Skip to content

ISO 27001NIS2 crosswalk

A control-by-control mapping between ISO/IEC 27001:2022 and NIS2 Directive (EU 2022/2555). 8 mappings.

ISO 27001NIS2RelationshipNotes
A.5.1
Policies for information security
Art. 21(2)(a)
Risk analysis and information system security policies
RelatedCurated
Governance & security policy
A.5.15
Access control
Art. 21(2)(i)
Access control and asset management
PartialCurated
Access control & identity
A.5.16
Identity management
Art. 21(2)(i)
Access control and asset management
PartialCurated
Access control & identity
A.5.24
Information security incident management planning and preparation
Art. 21(2)(b)
Incident handling
PartialCurated
Incident response & breach notification
A.5.24
Information security incident management planning and preparation
Art. 23
Reporting obligations
PartialCurated
Incident response & breach notification
A.5.26
Response to information security incidents
Art. 21(2)(b)
Incident handling
PartialCurated
Incident response & breach notification
A.5.26
Response to information security incidents
Art. 23
Reporting obligations
PartialCurated
Incident response & breach notification
A.8.24
Use of cryptography
Art. 21(2)(h)
Cryptography and encryption
EquivalentCurated
Cryptography & data protection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.