Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 10 July 2026

ISO 27001 and NIS2: Coverage, Differences and Remaining Gaps

Understand ISO 27001 and NIS2: shared controls, additional legal obligations and a practical implementation path for regulated organisations.

ISO/IEC 27001 provides a strong management framework for many technical and organisational NIS2 topics, but it does not replace a legal NIS2 assessment. Scope, registration, incident reporting, management duties and regulatory evidence arise from applicable law and may extend beyond the scope of an ISO 27001 certificate.

Germany's new BSI Act implementing NIS2 entered into force on 6 December 2025. Organisations operating in Germany should therefore assess their position against the current law rather than an earlier draft.

Classification depends on sector, activity, size and other statutory criteria. This legal role assessment should be documented before controls are mapped.

Where ISO 27001 provides a strong foundation

  • Risk management and documented treatment
  • Roles, responsibility and management involvement
  • Supplier and service-provider governance
  • Incident, continuity and recovery processes
  • Training and awareness
  • Effectiveness review, internal audit and improvement

NIS2 topics that need a separate check

Table 1: ISO 27001 and NIS2: Coverage, Differences and Remaining Gaps
TopicWhy ISO 27001 alone is not enough
Classification and registrationThese arise from law, not from a certificate.
Incident reportingDeadlines, channels and content must reflect the applicable regime.
Management bodyTraining, oversight and liability need legal interpretation.
ScopeThe certified scope may be smaller than the regulated activity.
Regulatory evidenceForm, depth and additional requirements depend on the procedure.

A practical combined approach

The German BSI itself notes that an ISO 27001 certificate can support certain evidence only under defined conditions and when the relevant scope is fully covered.

  1. Confirm NIS2 classification
  2. Align legal scope and ISMS scope
  3. Create a duty mapping without unsupported percentage claims
  4. Add missing registration, reporting and governance processes
  5. Integrate evidence into normal ISMS operation
  6. Review legal and system changes together

How Sternberg Consulting supports you

We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.

Discuss your project

Frequently asked questions

Does ISO 27001 automatically deliver NIS2 compliance?

No. It covers many governance and security processes, while legal obligations and scope still require a separate assessment.

Is ISO 27001 certification legally mandatory?

That depends on the applicable evidence regime. NIS2 does not impose a blanket ISO 27001 certification duty on every in-scope organisation.

Where should implementation start?

Start with classification, scope alignment and a traceable mapping of legal duties to existing ISMS processes.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.