ISO 27001 and NIS2: Coverage, Differences and Remaining Gaps
Understand ISO 27001 and NIS2: shared controls, additional legal obligations and a practical implementation path for regulated organisations.
ISO/IEC 27001 provides a strong management framework for many technical and organisational NIS2 topics, but it does not replace a legal NIS2 assessment. Scope, registration, incident reporting, management duties and regulatory evidence arise from applicable law and may extend beyond the scope of an ISO 27001 certificate.
The current German legal context
Germany's new BSI Act implementing NIS2 entered into force on 6 December 2025. Organisations operating in Germany should therefore assess their position against the current law rather than an earlier draft.
Classification depends on sector, activity, size and other statutory criteria. This legal role assessment should be documented before controls are mapped.
Where ISO 27001 provides a strong foundation
- Risk management and documented treatment
- Roles, responsibility and management involvement
- Supplier and service-provider governance
- Incident, continuity and recovery processes
- Training and awareness
- Effectiveness review, internal audit and improvement
NIS2 topics that need a separate check
| Topic | Why ISO 27001 alone is not enough |
|---|---|
| Classification and registration | These arise from law, not from a certificate. |
| Incident reporting | Deadlines, channels and content must reflect the applicable regime. |
| Management body | Training, oversight and liability need legal interpretation. |
| Scope | The certified scope may be smaller than the regulated activity. |
| Regulatory evidence | Form, depth and additional requirements depend on the procedure. |
A practical combined approach
The German BSI itself notes that an ISO 27001 certificate can support certain evidence only under defined conditions and when the relevant scope is fully covered.
- Confirm NIS2 classification
- Align legal scope and ISMS scope
- Create a duty mapping without unsupported percentage claims
- Add missing registration, reporting and governance processes
- Integrate evidence into normal ISMS operation
- Review legal and system changes together
How Sternberg Consulting supports you
We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.
Frequently asked questions
Does ISO 27001 automatically deliver NIS2 compliance?
No. It covers many governance and security processes, while legal obligations and scope still require a separate assessment.
Is ISO 27001 certification legally mandatory?
That depends on the applicable evidence regime. NIS2 does not impose a blanket ISO 27001 certification duty on every in-scope organisation.
Where should implementation start?
Start with classification, scope alignment and a traceable mapping of legal duties to existing ISMS processes.