In the field of cybersecurity, two terms are most frequently cited: ISO 27001 and NIS2. Companies are asking whether one replaces the other, whether having an ISO certificate and complying with the law is sufficient, or conversely, whether NIS2 obligations cover everything needed for ISO certification. The truth is more complex and depends on your situation.
What is ISO 27001?
ISO/IEC 27001 is an international standard for information security management (Information Security Management System, ISMS). It is a voluntary certification issued by accredited certification bodies. The standard defines a systematic approach to protecting information assets and covers the entire security management lifecycle: from policy through implementation of measures to regular review and improvement.
ISO 27001 operates on the PDCA cycle (Plan-Do-Check-Act) and includes 93 control measures divided into 4 themes: organisational, personnel, physical and technological measures. Certification is valid for three years with annual surveillance audits and requires demonstrable implementation of an ISMS, not just documentation.
Who typically obtains it: Companies wishing to demonstrate a high level of security to customers or partners, providers of cloud and IT services, and companies bidding for public procurement contracts in the public sector.
What is NIS2?
NIS2 is legal obligation resulting from EU Directive 2022/2555, implemented in the Czech Republic by Act No. 264/2025 Coll. On cybersecurity. Unlike ISO 27001, this is not a certification but a regulatory framework, if your organisation falls under the Act, you must comply with its requirements regardless of whether you wish to do so or not.
NIS2 applies to approximately 6,000 organisations in the Czech Republic across 18 regulated sectors (energy, healthcare, transport, digital infrastructure and others). The requirements are specified in Decree No. 409/2025 Coll., which defines 13 areas of security measures. Failure to comply may result in fines of up to 250 million Kč or 2% of global turnover.
Where do NIS2 and ISO 27001 overlap?
Both frameworks share a common core: a systematic approach to information security. The specific overlaps are as follows:
| Area | ISO 27001 | NIS2 / Decree 409/2025 |
|---|---|---|
| Risk management | Mandatory component of ISMS (clause 6.1) | Area 1 - Cybersecurity Risk Management |
| Incident response | Control measures 5.26, 5.27 | Area 9: Managing Cyber Incidents |
| Supplier safety | Control measures 5.19–5.22 | Area 2: Supply Chain Security |
| Access control | Control measures 5.15–5.18, 8.2–8.5 | Area 4 - Access Control and Authentication |
| Cryptography | Control measures 8.24 | Area 6 - Cryptography and Encryption |
| Staff training | Clauses 7.2, 7.3 | Area 11: Training and Awareness |
| BCM/Continuity | Control measures 5.29, 5.30 | Area 10: Continuity of Operations |
Key differences
1. Voluntary vs. Mandatory
ISO 27001 is a certification you choose voluntarily based on business benefit. NIS2 is a law, if it applies to you, there is no choice. This is the most important difference affecting all decisions.
2. Global standards versus EU regulations
ISO 27001 is an internationally recognised standard, suitable for demonstrating security to global customers and partners. NIS2 applies exclusively within the EU and focuses on the cyber resilience of networks and information systems in regulated sectors.
3. Scope of obligations
ISO 27001 covers the entire organisation (or a defined ISMS scope). NIS2 focuses specifically on the cyber resilience of essential and important services. NIS2 also explicitly adds obligations such as: reporting incidents to NÚKIB within 24 hours, registration with the regulator, appointment of a cybersecurity manager, and liability of the statutory body.
4. Incident reporting
ISO 27001 requires internal procedures for incident management. NIS2 goes further. It adds a legal obligation to report serious incidents to the regulator (NÚKIB) within strict deadlines: initial notification within 24 hours, detailed report within 72 hours.
Will ISO 27001 certification help meet NIS2 requirements?
Yes, but it is not sufficient on its own. ISO 27001 certification provides a very solid foundation, covering a large part of the NIS2 requirements for technical and organisational measures. Companies with a functional ISMS have significantly less work when implementing NIS2 compliance.
What ISO 27001 alone cannot guarantee for you:
- Registration with NÚKIB as a regulated entity
- Meeting deadlines for reporting incidents to the regulator
- Appointment of a cybersecurity manager in accordance with legal requirements
- Liability of the statutory body for cybersecurity (explicit NIS2 requirement)
- Specific technical requirements pursuant to Decree 409/2025 for your sector
Recommendations for different types of businesses
A company without ISO 27001 must comply with NIS2.
Focus primarily on meeting NIS2 requirements under Decree 409/2025. ISO 27001 certification may be a strategic goal for the future, but it is not necessary for legal compliance. Start NIS2 audit and a gap analysis.
A company with ISO 27001 certification, required to comply with NIS2
You have an excellent foundation. Conduct a gap analysis to identify specific NIS2 requirements not covered by ISO 27001 (particularly reporting, registration, and the CISO role). Then fill in the missing elements and integrate both frameworks into a consistent system.
The company holds ISO 27001 certification; NIS2 does not apply to it.
ISO 27001 certification is the right way for you to demonstrate security to customers and partners. Monitor NIS2 requirements continuously, as sectors expand, the regulation may affect you in the future.
A company without both is subject to NIS2.
The priority is meeting the legal obligations of NIS2. Also consider the ISO 27001 route if the business environment requires demonstrable security. The appropriate approach: first achieve NIS2 compliance, then pursue potential ISO certification, which builds on the NIS2 work and adds global recognition.
Conclusion: Two tools for one goal
ISO 27001 and NIS2 are not competitors; they are complementary frameworks. ISO 27001 is a tool for systematic security management that companies adopt voluntarily for business benefit. NIS2 is a legal obligation for regulated sectors with specific sanctions for non-compliance.
The best approach combines both: an ISMS according to ISO 27001 as the foundation, with NIS2-specific measures and processes as an add-on for regulatory compliance. The result is a stronger security position while meeting legal obligations.
Want to know exactly where you stand? Launch a free NIS2 audit on nis2ok.cz or read our guide how to carry out a NIS2 audit yourself.