All articles
Compliance

NIS2 vs ISO 27001: what's the difference?

5 min readVictor Pettersson, IT-säkerhetschef, Sokigo

NIS2 and ISO 27001 come up in the same conversations so often that people treat the names as interchangeable. They are related, but they are different kinds of thing. The short version: NIS2 is EU law, binding for organizations in the sectors it names whether they like it or not, while ISO 27001 is an international standard you choose to adopt and can certify against. And a well-run ISO 27001 ISMS takes you most of the way to what the law asks of you.

What NIS2 is, and where the national laws fit

NIS2 is the EU's directive on a high common level of cybersecurity, adopted in December 2022. A directive binds member states rather than companies, so each country transposes it into national law; the transposition deadline was October 2024, and several countries ran late. Sweden is one of them. Its implementation, cybersäkerhetslagen (guide in Swedish), took effect on 15 January 2026 and phases in through the year: incident reporting has applied since 1 July 2026, and the security-measure and management-training requirements start on 1 October 2026.

The obligations themselves are concrete. Organizations in scope must run documented risk management across areas the law lists (incident handling, business continuity, supply chain security, cryptography, access control, training), report significant incidents to the authorities in stages (an early warning within 24 hours, a notification within 72, a final report within a month), register with the designated national authority, and put responsibility on management personally. Fines reach 10 million euros or 2% of global turnover for essential entities, 7 million or 1.4% for important ones.

What ISO 27001 is

ISO/IEC 27001 is the international standard for information security management systems. It is risk-based: you identify the risks to your information and select controls from Annex A (93 of them in the 2022 edition), then run the whole thing as a management system under clauses 4 to 10, with internal audits and management reviews on a schedule. Nobody forces it on you. But certification, issued by an accredited body and valid for three years, is the established way to show customers and partners that your security work holds up. We wrote a step-by-step guide to getting certified.

The five differences that matter

Put side by side, they differ on five points:

  • Legal status: NIS2, through its national implementations, is mandatory for the sectors it covers. ISO 27001 is a voluntary commitment.
  • Who it applies to: the law names sectors and size thresholds, as a rule from 50 employees or 10 million euros in turnover. The standard is open to anyone.
  • Consequences: the law is backed by supervision and fines in the millions of euros. The standard's stick is a lost certificate and lost deals.
  • Incident reporting: the law requires reporting to authorities on fixed deadlines (24 hours, 72 hours, one month). The standard requires an incident process but sets no authority-facing clock.
  • Level of detail: the law says what outcomes you must achieve. ISO 27001 supplies the method and the structure for running the work over time.

How they fit together

The overlap is large and deliberate. Every risk-management area NIS2 lists has counterparts in ISO 27001's Annex A, and both EU and national authorities point to established standards as the way to meet the law. If you want to see where you stand against either yardstick, that is what a gap analysis is for, and it works the same way for both.

But certification is not automatic legal compliance. The law adds things the standard never asks for: registration with the national authority, the reporting channels with their deadlines, and management's personal training and approval duties. So treat them as a sequence: build the management system on ISO 27001, map it against the law's requirements, and close the gaps where the law is specific.

Build one system, not two

Organizations that keep a separate NIS2 binder next to their ISMS do the same work twice and keep neither current. In Aquil, the same documentation, processes and evidence serve several frameworks at once: the gap analysis shows where you stand against ISO 27001 and NIS2 side by side, and cross-framework mappings show how work done for one carries into the other. A mapping never marks anything automatically; the coverage judgment stays yours.

This is practical guidance, not legal advice. Check the details against the directive, your national law and your sector authority.

See what Aquil can do for your team