Accessibility links Skip to main content

ISO 27001 and NIS2

  • ISO 27001 certification helps you establish a sustainable information security framework using an internationally recognized management system.
  • Normec CertUp supports you in choosing between ISO 27001, CyFun®, or a combined approach to effectively meet the requirements of NIS2.

Request a Quote

Contact form

Naam
I would like to be contacted regarding a quality audit:
Privacy Policy 

ISO 27001 and NIS2: Ensuring Sustainable Information Security

ISO 27001 is one of the most widely recognized international standards for information security management. This standard helps organizations identify their risks, establish security measures, implement a management system, and demonstrate a structured approach.

Within the framework of NIS2, ISO 27001 can serve as a solid foundation. However, the standard does not automatically replace the specific requirements of the directive, which relate in particular to governance, incident reporting, management responsibility, and the supply chain.

Why ISO 27001?

ISO 27001 enables the establishment of an information security management system, also known as an ISMS. This system supports the organization in continuously managing risks, defining responsibilities, documenting measures, and gradually improving security.

For organizations already familiar with ISO audits, this approach may seem self-evident. It fits into an approach that encompasses management, governance, and continuous improvement.

ISO 27001 and NIS 2: Complementary, but Not Equivalent

ISO 27001 certification can support a NIS2 approach, as it covers a large portion of the expected practices in the areas of risk management and information security. However, it is not always sufficient to demonstrate full compliance.

NIS2 contains specific requirements, particularly regarding incident reporting deadlines, management responsibility, supply chain management, and the scope of application.

KeyConsiderations Under NIS2

Do you wish to rely on ISO 27001 certification to substantiate your NIS2 compliance? While this certification provides a useful foundation, it does not automatically cover all applicable requirements. Therefore, several points must be carefully reviewed:

  • The scope of the ISO 27001 certification may be more limited than that of NIS2;
  • certain NIS2 obligations go beyond the strict requirements of the ISO 27001 standard;
  • incident reporting must be organized in accordance with the applicable CyFun® requirements;
  • management must play a clearly defined role in steering cybersecurity;
  • Risks related to the supply chain must be the subject of a specific analysis;
  • the “Statement of Applicability” must be consistent, up-to-date, and sufficiently substantiated.

It must therefore be verified whether the certified management system actually covers the entire scope, all obligations, and the evidence required under NIS2.

ISO 27001 or CyFun®?

ISO 27001 certification is particularly well-suited for organizations seeking an internationally recognized framework, a sustainable management approach, and certification that is also useful outside the Belgian context.

This may be relevant for service-oriented companies, organizations already pursuing other ISO certifications, or companies seeking to structure their security for the long term.

CyFun® may be more suitable if the primary goal is to comply with the requirements of the Belgian NIS2 framework and to operate at the “Basic,” “Important,” or “Essential” levels.

Depending on your situation, the two approaches can serve as alternatives or as complementary options.

Why partner with Normec CertUp?

Normec is part of the Normec Group and possesses in-depth expertise in the areas of audits, certifications, and management processes. This experience is valuable in helping organizations choose between ISO 27001, CyFun®, or a combination of both.

The goal is to provide you with an approach that is meaningful, proportionate, and aligned with your obligations, your level of maturity, and your objectives.

Are you unsure whether to choose ISO 27001, CyFun®, or a combined approach?

Find the best path together with Normec

Frequently Asked Questions – ISO 27001

No, not automatically. ISO 27001 may cover much of the work, but NIS2 has specific requirements that must be analyzed separately.

An ISMS is an information security management system that organizes risk management, controls, and evidence.

The Statement of Applicability is a document required by the ISO/IEC 27001 standard. It lists the security controls selected by the organization, those that are not applicable, and the associated justifications. This document demonstrates that security choices are based on a consistent risk analysis. It must be up to date, aligned with the scope of the information security management system, and sufficiently documented to be defended during an audit or verification.

The Statement of Applicability is particularly important when an organization wishes to use its ISO/IEC 27001 certification as a pathway to NIS2 compliance, as an alternative to a direct assessment against the CyFun® framework. In this case, the Belgian Center for Cybersecurity reviews the scope of the ISO 27001 certification and the Statement of Applicability. The latter must demonstrate that the selected controls adequately cover the expected cybersecurity measures and that any exclusions are clearly justified.