NIS2 or ISO 27001: which to choose and who to hire
A client sent a questionnaire. Or you heard "we need NIS2". Or a competitor added an ISO 27001 badge. Now the real question is simple: where to start, and who to trust with it — so the money turns into a result, not a folder on a shelf.
NIS2 and ISO 27001 are not the same
A common mix-up: both are "about cybersecurity", so it looks like you must pick one. The reality is different — one is usually an obligation, the other a competitive advantage. And they overlap.
An EU directive — often mandatory
- Sets mandatory requirements for certain sectors.
- Management is personally accountable — not just the IT team.
- Reaches small companies through the supply chain: a large client passes requirements to its suppliers.
- The question isn't "do we have documents", but "what can we show when asked".
A voluntary standard — certifiable
- An international standard you can formally certify.
- The certificate is a sales tool: it wins tenders where words aren't enough.
- Provable control, not a "we're fine" declaration.
- A well-run ISO 27001 system covers a large part of NIS2 expectations.
In practice, for an SME it's rarely "either–or". The real question is usually: where to start, so the first step gives the most value for the lowest cost.
A short path for management
Which company or consultant to hire
This is the most common question — and the right one. After an audit or risk assessment, what matters is not the report itself but what stays in your hands. For a small or medium business, six things are worth checking:
Frequently asked
What is the difference between NIS2 and ISO 27001?
NIS2 is an EU directive with mandatory requirements for certain sectors and management accountability. ISO 27001 is a voluntary international standard you can certify and show to clients. NIS2 is often an obligation, ISO 27001 a competitive advantage. They overlap.
Is my company too small for this to apply?
Even if NIS2 doesn't apply directly, requirements reach you through the supply chain. A larger client passes them down via a questionnaire or contract — and "we're too small" stops working.
Do I have to choose only one?
No. The question is usually "where to start". A well-run ISO 27001 system covers a large part of NIS2 expectations, so the work doesn't duplicate.
How long and how much?
It depends on scope and your current state. That's why it's rational to start not with a big contract but with a short conversation — write to me, and we'll go over your situation and I'll estimate the real scope, no commitment.
Not sure where to start? That's normal — that's what I'm here for.
You don't need to decide upfront whether you need NIS2 or ISO 27001. Write a couple of sentences about your situation — your sector, and what triggered this (a client, a questionnaire, a tender, a regulator) — and I'll tell you which step you actually need first. No commitment, no sales pressure. And if talking is easier than writing — send me an email.
Delivered by Darius Jasiulionis — ISO 27001:2022 and ISO/IEC 42001 Lead Implementer. Real NIS2 implementations, an IT company assessment against an aviation client's questionnaire, and training. Remote work across the EU/EEA.