ISO/IEC 27001 — Information security management systems
NIS2 says what you must achieve, never how you demonstrate it. ISO 27001 is the reference published for that purpose. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Annex A is a REFERENCE SET, not a mandatory checklist. Which controls apply is decided by your risk assessment and recorded in the Statement of Applicability, so two certified organisations can hold very different control sets. A certificate therefore evidences a working management system — it does not prove that any particular article 21(2) measure is implemented. Auditors will ask to see the SoA before they accept the certificate as NIS2 evidence.
We put that first because it is the most expensive misunderstanding about any national framework. Where a member state publishes its own framework, ISO/IEC 27001 is accepted alongside it in every member state examined, and Estonian law names it as equivalent to E-ITS.
What it is built on
ISO 27001 does not invent its own taxonomy. It sits on A management-system standard (clauses 4 to 10) with a reference set of controls in Annex A.
The 2022 revision reorganised the 114 controls of the 2013 edition into 93 across four themes: Organizational (5.1–5.37), People (6.1–6.8), Physical (7.1–7.14) and Technological (8.1–8.34). The certifiable requirements are the clauses, not Annex A.
How it covers article 21(2)
Control-level mapping. Each article 21(2) measure is mapped to the Annex A controls whose stated purpose delivers it. This is the finest granularity available anywhere in this hub, because Annex A control numbers are stable and public.
Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
| Art. 21(2) | Measure | ISO 27001 — ISO/IEC 27001:2022 Annex A control |
|---|---|---|
| (a) | Risk analysis and security policies | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 |
| (b) | Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 |
| (c) | Business continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 |
| (d) | Supply chain security | 5.19 5.20 5.21 5.22 5.23 |
| (e) | Security in acquisition, development and maintenance | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 |
| (f) | Assessing the effectiveness of the measures | 5.33 5.35 5.36 8.16 |
| (g) | Basic cyber hygiene and cybersecurity training | 5.37 6.3 8.7 |
| (h) | Cryptography and encryption | 8.24 |
| (i) | Human resources security, access control and asset management | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 |
| (j) | Multi-factor authentication and secured communications | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 |
We are not affiliated with ISO and IEC. ISO 27001 and related marks belong to their owners.