images
Development of company-specific data protection and information security policies based on ISO 27001

ISO 27001 and NIS2 comparison matrix


Mapping of controls and requirements

ISO 27001 control Related NIS2 requirement
A.5.1 – Policies for information securitySecurity policies and risk management
A.5.14 – Information security in supplier relationshipsSupply chain cybersecurity
A.6.1 – Information security awareness, education, and trainingStaff training and awareness
A.7.4 – Protection of recordsLog retention and data integrity
A.8.1 – Access control policyAccess control mechanisms
A.10.1 – Cryptographic controlsEncryption and cryptography
A.12.3 – BackupData backup and recovery
A.15.1 – Management of information security incidentsIncident response and reporting
A.17.1 – Information security continuityBusiness continuity
A.18.1 – Compliance with legal and contractual requirementsLegal and regulatory compliance

Summary

Area ISO 27001 NIS2
CertificationYesNo, only compliance required
ScopeInternational standardEU legal directive
Legally bindingNot for everyoneOnly for affected entities
FocusFull information security systemCybersecurity compliance