NIS2 + ISO 27001 Certification: 12-Month Path
TL;DR
- ISO 27001 certification covers about 9 of 10 NIS2 measures and is the most efficient compliance path
- Timeline: 12 months from kickoff to Stage 2 audit
- Total cost (SME): EUR 50,000-150,000 including external consulting and certification body
- Surveillance audits are annual; recertification every three years
- Caveat: ISO 27001 alone does not deliver NIS2 supply-chain or Section 38 BSIG awareness
1. Months 1-2: Scope and preparation
Appoint an ISMS officer, define the certification scope (sites, processes, systems), run a gap analysis against ISO 27001:2022 Annex A, and build a 12-month roadmap with budget and milestones.
2. Months 3-6: Buildout
Author the 12 mandatory policies, complete the risk assessment, produce the Statement of Applicability (SoA), build the asset inventory, and run mandatory awareness training. This is the most documentation-heavy phase.
3. Months 7-8: Trial run
Run an internal audit, close gaps, formalize a CAPA process for non-conformities, and hold the first management review. The CAPA log will be reviewed at Stage 2.
4. Months 9-10: Stage 1 audit
The certification body conducts a documentation review. Findings are typically minor non-conformities. Close gaps before Stage 2.
5. Months 11-12: Stage 2 audit
On-site audit including evidence sampling, interviews, and walkthroughs. On success, the certificate is valid for three years with annual surveillance audits.
6. Costs and effort
| Item | Range (SME) |
|---|---|
| Certification body | EUR 8,000-25,000 |
| External consulting | EUR 20,000-80,000 |
| Internal effort | 50-150 person-days |
| Total | EUR 50,000-150,000 |
7. Coverage gap vs. NIS2
ISO 27001 maps to roughly 9 of 10 NIS2 measures. The remaining gap is supply-chain security (Annex A.5.19-A.5.23 needs additional structure) and explicit Section 38 BSIG management-liability awareness. Add a focused supply-chain audit program and management training to close the gap.
Summary
For NIS2-regulated SMEs, ISO 27001 is the highest-leverage path: it handles most controls, signals seriousness to customers, and creates a recurring audit cadence. Plan for 12 months and a budget under EUR 150,000 in the SME segment.
Frequently Asked Questions
Does the certificate bring NIS2 compliance?
Re-certification?
Sources
- Directive (EU) 2022/2555 — NIS2 (As of: 2026-05-02)
- BSIG 2025 (Section 30 measures) (As of: 2026-05-02)
- BSI — NIS-2 FAQ (as of: ongoing)