Skip to content
atlas

Don't confuse these

ISO 27001 vs NIS2 Directive

Why they differ

NIS2 is a law you must obey; ISO 27001 is a voluntary standard you can use to meet it.

ISO 27001

Compliance & regulation

The international standard for running an information security management system that can be certified.

Formal

An international standard, current edition 2022, whose clauses 4-10 set the requirements for an information security management system - context, leadership, planning, support, operation, performance evaluation and improvement - with Annex A listing 93 controls to choose from.

In plain English

A set of house rules for running security as a daily routine rather than a one-off clean-up - written so that an outside inspector can check it is really followed.

In practice

Danish state bodies must follow ISO 27001, so the security lead at a ministry uses its clauses to set the scope, run the risk assessment, pick controls from Annex A and report maturity each year - without seeking a certificate.

Why it matters

Without a common measure every customer, auditor and authority would ask for security to be shown in a different way; ISO 27001 gives one structure that can be recognised, audited and mapped to laws such as NIS2.

NIS2 Directive

Compliance & regulation

The EU cybersecurity law that sets shared security duties for organisations in important and critical sectors.

Formal

Directive (EU) 2022/2555, to be written into national law by 17 October 2024, which obliges essential and important entities in 18 sectors to manage cyber risk, report significant incidents in stages and make their management body answerable.

In plain English

Like common building safety rules for the whole EU - every country must write them into its own law, and those who keep society running must build by them.

In practice

The board of a mid-sized Danish shipping company learns it falls under NIS2, so it approves a risk assessment, a routine for reporting incidents within 24 hours and security terms for its suppliers.

Why it matters

The first NIS rules covered too few sectors and were applied unevenly; NIS2 brings in thousands more organisations, fines of up to 10 million euro or 2% of turnover, and personal liability for leaders.

Shared connections

Atlas is in beta.