Directive NIS2 European Union
ISO/IEC 27001:2022 · 2022 revision

ISO/IEC 27001 — Information security management systems

NIS2 says what you must achieve, never how you demonstrate it. ISO 27001 is the reference published for that purpose. If you operate there, this is what your regulator reads.

Published
Member states using it
0

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Annex A is a REFERENCE SET, not a mandatory checklist. Which controls apply is decided by your risk assessment and recorded in the Statement of Applicability, so two certified organisations can hold very different control sets. A certificate therefore evidences a working management system — it does not prove that any particular article 21(2) measure is implemented. Auditors will ask to see the SoA before they accept the certificate as NIS2 evidence.

We put that first because it is the most expensive misunderstanding about any national framework. Where a member state publishes its own framework, ISO/IEC 27001 is accepted alongside it in every member state examined, and Estonian law names it as equivalent to E-ITS.

What it is built on

ISO 27001 does not invent its own taxonomy. It sits on A management-system standard (clauses 4 to 10) with a reference set of controls in Annex A.

The 2022 revision reorganised the 114 controls of the 2013 edition into 93 across four themes: Organizational (5.1–5.37), People (6.1–6.8), Physical (7.1–7.14) and Technological (8.1–8.34). The certifiable requirements are the clauses, not Annex A.

Mapping

How it covers article 21(2)


Basis

Control-level mapping. Each article 21(2) measure is mapped to the Annex A controls whose stated purpose delivers it. This is the finest granularity available anywhere in this hub, because Annex A control numbers are stable and public.

Limit of this mapping

Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.

Mapped at the level of
ISO/IEC 27001:2022 Annex A control
Units in the framework
93
Units carrying article 21(2)
91
Each of the ten risk-management measures of article 21(2), mapped to the ISO/IEC 27001:2022 Annex A control units of ISO 27001
Art. 21(2) Measure ISO 27001 — ISO/IEC 27001:2022 Annex A control
(a) Risk analysis and security policies 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16
(c) Business continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14
(d) Supply chain security 5.19 5.20 5.21 5.22 5.23
(e) Security in acquisition, development and maintenance 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34
(f) Assessing the effectiveness of the measures 5.33 5.35 5.36 8.16
(g) Basic cyber hygiene and cybersecurity training 5.37 6.3 8.7
(h) Cryptography and encryption 8.24
(i) Human resources security, access control and asset management 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19
(j) Multi-factor authentication and secured communications 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23
Sources

We are not affiliated with ISO and IEC. ISO 27001 and related marks belong to their owners.

Cart 0