NIS2ISO 27001Compliance

ISO 27001 vs NIS2: comparison and combined strategy

ISO 27001 or NIS2? You can prepare for both together. A clear comparison, overlaps to leverage and a 12-month roadmap.

Hakim Djelili7 min read

Many business leaders ask the wrong question: “ISO 27001 or NIS2?” The right question is: “How can we build a single framework that addresses both?” ISO 27001 is a voluntary certification; NIS2 is an EU directive whose transposition into French law is being carried out through bill PRMD2412608L. They share many common requirements. When properly coordinated, the second project costs far less than a separate programme.

Overview

Three differences that change everything

Voluntary

ISO 27001

You choose certification as commercial evidence

Mandatory

NIS2

A directive to be transposed, with penalties under the final framework

≈ 70%

Overlap

Requirements shared by both frameworks

The two frameworks

Side-by-side comparison

Voluntary standard

ISO 27001

  • International ISO/IEC standard, 2022 version
  • Certification by an accredited body (LSTI, AFNOR, BSI, etc.)
  • 114 security controls (Annex A) across four themes
  • Annual audit and recertification every three years
  • Audit cost: €8,000 to €25,000 for an SME
  • International commercial recognition
  • Risk-based approach, with a documented and active ISMS

EU directive

NIS2

  • EU Directive 2022/2555, with French transposition under way through PRMD2412608L
  • Supervision by ANSSI under the final French arrangements
  • 10 minimum technical and organisational measures
  • Incident notification within 24 hours / 72 hours
  • Maximum penalties under the Directive of up to €10m or 2% of worldwide revenue
  • Stronger accountability for senior management
  • No certification audit comparable to ISO 27001

The table that matters

Requirement by requirement

AreaISO 27001:2022NIS2Overlap
Information security policyRequired (clause 5)Required100%
Risk analysisFormal methodRequired100%
Incident managementProcedure + logProcedure + 24-hour notice80%
Business continuityTested BCP / DRPTested BCP / DRP100%
Supplier securityContractual assessmentCybersecurity assessment90%
CryptographyFormal policyAppropriate measures100%
Access controlA.5.15 to A.5.18MFA + least privilege90%
AwarenessA.6.3Annual training100%
Internal auditsMandatory annual programmeNot required0%
Management reviewAt least quarterlyApproval of measures60%
Incident notificationNo statutory deadline24 hours / 72 hours / 1 month0%
Personal management commitmentNoStronger accountability0%

How to choose

Which path for which SME?

1Could NIS2 apply to you (50+ employees or €10m+ revenue in a listed sector)?

Yes

NIS2 first: it is the future regulatory framework to anticipate.

No

ISO 27001 remains relevant for your tenders.

2Do you sell to large companies, international customers or the public sector?

Yes

Add ISO 27001: certification opens up markets.

No

NIS2 readiness may be sufficient in the short term.

3Is your annual cybersecurity budget above €50,000?

Yes

You can target both within 18 to 24 months (combined strategy).

No

Work in phases: NIS2 readiness first (12 months), then ISO 27001 (an additional 12 to 18 months).

The smart approach

The combined strategy in 4 steps

The central idea is to build a single information security management system (ISMS) that addresses both frameworks instead of running two parallel systems.

  1. Months 1 to 3

    Dual gap assessment

    A single engagement that measures ISO 27001 and NIS2 gaps simultaneously. Sixty per cent of the work is shared.

  2. Months 4 to 9

    Build the shared foundations

    Information security policy, risk analysis, asset management, access control and awareness: these building blocks address both frameworks in a single pass.

  3. Months 10 to 12

    NIS2-specific requirements

    24-hour notification procedure, management training, preparation of registration information and a crisis management plan involving senior management.

  4. Months 13 to 18

    ISO 27001-specific requirements

    Internal audit programme, quarterly management reviews, readiness assessment and certification audit.

Pitfalls to avoid

The 4 costly mistakes

  • Assuming an old ISO 27001 certification (the 2013 version or one that has not been revised) still covers NIS2: the 2022 revision is expected.
  • Starting the NIS2 project without mapping ISO 27001 overlaps and paying twice for the same controls.
  • Outsourcing NIS2 governance to an MSP while keeping the ISO ISMS in-house: two owners, two approaches and less efficiency.
  • Waiting for the first inspections before aligning: reactive programmes always cost more.
Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call