Does ISO/IEC 27001 make you NIS2 compliant?
· Cryptaguard · 8 min read
No, and the reason is more useful than the answer. A certificate proves you run a management system. NIS2 asks which measures you implemented. Those are different questions, and the gap between them is exactly the Statement of Applicability.
This is the most common question we get, usually phrased hopefully, and the honest answer is no. But "no" on its own is not worth much, because ISO/IEC 27001 is genuinely the single most useful thing most organisations bring to NIS2. The useful answer is about where exactly it stops.
What the directive actually asks for
Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.Directive (EU) 2022/2555
Then article 21(2) lists ten measures those arrangements must include, as an outcome — risk analysis and information system security policies, incident handling, business continuity, supply chain security, and so on down the list. Nowhere does the directive name a standard as sufficient. Article 25 encourages the use of European and international standards; encouragement is not equivalence.
And the obligation is not owed to the directive. It is owed under your national transposition law, which is why the same certificate is read slightly differently in Brussels and in The Hague.
The structural reason a certificate cannot answer the question
This is the part that is worth understanding properly, because it explains every national position at once.
Annex A of ISO/IEC 27001 is a reference set, not a mandatory checklist. Which controls apply to you is decided by your own risk assessment and recorded in the Statement of Applicability. Two certified organisations in the same sector can hold materially different control sets and both be correctly certified. The certificate attests that you run a working management system over a defined scope — it does not attest that any particular control is implemented.
NIS2 asks the opposite kind of question. It does not ask whether you have a management system; it asks whether you have addressed ten named areas. So a supervisor holding your certificate still does not know the answer, and will ask for two documents:
- The Statement of Applicability, to see which controls you determined applied and which you excluded, with reasons.
- The scope statement, to see whether the certified scope covers the services that put you in NIS2 scope in the first place.
Read your own scope statement
Scope is where this most often falls apart. A certificate covering a data centre, a product line or a shared services entity is common and perfectly legitimate — and useless as NIS2 evidence if the in-scope service sits outside it. Check the scope statement before you rely on the certificate, not after the inspector does.
What member states actually do with it
In every member state we have examined, ISO/IEC 27001 is accepted as a route or as evidence. In none of them is it accepted as proof of compliance. The three most instructive positions:
Belgium — an explicit alternative track
Belgium runs the most developed assessment regime in the Union, built on CyberFundamentals, and it deliberately left a second door open. Essential entities could satisfy the April 2026 milestone either by showing a CyFun Basic or Important verification, or by submitting an ISO/IEC 27001 Statement of Applicability to the CCB. Note which artefact Belgium asks for: not the certificate, the SoA.
Estonia — equivalence in law
Estonian law recognises ISO/IEC 27001 as equivalent to E-ITS, the national standard. This is as good as it gets for an internationally certified group, and it is why Estonia is unusually cheap to add to a multinational programme. Even here, E-ITS conformity — and therefore its ISO equivalent — is a means of meeting the security obligations, not a discharge of registration, governance or incident notification duties.
The Netherlands — an explicit warning
The Dutch RDI is the bluntest supervisor on this point: meeting your own normenkader does not mean you meet the duty of care. ISO/IEC 27001 and 27002 are treated as guidance rather than as a route. Private entities in the Netherlands have no national framework at all, so the evidence has to be argued against the Cyberbeveiligingsbesluit directly.
The three things no certificate will ever cover
Even with perfect scope and a generous SoA, three families of NIS2 obligation sit entirely outside any management system certification.
- Registration. You must be on the national register, in the right member state, by the national deadline. No certificate registers you.
- Management body duties under article 20. The management body must approve the risk-management measures, oversee implementation, and follow training. This is a named body doing named things, minuted — and it is where personal liability attaches.
- Incident notification under article 23. Early warning within 24 hours of awareness, notification at 72 hours, final report at one month, to the national CSIRT or competent authority. A certified organisation that misses the 24-hour clock is in breach exactly like an uncertified one.
So what is the certificate worth?
A great deal, in the right frame. If you hold ISO/IEC 27001 you have already built the expensive parts: a risk assessment method, an asset and supplier inventory, an incident process, an internal audit cycle, and management review. Those map onto most of article 21(2) with work but without invention.
The honest framing to give a board is this: the certificate is the chassis and NIS2 is the road test. The gap analysis you owe is not "27001 versus NIS2" in the abstract — it is your SoA against the ten measures, plus the three families above, plus whatever your member state adds. Belgium adds an eleventh measure, a coordinated vulnerability disclosure policy, that an entity working only from the directive would miss entirely.
A word on article 24, which is a different thing
Article 24 lets member states require entities to use ICT products, services and processes certified under European cybersecurity certification schemes adopted under the Cybersecurity Act. This gets confused with management system certification constantly. It is about the things you buy, not about how you are run, and holding ISO/IEC 27001 says nothing about it either way.
- Pull your Statement of Applicability and your scope statement before claiming the certificate as evidence.
- Check that the certified scope actually covers the service that puts you in NIS2 scope.
- Gap-analyse the SoA against the ten measures of article 21(2), not against the standard in the abstract.
- Handle registration, article 20 management duties and article 23 reporting separately — no certificate touches them.
- Check your member state for additions. Belgium requires an eleventh measure the directive does not list.