do I still need ISO 27001 if I am already compliant with NIS2
Certification is not a requirement, but often useful
No, ISO 27001 is not required to comply with the Dutch Cybersecurity Act — the law does not mandate certification, but rather a set of measures. Article 21(2) of the NIS2 Directive lists ten subject areas for which an organization subject to the duty of care must have policies and measures, ranging from risk analysis to access control to incident reporting procedures. This is an outcome obligation: what matters is what has been arranged, not what label is attached to it. An organization that has the ten measures required by law in order without a certificate is equally compliant as one that holds one. the ten measures from the law in order, complies equally under the law as one that does.
Yet in practice the two often go together. ISO 27001, and in particular the control measures in Annex A, covers much of the same ground substantively: risk management, supplier management, incident management, access control. An organization already ISO 27001-certified typically has evidence documents already on hand that are also usable for the duty of care — the work then lies in translating existing policies to align with the law's structure, not in rebuilding from scratch. Conversely: an organization following the law without certification often unknowingly builds much of an ISO 27001 management system anyway, only without the external audit and certificate. For businesses asked from the supply chain to demonstrate security — see the questionnaire a customer may impose — a certificate counts as external evidence, whereas an internal file without certification can be equally sound in substance, only harder for an outsider to verify.
Where this becomes clear: Article 21 compared with Annex A
The Dutch Cybersecurity Act, as the national implementation of the NIS2 Directive, nowhere refers to ISO 27001 as a mandatory standard; Article 21(2) describes the ten measures in its own terms, independent of any certification standard. ISO/IEC 27001 is a voluntary standard with its own structure, where Annex A provides a list of control measures that overlaps with what the law requires, but has no formal link to it. NCSC guidance on the duty of care confirms that what matters is demonstrable measures, not a mandatory certificate.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.