An Edge Built on Knowledge and Experience
Standards Comparison

NIS2 vs. ISO 27001 vs. BSI IT-Grundschutz

Three frameworks, three roles — not competitors, but complements. We explain what each framework delivers and where the decisive differences lie.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
Three Frameworks — Three Roles

NIS2, ISO 27001 and BSI IT-Grundschutz Compared

The three frameworks are often discussed as alternatives. That is a misconception: they address different layers of the same question and, when combined correctly, can create significant synergy.

CriterionNIS2 / BSIGISO 27001BSI IT-Grundschutz
NatureEU law, mandatory for affected entitiesInternational standard, voluntaryNational standard (BSI), voluntary
PurposeRegulatory obligation, sanctions for non-complianceCertification, proof of trustOperational security measures
Management training obligationYes, § 38 BSIG, mandatoryNoNo
Reporting obligationsYes, 24h/72h/1 month to the BSINoNo
FinesYes, up to €10 million / 2% of turnoverNoNo
Can be certifiedNo (compliance evidence is possible)YesYes
Supply chain obligationExplicit, § 30 (2) No. 4 BSIGRecommended (A.15)Recommended
Leveraging What You Have

What ISO 27001 Already Delivers for NIS2

Organisations certified to ISO 27001 have already structurally fulfilled most NIS2 requirements. Risk analysis, documentation, audit cycles, incident management — all in place. But three areas require targeted additions.

Gap 1: Management Training Obligation

ISO 27001 does not require personal, demonstrable training of executive management. § 38 BSIG does — with a duty of evidence.

Gap 2: BSI Reporting Obligations

ISO 27001 has no regulatory reporting deadlines. NIS2 requires an initial notification within 24 hours.

Gap 3: Registration With the BSI

Affected entities must register with the BSI — regardless of any ISO certification.

Recommendation: Use ISO 27001 as the ISMS foundation and add the NIS2-specific requirements in a targeted way. This saves significant effort compared to building a parallel system.

Decision Support

Which Framework for Which Situation?

We're subject to NIS2 and have no ISMS — where do we start?
Start with a gap analysis based on the BSIG requirements. Build an ISMS in parallel that covers the mandatory NIS2 building blocks. You can pursue ISO 27001 certification as a next step — it eases future audits and strengthens the evidence you provide to the BSI.
We have ISO 27001 — do we still need to implement NIS2 compliance measures?
Yes. ISO 27001 is not NIS2 compliance. It provides an excellent foundation, but does not replace the BSIG-specific obligations: management training, BSI registration, reporting obligations, and evidence to the German supervisory authority.
Can ISO 27001 certification serve as NIS2 evidence?
Partially. The BSI recognises existing certifications as an indicator of a functioning ISMS. However, they do not replace complete NIS2 compliance evidence — particularly not for the areas ISO 27001 does not cover (reporting obligations, management liability, registration).
Related Topics

Further NIS2 Topics

NIS2 Compliance Built on Your Existing Certifications

We analyse your starting position and show which targeted measures deliver the greatest NIS2 leverage.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com