Three frameworks, three roles — not competitors, but complements. We explain what each framework delivers and where the decisive differences lie.
The three frameworks are often discussed as alternatives. That is a misconception: they address different layers of the same question and, when combined correctly, can create significant synergy.
| Criterion | NIS2 / BSIG | ISO 27001 | BSI IT-Grundschutz |
|---|---|---|---|
| Nature | EU law, mandatory for affected entities | International standard, voluntary | National standard (BSI), voluntary |
| Purpose | Regulatory obligation, sanctions for non-compliance | Certification, proof of trust | Operational security measures |
| Management training obligation | Yes, § 38 BSIG, mandatory | No | No |
| Reporting obligations | Yes, 24h/72h/1 month to the BSI | No | No |
| Fines | Yes, up to €10 million / 2% of turnover | No | No |
| Can be certified | No (compliance evidence is possible) | Yes | Yes |
| Supply chain obligation | Explicit, § 30 (2) No. 4 BSIG | Recommended (A.15) | Recommended |
Organisations certified to ISO 27001 have already structurally fulfilled most NIS2 requirements. Risk analysis, documentation, audit cycles, incident management — all in place. But three areas require targeted additions.
ISO 27001 does not require personal, demonstrable training of executive management. § 38 BSIG does — with a duty of evidence.
ISO 27001 has no regulatory reporting deadlines. NIS2 requires an initial notification within 24 hours.
Affected entities must register with the BSI — regardless of any ISO certification.
Recommendation: Use ISO 27001 as the ISMS foundation and add the NIS2-specific requirements in a targeted way. This saves significant effort compared to building a parallel system.
We analyse your starting position and show which targeted measures deliver the greatest NIS2 leverage.
Request Consultation Now