NIS2 vs ISO 27001, Gap Analysis With Mapping Table
Introduction
Holding an ISO/IEC 27001:2022 certificate does not make you NIS2-compliant automatically, but it puts you a long way ahead of someone who does not. The ten minimum measures of Art. 21(2) NIS2 map to the 93 Annex A controls of the standard with a high coverage ratio. A clean mapping exercise quickly reveals where existing ISMS investment is sufficient and where targeted retrofits are needed.
This article covers:
- The substantive difference between NIS2 (mandatory, regulators, fines) and ISO 27001 (voluntary standard, certification bodies).
- A mapping table of the ten Art. 21(2) measures to specific Annex A controls of ISO/IEC 27001:2022.
- The five typical residual gaps that even well-run ISO-certified companies must close under NIS2.
- A procedure for a four-week gap analysis.
- Reference to national transposition acts (NIS2UmsuCG in Germany, NISG 2024 in Austria).
The legal anchors are Art. 21 NIS2 (cybersecurity risk management), Art. 23 NIS2 (reporting obligations), Art. 24 NIS2 (certification schemes), and the standard ISO/IEC 27001:2022 with Annex A (93 controls across four themes: organisational, people, physical, technological). In November 2024 ENISA published an official NIS2-to-ISO 27001 mapping as an annex to its Technical Implementation Guidance, which we adapt here for practical use.
What each regime does and does not do
ISO/IEC 27001:2022 is a voluntary international standard for information-security management systems. Implementing it establishes a risk-based PDCA cycle (Plan-Do-Check-Act) with documented context, stakeholder and risk analysis, defined policies, awareness, internal audit and management review. Conformity is assessed by accredited certification bodies (in DACH, e.g. SQS, TÜV, DNV, DQS) over a three-year cycle with annual surveillance audits.
NIS2 by contrast is a mandatory EU regime targeting designated sectors (Annexes I and II), with sharp sanctions: essential entities face up to EUR 10 million or 2% of global annual turnover (Art. 34(4) NIS2), and management can be held personally accountable (Art. 20(1) NIS2). Supervision sits with national cybersecurity authorities, Germany: BSI; Austria: BMI/BMLV; Italy: ACN.
The headline message: ISO 27001 gives you the tooling; NIS2 demands the outcome. A certified ISMS technically covers around 75-80% of the Art. 21 measures, but NIS2 adds notification pathways, board-level training, registration obligations, and partly more prescriptive technical controls (e.g. MFA for all relevant access per Art. 21(2)(j)).
Mapping table Art. 21(2) NIS2 to Annex A
The following mapping table summarises the ENISA template and adds field-level commentary. The coverage column shows where an ISO/IEC 27001:2022 ISMS already suffices and where NIS2 demands extra steps:
| NIS2 Art. 21(2) | ISO/IEC 27001:2022 (clause · Annex A) | Coverage |
|---|---|---|
| (a) Risk analyses, security policies | 6.1.2, 6.1.3, 8.2, 8.3 · A.5.1, A.5.4 | Full |
| (b) Incident handling | A.5.24–A.5.28 | Partial (add 24/72/30 reporting) |
| (c) Business continuity, backup, crisis management | A.5.29, A.5.30, A.8.13 | Covered (RTO/RPO often stricter) |
| (d) Supply chain security | A.5.19–A.5.23 | Partial (sub-outsourcing control) |
| (e) Acquisition, development, maintenance, vulnerabilities | A.8.8, A.8.25–A.8.34 | Full |
| (f) Effectiveness assessment | 9.1, 9.2, 9.3 | Full |
| (g) Cyber hygiene, training | A.6.3 | Partial (add board training per Art. 20(2)) |
| (h) Cryptography | A.8.24 | Full |
| (i) HR security, access, asset management | A.5.9–A.5.18, A.6.1–A.6.8 | Full |
| (j) MFA, secure communications | A.5.17, A.8.5 | Partial (NIS2 broader in scope) |
The five typical residual gaps
Even with an exemplary ISO/IEC 27001:2022 ISMS, almost every gap analysis surfaces the same five gaps:
- 1. Notification operationalisation: The ISO incident process does not impose hard external deadlines. NIS2 requires a 24-hour early warning, a 72-hour incident notification and a 30-day final report to the competent authority. Recommendation: separate notification playbooks with templates, escalation matrix and at least one annual exercise.
- 2. Board-level training: Art. 20(2) NIS2 obliges management body members to receive training "to gain sufficient knowledge and skills." ISO 27001 only requires generic awareness. Recommendation: documented board-level cyber training with annual refresh.
- 3. Registration and cooperation: NIS2 requires self-registration with the national authority (in Germany, the BSI reporting portal), regular updates and responses to authority queries. ISO 27001 has no such element.
- 4. MFA scope: Art. 21(2)(j) NIS2 requires MFA "where appropriate." Authority interpretation across DACH converges on: all privileged access, all remote access, all access to productive admin interfaces.
- 5. Management body accountability: Art. 20(1) NIS2 establishes personal liability of management body members. That means formally documented approvals, D&O adjustments and clear reporting to the executive board.
A four-week gap-analysis procedure
A proven sequence for Swiss companies with an existing ISO 27001:2022 ISMS:
- Week 1, Scoping & document review: Collect the Statement of Applicability, relevant policies, last internal-audit reports, the risk register, the asset inventory and supplier-clause library. Identify the relevant sector classification and competent national authority.
- Week 2, Interviews & walkthroughs: Structured interviews with the CISO/ISO, IT operations, HR, supplier management, crisis coordinator, data protection officer. Walkthrough incident response, backup-restore, patching.
- Week 3, Gap assessment: Line-by-line comparison against the ten Art. 21 measures, rating "covered / partial / gap", gaps captured by risk and effort.
- Week 4, Roadmap & report: 90/180/365-day action catalogue, prioritisation by fine exposure (Art. 34 NIS2), effort estimate, presentation to the management body.
The deliverables are a readable management report (20-30 pages), a detail mapping table (Excel) and a prioritised roadmap. Investment for a mid-sized company is typically CHF 25,000 to CHF 60,000 depending on complexity.
Sanctions risk and management accountability
Art. 34 NIS2 sets sharp fine ceilings: for essential entities up to EUR 10 million or 2% of global prior-year turnover (whichever is higher), for important entities up to EUR 7 million or 1.4%. Germany's transposition (NIS2UmsuCG) additionally lays out tiered fine categories for individual breaches (e.g. EUR 100,000 to EUR 10 million depending on type).
Art. 20 NIS2 establishes personal responsibility of the management body. Members must approve the measures, supervise their implementation, and continuously train themselves. National law may impose sanctions against management body members, Germany's draft NIS2UmsuCG envisages temporary disqualification for repeated or wilful breaches.
ISO 27001, by comparison, is sanction-free, losing a certificate only hurts you commercially and reputationally. The differential consequences explain why NIS2 programmes attract markedly higher boardroom attention than pure ISO initiatives.
Swiss angle: ISG, BACS and EU cross-border
Swiss companies are directly subject to NIS2 only if they fall under Art. 26(1) NIS2 as providers of specified digital services in the EU (cloud, online marketplaces, search engines, social networks, data centres, CDNs). In that case an EU representative must be appointed (Art. 26(3) NIS2) and the full obligations apply vis-à-vis the competent authority of the representative's Member State.
The Swiss counterpart is the Information Security Act (ISG), in force since 1 January 2024, complemented by the reporting duties to the Federal Office for Cyber Security (BACS / NCSC) under Art. 74a–74f ISG (in force since 1 April 2025). These oblige critical-infrastructure operators to report cyber incidents within 24 hours of knowledge. The substance overlaps strongly with NIS2 but is less prescriptive.
In practice, most Swiss SMEs encounter NIS2 through their EU customers' supply chains. Suppliers to a German energy utility or an Austrian bank will see NIS2 clauses in every new and renewal contract from 2025 onwards. An ISO/IEC 27001:2022 certificate is the most pragmatic single investment to address the bulk of these demands. More in our ISMS & ISO 27001 consulting.
How SIDD supports you
SIDD runs structured NIS2-vs-ISO 27001 gap analyses and translates the result into an actionable roadmap. We use the ENISA mapping template, extend it for national specifics (DE: BSI, AT: BMI, IT: ACN) and integrate Swiss requirements (ISG, BACS / NCSC reporting, FDPIC / EDÖB). The deliverable is a management report with risk heat-map, detailed table and a prioritised 90/180/365-day roadmap.
If you do not yet have an ISMS, we accompany the build-out from scratch, see our ISMS & ISO 27001 consulting. If you want to make an existing ISMS NIS2-fit, we add notification paths, board training, supplier clauses and an MFA rollout in a targeted way. For ongoing demand, we can take the mandate as external CISO or ISO and run the annual effectiveness cycle.
For implementation evidence vis-à-vis EU customers we deliver technical audits, penetration tests and vulnerability scans that feed into consolidated supplier-security documentation. Book a first conversation at /kontakt or request a fixed-price quote for the four-week gap analysis at /offerte. For management bodies we also run half-day NIS2 obligation workshops, an efficient way to evidence the Art. 20(2) training duty.
Looking for hands-on help with NIS2 implementation? Our NIS2 consulting for Swiss companies takes you from applicability analysis through gap analysis to demonstrable evidence, from CHF 500 per month.
