NIS2 and ISO 27001 side by side
Legal duty or voluntary standard, which supervisor, which deadline. Eight criteria side by side, so you do not have to guess which framework applies to you.
Updated 25 September 2026
Eight criteria side by side
Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.
What it is
- NIS2
- EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
- ISO 27001
- A standard for an information security management system, an ISMS.
Who it applies to
- NIS2
- Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
- ISO 27001
- Any organisation, of any type or size, that chooses to adopt it.
Mandatory or voluntary
- NIS2
- Mandatory. Registration, duty of care and incident reporting, all from day one.
- ISO 27001
- Voluntary. One exception: essential entities in the government sector must apply it.
Applies since
- NIS2
- 15 August 2026, when the Cyberbeveiligingswet entered into force.
- ISO 27001
- Current edition published 25 October 2022, with a climate amendment added in 2024.
Supervisor or issuing body
- NIS2
- Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
- ISO 27001
- An accredited certification body, in the Netherlands accredited by the RvA.
What you must be able to show
- NIS2
- Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle.
- ISO 27001
- A documented ISMS: scope, risk method, Statement of Applicability, audit and review records.
Consequence of non-compliance
- NIS2
- Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher.
- ISO 27001
- No fine. The certificate is suspended or withdrawn, which customers and tenders notice.
Certification available
- NIS2
- No. There is no NIS2 certificate and the Cbw does not require one.
- ISO 27001
- Yes, by an accredited certification body.
| Criterion | NIS2EU directive, Dutch Cbw | ISO 27001Voluntary international standard |
|---|---|---|
| What it is | EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw). | A standard for an information security management system, an ISMS. |
| Who it applies to | Essential and important entities in 18 sectors. More than 8,000 Dutch organisations. | Any organisation, of any type or size, that chooses to adopt it. |
| Mandatory or voluntary | Mandatory. Registration, duty of care and incident reporting, all from day one. | Voluntary. One exception: essential entities in the government sector must apply it. |
| Applies since | 15 August 2026, when the Cyberbeveiligingswet entered into force. | Current edition published 25 October 2022, with a climate amendment added in 2024. |
| Supervisor or issuing body | Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal. | An accredited certification body, in the Netherlands accredited by the RvA. |
| What you must be able to show | Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle. | A documented ISMS: scope, risk method, Statement of Applicability, audit and review records. |
| Consequence of non-compliance | Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher. | No fine. The certificate is suspended or withdrawn, which customers and tenders notice. |
| Certification available | No. There is no NIS2 certificate and the Cbw does not require one. | Yes, by an accredited certification body. |
Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.
Which one applies to you
If your organisation falls under the Cyberbeveiligingswet, NIS2 is a legal duty. ISO 27001, with one exception, is not. It is the voluntary management system that organises the evidence the Cbw asks for, and answers supplier assessments in one document.
What clients ask us
Start with the applicability check
Fill in the form. Within 24 hours you receive a written analysis: which framework applies to your organisation, and which steps are immediately required.