For management · without panic

NIS2 or ISO 27001: which to choose and who to hire

A client sent a questionnaire. Or you heard "we need NIS2". Or a competitor added an ISO 27001 badge. Now the real question is simple: where to start, and who to trust with it — so the money turns into a result, not a folder on a shelf.

The point in 30 seconds

NIS2 and ISO 27001 are not the same

A common mix-up: both are "about cybersecurity", so it looks like you must pick one. The reality is different — one is usually an obligation, the other a competitive advantage. And they overlap.

NIS2

An EU directive — often mandatory

  • Sets mandatory requirements for certain sectors.
  • Management is personally accountable — not just the IT team.
  • Reaches small companies through the supply chain: a large client passes requirements to its suppliers.
  • The question isn't "do we have documents", but "what can we show when asked".
ISO 27001

A voluntary standard — certifiable

  • An international standard you can formally certify.
  • The certificate is a sales tool: it wins tenders where words aren't enough.
  • Provable control, not a "we're fine" declaration.
  • A well-run ISO 27001 system covers a large part of NIS2 expectations.

In practice, for an SME it's rarely "either–or". The real question is usually: where to start, so the first step gives the most value for the lowest cost.

Where to start

A short path for management

1
If NIS2 applies or a client demands evidenceStart with a NIS2 readiness assessment. The first goal: know what you could show today if a client or regulator asked tomorrow. You can also start with a quick 2-minute self-check.
2
If you want a demonstrable, certifiable system for advantageStart with ISO 27001. The first step is the business case: will the certificate win deals, what scope, what realistic path.
3
If it's not yet clear which case is yoursJust write to me. We'll briefly go over your situation and I'll tell you which step you need first — without rushed investment.
How to choose

Which company or consultant to hire

This is the most common question — and the right one. After an audit or risk assessment, what matters is not the report itself but what stays in your hands. For a small or medium business, six things are worth checking:

Recognised qualifications, not just a pitchFor example ISO 27001 Lead Implementer and real implementation experience — not only theory or templates.
Speaks to management, not only ITRisk, accountability and decisions must be understandable beyond the IT team. If you only follow half — wrong fit.
A defined, concrete scopeA clear deliverable and price, not an open-ended monthly fee "for everything".
A result you can useA plan and documents you can show a client or auditor — not a risk list for the shelf.
Personal attention and discretionAn SME doesn't need a corporate machine. It needs someone who understands its reality.
A doer, not a fear-sellerA good sign: "I'll come in and make sure you have something to show" — not just "be afraid and hire us".
FAQ

Frequently asked

What is the difference between NIS2 and ISO 27001?

NIS2 is an EU directive with mandatory requirements for certain sectors and management accountability. ISO 27001 is a voluntary international standard you can certify and show to clients. NIS2 is often an obligation, ISO 27001 a competitive advantage. They overlap.

Is my company too small for this to apply?

Even if NIS2 doesn't apply directly, requirements reach you through the supply chain. A larger client passes them down via a questionnaire or contract — and "we're too small" stops working.

Do I have to choose only one?

No. The question is usually "where to start". A well-run ISO 27001 system covers a large part of NIS2 expectations, so the work doesn't duplicate.

How long and how much?

It depends on scope and your current state. That's why it's rational to start not with a big contract but with a short conversation — write to me, and we'll go over your situation and I'll estimate the real scope, no commitment.

A simple first step

Not sure where to start? That's normal — that's what I'm here for.

You don't need to decide upfront whether you need NIS2 or ISO 27001. Write a couple of sentences about your situation — your sector, and what triggered this (a client, a questionnaire, a tender, a regulator) — and I'll tell you which step you actually need first. No commitment, no sales pressure. And if talking is easier than writing — send me an email.

Delivered by Darius Jasiulionis — ISO 27001:2022 and ISO/IEC 42001 Lead Implementer. Real NIS2 implementations, an IT company assessment against an aviation client's questionnaire, and training. Remote work across the EU/EEA.

Cookie settings