"We're ISO 27001 certified – so we're NIS 2 compliant."
We hear this statement remarkably often in our advisory practice. It is understandable, but incorrect. An ISO 27001 certification is an excellent foundation, but it is not a free pass for NIS 2 compliance. Anyone relying on it risks fines of up to EUR 10 million or 2% of global annual turnover, and personal responsibility of the management.
Two systems, two logics
ISO/IEC 27001 is an internationally recognised standard for information security management systems (ISMS). It provides a risk-based framework for implementing, operating, and continuously improving organisational information security processes.
Significantly, the standard is organisation-centered and voluntary. It serves as evidence of structured security management; the scope of application is defined by the organisation itself through the Scope and the Statement of Applicability.
NIS 2 and the NISG 2026 respectively pursue the objective of ensuring a high level of cybersecurity throughout the EU. Organisations in the sectors listed in Annexes 1 and 2 that meet or exceed the relevant thresholds are obliged to implement specific risk management measures and comply with reporting, registration, and governance obligations. The scope of application is prescribed by law and cannot be freely chosen.
This is where the first, frequently overlooked difference becomes apparent: An ISMS scope covering only the IT department, or a single data centre does not address the holistic, organisational approach with an "all-hazards" perspective required by the NISG.
Concrete gaps in certification
- Incident reporting: While Annex A of ISO 27001 contains guidelines on incident management, it neither governs reporting deadlines nor the responsible addressees. The NISG 2026, by contrast, provides for specific obligations: early warnings within 24 hours, notifications within 72 hours, and final or progress reports after one month. Furthermore, the notification of affected service recipients is likewise not provided for under ISO 27001. These requirements must therefore be expressly reflected in playbooks, escalation paths, and assigned responsibilities.
- Governance and training of the management bodies: ISO 27001 requires "management commitment" – deliberately worded in general terms. The NISG 2026 goes further: management bodies must approve risk management measures, monitor their implementation, and complete mandatory training themselves. In addition, management faces personal responsibility.
- Supply chain security: Annex A does include controls on supplier management, but it does not establish an express obligation to assess the cybersecurity practices of each individual supplier or secure development processes along the supply chain. NIS 2 requires precisely this. In practice, this primarily means contractual safeguards, such as security annexes, audit and information rights, and supplier reporting obligations with clear deadlines.
- Registration, self-declaration, and evidence: The NISG 2026 requires registration within three months of its entry into force and, as well as a structured self-declaration on the status of the risk management measures within twelve months. Essential entities must additionally submit evidence or independent audit reports to the authority upon request. An ISO certificate can be a valuable building block in this regard, but it neither replaces the declaration that the organisation must submit itself nor an external audit.
ISO 27001 is a head start, but not an end point. Certified organisations usually already have most of the technical and organisational groundwork in place. The remaining gaps therefore often lie in the legal and procedural areas, not in technology. For implementing NIS 2, it is recommended to conduct a structured mapping of the ISO controls against the obligations under the NISG 2026, from which concrete measures can be derived.
What to do now
In less than a month, on October 1, 2026, the NISG 2026 will take effect. Registration must be completed by the end of the year. Anyone who waits until October will find themselves under time pressure, particularly when negotiating supplier contracts; experience shows that this is one of the most demanding tasks.
For the coming weeks, we therefore recommend:
- Formally determine whether the organisation is affected, if this has not yet been done.
- Carry out a delta analysis between ISO 27001 and the NISG 2026.
- Align risk management measures with the legal requirements.
- Identify critical supplier contracts and prepare as well as roll out security annexes.
Are you unsure whether your organisation falls under NIS 2 or where the gaps between certification and statutory requirements lie? We support you with the applicability analysis, the delta analysis, and the contractual safeguarding of your supply chain. Now is the right time to implement the remaining steps.