ISO 27001 → NIS2 crosswalk
A control-by-control mapping between ISO/IEC 27001:2022 and NIS2 Directive (EU 2022/2555). 8 mappings.
| ISO 27001 | NIS2 | Relationship | Notes |
|---|---|---|---|
| A.5.1 Policies for information security | Art. 21(2)(a) Risk analysis and information system security policies | RelatedCurated | Gouvernance et politique de sécurité |
| A.5.15 Access control | Art. 21(2)(i) Access control and asset management | PartialCurated | Contrôle d'accès et identité |
| A.5.16 Identity management | Art. 21(2)(i) Access control and asset management | PartialCurated | Contrôle d'accès et identité |
| A.5.24 Information security incident management planning and preparation | Art. 21(2)(b) Incident handling | PartialCurated | Réponse aux incidents et notification des violations |
| A.5.24 Information security incident management planning and preparation | Art. 23 Reporting obligations | PartialCurated | Réponse aux incidents et notification des violations |
| A.5.26 Response to information security incidents | Art. 21(2)(b) Incident handling | PartialCurated | Réponse aux incidents et notification des violations |
| A.5.26 Response to information security incidents | Art. 23 Reporting obligations | PartialCurated | Réponse aux incidents et notification des violations |
| A.8.24 Use of cryptography | Art. 21(2)(h) Cryptography and encryption | EquivalentCurated | Cryptographie et protection des données |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.