A.5.15 to A.5.18, and A.5.9 to A.5.11. Direct match.
- MFA, secured communications and secured emergency communications — A.8.5 and A.8.20 to A.8.22. Mostly a match, with one wrinkle: secured emergency communications means an out-of-band channel that still works when your primary estate is compromised. Few ISMS scopes address it explicitly.
The four gaps certification does not close
Run the crosswalk on your own control set
GRC Copilot maps your existing ISO 27001 controls and evidence onto NIS2 measures automatically, and shows exactly which measures are uncovered.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
1. Registration
NIS2 requires in-scope entities to register with the competent authority and keep the details current. It is a standalone, independently enforceable duty with no ISO equivalent whatsoever. It is also the gap most often discovered late, because nothing in a surveillance audit will ever surface it.
2. The reporting clocks
ISO requires you to manage incidents. NIS2 requires you to tell an authority on a schedule: an early warning within 24 hours of awareness, a notification with an initial assessment within 72 hours, and a final report within one month, plus recipient notification where users may be adversely affected. A mature ISO incident process routinely fails this, because it optimises for investigating properly rather than filing fast.
3. Management accountability as a legal duty
ISO clause 5.1 requires leadership commitment and 9.3 requires management review. NIS2 goes further: management bodies must approve the cybersecurity risk measures and oversee implementation, must undergo training, and can be held personally liable, with authorities able to temporarily bar individuals from management functions in serious cases. The practical delta is evidentiary — you need the approval minuted specifically, not inferred from a management review record.
4. Scope
This is the subtle one. An ISO 27001 scope is yours to define, and many certificates cover a single product, platform or business unit. NIS2 attaches to the entity and reaches the network and information systems that its in-scope services depend on. A certificate covering 30 per cent of your estate evidences 30 per cent of your NIS2 obligation. Compare the two scope statements side by side before assuming coverage.
Certification tells a supervisor that what is inside the scope is well managed. It says nothing about what you left outside it — and NIS2 draws that boundary for you.
A practical order of work
- Register, and record the date.
- Put your ISO scope statement next to the NIS2 service scope and list the delta.
- Add authority notification to the incident procedure, with the three clocks and a pre-agreed definition of significant.
- Table the measures for board approval and minute it; run management training.
- Deepen supplier assessment and stand up a vulnerability disclosure route.
- Address secured emergency communications if your current plan assumes your own estate is available.
For most certified organisations, that is weeks of work, not quarters — provided the scope delta in step 2 turns out to be small. When it is large, that is the real project, and it is better to discover it now than during a supervisory engagement.
Frequently asked questions
Does ISO 27001 certification make us NIS2 compliant?
No. It covers most of the ten measures within its scope, but registration, authority reporting timelines, evidenced management approval and entity-wide scope are not addressed by certification.
Will a supervisor accept our certificate as evidence?
It is generally strong supporting evidence for the measures it covers, and some national implementations reference standards explicitly. It is not a substitute for the duties above, and its weight depends on the scope statement.
Should we extend our ISO scope to match NIS2?
Often yes, and it is usually cheaper than running two control sets. Where the delta is small, extending the ISMS scope at the next recertification is the tidiest route.
What about ISO 27001 to DORA?
The same pattern holds but the gaps are wider: DORA adds prescriptive requirements on ICT third-party contracts, a register of information, and threat-led penetration testing that go well beyond Annex A.
Key takeaways
- All ten NIS2 measures map onto Annex A; the security substance largely carries over.
- Registration and the 24/72-hour/one-month reporting clocks have no ISO equivalent.
- Management approval must be specifically minuted, because NIS2 makes it a personally liable duty.
- Compare scope statements first — a narrow certificate evidences a narrow slice of the obligation.