
NIS2 certification: it does not exist, and this is what counts instead
It is the most common question about NIS2 and the answer disappoints almost everyone: you cannot get certified for it. There is no mark, no certificate and no body that issues one. What there is, is an obligation you have to be able to demonstrate, and that is a different thing from a document on the wall.
There is no NIS2 certificate. NIS2 is a European directive transposed into national law in each member state, with a regulator behind it. Supervision is not certification: a regulator inspects, it does not hand out a mark.
People asking for "NIS2 certification" almost always mean one of three things: a completed supplier questionnaire, an ISO/IEC 27001 certificate, or evidence that the measures were already in place before the incident.
ISO 27001 comes closest and covers a good part of what NIS2 asks for, but it is not a substitute: the reporting deadlines and the personal accountability of the board are not in it.
Why there is no certificate
NIS2 is a directive, not a standard. That difference is the whole explanation. A standard such as ISO/IEC 27001 is maintained by a standards body, and an accredited organisation may assess whether you meet it and issue a certificate. A directive is transposed by member states into law, and law is supervised by a regulator.
In the Netherlands that transposition is the Cyberbeveiligingswet. It comes with a regulator that can request, inspect and enforce. What it does not come with is a register of certified companies, because there is nothing to enter into.
That is not a formality. It means you are never "finished" the way you are finished when an audit has been passed. There is no date on which it is done and no document you can show instead of showing how you work.
What does exist, and who is asking
The question rarely comes out of nowhere. There is usually a trigger, and the trigger decides what is really being asked.
| Who is asking | What they mean | What exists |
|---|---|---|
| A customer who is in scope | "Show me you are not my supply chain risk" | A completed supplier questionnaire, with evidence attached |
| A buyer in a tender | "Tick the information security box" | ISO/IEC 27001, or a reasoned description of the measures |
| The regulator | "Show that the measures were in place" | Risk analysis, incident log, logging and a board-level report |
| Your own board | "Are we exposed" | A baseline against the requirements, with an order and owners |
In all four cases the answer is not a certificate. It is material. Anyone without that material ready finds out when a customer sends a questionnaire with a two-week deadline, and that is usually the first time a mid-sized company meets NIS2 at all.
ISO 27001: how close does it get
ISO/IEC 27001 is a real certification, with an accredited assessing party and a period of validity. It is also the standard that overlaps most with what NIS2 asks: risk management, access management, supplier management, continuity and keeping evidence.
Where it stops matters as much as where it overlaps:
- The reporting duty is not in it. NIS2 asks for an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification and a final report. ISO 27001 asks you to handle incidents, not to report them to a regulator within a deadline.
- The board stays personally accountable. That is a choice by the legislator and not part of a standard. A certificate does not take that accountability over.
- The scope is yours. An ISO certificate applies to the scope you drew yourself. If the part that falls under NIS2 sits outside it, the certificate proves nothing about it.
In practice that makes ISO 27001 a good foundation and a poor finish line. If you already have it, you are a long way along. If you only want it because a customer said "NIS2", you are buying a months-long programme for a question that a questionnaire and some evidence would have answered.
What we do here, and what we do not
We do the side that has to do with technology and management: making sure the measures exist, that they are switched on, and that there is evidence of it an outsider can read. Access management, multi-factor authentication, patching, backup and restore, logging kept long enough to reconstruct an incident, and reporting a board understands without translation.
We hold ISO 9001 and ISO/IEC 27001 ourselves. That says something about how we work and nothing about how you meet the directive; it is not a certification you can inherit from us.
What we do not do: we are not an auditor and we certify no one. We do not determine whether your organisation is in scope, we do not approve a questionnaire and we issue no statement. That assessment belongs with a qualified, independent party, and the signature under a self-declaration is the entrepreneur’s own. Putting both roles with one supplier lets the party that builds the measures also judge whether they are enough.
Questions we get about this
The four that come back most often.
Can we get certified for NIS2?
No. There is no NIS2 certificate, no mark and no body that issues one. NIS2 is a European directive transposed into national law in each member state (in the Netherlands the Cyberbeveiligingswet) and that comes with supervision, not certification. Anyone offering you "NIS2 certified" is selling something that does not exist. What you can do is make it demonstrable that the measures are in place, and record that in a way a customer or a regulator can read.
Our customer asks for a NIS2 certificate. What do we send?
Ask first what they actually need, because they almost never mean it literally. In most cases it is a completed supplier questionnaire with evidence: your risk analysis, your incident procedure, how access is arranged and how long you keep logging. If you hold ISO/IEC 27001, send the certificate with its scope, without the scope it says less than you think.
Is ISO 27001 enough to meet NIS2?
It helps a great deal but it is not enough. The overlap is in risk management, access management, supplier management and continuity. What is not in it is the reporting duty with its deadlines, and the personal accountability of the board. Also watch the scope of your certificate: if the part that falls under NIS2 is not in it, it proves nothing about that part.
Can you determine whether we fall under NIS2?
No, and that is a line we draw deliberately. We are not an auditor and we certify no one. We do the network, the workplace and the management, and make sure the evidence exists; whether your organisation is in scope and whether a self-declaration holds is a judgement that belongs with a qualified independent party, and one the board signs for itself.
Further reading
What this connects to.
Shall we look at what you already have?
Tell us which questionnaire came in or which customer asked. We will say what you can already demonstrate, what is missing and in which order that is quickest to put right.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.