NIS2 and ISO 27001: How to Implement Cybersecurity Efficiently in Your Company

Martin Bastius
09.07.2026
5
min.

NIS2 and ISO 27001: What You Really Need to Know Now

Cybersecurity has long ceased to be a voluntary IT project for your company. With the NIS2 regulation, it becomes a clear compliance requirement — and thus a central issue for management, legal, IT, procurement, and operations.

The German NIS2 Implementation Act has comprehensively modernized cybersecurity law. The central provisions can be found in the amended BSI Act. They primarily concern risk management measures, registration obligations, extremely tight reporting deadlines, and the personal responsibility of company management.

For many companies, the decisive question now is: Do we have to start completely from scratch — or can we build on existing structures like ISO 27001?

The good news: ISO 27001 is an extremely strong foundation. The less comfortable truth: An ISO certificate does not automatically mean you meet all NIS2 requirements.

In this article, we show you how to approach NIS2 pragmatically, where ISO 27001 helps, and which gaps you should close in a targeted way.

Prefer watching over reading? This article is based on our exclusive heyData webinar "NIS 2 und ISO 27001: Cybersicherheit effizient umsetzen". If you'd rather see our experts' explanations in video format and dive deeper into the practical side, watch the recording here.

What Is NIS2?

NIS2 is a European directive to strengthen cybersecurity in the EU. It obligates certain companies and organizations to implement appropriate technical and organizational measures to protect their IT systems.

The goal: Your company should become more resilient against cyberattacks, detect security incidents faster, and limit damage more effectively. In Germany, the Federal Office for Information Security (BSI) is the central authority for implementation and supervision.

Important for you: NIS2 is not just an issue for classic critical infrastructure operators (such as electricity or water suppliers). The scope is significantly broader. It covers the upper mid-market, digital services, SaaS providers, the manufacturing industry, and numerous service providers embedded in relevant supply chains.

Who Is Affected by NIS2?

Whether your company falls directly under NIS2 essentially depends on two main factors: sector and company size.

1. The Sectors (Does Your Company Belong to One?)

There are 18 regulated sectors in total. These include, among others:

  • Energy, transport, banking, financial market infrastructures, health, drinking water, wastewater
  • Digital infrastructure (important for cloud providers and data centers!)
  • Postal and courier services, waste management, chemicals, food (production and wholesale)
  • Manufacturing (e.g., mechanical engineering, vehicle construction, electrical engineering)
  • Digital services (important for providers of online marketplaces, search engines, and social platforms)
  • Research institutions (note: universities are generally exempt)

2. The Thresholds (Company Size)

As a rule, you are affected if your sector matches and your company:

  • has at least 50 employees OR
  • has an annual turnover of more than 10 million euros (or a balance sheet total of more than 10 million euros).

Special case: Certain providers (e.g., DNS services, trust services, or TLD registries) are regulated regardless of their size, starting with the very first employee.

Why NIS2 Also Affects You Through the Supply Chain

Many companies only check whether they are directly affected. That is a fatal mistake. Even if your company is formally too small or does not belong to the listed sectors, NIS2 can hit you with full force through your customers.

The law obligates directly affected corporations and large companies to secure their entire supply chain. In practice, this means for you as a service provider or SaaS vendor:

  • You will receive significantly stricter and more detailed security questionnaires from your customers.
  • You must demonstrate IT security measures contractually and organizationally.
  • Certificates such as ISO 27001 or proof of a functioning ISMS are becoming mandatory in tenders and B2B contracts.

In short: If you cannot demonstrate cybersecurity, in the worst case you will be dropped from the supply chain. NIS2 is therefore not just a compliance issue — it secures your market access.

The 10 Core Obligations of NIS2 at a Glance

NIS2 requires affected companies to take "appropriate, proportionate, and effective technical and organizational measures". The law specifies 10 minimum measures that you must implement:

1. Risk Analysis & Security Policies

You need to know your business-critical systems, data, and processes, assess risks systematically, and put information security concepts in writing.

2. Incident Handling

You need clear processes for detecting, containing, and remediating cyberattacks. Important: Significant incidents must be reported to the BSI within 24 hours (early warning) and 72 hours (full report).

3. Business Continuity (BCM)

What happens in the event of a total outage? You must be able to demonstrate emergency plans, backup management, and crisis structures to restore operations as quickly as possible.

4. Supply Chain Security

You must actively assess the security level of your own service providers and suppliers (e.g., cloud providers, IT service providers) and demand it contractually.

5. Security in Development & IT

If you develop software or procure IT systems, security must be considered from the start (security by design, vulnerability management).

6. Effectiveness Reviews

Your measures must not exist only on paper. You must verify through regular audits, penetration tests, or reviews that your safeguards actually work in reality.

7. Training & Cyber Awareness

Phishing remains the number one entry point. You must regularly raise awareness among your workforce. New: Company management must also complete verifiable cybersecurity training.

8. Cryptography & Encryption

You must encrypt sensitive data at rest and in transit according to the current state of the art.

9. Personnel & Access Controls

Who is allowed to access what? You need strict authorization concepts (least-privilege principle) as well as secure processes for employee onboarding and offboarding.

10. Multi-Factor Authentication

The use of MFA (e.g., via an authenticator app) becomes mandatory — especially for admin access, remote work, and logins to business-critical cloud systems.

What Role Does ISO 27001 Play?

ISO 27001 is the internationally recognized standard for an information security management system (ISMS). An ISMS ensures that you treat IT security not as a one-off project but as an ongoing process (Plan-Do-Check-Act).

If your company is already certified to ISO 27001, you have an enormous head start. According to estimates by ENISA (the European Union Agency for Cybersecurity), a functioning ISO standard already covers approximately 70 to 80% of NIS2 requirements.

ISO 27001 provides you with the perfect structural framework for:

  • Systematic risk analyses
  • Asset management (an inventory of your IT landscape)
  • Role definitions and responsibilities
  • Documentation logic for regulatory audits

The Direct Comparison: Where ISO 27001 Is Not Enough

An ISO 27001 certificate is a strong signal to the market, but it does not exempt you from the specific additional legal obligations of NIS2. There are fundamental differences you need to know:

Here are the critical gaps where you need to step up despite ISO certification:

  1. The statutory registration obligation: Affected organizations must actively register in the BSI portal. Missing the deadline directly risks fines.
  2. The ultra-tight reporting obligations: While ISO 27001 only requires you to manage incidents internally, NIS2 demands compliance with the statutory deadlines (24 hours for the initial report to the BSI).
  3. Management obligations: NIS2 holds management personally accountable. Executives must not only sign off on the measures but actively monitor them and undergo training themselves. Delegating this to the IT department is legally ruled out.
  4. Liability and sanctions: With ISO violations, the worst case is losing your certificate. With NIS2 violations, companies face fines of up to 10 million euros (or 2% of global turnover), and executives face personal recourse liability with their private assets.

6 Steps to Practical Implementation

Whether you are starting from scratch or want to extend an existing ISO system — this roadmap helps you implement pragmatically:

Step 1: Determine Beyond Doubt Whether You Are Affected

Determine your sector affiliation and your key figures. Are you in a legal gray area, or are you indirectly affected as a B2B service provider through the supply chain? Document the result of this assessment carefully.

Step 2: Create a Complete Asset Register

You can only protect what you know. Systematically record all IT systems, software applications, cloud services, critical data assets, and external service providers.

Step 3: Conduct a Risk Assessment

Analyze your assets: Which threats exist? What impact would the failure of a particular SaaS tool or cloud host have on your core business?

Step 4: Build or Extend Your ISMS

Use the structure of ISO 27001 to set up security policies and appoint responsible team members. A digital compliance platform helps you manage all evidence and deadlines centrally.

Step 5: Implement the Statutory Special Processes

Add the specific NIS2 requirements to your system: Set up access to the BSI portal, integrate the 24-hour reporting obligation into your incident response playbook, and schedule the mandatory training for your management.

Step 6: Continuously Review Effectiveness

Cybersecurity is not a state but a process. Review your measures regularly (e.g., once per quarter) to ensure they actually work, and adapt them to new threat landscapes.

Common Mistakes in NIS2 Implementation

  • Mistake 1: Offloading the topic entirely to IT. NIS2 requires holistic governance. Procurement (supplier contracts), HR (employee training), and company management absolutely must be at the table.
  • Mistake 2: Blind actionism with individual tools. Buying a new security tool is useless if the organizational processes, emergency plans, and policies behind it are missing.
  • Mistake 3: Underestimating the inertia of the supply chain. Many attacks come through seemingly insignificant interfaces to service providers. If you don't vet your suppliers, you leave the back door open.

How heyData Can Support Your Company with NIS2

The flood of regulations like GDPR, ISO 27001, and now NIS2 can quickly feel overwhelming. This is exactly where we come in. heyData is your digital operating system for compliance.

We support you in implementing regulatory requirements efficiently, transparently, and without bureaucratic frustration:

  • Smart applicability check & orientation: Together with you, we clarify which obligations specifically apply to you.
  • Pragmatic ISMS setup: Manage your assets, risks, and security measures centrally via our digital platform.
  • ISO 27001 & NIS2 from a single source: We help you seamlessly extend existing ISO processes with the statutory NIS2 requirements.
  • Efficient vendor management: Use our extensive database of over 6,000 pre-assessed software vendors and service providers to secure your supply chain in no time.
  • Automated trainings: Raise awareness across your entire team — including the legally required specialized training for your management — directly via our platform.

With heyData, you don't treat NIS2 as an isolated compliance mountain but integrate it seamlessly into your existing business processes. This way, you turn legal pressure into a real competitive advantage.

Conclusion: NIS2 Is the Obligation — ISO 27001 Is Your Lever

NIS2 definitively elevates cybersecurity to the management level. What used to be a purely technical safeguard in the IT department is now a legal obligation for company leadership.

ISO 27001 provides you with the perfect foundation and structure to fulfill these obligations efficiently. Those who now specifically add the additional requirements such as reporting obligations and BSI registration not only minimize liability risks but also position themselves as a trustworthy and secure partner in the market.

FAQ

What is NIS2 in simple terms?

NIS2 is an EU-wide legal directive that obligates companies to massively improve their IT and information security, actively manage risks, and report serious security incidents to government authorities (in Germany, the BSI) extremely quickly.

Is our ISO 27001 certification enough for NIS2?

No, unfortunately not quite. ISO 27001 does cover around 70–80% of the technical and organizational measures. However, you must additionally implement legal obligations such as registration with the BSI, the extremely short 24-hour reporting deadlines, and management's personal training and liability obligations.

Does NIS2 also affect smaller companies with fewer than 50 employees?

Directly under the law, only in rare exceptional cases (e.g., DNS services). However, indirect exposure via the supply chain comes into play here: if your customers are subject to NIS2, they'll contractually require you, as a supplier or SaaS provider, to demonstrate compliance with the security standards as well.

Published
09.07.2026
Martin Bastius
Co-Founder & CLO

More articles

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
View all articles
AI & Data Governance
8/18/26

Vibe coding in the enterprise: Understanding and avoiding GDPR risks from AI-powered apps

Vibe coding in the enterprise: Understanding and avoiding GDPR risks from AI-powered apps
AI & Data Governance
8/17/26

Shadow Builder Policy: How to securely manage AI-built apps in your company

Shadow Builder Policy: How to securely manage AI-built apps in your company
Compliance in Practice
8/14/26

Compliance software vs. legal expertise: What your company really needs for modern compliance

Compliance software vs. legal expertise: What your company really needs for modern compliance
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Discover all stories