ISO 27001 or NIS2: Which One Does Your Business Actually Need?

ISO 27001 or NIS2: Which One Does Your Business Actually Need?

· by IDE Solutions

A logistics client sends over a security questionnaire before renewing your contract. Halfway down the form: "Are you ISO 27001 certified?" A few lines later: "Confirm your NIS2 compliance status." Two acronyms, one form, and a decision you now have to make before the renewal deadline. Most business owners have never had to tell these two apart, because until recently neither one applied to a 20-person company. That has changed, not because your business got bigger, but because your customers did, and their compliance duties now roll downhill to their suppliers, which includes you.

The two get lumped together constantly, in questionnaires, in sales pitches from consultants, in casual conversation, as if they were interchangeable or as if doing one automatically covers the other. They do not. One is a certification you choose to pursue. The other is a law that may or may not apply to you, with no certificate involved at all. Getting the difference wrong costs real money, either spending on a certification nobody asked for, or ignoring a legal duty because a sales call said a certificate would cover it. Our IT governance and compliance service exists mostly to sort exactly this out before a company commits budget to the wrong one.

What ISO 27001 actually is

ISO 27001 is an international standard for running an information security management system, a documented, repeatable way of deciding what needs protecting, who is responsible, and how you check it is working. It is not a piece of software and not a specific technical control. It is closer to a quality management framework, borrowed from the same family as ISO 9001, applied to security instead of manufacturing.

Getting certified means an external auditor reviews your documented policies, interviews staff, and checks that what you claim to do actually happens, then issues a certificate valid for three years with annual surveillance audits in between. Nobody requires you to have it by law. Companies pursue it because a customer, an insurer, or a public-sector tender demands proof, or because they want a structured way to reduce security risk and a badge that says so to the outside world.

The catch for a small business: certification is voluntary, but it is not free or quick. A first certification for a company of 20 to 50 people typically runs from the mid five figures into six figures in consulting and audit fees, spread over six to twelve months, plus real internal time from whoever ends up owning the paperwork. That is a meaningful commitment to make on the strength of one customer's questionnaire, which is exactly why the next section matters before you sign a consultant's proposal.

What NIS2 actually is

NIS2 is an EU directive, not a certification. There is no NIS2 certificate to earn and no auditor who stamps you compliant. Instead, national law (in Germany, the NIS2 implementation law, still working through the legislative process at time of writing) obliges specific categories of company, mostly larger operators in sectors like energy, transport, health, digital infrastructure and a defined list of others, to implement security measures, report significant incidents within tight deadlines, and accept liability that in some cases reaches company management personally.

Most companies under roughly 50 employees and under about 10 million euros in annual turnover fall outside NIS2's direct scope entirely. If that is your business, the law itself does not name you. What does reach you is indirect: a directly regulated customer is required to vet the security of its suppliers, and that vetting shows up in your inbox as a questionnaire, a contract clause, or a flat requirement to demonstrate specific controls before the relationship continues. We covered this supply-chain mechanism in detail in a separate piece on NIS2 and supply chains, because it catches more small businesses by surprise than direct regulation does.

Where they overlap, and where they genuinely differ

The overlap is real and it is why people confuse them: both push a company toward the same practical controls, access management, incident response, backup and recovery, staff awareness, vendor oversight. If you build a solid information security management system for ISO 27001, most of the technical substance NIS2 expects is already in place. That is the useful part.

  • Nature. ISO 27001 is a voluntary standard you choose. NIS2 is a legal obligation that either applies to you or does not, with no opt-in.
  • Proof. ISO 27001 gives you a certificate an auditor issues. NIS2 gives you no certificate at all, only a legal duty to comply and to prove it if a regulator asks or an incident happens.
  • Who is on the hook. An ISO 27001 failure means you lose or fail to renew a certificate. A NIS2 failure, for a company actually in scope, can mean regulatory fines and personal liability for management.
  • Who it reaches. ISO 27001 reaches whoever wants it or whoever a customer demands it from. NIS2 reaches a legally defined set of sectors and sizes directly, and reaches everyone else indirectly through supplier questionnaires.

A well-implemented ISO 27001 system covers a large share of what a NIS2 customer questionnaire will ask about. It does not automatically satisfy a legal NIS2 obligation on its own, because NIS2 also expects things a generic ISMS does not force, specific incident reporting timelines to a national authority, and documented supply-chain risk management aimed at NIS2's exact requirements rather than ISO's general framework.

So which one does your business actually need?

Run through this in order, it takes ten minutes and settles most of the confusion.

First, check if NIS2 directly applies to you. That mostly means a specific sector (energy, health, transport, digital infrastructure, and a defined list of others) combined with roughly 50 or more employees, or annual turnover above about 10 million euros. If neither condition is met, the law does not name your business directly, whatever a consultant's sales pitch implies.

Second, if NIS2 does not apply directly, check whether it is reaching you through a customer. Has a client sent a security questionnaire referencing NIS2, added a security clause to a renewing contract, or asked for evidence of specific controls it did not ask for two years ago? If so, you are dealing with a contractual requirement flowing from someone else's NIS2 duty, not a legal obligation of your own, and it needs to be answered on its own terms, usually with documented controls rather than a full certification.

Third, decide about ISO 27001 on its own merits, separately from NIS2. Pursue it if a customer explicitly asks for the certificate by name, if you sell into regulated industries or public-sector tenders where it is a prerequisite, or if you want a structured, externally verified way to reduce security risk and you have the budget and staff time to sustain it for years, not just get through one audit. Do not pursue it purely because a NIS2-adjacent questionnaire mentioned both terms in the same sentence; that conflation is common and usually just means the person who wrote the questionnaire used both words loosely.

A genuinely common outcome for a 20 to 50 person company: NIS2 does not apply directly, a customer's supply-chain questionnaire does need answering, and ISO 27001 certification is not worth the cost yet, documented policies and demonstrable controls satisfy the questionnaire without the six-figure certification spend. That is not a shortcut, it is usually the correct call, and it is one our governance and compliance team makes with clients regularly rather than defaulting everyone toward full certification.

What it costs and takes, side by side

Answering a customer's NIS2-flavoured security questionnaire without pursuing certification typically means documenting policies you may already partly follow: access control, incident response, backup testing, staff security training, vendor risk review. For a company that has never written any of this down, that is commonly two to six weeks of focused work, often with outside help to structure it correctly the first time, and effectively no recurring certification fee.

Full ISO 27001 certification is a different order of commitment: mid five figures to low six figures for the first certification cycle, six to twelve months of preparation, an external audit, and an ongoing annual surveillance audit plus a full recertification every three years. It buys you something the documentation-only route does not, an independently verified certificate that closes the conversation with any customer or tender that specifically demands it by name, rather than one that accepts equivalent evidence.

A concrete way to frame the decision: if answering the questionnaire correctly protects the one contract in front of you, do the documentation route. If losing that certificate would put multiple contracts, tenders or an entire market segment at risk over the coming years, the certification cost is closer to insurance than overhead, and the calculation changes.

Quick answers

Does ISO 27001 certification automatically make us NIS2 compliant? No. It covers most of the practical security substance NIS2 expects, but NIS2 also requires specific incident reporting timelines and supply-chain documentation an ISO audit does not check for on its own. Treat the certificate as a strong head start, not a finish line.

A supplier told us we need ISO 27001 to keep the contract. Do we have to get certified? Only if the contract genuinely requires the certificate by name. Many suppliers ask for "ISO 27001 or equivalent" and will accept documented controls, especially once you point out the certification cost is disproportionate for the contract size. Worth confirming in writing before committing budget.

We're under 50 employees. Can we ignore NIS2 completely? Directly, in most cases yes, the law does not name you. Indirectly, no, if any of your customers are in scope, expect their compliance duties to show up in your contracts sooner or later, and it is cheaper to prepare early than to scramble when a renewal is on the line.

How do we know which controls a questionnaire actually needs, versus what's just asked out of habit? Read it against the specific clauses cited, not the acronyms in the subject line. Our Microsoft 365 security assessment maps your current setup against what is actually being asked, which is usually a shorter list than the questionnaire makes it look.

We tell you which one you actually need, before you spend on either

We review the questionnaire or contract clause in front of you, check whether NIS2 applies directly or indirectly, and map what's realistic: documented controls that satisfy a customer's request, or full ISO 27001 certification when the numbers justify it. No default answer, no upsell toward the bigger project.

Where backups, access control or incident response need real work rather than paperwork, we build those alongside the compliance documentation, so the policy matches what actually happens in your systems.

More Articles