NIS2 and ISO 27001 side by side

Legal duty or voluntary standard, which supervisor, which deadline. Eight criteria side by side, so you do not have to guess which framework applies to you.

Updated 25 September 2026

Eight criteria side by side

Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.

  • What it is

    NIS2
    EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
    ISO 27001
    A standard for an information security management system, an ISMS.
  • Who it applies to

    NIS2
    Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
    ISO 27001
    Any organisation, of any type or size, that chooses to adopt it.
  • Mandatory or voluntary

    NIS2
    Mandatory. Registration, duty of care and incident reporting, all from day one.
    ISO 27001
    Voluntary. One exception: essential entities in the government sector must apply it.
  • Applies since

    NIS2
    15 August 2026, when the Cyberbeveiligingswet entered into force.
    ISO 27001
    Current edition published 25 October 2022, with a climate amendment added in 2024.
  • Supervisor or issuing body

    NIS2
    Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
    ISO 27001
    An accredited certification body, in the Netherlands accredited by the RvA.
  • What you must be able to show

    NIS2
    Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle.
    ISO 27001
    A documented ISMS: scope, risk method, Statement of Applicability, audit and review records.
  • Consequence of non-compliance

    NIS2
    Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher.
    ISO 27001
    No fine. The certificate is suspended or withdrawn, which customers and tenders notice.
  • Certification available

    NIS2
    No. There is no NIS2 certificate and the Cbw does not require one.
    ISO 27001
    Yes, by an accredited certification body.

Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.

Which one applies to you

If your organisation falls under the Cyberbeveiligingswet, NIS2 is a legal duty. ISO 27001, with one exception, is not. It is the voluntary management system that organises the evidence the Cbw asks for, and answers supplier assessments in one document.

Applicability check

What clients ask us

NIS2 is an EU directive, implemented in the Netherlands as the Cyberbeveiligingswet, and a legal duty for essential and important entities. ISO 27001 is a voluntary international standard for an information security management system. NIS2 comes with supervision and fines; ISO 27001 with certification by an accredited body. There is no NIS2 certificate.

Start with the applicability check

Fill in the form. Within 24 hours you receive a written analysis: which framework applies to your organisation, and which steps are immediately required.