Accessibility links Skip to main content

ISO 27001 certification is not the same as NIS2 compliance

Moniek Steegers has been working at Normec Certification Institute (NCI) for over two years as an ISO auditor for ISO 27001 and ISO 9001. Prior to that, she worked at KPMG and PricewaterhouseCoopers as an IT auditor and consultant, as well as a compliance and information risk officer at NXP and Canon. Given her background, she understands well why ISO 27001 certification is an appropriate way for organizations to have their information security management systems independently assessed. However, it is not necessarily sufficient to also comply with the European NIS 2 Directive, for which Dutch legislation will soon apply as well, as she explains in this interview.

Continue reading
user typing login and password in the concept of cyber security, information security, data protection, and encryption for secure access to user's personal information

Cybersecurity Act is getting closer

The Senate has not yet finalized the Dutch Cybersecurity Act. Still, it’s coming, one way or another. However, not all companies are actively preparing for it yet: “As long as the law hasn’t been published, we don’t know exactly what’s in it, so many companies are still waiting to see what happens.” Still, things could move very quickly once the law is finalized. On July 6 and 7, the Senate will meet to discuss the Cybersecurity Act (Cbw). A vote on the bill will also take place then. If the Senate passes the bill, the Cbw is expected to take effect on August 15, 2026. Organizations subject to the law will then face new obligations regarding digital resilience. Bringing an organization into compliance often takes quite some time. That is precisely why it is so important for organizations to start thinking about their information security now. ISO 27001 certification would be an excellent starting point for most organizations. From there, you can continue building toward NIS2 compliance.

Greater Awareness of Risks

A key benefit of the process leading to ISO 27001 certification is that employees at these organizations become much more aware of the risks involved in cybersecurity. Moniek has also noticed this in practice: “A risk analysis has already been conducted, it’s clear what the ‘crown jewels’ are, efforts are being made to raise awareness, and technical measures have been implemented. That awareness is particularly important; after all, behavior often turns out to be one of the main causes of an incident. You see that some companies have actually linked that awareness to employees’ technical skills: If an employee doesn’t demonstrate sufficient awareness. For example, by falling for too many phishing emails or not attending enough training sessions—they’ll have limited or even no access to the system. As auditors, we also assess that awareness. Moniek explains: “What does an employee know about ISO 27001 certification, cyber risks, and security measures? How does this information relate to their daily work, and how do they apply it?”

Moniek Steegers, ISO Auditor Normec Certification Institute

Continuously Improving Measures

It’s not entirely black and white to determine which areas still need improvement to be NIS2-compliant once you’re ISO 27001-certified, according to Moniek: “If you have the ISO 27001 certificate, you have a very solid foundation. You have an information security management system (ISMS) that helps you establish structure, comply with certain laws and regulations, and raise awareness within the organization. From a risk-based perspective (with the question “What are the ‘crown jewels’?” as the starting point), you conduct a risk analysis and implement measures that you continuously improve. That risk-based approach and continuous improvement are also central to the NIS2 Directive. All sorts of topics—such as incident management, business continuity, and supplier management—are also relevant to NIS2. After all, we’re talking about information security, so it would be quite strange if these were entirely different topics.”

Executive Management Becomes Personally Liable

However, the NIS addresses these topics in greater detail, Moniek continues: “For example, ISO 27001 states that management must be involved in information security. NIS 2 goes further in this regard; it holds executives personally liable, which can even lead to fines. Incident management is another such topic. Under ISO 27001, this is a policy matter. You look at how it’s implemented. But under NIS2, you’re actually required to report major incidents through a central reporting point. Supplier management is also very important under ISO 27001. You must assess your suppliers and set requirements for your own organization; NIS 2 delves into this in even greater depth. This entire concept of supply chain responsibility is extremely important there. Suppliers must also meet requirements themselves and demonstrate compliance. NIS 2 has defined 10 duty-of-care measures. These are also included, to a greater or lesser extent, in ISO 27001, but depending on your risk analysis, NIS 2 imposes slightly stricter requirements.”

Moniek Steegers, ISO Auditor Normec Certification Institute

Start with a thorough risk analysis and a gap analysis

But how does an organization get started when it wants to identify areas for improvement—especially if it’s already ISO 27001-certified but also wants to comply with NIS2? In practice, Moniek observes that organizations often begin by critically reviewing their risk analysis and conducting a gap analysis: “Start by taking a truly critical look at your risk analysis and conducting a gap analysis. Take a really close look: what exactly does NIS2 require of us? How have we interpreted and implemented ISO 27001? Maybe you’re already at a point where you largely comply with NIS2. But this won’t always be the case. A thorough risk analysis followed by a gap analysis is therefore very important. First and foremost, this demonstrates that you’ve been working on this—including to senior management and other departments. Investigate the situation and document it. Only then can you get to work on it in a concrete way. The website of the National Cyber Security Center, ncsc.nl, contains very useful tips, templates, guidelines, and information on this topic.”

In conclusion: Whether or not an organization falls under the NIS2 legislation, cybersecurity remains a key priority for every organization. Think carefully about information security, identify which risks are relevant, and ensure you have an approach that fits your organization.

Preparing for NIS2For organizations that may fall under the NIS2 legislation, it is important to gain insight into their current information security framework in a timely manner. A risk analysis and, for ISO 27001-certified organizations, a gap analysis can serve as a valuable starting point. An independent ISO 27001 audit provides organizations with insight into how information security is structured and safeguarded. For many organizations, this also serves as an important foundation for further preparation for NIS2.

Want to learn more about ISO 27001 or NIS2?