Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Two colleagues at a table with a laptop between them in a warmly lit office

NIS2 certification: it does not exist, and this is what counts instead

It is the most common question about NIS2 and the answer disappoints almost everyone: you cannot get certified for it. There is no mark, no certificate and no body that issues one. What there is, is an obligation you have to be able to demonstrate, and that is a different thing from a document on the wall.

5 min read Written by the ITproposal team
Short answer

There is no NIS2 certificate. NIS2 is a European directive transposed into national law in each member state, with a regulator behind it. Supervision is not certification: a regulator inspects, it does not hand out a mark.

People asking for "NIS2 certification" almost always mean one of three things: a completed supplier questionnaire, an ISO/IEC 27001 certificate, or evidence that the measures were already in place before the incident.

ISO 27001 comes closest and covers a good part of what NIS2 asks for, but it is not a substitute: the reporting deadlines and the personal accountability of the board are not in it.

Why there is no certificate

NIS2 is a directive, not a standard. That difference is the whole explanation. A standard such as ISO/IEC 27001 is maintained by a standards body, and an accredited organisation may assess whether you meet it and issue a certificate. A directive is transposed by member states into law, and law is supervised by a regulator.

In the Netherlands that transposition is the Cyberbeveiligingswet. It comes with a regulator that can request, inspect and enforce. What it does not come with is a register of certified companies, because there is nothing to enter into.

That is not a formality. It means you are never "finished" the way you are finished when an audit has been passed. There is no date on which it is done and no document you can show instead of showing how you work.

What does exist, and who is asking

The question rarely comes out of nowhere. There is usually a trigger, and the trigger decides what is really being asked.

Who asks, what they mean, and what you give them.
Who is askingWhat they meanWhat exists
A customer who is in scope"Show me you are not my supply chain risk"A completed supplier questionnaire, with evidence attached
A buyer in a tender"Tick the information security box"ISO/IEC 27001, or a reasoned description of the measures
The regulator"Show that the measures were in place"Risk analysis, incident log, logging and a board-level report
Your own board"Are we exposed"A baseline against the requirements, with an order and owners

In all four cases the answer is not a certificate. It is material. Anyone without that material ready finds out when a customer sends a questionnaire with a two-week deadline, and that is usually the first time a mid-sized company meets NIS2 at all.

ISO 27001: how close does it get

ISO/IEC 27001 is a real certification, with an accredited assessing party and a period of validity. It is also the standard that overlaps most with what NIS2 asks: risk management, access management, supplier management, continuity and keeping evidence.

Where it stops matters as much as where it overlaps:

  • The reporting duty is not in it. NIS2 asks for an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification and a final report. ISO 27001 asks you to handle incidents, not to report them to a regulator within a deadline.
  • The board stays personally accountable. That is a choice by the legislator and not part of a standard. A certificate does not take that accountability over.
  • The scope is yours. An ISO certificate applies to the scope you drew yourself. If the part that falls under NIS2 sits outside it, the certificate proves nothing about it.

In practice that makes ISO 27001 a good foundation and a poor finish line. If you already have it, you are a long way along. If you only want it because a customer said "NIS2", you are buying a months-long programme for a question that a questionnaire and some evidence would have answered.

What we do here, and what we do not

We do the side that has to do with technology and management: making sure the measures exist, that they are switched on, and that there is evidence of it an outsider can read. Access management, multi-factor authentication, patching, backup and restore, logging kept long enough to reconstruct an incident, and reporting a board understands without translation.

We hold ISO 9001 and ISO/IEC 27001 ourselves. That says something about how we work and nothing about how you meet the directive; it is not a certification you can inherit from us.

What we do not do: we are not an auditor and we certify no one. We do not determine whether your organisation is in scope, we do not approve a questionnaire and we issue no statement. That assessment belongs with a qualified, independent party, and the signature under a self-declaration is the entrepreneur’s own. Putting both roles with one supplier lets the party that builds the measures also judge whether they are enough.

Frequently asked

Questions we get about this

The four that come back most often.

Can we get certified for NIS2?

No. There is no NIS2 certificate, no mark and no body that issues one. NIS2 is a European directive transposed into national law in each member state (in the Netherlands the Cyberbeveiligingswet) and that comes with supervision, not certification. Anyone offering you "NIS2 certified" is selling something that does not exist. What you can do is make it demonstrable that the measures are in place, and record that in a way a customer or a regulator can read.

Our customer asks for a NIS2 certificate. What do we send?

Ask first what they actually need, because they almost never mean it literally. In most cases it is a completed supplier questionnaire with evidence: your risk analysis, your incident procedure, how access is arranged and how long you keep logging. If you hold ISO/IEC 27001, send the certificate with its scope, without the scope it says less than you think.

Is ISO 27001 enough to meet NIS2?

It helps a great deal but it is not enough. The overlap is in risk management, access management, supplier management and continuity. What is not in it is the reporting duty with its deadlines, and the personal accountability of the board. Also watch the scope of your certificate: if the part that falls under NIS2 is not in it, it proves nothing about that part.

Can you determine whether we fall under NIS2?

No, and that is a line we draw deliberately. We are not an auditor and we certify no one. We do the network, the workplace and the management, and make sure the evidence exists; whether your organisation is in scope and whether a self-declaration holds is a judgement that belongs with a qualified independent party, and one the board signs for itself.

Shall we look at what you already have?

Tell us which questionnaire came in or which customer asked. We will say what you can already demonstrate, what is missing and in which order that is quickest to put right.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. See our privacy policy.

Request a quote Call