NIS2
NIS2 vs DORA vs ISO 27001: which ones apply to you
NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

Ask a boardroom which cybersecurity framework the company needs and you will usually hear a question back: “Is it NIS2, DORA, or ISO 27001?” It is the wrong question, asked in the wrong shape. These three are not items on a menu where you pick one. They sit on different layers, bind different populations, and in places explicitly reference each other — to the point where the law tells you to use the standard. For a mid-market company in France, Belgium or Luxembourg, the realistic answer is rarely “one of them.” It is “two of these, built on the third.”
The confusion is understandable. All three arrived or matured within the same eighteen-month window, all three talk about risk management, incident handling and third-party oversight, and all three are sold by consultancies as the thing you must do next. This is the single-page map that sorts them out: what each one is, who it binds, where they overlap, and which one wins when more than one applies.
The one distinction that resolves most of the confusion
Two of these are laws. One is a standard. That single line settles most arguments.
NIS2 and DORA are EU legislation — you do not choose to be in scope, the text decides for you, and non-compliance is an enforcement matter with fines and personal consequences. ISO 27001 is a voluntary international standard you elect to certify against. No regulator compels ISO 27001 certification. Your customers might, your insurer might, a tender might — but that is commercial pressure, not legal obligation.
The practical consequence: you can ignore ISO 27001 and break no law. You cannot “ignore” NIS2 or DORA if you are in scope — you can only be compliant or exposed. Everything else about these three regimes follows from this distinction.
Three regimes on three different layers: one voluntary standard, two mandatory laws, distinct populations.
NIS2, in one paragraph
NIS2 — Directive (EU) 2022/2555 — is the EU’s baseline cybersecurity law for organisations that matter to the functioning of the economy and society. It covers eighteen sectors, splitting in-scope organisations into “essential” and “important” entities, and generally catches medium-sized and larger organisations (broadly, 50+ staff or more than €10M turnover) in those sectors. Its core obligations are governance accountability at management-body level (Article 20), a set of ten baseline risk-management measures (Article 21), and incident reporting on a 24-hour / 72-hour / one-month cadence (Article 23). The catch in 2026 is uneven: because NIS2 is a directive, each member state transposes it into national law on its own timetable, and the dates now sit far apart. Belgium has been live since October 2024, and its essential entities on the certification route must hold CyberFundamentals or ISO/IEC 27001 certification by 18 April 2027. Germany’s law has applied since December 2025, Luxembourg’s since May 2026, the Netherlands’ since 15 August 2026, and Austria’s takes effect on 1 October 2026. France has still not transposed: the bill has not reached the floor of the Assemblée nationale, and on 8 July 2026 the Commission referred France — with Ireland, Spain and the Netherlands — to the Court of Justice. Being “not yet transposed” in your country is a timing reprieve, not an exemption — and our NIS2 readiness services exist precisely for the firms using that window well.
DORA, in one paragraph
DORA — Regulation (EU) 2022/2554 — is the EU’s digital operational resilience law for the financial sector, and only the financial sector. It has been fully applicable since 17 January 2025, with no national transposition because, as a regulation, it bites directly in every member state at once. It reaches far beyond banks: payment institutions, e-money firms, investment firms, asset managers, crypto-asset service providers and crowdfunding platforms are all caught, alongside the ICT suppliers that serve them. Its substance covers ICT risk management, incident reporting, resilience testing, and — most distinctively — third-party risk, including a mandatory Register of Information and direct EU oversight of critical providers. If DORA applies to you, it is not a future project: the European Supervisory Authorities designated the first 19 critical ICT third-party providers in November 2025, and national supervisors have moved from tolerance to active supervision in 2026 — and our DORA readiness services are built for firms that now have to prove resilience, not just plan for it.
ISO 27001, in one paragraph
ISO/IEC 27001 is the international standard for an Information Security Management System — a documented, audited, continuously improved way of managing security risk. Its 2022 revision is now the only valid version: every certificate issued against the older 2013 edition expired on 31 October 2025, so any organisation still citing “ISO 27001:2013” is, as of this year, citing an expired credential. The standard’s 93 Annex A controls are the practical vocabulary that both NIS2 and DORA borrow from. Certification is voluntary, but it is the most efficient scaffolding on which to build either regulatory programme — which is why our ISO 27001 readiness services are usually where a multi-regulation engagement starts.
Where they overlap — and which one wins
Here is where most explanations go wrong. The three regimes overlap heavily on substance — risk management, access control, encryption, logging, incident response, business continuity, supplier oversight all appear in each. If you have implemented ISO 27001 well, you have already done a large share of the technical and organisational work NIS2 and DORA demand.
But overlap on substance is not the same as interchangeability in law, and there is a precedence rule that financial firms in particular must understand. For a financial entity that would otherwise fall under both DORA and NIS2, DORA takes priority for ICT risk and resilience matters. This is the lex specialis principle: NIS2’s own Article 4 yields to sector-specific Union law where that law imposes at least equivalent requirements, NIS2’s Recital 28 names DORA as that sector-specific law for financial entities, and DORA says it of itself — Article 1(2), and Recital 16 in so many words: “lex specialis with regard to Directive (EU) 2022/2555”. In plain terms — a bank does not run two parallel ICT-risk regimes; it follows DORA. ISO 27001, being voluntary, never “wins” or “loses” this contest; it sits underneath both as the control framework you build once and point at whichever law binds you.
What none of this changes: ISO 27001 certification does not by itself make you NIS2- or DORA-compliant. The laws add specifics the standard does not — statutory incident-reporting deadlines, named management-body accountability, customer and threat notification, regulator-facing registers. Certification gets you most of the way on controls; it does not discharge a legal obligation. Which documents each of the three actually asks for, and why each one rejects them for a different reason, is the subject of our follow-up, One ISMS, three regulators: the same nine documents. We made a closely related point in You’re Not a Bank. DORA Still Applies.: a clean control environment is necessary, but it is not the same thing as proving compliance to a supervisor.
Which ones apply to you
A four-question test for which regimes apply to your organisation — most mid-market firms hit more than one.
The map collapses into four questions, in order.
First: are you a financial entity under DORA’s Article 2 — a payment firm, e-money institution, investment firm, asset manager, crypto-asset service provider or similar? If yes, DORA applies now, and it is your governing ICT-resilience regime. Second: are you in one of NIS2’s eighteen sectors, above the size threshold? If yes, NIS2 applies once your country’s transposing law is in force — unless DORA has already displaced it for you. Third: do enterprise customers, insurers or tenders demand a recognised certificate? If yes, ISO 27001 is effectively mandatory for commercial reasons even though no law requires it. Fourth: do you handle personal data at scale? Then GDPR sits across all of the above, and an ISO 27001 ISMS is the cleanest way to evidence the security obligations it imposes.
Most mid-market firms we assess answer “yes” to two or three of these. A Luxembourg fintech is squarely DORA, will likely pursue ISO 27001 for its enterprise pipeline, and carries GDPR throughout. A Belgian manufacturer is NIS2 and, increasingly, ISO 27001 because its customers audit it.
What to build once and reuse
The mistake that wastes the most money is treating these as three separate projects with three separate teams, three sets of policies and three audits. The smarter approach inverts it: build one Information Security Management System, using ISO 27001 as the backbone, then map the specific obligations of whichever laws bind you onto that single foundation. NIS2’s Article 21 measures and DORA’s ICT controls overlap with Annex A by a wide margin; you instrument the controls once and report against them in the format each regime requires. A board-level Virtual CISO engagement is the most efficient way to run that consolidation at mid-market scale, because the hard part is not the controls — it is the governance, the mapping, and the evidence.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.


