Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Regulation and compliance

NIS2 vs ISO 27001

NIS2 is a European Union law: anyone in scope complies because they must, under the risk of heavy fines and personal liability for company directors. ISO 27001 is a voluntary standard that earns a certificate. Holding ISO 27001 delivers much of what NIS2 demands in terms of controls, but it does not deliver the incident reporting deadlines or the supply chain oversight.

Explore governance and complianceGo to the comparison

In short

  • NIS2 is mandatory and reaches 18 sectors considered critical in the European Union, with fines running into millions of euros.
  • ISO 27001 is voluntary, certifiable and recognised worldwide, but no member state accepts the certificate as automatic compliance.
  • NIS2 sets hard reporting deadlines: early warning in 24 hours, notification in 72 hours and a final report within one month.
  • Companies outside the EU come into scope when they provide services there or supply someone who is in scope.

Side by side

What separates a law from a standard

What to compareNIS2ISO/IEC 27001
What it isA European Union directive, transposed into each member state's law.A voluntary international standard, with a certificate.
MandatoryMandatory for anyone in scope, with fines attached.Voluntary. You adopt it because you want to or a customer asks.
Who it reachesEssential and important entities across 18 critical sectors.Any organisation, in the scope it defines for itself.
Incident reportingWarning in 24 hours, notification in 72 hours, final report in one month.Requires an incident management process, with no external deadline.
Director liabilityExplicit: leadership approves, oversees and answers personally.Requires leadership commitment, with no personal sanction attached.
Supply chainRequires assessing and controlling direct suppliers and service providers.Includes supplier controls, in less detail than the law demands.
ProofOversight by the national authority, which can audit and fine.Certificate issued by an accredited body.
SanctionUp to 10 million euros or 2% of worldwide turnover for essential entities.Loss of the certificate, with no fine.

NIS2 is the general rule. In the European financial sector DORA applies instead, and it is both more specific and stricter, with an initial warning inside 4 hours.

The law with deadlines and fines

NIS2

It replaced the earlier directive and widened the reach considerably: it now covers 18 sectors considered critical, from energy and healthcare to digital services and waste management. It splits companies into essential and important, with different oversight and fines for each group. It sets minimum risk management measures, rigid reporting deadlines and direct responsibility for whoever runs the company. And it pushes down the chain: entities in scope must demand security from their own suppliers.

  • Mandatory, with fines in the millions of euros
  • 18 critical sectors, split into essential and important
  • Warning in 24 hours and notification in 72 hours
  • Directors carry personal liability
The standard that organises and certifies

ISO/IEC 27001

It structures information security management as a cycle: scope, risk assessment, justified choice of controls, measurement and correction. It is voluntary and applies to any sector. An external auditor checks the work and issues a certificate accepted in any market. For anyone facing NIS2, it is the best shortcut available, because it builds most of the risk management structure the law demands and leaves evidence tidy for the regulator.

  • Voluntary, certifiable and recognised worldwide
  • Builds the risk management NIS2 demands
  • Leaves evidence ready for the authority
  • Serves any sector, inside and outside Europe

How they fit together

The standard is a shortcut, not a free pass

A company with a mature ISO 27001 management system arrives at NIS2 with most of the risk management measures already handled: policy, risk assessment, access control, continuity, incident handling, supplier management. What the standard does not solve on its own are the obligations the law layered on top: meeting the reporting deadlines, keeping the supplier register in the format regulators want, proving leadership approved and monitored the programme, and following the required testing regime. That is extra work, but small next to starting from nothing.

  • ISO 27001 delivers most of the risk management measures
  • Reporting deadlines and the supplier register remain extra work
  • No member state accepts the certificate as automatic compliance

Which case is yours

Where to start

You do not know whether NIS2 reaches you

Start with a scoping assessment

Sector, size and what you sell in Europe decide whether you are an essential entity, an important one or neither.

You supply a European company

Get ready for the questionnaire

Even outside direct scope, your customer will pass on what the law demands of them. ISO 27001 answers most of it.

You are directly in scope of the law

ISO 27001 as the base, NIS2 as the layer

Certify the management system and add the deadlines, the supplier register and the governance evidence on top.

Numbers that matter

24 h

for the initial incident warning

72 h

for full notification to the authority

10 m €

or 2% of worldwide turnover, whichever is higher

How DM11 solves it

From NIS2 scoping to the ISO 27001 certificate

We start by telling you whether and how the law reaches you, build the ISO 27001 foundation and add what NIS2 asks for on top: rehearsed reporting deadlines, a supplier register and evidence that leadership is engaged.

  • You find out early whether you are in direct scope or only as a supplier
  • The 24 and 72 hour deadlines stop being a risk: the process is rehearsed before you need it
  • Directors get what they need to approve and oversee without becoming specialists
  • One project covers the certification and the legal obligation, with no duplicated effort
Talk about NIS2 and ISO 27001

Common questions

What people ask before deciding

Answers checked against Directive (EU) 2022/2555 and ISO/IEC 27001:2022.

Not on its own, but it is the biggest shortcut there is. The standard builds the risk management, the controls and the evidence the law demands. Left outside are the reporting deadlines, the documented supply chain oversight, the formal responsibility of leadership and the testing regime. No European Union member state accepts the certificate as automatic compliance.

More questions? Talk to DM11

Find out whether NIS2 reaches your company, and what to do about it

A short conversation clarifies your scope and shows how much of the path ISO 27001 already covers.

Talk to a specialistExplore governance and compliance