Many business leaders ask the wrong question: “ISO 27001 or NIS2?” The right question is: “How can we build a single framework that addresses both?” ISO 27001 is a voluntary certification; NIS2 is an EU directive whose transposition into French law is being carried out through bill PRMD2412608L. They share many common requirements. When properly coordinated, the second project costs far less than a separate programme.
Overview
Three differences that change everything
Voluntary
ISO 27001
You choose certification as commercial evidence
Mandatory
NIS2
A directive to be transposed, with penalties under the final framework
≈ 70%
Overlap
Requirements shared by both frameworks
The two frameworks
Side-by-side comparison
Voluntary standard
ISO 27001
- International ISO/IEC standard, 2022 version
- Certification by an accredited body (LSTI, AFNOR, BSI, etc.)
- 114 security controls (Annex A) across four themes
- Annual audit and recertification every three years
- Audit cost: €8,000 to €25,000 for an SME
- International commercial recognition
- Risk-based approach, with a documented and active ISMS
EU directive
NIS2
- EU Directive 2022/2555, with French transposition under way through PRMD2412608L
- Supervision by ANSSI under the final French arrangements
- 10 minimum technical and organisational measures
- Incident notification within 24 hours / 72 hours
- Maximum penalties under the Directive of up to €10m or 2% of worldwide revenue
- Stronger accountability for senior management
- No certification audit comparable to ISO 27001
The table that matters
Requirement by requirement
| Area | ISO 27001:2022 | NIS2 | Overlap |
|---|---|---|---|
| Information security policy | Required (clause 5) | Required | 100% |
| Risk analysis | Formal method | Required | 100% |
| Incident management | Procedure + log | Procedure + 24-hour notice | 80% |
| Business continuity | Tested BCP / DRP | Tested BCP / DRP | 100% |
| Supplier security | Contractual assessment | Cybersecurity assessment | 90% |
| Cryptography | Formal policy | Appropriate measures | 100% |
| Access control | A.5.15 to A.5.18 | MFA + least privilege | 90% |
| Awareness | A.6.3 | Annual training | 100% |
| Internal audits | Mandatory annual programme | Not required | 0% |
| Management review | At least quarterly | Approval of measures | 60% |
| Incident notification | No statutory deadline | 24 hours / 72 hours / 1 month | 0% |
| Personal management commitment | No | Stronger accountability | 0% |
How to choose
Which path for which SME?
Yes
NIS2 first: it is the future regulatory framework to anticipate.
No
ISO 27001 remains relevant for your tenders.
Yes
Add ISO 27001: certification opens up markets.
No
NIS2 readiness may be sufficient in the short term.
Yes
You can target both within 18 to 24 months (combined strategy).
No
Work in phases: NIS2 readiness first (12 months), then ISO 27001 (an additional 12 to 18 months).
The smart approach
The combined strategy in 4 steps
The central idea is to build a single information security management system (ISMS) that addresses both frameworks instead of running two parallel systems.
Months 1 to 3
Dual gap assessment
A single engagement that measures ISO 27001 and NIS2 gaps simultaneously. Sixty per cent of the work is shared.
Months 4 to 9
Build the shared foundations
Information security policy, risk analysis, asset management, access control and awareness: these building blocks address both frameworks in a single pass.
Months 10 to 12
NIS2-specific requirements
24-hour notification procedure, management training, preparation of registration information and a crisis management plan involving senior management.
Months 13 to 18
ISO 27001-specific requirements
Internal audit programme, quarterly management reviews, readiness assessment and certification audit.
Pitfalls to avoid
The 4 costly mistakes
- Assuming an old ISO 27001 certification (the 2013 version or one that has not been revised) still covers NIS2: the 2022 revision is expected.
- Starting the NIS2 project without mapping ISO 27001 overlaps and paying twice for the same controls.
- Outsourcing NIS2 governance to an MSP while keeping the ISO ISMS in-house: two owners, two approaches and less efficiency.
- Waiting for the first inspections before aligning: reactive programmes always cost more.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call