NIS2 and ISO 27001: what's the difference and do you need both?

NIS2 is law, ISO 27001 is voluntary. Learn where they overlap, what the 30% gap covers, and how SMBs in Germany can approach both frameworks practically.

200+ companies already trust deeploi

Key Takeaways

  • NIS2 and ISO 27001 are fundamentally different instruments: NIS2 is binding EU law with fines up to €10 million or 2% of global turnover — ISO 27001 is a voluntary international standard available to any organisation regardless of size or sector.

  • ISO 27001 covers approximately 70% of NIS2 Article 21 requirements — risk management, access control, incident response planning, and documentation — making it a strong foundation but not a complete substitute for NIS2 compliance.

  • The 30% gap is where most SMBs get caught: BSI registration, 24-hour incident notification to authorities, personal management liability for founders and directors, and supply chain security obligations that go beyond ISO 27001's scope.

  • The practical building blocks both frameworks require are the same — device encryption, MFA, patch management, access control, and automated offboarding — but the gap is consistent enforcement, not tooling: a policy is meaningless if three laptops are running with encryption disabled.

  • GRC platforms (Vanta, Drata) document your compliance posture; managed IT platforms like deeploi enforce the technical controls at device level — the two categories are complementary, and pairing them replaces what would otherwise require a dedicated security team.

If you're trying to get your company's IT compliance in order, you've probably seen NIS2 and ISO 27001 mentioned side by side, sometimes as if they were interchangeable. They aren't, and confusing the two is one of the most common mistakes SMBs make when planning their security budgets. One is a legally binding EU directive with enforcement mechanisms and fines. The other is a voluntary international standard you can choose to certify against. Understanding which is which, and how much overlap actually exists, will save you from either over-investing or leaving critical gaps uncovered.

This article answers the three questions most founders and IT-responsible managers are really asking: what's the actual difference, how much does one cover the other, and what do you concretely need to do?

What is the difference between NIS2 and ISO 27001?

NIS2 (the Network and Information Security Directive 2) is an EU directive that member states must transpose into national law. In Germany, the implementing legislation (NIS2UmsuCG) makes it directly enforceable. Non-compliance can result in fines of up to €10 million or 2% of global annual turnover, whichever is higher. It isn't optional for companies that fall within its scope.

ISO 27001 is a voluntary, internationally recognized standard for building and certifying an information security management system (ISMS). It provides a structured framework for managing risks, documenting controls, and continuously improving your security posture. Certification is a business decision, not a legal requirement.

The scope is very different too. According to the BSI, roughly (BSI) 29,500 companies in Germany will need to comply with NIS2's cybersecurity requirements. Across the EU, around 160,000 companies in 18 defined sectors are affected (European Commission). ISO 27001, by contrast, is available to any organisation regardless of size or industry.

This is where it gets uncomfortable: only 16% of businesses required to comply with NIS2 report being fully compliant (CyberSmart). Many assumed their existing ISO 27001 certification had them covered. It hadn't, because the two frameworks serve different purposes and carry different obligations.

Where the two frameworks overlap

Despite these differences, ISO 27001 and NIS2 share substantial common ground. ISO 27001 covers approximately 70% of the requirements outlined in NIS2 Article 21, which defines the specific security measures in-scope companies must implement. The overlap includes risk management processes, access control policies, incident response planning, patch management, and security documentation.

If your company already holds ISO 27001 certification, you have a significant head start. The discipline of maintaining an ISMS, running internal audits, and documenting controls maps directly onto much of what NIS2 demands. But a head start is not the finish line. The remaining 30% covers obligations that ISO 27001 was simply never designed to address.

What NIS2 requires that ISO 27001 does not

That 30% gap is where most SMBs get caught off guard. Four areas stand out:

  1. BSI registration. Companies in scope must register with the Bundesamt für Sicherheit in der Informationstechnik. This is mandatory, and late registration doesn't exempt you from compliance.

  2. Tiered incident reporting. NIS2 requires an initial notification to authorities within 24 hours of becoming aware of a significant incident, followed by a detailed report within 72 hours. ISO 27001 requires you to have an incident response process, but it doesn't prescribe reporting timelines to regulators.

  3. Personal management liability. Under NIS2, founders and directors can be held personally liable for compliance failures. This goes well beyond anything ISO 27001 touches and is a point that should concern every managing director directly.

  4. Supply chain security. NIS2 sets specific expectations for how you assess and manage cybersecurity risks in your supply chain. ISO 27001's Annex A includes supplier management controls, but they don't meet the depth NIS2 demands.

Understanding these gaps is essential for NIS2 compliance planning. Certification alone won't protect you from regulatory consequences if you haven't addressed these NIS2-specific obligations.

How do you implement the technical controls both frameworks require?

Regardless of whether you're pursuing NIS2 compliance, ISO 27001 certification, or both, the practical building blocks are largely the same: device encryption, automated patch management, multi-factor authentication (MFA), role-based access control, audit logging, and immediate offboarding when employees leave.

Most SMBs already use some of these tools in isolation. The gap isn't usually tooling. It's consistent enforcement. Having an encryption policy is meaningless if three laptops in the field are running with FileVault disabled. Strong cybersecurity strategies depend on controls that are actively enforced, not just documented.

This is where it helps to distinguish between two categories of tools. GRC platforms (governance, risk, and compliance tools like Vanta or Drata) are excellent at evidence collection, policy documentation, and preparing for audits. They help you prove what you've done. But they don't enforce technical controls on your devices.

Managed IT platforms work at a different layer. They enforce controls at the device level as part of daily operations: encrypting drives, pushing patches, restricting access based on roles, and revoking accounts automatically when someone is offboarded. deeploi operates in this second category, handling the technical implementation that both NIS2 and ISO 27001 require across devices, users, and access policies in a single platform. It's worth noting that this covers the technical layer only. BSI registration, incident reporting to authorities, management liability documentation, and governance obligations still need to be addressed separately.

The two tool categories are complementary, not competing. A GRC platform documents your compliance posture. A managed IT platform like deeploi makes sure the controls it documents are actually running. Companies pursuing both frameworks benefit from pairing the two, and for SMBs without dedicated IT staff, this combination replaces what would otherwise require a full-time security team.

How do you know if you're actually compliant?

Forget the word "audit" for a moment and ask a simpler question: can you demonstrate, right now, that your devices are encrypted, that access is role-appropriate, that MFA is enforced across all critical systems, and that offboarding happens immediately when someone leaves?

If the answer depends on checking a spreadsheet or asking someone to verify manually, you have a gap. Compliance that relies on manual checks tends to decay quickly. The better approach is building audit-readiness into your daily IT operations so that documentation and GDPR-relevant audit logs are generated as a byproduct of enforcement, not assembled in a panic before an audit.

The threat landscape adds urgency. Cyberattacks caused an estimated €266.6 billion in damage to German companies in 2024, a 29% increase year over year (Bitkom). And 65% of German companies now see cyber attacks as an existential threat (Bitkom). More than one in three companies (35%) in Germany has been hit by a cyber attack in the past two years, with 57% of victims reporting that financial damage has increased (KPMG). Compliance isn't bureaucracy for its own sake. It's the structured response to a very real problem.

If you're considering ISO 27001 certification as a foundation for broader NIS2 compliance, factor in time. Certification typically takes 6 to 12 months for an SMB, depending on your current maturity level. Starting early matters, especially if you're also navigating IT security measures for SMEs for the first time.

FAQ

Does NIS2 apply to my company?

Two criteria determine this: your company has 50 or more employees or exceeds €10 million in annual turnover, and it operates in one of 18 sectors defined by the directive (energy, transport, finance, healthcare, digital setup, and others). Checking takes under two minutes. If both criteria apply, you're in scope.

Does my company need both NIS2 compliance and ISO 27001 certification?

NIS2 compliance is mandatory if you're in scope. ISO 27001 certification is voluntary but covers roughly 70% of NIS2's technical and governance requirements. It also adds credibility with clients and partners who increasingly ask for it during procurement. Pursuing both is strategically valuable, but only NIS2 is legally required.

Can ISO 27001 certification replace NIS2 compliance?

It cannot. The 30% gap includes BSI registration, tiered incident reporting with a 24-hour initial notification window, personal management liability, and supply chain security requirements that go beyond ISO 27001's scope. Certification is a strong foundation, not a substitute.

Which tools help with NIS2 and ISO 27001?

GRC platforms like Vanta or Drata handle evidence collection, policy documentation, and audit preparation. Managed IT platforms enforce technical controls (encryption, patching, access, offboarding) at the device level. The two categories complement each other. Proposed amendments published in January 2026 aim to ease compliance for 28,700 companies, including 6,200 micro and small enterprises, so staying current on regulatory updates is worthwhile too.

Conclusion

Before spending budget on either framework, understand which rules actually apply to your company. NIS2 is mandatory for in-scope organisations. ISO 27001 is voluntary but strategically valuable, covering roughly 70% of NIS2's technical requirements and providing a credible security posture for clients and partners.

ISO 27001 gives you the strongest starting point for technical and governance groundwork. But NIS2 carries obligations, including registration, reporting timelines, and personal management liability, that no certification can replace.

Your practical next step: run the two-criteria scope check, conduct a gap analysis against the NIS2 Article 21 measures most relevant to your business, and register with the BSI if you haven't already. The companies that treat compliance as an operational habit rather than a project will be the ones that pass audits without breaking a sweat.

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist