Basics & Compliance
NIS2 and ISO 27001, and how the two fit together
ISO 27001-certified organisations already cover eight of ten NIS2 mandatory measures, but four critical gaps remain: the BSI notification cascade, the MFA mandate, registration obligations, and management liability. This article maps the overlaps, identifies the gaps, and answers whether ISO certification counts as BSI evidence.
15 min read · Published 18 February 2026
Organisations with an existing ISO 27001 ISMS have a significant head start on NIS2 implementation – but ISO 27001 is not NIS2. Those who do not know the differences will miss specific obligations that no ISO control covers: the BSI notification cascade, MFA as a mandatory requirement, and the personal liability regime for management. This article is for IT managers and CISOs who already operate an ISMS or are considering ISO 27001 as the implementation path for NIS2.
How the BSI Positions ISO 27001 in the NIS2 Context
In its April 2026 #nis2know webinar, the BSI answered the question "Is ISO 27001 sufficient for NIS2 compliance?" in one word: no. The answer is unambiguous, but it is not the end of the story. Immediately afterwards, the supervisory authority laid out three statements that precisely describe the relationship between ISO 27001 and Section 30 BSIG – and which the BSI itself presents on a dedicated slide as a three-step logical chain.
"A certification under ISO/IEC 27001 can be a good foundation and, if implemented comprehensively, generally covers a substantial portion of the risk management measures under Section 30 BSIG." (BSI #nis2know, 7 April 2026, slide 13)
"A certification under ISO/IEC 27001 does not automatically mean that all NIS-2 requirements under the BSIG are fulfilled." (BSI #nis2know, 7 April 2026, slide 13)
"A comprehensive gap analysis of the NIS-2 requirements not covered by ISO/IEC 27001 is required." (BSI #nis2know, 7 April 2026, slide 13)
The internal logic of these three statements matters. First: ISO 27001 is not an obstacle but an asset – a comprehensive certification covers a substantial portion of the Section 30 BSIG requirements. Second: that coverage is neither automatic nor complete. The reason, in the BSI's own words, lies in the systematics of ISO certification itself, which allows organisations to define their scope freely and to accept or transfer risks – both of which are incompatible with Section 30 BSIG, which mandates the implementation of every risk management measure across the entire organisation. Third: this necessarily implies a gap analysis in which every individual NIS2 requirement is checked against the existing ISO implementation and the result is documented.
These three statements are the reference axis of this article. The following sections show what ISO 27001:2022 substantially delivers for NIS2, document the official BSI mapping from slide 19, and then work out the four gaps where ISO – even when fully implemented – falls short.
What ISO 27001:2022 Delivers for NIS2
ISO 27001:2022 structures information security requirements in ten management clauses (Chapters 4–10) and 93 controls across four thematic groups. The official BSI/ENISA mapping table (see section below) shows: all ten mandatory measures under Section 30(2) BSIG (Art. 21(2) NIS2 Directive) can be mapped onto ISO 27001:2022 clauses and controls – but with substantially varying depth. Eight areas are substantially covered; two only in principle. In detail:
1. Risk analysis and security policies (Art. 21(2)(a) NIS2 Directive)
ISO 27001 Clause 6.1.2 (risk assessment) and 8.2 (risk treatment) form precisely the methodological foundation that Section 30(1) BSIG requires for its risk-based approach. ISO-certified organisations already have a documented risk assessment, a risk treatment plan, and a policy framework (A.5.1). This corresponds to the core content of this NIS2 requirement.
2. Security incident management (Art. 21(2)(b) NIS2 Directive)
A.5.24 (planning and preparation), A.5.25 (assessment of events), and A.5.26 (response to incidents) cover the internal incident response process. An ISO ISMS requires defined roles, escalation processes, and documentation requirements for security incidents. Well covered – with one critical exception addressed under gaps.
3. Business continuity (Art. 21(2)(c) NIS2 Directive)
A.5.29 (information security during disruption), A.5.30 (ICT readiness for business continuity), A.8.13 (backup), and A.8.14 (redundancy) address BCM and recovery capability. ISO 27001:2022 substantially strengthened the BCM area compared to the 2013 version – the requirements from Art. 21(2)(c) are largely covered.
4. Supply chain security (Art. 21(2)(d) NIS2 Directive)
A.5.19 (information security in supplier relationships), A.5.20 (contractual requirements), A.5.21 (ICT supply chain), and A.5.22 (monitoring and review of supplier services) form a complete control family for supply chain security. Organisations that have fully implemented A.5.19–5.22 satisfy the core content of the NIS2 supply chain requirements.
5. Secure development and maintenance (Art. 21(2)(e) NIS2 Directive)
A.8.25–A.8.32 (secure development and maintenance, test environments, secure coding guidelines, vulnerability management) comprehensively cover software and system security requirements.
6. Effectiveness assessment (Art. 21(2)(f) NIS2 Directive)
ISO 27001 Clause 9 (performance evaluation) requires monitoring and measurement (9.1), internal audits (9.2), and management reviews (9.3). This is methodologically aligned with the NIS2 requirement to assess the effectiveness of cybersecurity risk-management measures.
7. Cyber hygiene and training (Art. 21(2)(g) NIS2 Directive)
A.6.3 (training and awareness), A.6.8 (reporting of information security events), Clause 7.2 (competence), and 7.3 (awareness) address awareness and training. Principally covered – with the caveat that the NIS2-specific mandatory training for management bodies (Section 38(3) BSIG) goes beyond the ISO framework.
8. Cryptography (Art. 21(2)(h) NIS2 Directive)
A.8.24 (use of cryptography) requires a policy for cryptographic controls and key management. This corresponds to the requirement content of the NIS2 cryptography obligation.
9. Human resources security, access control, asset management (Art. 21(2)(i) NIS2 Directive)
A.5.9 (asset inventory), A.5.15 (access control), A.6.1 (applicant screening), A.6.5 (responsibilities after employment termination), A.6.6 (confidentiality agreements), and A.6.7 (remote working) cover the personnel management and access control requirements.
10. Multi-factor authentication (Art. 21(2)(j) NIS2 Directive / Section 30(2)(9) BSIG)
A.8.5 (secure authentication) covers authentication requirements – but only in principle. ISO 27001 leaves open which authentication method must be used; the outcome follows from the risk assessment. Section 30(2)(9) BSIG mandates MFA as a minimum measure – regardless of risk assessment outcomes. This is a qualitative difference: ISO allows discretion, NIS2 does not.
The Official BSI Mapping from Slide 19
In the same webinar, the BSI presented a simplified mapping table that explicitly maps each of the ten mandatory measures under Section 30(2) sentence 2 BSIG to specific ISO 27001:2022 clauses and Annex A controls. The table is based on an analysis by ENISA and the NIS Cooperation Group and is currently the most authoritative source for the question "which ISO controls cover which Section 30 requirement?". The BSI accompanies it with an explicit note on the character of this overview:
"The mapping is based on an analysis by the European Union Agency for Cybersecurity (ENISA) and the NIS Cooperation Group. It serves exclusively as a simplified overview and is purely informative in nature. Note: implementation in line with these standards/requirements does not mean that entities thereby automatically fulfil the requirements under Section 30 BSIG in full." (BSI #nis2know, 7 April 2026, slide 19)
In detail, the mapping is as follows. The notation and order of the ISO references are reproduced unchanged from the BSI slide.
- Section 30(2) sent. 2 no. 1 – Risk analysis and IT security policies: 5.2, 5.3, 6.1, 6.1.2, 6.1.3, 6.2, 8.2, 8.3, 9.2, 9.3, 10.1, A.5.1, A.5.2, A.5.3, A.5.36, A.5.4, A.5.7, A.5.19, A.5.20, A.5.21, A.5.31, A.5.35, A.5.36, A.8.34
- Section 30(2) sent. 2 no. 2 – Incident handling: A.5.24, A.5.25, A.5.26, A.5.27, A.5.28, A.6.8, A.8.15, A.8.16, A.8.17
- Section 30(2) sent. 2 no. 3 – Business continuity management: A.5.26, A.5.29, A.5.30, A.7.11, A.8.13, A.8.14
- Section 30(2) sent. 2 no. 4 – Supply chain security: A.5.19, A.5.20, A.5.21, A.5.22, A.8.30
- Section 30(2) sent. 2 no. 5 – Security measures and vulnerability management: 6.3, 8.1, A.5.21, A.5.23, A.7.3, A.7.5, A.7.13, A.8.7, A.8.8, A.8.25, A.8.31, A.8.9, A.8.16, A.8.20, A.8.22, A.8.29, A.8.31, A.8.32, A.8.33, A.8.34
- Section 30(2) sent. 2 no. 6 – Assessment of effectiveness of measures: 6.2, 9.1, 9.3
- Section 30(2) sent. 2 no. 7 – Training and awareness measures: 7.2, 7.3, A.6.3, A.8.7
- Section 30(2) sent. 2 no. 8 – Cryptographic procedures: A.5.31, A.8.24
- Section 30(2) sent. 2 no. 9 – Personnel security, access control and asset management: 5.28, 7.1, 7.2, A.5.9, A.5.10, A.5.11, A.5.12, A.5.13, A.5.14, A.5.15, A.5.16, A.5.17, A.5.18, A.8.24, A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, A.7.1, A.7.2, A.7.4, A.7.7, A.7.10, A.8.2, A.8.3, A.8.5, A.8.18, A.8.21, A9
- Section 30(2) sent. 2 no. 10 – Multi-factor authentication and secured communication: A.5.15, A.5.16, A.5.17, A.5.18, A.7.2, A.8.2, A.8.3, A.8.5, A.8.18, A.8.21, A9
A note on notation: in no. 9, "5.28" appears in the slide. ISO 27001:2022 has no clause 5.28; what is presumably meant is either A.5.28 (collection of evidence) or clause 5.2. The label "A9" at the end of nos. 9 and 10 is also unusual – ISO 27001:2022 structures Annex A in four themes (A.5–A.8), and an "A.9" does not exist in the 2022 version. This is presumably a reference to Annex A.9 (Access Control) of the older ISO 27001:2013, which was reorganised into A.5.15–A.5.18 + A.8.2–A.8.5 in the 2022 edition. These notation quirks are present in the original slide and are reproduced here unchanged.
This overview shows two things. First, coverage is comprehensive – every one of the ten Section 30 numbers can be mapped onto ISO clauses and controls; not a single area is left without an ISO reference. Second, depth varies sharply. No. 1 (risk analysis) is mapped onto 23 clauses/controls; no. 8 (cryptography) onto two. Coverage alone therefore says nothing about actual fulfilment. What is missing in detail – and which of those missing items make the difference between ISO conformity and NIS2 conformity – is the subject of the next section.
The Four Critical Gaps
The mapping table from slide 19 shows: coverage exists in all ten areas. But coverage and actual fulfilment are two different things. The four gaps below are not marginal – they touch some of the most operationally and legally significant NIS2 specifics, and they are not automatically closed by even a comprehensive ISO 27001 implementation.
Gap 1: The BSI notification cascade (Section 32 BSIG)
This is the largest and most consequential gap. ISO 27001 A.5.26 covers the internal response to security incidents – but not a 24-hour early warning, 72-hour full notification, and 30-day final report cycle submitted to a government authority. Neither timelines, nor content requirements, nor escalation paths to the BSI are reflected in any ISO control or management clause. An ISO-certified organisation with a fully implemented incident response process still has no BSI notification cascade – because ISO has no concept of mandatory government reporting.
Consequence: The internal incident response process must be extended with an explicit BSI notification procedure: who decides on significance? Who submits the 24-hour notification? What content must be provided within which time window? These questions must be answered independently of ISO.
Gap 2: MFA as a mandatory minimum measure (Section 30(2)(9) BSIG)
ISO A.8.5 "Secure authentication" allows the use of strong passwords to be classified as a sufficient control based on a risk assessment. That is ISO-compliant. Section 30(2)(9) BSIG does not accept this: MFA is mandatory, not a risk-assessment outcome.
Consequence: Having A.8.5 marked as "applicable" in the SoA does not mean MFA is in place. And exceptions for legacy systems or specific user groups must be explicitly reviewed against Section 30(2)(9) BSIG.
Gap 3: BSI registration obligation (Section 33 BSIG)
ISO 27001 has no concept of mandatory government registration. The legal obligation to register as a subject entity with the BSI – including a designated contact point, sector information, and company size – has no equivalent in any ISO control. How reachable that contact point must be depends on the entity type: operators of critical installations must keep it reachable at all times, de facto around the clock (Section 33(2) sentence 2 BSIG), whereas for other particularly important and important entities a function mailbox monitored during business hours with an internal escalation chain is sufficient. This is an external compliance obligation, not a security measure.
Gap 4: Personal liability and mandatory management training (Section 38 BSIG)
ISO 27001 Clause 5.1 requires leadership commitment and top management engagement for the ISMS – but not a personal liability regime for individual management members. Section 38 BSIG goes further: management bodies are personally liable for serious breaches, must demonstrably approve and oversee measures, and are required to attend training. ISO Clause 5.1 is a structural management principle; Section 38 BSIG creates individual legal obligations.
Consequence: A management review under ISO Clause 9.3 does not substitute for a documented management resolution under Section 38 BSIG. The training obligation under Section 38(3) BSIG is not an ISO audit criterion.
Does ISO 27001 Certification Count as BSI Evidence?
No – but that is not the right question.
Article 24 NIS2 Directive creates the legal basis for conformity assessments under European cybersecurity certification schemes (under the EU Cybersecurity Act) to be recognised as evidence of compliance with certain NIS2 requirements. ISO 27001 is not an EU cybersecurity certification scheme under the Cybersecurity Act – it is an international ISO standard. An ISO 27001 certificate therefore cannot be directly submitted to the BSI as proof of NIS2 compliance.
What this means in practice: BSI supervision is risk-based. An organisation with ISO 27001 certification and a documented NIS2 gap analysis that closes the four described gaps is in a substantially stronger position than an organisation without an ISMS. No BSI auditor ignores an ISO certificate – but they will still verify the NIS2-specific requirements.
ISO 27001 certification is not a free pass for NIS2 compliance – but it substantially shortens the path and gives the BSI a structured foundation on which the review can build.
The SoA as a Trap
A particular risk for ISO-certified organisations is the Statement of Applicability (SoA). ISO 27001 allows Annex A controls to be classified as "not applicable" if they are not relevant to the scope. This mechanism collides with NIS2 in two scenarios:
- Excluded control, NIS2-relevant: An organisation has classified A.5.21 (ICT supply chain security) as not applicable because no software is developed in-house. Section 30(2) BSIG requires supply chain security for service providers as well. The ISO exclusion cannot be sustained against the BSI.
- Applied control, insufficiently implemented: A.8.5 (Secure authentication) is classified as applicable and implemented as a strong password policy. ISO audit: passed. BSI review: MFA obligation under Section 30(2)(9) BSIG not met.
For NIS2 purposes, the SoA must be reconciled against the statutory minimum requirements. NIS2 mandatory measures cannot be disapplied by an ISO SoA exclusion.
What This Means in Practice
The BSI explicitly framed two scenarios as guidance for ISO organisations in the #nis2know webinar (slide 18): the already-certified organisation and the organisation working towards certification. The recommendations below follow that split and add the immediate measures that must run in both scenarios independently of ISO status.
Scenario 1: The organisation is already ISO 27001-certified
Most of the NIS2 implementation is already done. The open items are manageable and have clear priorities:
- Register with the BSI (Section 33 BSIG) – administrative, not technically complex; check the registration deadline.
- Specify the BSI notification process: integrate the 24h/72h/30-day cycle explicitly into the incident response process (A.5.26); define responsibilities and notification templates.
- Concretely verify MFA compliance: check whether A.8.5 is actually implemented as MFA – especially for privileged accounts, remote access, and critical applications. Where not: plan and document rollout.
- Introduce the compliance track for management bodies: the Section 38(3) BSIG training is not an ISO audit criterion. Implement formally, document, repeat.
- Document the management resolution under Section 38 BSIG: ISO management reviews (Clause 9.3) do not substitute for this resolution.
- SoA review against NIS2 mandatory measures: check whether NIS2-relevant controls have been excluded as not applicable in the SoA; correct if necessary.
This is not a multi-month project. For a well-managed ISO ISMS, this is typically four to six weeks of additional work – concentrated on the four described gaps.
Scenario 2: The organisation is building toward ISO 27001
ISO 27001 certification is not a NIS2 requirement – but the ISO methodology makes NIS2 compliance largely a byproduct. Building a risk assessment, risk treatment plan, control library, and ISMS documentation to ISO standard satisfies eight of the ten Section 30(2) BSIG mandatory measures in the process.
Important caveat: ISO certification typically takes 12–18 months. NIS2 obligations – including BSI registration and notification duties – apply now. NIS2 compliance cannot wait for ISO certification to complete.
Recommended strategy for this scenario:
- Immediate measures without a full ISMS: BSI registration, provisional notification process, MFA for critical accounts, management resolution.
- Build ISMS in parallel: ISO 27001 scope, risk assessment, treatment plan, SoA – with NIS2 mandatory measures as an explicit objective.
- Incorporate NIS2 gaps from the start: BSI notification process, MFA obligation, and management training as fixed items in the ISMS project – not as afterthoughts.
Typical mistakes ISO-certified organisations make in BSI reviews
- SoA lists NIS2-relevant controls as "applicable" without concrete implementation evidence – ISO audit accepts this; BSI review does not.
- A.5.26 (Incident Response) implemented, but BSI notification cascade not elaborated. No reporting channel, no responsible person, no template.
- A.8.5 applied but MFA only for administrators; broad user base without a second factor. Section 30(2)(9) BSIG still applies.
- ISO Clause 9.3 (management review) present, but no evidence of training under Section 38(3) BSIG.
- Supply chain security (A.5.19–5.22) classified as SoA exclusion despite critical SaaS providers being in scope.
The Gap Analysis NIS2 vs. ISO 27001 template supports the systematic identification of gaps. It contains the complete mapping between the ten Section 30(2) BSIG mandatory measures and the relevant ISO 27001:2022 controls, checkboxes for the four described gaps, and a prioritised remediation list.
Placing This in the Implementation Journey
For ISO 27001-certified organisations, NIS2 is a delta project, not a greenfield project. The NIS2 Guide covers risk analysis and mandatory measures in Chapter 2, with references to ISO counterparts throughout. Next steps: Article A-04 (The 10 Mandatory Measures Under Section 30 BSIG Explained) provides the complete overview of all requirements and their practical implications. For organisations without an ISMS, B-03 (How to Conduct a NIS2 Risk Analysis) is the direct entry point.
Sources: BSI #nis2know webinar "Der Weg zur Umsetzung" of 7 April 2026, slides 12 (Is ISO 27001 alone sufficient?), 13 (three key statements), 17 (three-step logic), 18 (two scenarios), 19 (mapping table Section 30 BSIG → ISO 27001:2022). Speakers: Marian Blok, Fabian Nissing (BSI). The mapping table from slide 19 is based on an analysis by ENISA and the NIS Cooperation Group.
This article does not constitute legal advice. For questions about the specific legal classification of your situation, please consult a lawyer specialising in IT law or information security law.
This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.
More in Basics & Compliance