NIS2 Directive + ISO 27001:2022

NIS2 and ISO 27001 Mapping: What Overlaps, What Doesn't, and How to Close the Gaps

Updated 2026-07-19
Key Takeaways: Priverion is a Swiss-hosted GRC platform that maps NIS2 Article 21 against ISO 27001 Annex A controls to close compliance gaps across corporate groups.

If your organization already holds ISO 27001 certification, you're closer to NIS2 compliance than you think , but "closer" isn't "there." Here's exactly where the two frameworks align, where critical gaps remain, and how multi-entity organizations can build a unified approach without duplicating work.

Name + business email only. No demo commitment required.

Or scroll down to read the full mapping breakdown on this page

Trusted by compliance teams managing privacy and security programs across 50+ jurisdictions. Swiss-built. Swiss-hosted. Enterprise-grade.

Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Key Capabilities for Dual-Framework Compliance

What You Actually Need to Manage NIS2 and ISO 27001 in One Place

Mapping two frameworks on paper is one thing. Operationalizing that mapping across multiple entities, keeping evidence current, and proving compliance to auditors and regulators , that's where most organizations break down. These are the capabilities that close the gap between knowing the overlap and actually managing it.

Cross-Framework Control Mapping

Map NIS2 Article 21 requirements directly against your existing ISO 27001:2022 Annex A controls. See at a glance which NIS2 obligations are already satisfied by your ISMS, which have partial coverage, and where net-new controls are needed , without building another spreadsheet.

200+ hours saved in ISO 27001 preparation alone

Medtec , during initial certification process

Incident Management with NIS2 Timelines Built In

ISO 27001 requires incident handling, but NIS2 demands specific reporting deadlines: 24-hour early warnings and 72-hour formal notifications to CSIRTs. Our incident workflows enforce these timelines automatically across every entity, so nothing falls through the cracks when a breach spans multiple subsidiaries.

24/7 DPO support across multiple entities

Trapeze Group , ongoing multi-entity compliance operations

Supply Chain Risk Assessments at NIS2 Depth

ISO 27001 Annex A covers supplier relationships generally. NIS2 demands you assess each direct supplier's cybersecurity posture specifically , including contractual obligations and cascading risk. Our vendor risk assessment workflows go to NIS2 depth, with automated recertification cycles so coverage never lapses.

100% vendor risk assessment coverage

Zurzach Care , across all third-party vendors

Group-Wide Compliance Dashboards

NIS2 introduces personal liability for management bodies. Your CISO and board need a single view of compliance posture across every subsidiary and jurisdiction , not a patchwork of local reports. Our dashboards show framework coverage, open gaps, and remediation status in real time, ready for board presentation or regulatory inquiry.

60% reduction in compliance admin time

Aircraft manufacturer , within first 6 months of deployment

AI-Assisted Gap Analysis and Risk Scoring

NIS2 requires regular effectiveness assessments of your cybersecurity measures. Our AI-assisted risk scoring identifies where your existing ISO 27001 controls fall short of NIS2 requirements and prioritizes remediation by risk severity. AI assists your team's judgment , every output is reviewed before it becomes a compliance record. No customer data is used for model training.

100% ROPA recertification rate, fully automated

AXA , automated recertification across all processing activities

Audit-Ready Evidence Packages

When a supervisory authority or ISO auditor asks for proof, you need it in minutes , not weeks of scrambling across subsidiaries. Priverion generates evidence packages that demonstrate compliance against both frameworks simultaneously, with full traceability from controls to policies to implementation evidence across every group entity.

Operational in weeks, not months

Average time-to-value across Priverion customers

200+

Hours saved on ROPA management

Medtec redirected 200+ hours from manual record-keeping to ISO 27001 preparation in their first year on Priverion

60%

Lower total cost vs. legacy platforms

Based on published per-user, per-module pricing of OneTrust Enterprise vs. Priverion group licensing for comparable multi-entity deployments

3 mo

Ahead of schedule on ISO 27001 certification

Medtec accelerated their ISO 27001 timeline by three months using Priverion's audit-ready evidence packages and automated documentation

Comparison

Why mid-market teams are switching from OneTrust

Enterprise-grade privacy management shouldn't require enterprise-grade budgets , or a six-month implementation timeline. Here's what the comparison actually looks like.

Typical enterprise platform

What mid-market teams keep running into

Per-user, per-module pricing

Costs balloon as you add subsidiaries, users, or modules. Budget predictability disappears. CFOs start asking uncomfortable questions at renewal.

US-headquartered, US-hosted

In a post-Schrems II world, US Cloud Act exposure creates legal uncertainty for cross-border data transfers. Your legal team knows this keeps them up at night.

Complex implementation

Multi-month deployments requiring dedicated consultants. Your team is still managing spreadsheets while waiting for the "real tool" to go live.

Feature overload

ESG, ethics hotlines, cookie consent, and 200 integrations you'll never use. You're paying for a platform designed for the Fortune 500 buyer profile.

Steep learning curve

Business unit leads avoid the tool entirely because it takes training just to file a basic processing activity. Adoption stalls, and the DPO is back to chasing people.

Priverion

What group-wide privacy management should feel like

Predictable pricing by company count

Based on number of entities and organizational size , not per-user or per-module. Add users freely. No expansion traps at renewal. Your CFO will thank you.

Swiss-built, Swiss-hosted, European data residency

All data processing within Swiss infrastructure. No US Cloud Act exposure. In a post-Schrems II world, this isn't a marketing checkbox . it's a legal requirement for cross-border data transfers.

Operational in weeks, not months

Aircraft manufacturer cut compliance admin time by 60% within six months of going live. No multi-month consulting engagement required to get started.

Aircraft manufacturer, first 6 months post-implementation

All-in-one platform, nothing you don't need

ROPA, DPIA, vendor risk, DSR handling, incident management, AI Register, and audit-ready reporting , in a single platform. We don't cover ESG, ethics hotlines, or cookie consent. That's by design.

UX that business units actually use

AXA achieved 100% ROPA recertification , fully automated , because their teams could actually navigate the tool without training. Adoption isn't a problem when the interface respects people's time.

AXA, automated ROPA recertification across all entities

Full Mapping Breakdown

NIS2 Article 21 vs. ISO 27001:2022 Annex A . Requirement by Requirement

This is the mapping your compliance team needs. For each NIS2 obligation, we show which ISO 27001 controls apply, how much coverage you already have, and what additional work is required. If you hold ISO 27001 certification, roughly 70% of NIS2's technical requirements are already addressed , but the remaining 30% includes some of the highest-risk gaps.

NIS2 Article 21 Requirement ISO 27001:2022 Annex A Controls Coverage Gap Summary
Risk analysis and information system security policies A.5.1, A.5.2, A.8.1 to A.8.3 Full ISO 27001's risk-based approach aligns well. Ensure policies explicitly reference NIS2 scope and essential/important entity classification.
Incident handling A.5.24, A.5.25, A.5.26, A.6.8 Partial ISO 27001 covers incident management broadly. NIS2 adds mandatory 24-hour early warning and 72-hour notification to CSIRTs , timelines not specified in ISO 27001.
Business continuity and crisis management A.5.29, A.5.30, A.8.13, A.8.14 Full Strong alignment. ISO 27001's business continuity controls satisfy NIS2's requirements when properly scoped to network and information systems.
Supply chain security A.5.19, A.5.20, A.5.21, A.5.22 Partial ISO 27001 addresses supplier relationships. NIS2 requires deeper assessment of each direct supplier's cybersecurity posture and contractual security obligations.
Security in network and information systems acquisition, development, and maintenance A.8.25, A.8.26, A.8.27, A.8.28 Full Good coverage through secure development lifecycle controls. Ensure vulnerability handling includes NIS2's coordinated disclosure requirements.
Policies and procedures to assess effectiveness of cybersecurity risk measures A.5.35, A.5.36 Partial ISO 27001 requires monitoring and review. NIS2 expects regular, documented effectiveness assessments with evidence available for supervisory authorities.
Basic cyber hygiene practices and cybersecurity training A.6.3, A.7.1 to A.7.3 Full ISO 27001's awareness and training controls align well with NIS2's cyber hygiene requirements.
Cryptography and encryption policies A.8.24 Full ISO 27001's cryptography controls satisfy NIS2. Ensure encryption-at-rest and in-transit policies are documented and enforced.
Human resources security, access control policies, and asset management A.5.15 to A.5.18, A.6.1 to A.6.6, A.8.2 to A.8.5 Full Comprehensive coverage across access control, HR security, and asset management domains.
Multi-factor authentication, secured communications, and secured emergency communications A.8.5 (partial) Gap ISO 27001 references authentication generally. NIS2 specifically requires MFA or continuous authentication, plus secured emergency communication channels , areas requiring net-new controls.

A note on this mapping

This table reflects our analysis of NIS2 Article 21 against ISO 27001:2022. Coverage assessments assume a mature ISMS implementation. Organizations with newly certified or partially implemented systems should conduct a gap analysis specific to their control maturity. The downloadable guide below includes detailed remediation guidance for each partial and gap area.

Critical Gaps to Address

Where ISO 27001 Falls Short of NIS2 , and What to Do About It

These are the areas that catch most organizations off guard. If your compliance strategy is "we have ISO 27001, so we're covered," these gaps represent your highest residual risk under NIS2.

Net-new requirement

Mandatory Incident Notification Timelines

NIS2 requires a 24-hour early warning to the relevant CSIRT after becoming aware of a significant incident, followed by a full notification within 72 hours. ISO 27001 has no equivalent mandatory timeline. You need automated workflows that trigger escalation paths and notification drafts the moment an incident is classified , especially when incidents span multiple subsidiaries in different Member States.

Net-new requirement

Multi-Factor Authentication and Secured Emergency Communications

NIS2 Article 21(2)(j) specifically calls for MFA or continuous authentication solutions and secured voice, video, and text communications for emergencies. ISO 27001's A.8.5 covers authentication controls generally but doesn't mandate MFA or emergency communication channels. These require both technical implementation and documented policies.

Requires deepening

Supply Chain Cybersecurity Assessments

ISO 27001's supplier management controls address vendor relationships at a policy level. NIS2 demands you assess the cybersecurity posture of each critical supplier , including their vulnerabilities, product quality, and the results of coordinated security risk assessments. This means moving from checkbox vendor assessments to substantive, recurring security evaluations with contractual enforcement.

Requires deepening

Documented Effectiveness Assessments

ISO 27001 requires monitoring and reviewing the ISMS. NIS2 goes further: Article 21(2)(f) mandates "policies and procedures to assess the effectiveness of cybersecurity risk-management measures." This means producing regular, structured evidence that your controls actually work , assessments that supervisory authorities can request and audit. Generic audit reports won't suffice.

Requires deepening

Management Body Accountability

NIS2 Article 20 introduces personal liability for management bodies who fail to ensure compliance. This goes beyond ISO 27001's management commitment requirements. Board members must approve cybersecurity risk measures, undergo training, and demonstrate oversight. You need documented evidence of management engagement , not just a signed policy statement, but ongoing training records and decision logs.

Requires deepening

Coordinated Vulnerability Disclosure

NIS2 requires entities to participate in coordinated vulnerability disclosure programs. ISO 27001 addresses vulnerability management through A.8.8 but doesn't mandate participation in coordinated disclosure frameworks. You need a documented process for receiving, triaging, and responsibly disclosing vulnerabilities that aligns with your national CSIRT's expectations.

Free Resource

Download the Complete NIS2 / ISO 27001 Mapping Guide

The full mapping with detailed remediation steps for every gap and partial-coverage area , plus a prioritization framework based on NIS2 enforcement timelines. Built by practitioners, for practitioners.

We'll send the guide to your inbox. No spam, no sales sequence. Your data is processed in Switzerland under the Swiss FADP. See our privacy policy.

Your compliance transformation starts here

Stop managing privacy in spreadsheets. Start managing it as a program.

In 30 minutes

About this page: references, definitions, and FAQs

Key Takeaways: NIS2 and ISO 27001 Mapping

ISO 27001:2022 provides a strong foundation for NIS2 compliance, covering roughly 70% of Article 21 requirements through existing Annex A controls. However, critical gaps remain in incident reporting timelines, supply chain cybersecurity due diligence, management body liability, and mandatory effectiveness assessments. Multi-entity organizations need centralized cross-framework control mapping, automated incident workflows with NIS2-specific deadlines, and group-wide dashboards to achieve and demonstrate dual-framework compliance efficiently.

Definitions

What is NIS2?

NIS2 (Directive (EU) 2022/2555) is the European Union's updated directive on measures for a high common level of cybersecurity across the Union. It replaces the original NIS Directive (2016/1148) and significantly expands the scope of covered entities, strengthens incident reporting obligations, and introduces personal accountability for management bodies. The full text is available at EUR-Lex: Directive (EU) 2022/2555.

What is ISO 27001:2022?

ISO 27001:2022 is the international standard for information security management systems (ISMS), published by the International Organization for Standardization. The 2022 revision restructured Annex A controls into four themes (Organizational, People, Physical, Technological) with 93 controls, down from 114 in the 2013 version. See ISO (ISO/IEC 27001).

What is a CSIRT?

CSIRT (Computer Security Incident Response Team) is the designated national or sectoral body to which essential and important entities must report significant cybersecurity incidents under NIS2 Articles 23 and 24. Each EU Member State must designate at least one CSIRT.

What is NIS2 Article 21?

NIS2 Article 21 sets out the cybersecurity risk-management measures that essential and important entities must implement. It covers risk analysis, incident handling, business continuity, supply chain security, network security, vulnerability disclosure, cryptography, access control, multi-factor authentication, and cybersecurity training, forming the core compliance checklist that maps against ISO 27001 Annex A.

Frequently Asked Questions

How much of NIS2 does ISO 27001 already cover?

ISO 27001:2022 Annex A controls address approximately 70% of NIS2 Article 21 requirements. Areas such as risk management (A.5.1 to A.5.4), access control (A.5.15 to A.5.18, A.8.2 to A.8.5), cryptography (A.8.24), and business continuity (A.5.29 to A.5.30) overlap significantly. However, NIS2 introduces obligations around incident reporting timelines, supply chain cybersecurity assessments, and management body accountability that go beyond ISO 27001's scope. ENISA's guidance on NIS2 implementation confirms these gaps: see ENISA (NIS Directive).

What are the main gaps between NIS2 and ISO 27001?

The primary gaps include: (1) NIS2's mandatory incident reporting to CSIRTs within 24 hours (early warning) and 72 hours (formal notification) under Article 23, which ISO 27001 does not prescribe with specific timelines; (2) NIS2's explicit supply chain cybersecurity due diligence requirements under Article 21(2)(d), going beyond ISO 27001 Annex A.5.19 to A.5.23; (3) personal liability for management bodies under NIS2 Article 20; and (4) NIS2's requirement for regular effectiveness assessments with regulatory reporting. The directive text is available at EUR-Lex: Directive (EU) 2022/2555.

Does ISO 27001 certification guarantee NIS2 compliance?

No. While ISO 27001 certification provides a strong foundation, it does not guarantee NIS2 compliance. According to ENISA, NIS2 imposes sector-specific obligations and mandatory incident reporting timelines that fall outside the ISO 27001 framework. Organizations must perform a dedicated gap analysis to identify and remediate NIS2-specific requirements not covered by their ISMS. The European Commission's NIS2 FAQ confirms that "certification under international standards may be taken into account but does not constitute automatic compliance": see NIS2 Directive, Recital 79.

Who must comply with NIS2?

NIS2 applies to essential and important entities across 18 sectors including energy, transport, banking, health, digital infrastructure, ICT service management, and public administration. Medium-sized enterprises (50+ employees or €10M+ annual turnover) in these sectors are in scope. According to the European Commission, NIS2 brings an estimated 160,000 entities across the EU into scope, a significant expansion from the approximately 15,000 entities covered under the original NIS Directive. EU Member States were required to transpose NIS2 into national law by 17 October 2024.

How can multi-entity organizations align NIS2 and ISO 27001 efficiently?

Multi-entity organizations should: (1) perform a cross-framework control mapping of NIS2 Article 21 against ISO 27001 Annex A controls at the group level; (2) identify net-new NIS2 obligations per subsidiary and jurisdiction; (3) implement centralized incident management workflows with NIS2-specific 24h/72h timelines; (4) conduct supply chain risk assessments at NIS2 depth with automated recertification; and (5) maintain group-wide compliance dashboards for board-level visibility and regulatory readiness.

What are the penalties for NIS2 non-compliance?

Under NIS2 Article 34, essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of turnover. Additionally, NIS2 Article 20 introduces personal accountability for management bodies, who can be held liable for failures to ensure compliance with cybersecurity risk-management measures.

What is the NIS2 incident reporting timeline?

NIS2 Article 23 establishes a multi-stage incident reporting process: (1) an early warning within 24 hours of becoming aware of a significant incident; (2) an incident notification within 72 hours providing an initial assessment including severity and impact; and (3) a final report within one month including root cause analysis and mitigation measures. This is significantly more prescriptive than ISO 27001's incident management requirements under Annex A.5.24 to A.5.28.

How does NIS2 address supply chain security differently from ISO 27001?

While ISO 27001 Annex A.5.19 to A.5.23 addresses supplier relationships and information security in supplier agreements, NIS2 Article 21(2)(d) requires entities to assess each direct supplier's cybersecurity posture specifically, including contractual obligations and cascading risk through the supply chain. NIS2 also requires consideration of the overall quality and resilience of products and services, cybersecurity practices of suppliers, and the results of coordinated security risk assessments: see ENISA (NIS Directive guidance).

Statistics and Sources

According to the European Commission, NIS2 expands cybersecurity obligations to approximately 160,000 entities across the EU, up from roughly 15,000 under the original NIS Directive. ENISA's 2023 Threat Landscape report found that supply chain attacks increased by 26% year-over-year, underscoring the importance of NIS2's enhanced supply chain security requirements: see ENISA Threat Landscape. The ISO Survey 2023 reported over 70,000 ISO 27001 certificates worldwide, reflecting growing adoption of the standard as a baseline for cybersecurity governance. NIS2 penalties for essential entities can reach €10 million or 2% of global turnover (Article 34), while important entities face up to €7 million or 1.4% of turnover. The directive's transposition deadline was 17 October 2024, with enforcement beginning immediately upon national implementation.

NIS2 Article 21 vs. ISO 27001 Annex A: Mapping Summary

NIS2 Article 21 RequirementISO 27001:2022 Annex A ControlsCoverage Level
Risk analysis and information system security policiesA.5.1, A.5.2, A.5.3, A.5.4Full overlap
Incident handlingA.5.24, A.5.25, A.5.26, A.5.27, A.5.28Partial: NIS2 adds 24h/72h reporting timelines
Business continuity and crisis managementA.5.29, A.5.30Full overlap
Supply chain securityA.5.19, A.5.20, A.5.21, A.5.22, A.5.23Partial: NIS2 requires deeper supplier cybersecurity assessment
Network and information systems securityA.8.20, A.8.21, A.8.22, A.8.23Full overlap
Vulnerability handling and disclosureA.8.8, A.5.7Full overlap
Cybersecurity risk-management effectiveness assessmentA.5.35, A.5.36Partial: NIS2 mandates regulatory reporting
Cryptography and encryptionA.8.24Full overlap
Human resources security and access controlA.5.15, A.5.16, A.5.17, A.5.18, A.6.1 to A.6.5Full overlap
Multi-factor authenticationA.8.5Full overlap
Management body accountabilityA.5.4 (partial)Gap: NIS2 Article 20 adds personal liability