ISO 27001 is the international standard for information security management. EU regulations — GDPR, NIS2, DORA, and the AI Act — each create their own security and compliance requirements. A common question: if you have ISO 27001, are you covered? And conversely: if you comply with EU regulations, do you still need ISO 27001?
The short answer: ISO 27001 and EU regulation compliance overlap significantly but are not substitutes for each other. Both have unique requirements that the other does not cover.
What ISO 27001 Covers
ISO 27001 is a management system standard. It specifies requirements for establishing, implementing, maintaining, and continuously improving an Information Security Management System (ISMS). The 2022 version (ISO 27001:2022) includes:
- Risk assessment and treatment for information security
- Security controls across 93 areas (Annex A)
- Management commitment and governance
- Asset management, access control, cryptography
- Physical security, operations security, communications security
- Supplier relationships
- Incident management
- Business continuity
- Compliance monitoring
ISO 27001 certification is issued by accredited certification bodies after an independent audit. The certification has a 3-year validity with annual surveillance audits.
GDPR and ISO 27001
Overlap: GDPR Article 32 requires "appropriate technical and organisational measures" for information security. ISO 27001 is widely accepted as evidence of appropriate security measures. An ISO 27001 certificate is a strong indicator of GDPR Article 32 compliance.
What ISO 27001 does NOT cover:
- Lawful basis for processing personal data
- Privacy notices and transparency obligations
- Data subject rights (access, erasure, portability)
- Records of Processing Activities (ROPA)
- Data Protection Impact Assessments (DPIAs)
- Sub-processor management under Article 28
- International transfer mechanisms (SCCs, DPF)
Conclusion: ISO 27001 helps significantly with GDPR Article 32 security requirements but does not address the privacy governance and rights dimensions of GDPR. You need both.
NIS2 and ISO 27001
NIS2 Article 21 specifies security risk management measures. ENISA guidance acknowledges that ISO 27001 aligns well with NIS2 requirements.
Overlap: Most of the NIS2 Article 21 technical measures are covered by ISO 27001:
- Multi-factor authentication: ISO 27001 Annex A 8.5
- Encryption: ISO 27001 Annex A 8.24
- Access control: ISO 27001 Annex A 8.2-8.5
- Vulnerability management: ISO 27001 Annex A 8.8
- Business continuity: ISO 27001 Annex A 5.29-5.30
- Supply chain security: ISO 27001 Annex A 5.19-5.22
What ISO 27001 does NOT cover (NIS2-specific):
- Mandatory registration with national NIS2 competent authority
- Specific incident reporting timelines: 24-hour early warning, 72-hour notification, 30-day final report — these are regulatory requirements not addressed in ISO 27001
- Board-level personal liability (NIS2 Article 20) — management training requirement
- National regulatory engagement obligations
Conclusion: ISO 27001 covers most of NIS2's technical requirements but does not substitute for NIS2-specific registration, incident reporting, and governance obligations.
DORA and ISO 27001
DORA applies to financial entities and has the most detailed and specific technical requirements of any EU regulation.
Overlap: ISO 27001 covers significant portions of DORA's ICT risk management framework requirements:
- Security policy
- Asset management
- Access control and privileged access
- Encryption
- Change management
- Incident management
What ISO 27001 does NOT cover (DORA-specific):
- Register of Information (ICT third-party risk register) — unique DORA requirement
- Specific DORA incident reporting: 4-hour initial notification with specific content requirements
- DORA resilience testing (TLPT) — threat-led penetration testing with specific scope and methodology
- Critical ICT third-party provider assessment framework
- Article 30 mandatory contract provisions — specific contractual requirements
- Regulatory submission and supervisory engagement
Conclusion: ISO 27001 helps significantly with DORA's technical requirements but financial entities cannot rely on ISO 27001 alone for DORA compliance.
EU AI Act and ISO 27001
ISO 27001 is almost entirely silent on AI system governance.
What ISO 27001 covers (partially):
- Third-party risk management (relevant for AI vendors and GPAI providers)
- Information classification (relevant for training data management)
- Change management (relevant for model updates)
What ISO 27001 does NOT cover:
- AI risk classification and risk-tiered requirements
- Technical documentation (Annex IV) for high-risk AI
- Conformity assessment
- Transparency and explainability obligations
- Human oversight requirements
- EU AI database registration
- Post-market monitoring
Conclusion: ISO 27001 is largely irrelevant for AI Act compliance. The AI Act is primarily about governance and transparency of AI systems, not general information security.
Do You Need Both?
Yes — for most regulated companies.
| Situation | ISO 27001 | EU regulation compliance |
|---|---|---|
| GDPR (security obligations only) | Strong evidence for Article 32 | Required for privacy governance |
| GDPR (full compliance) | Helpful | Required |
| NIS2 essential entity | Strongly recommended | Required |
| DORA financial entity | Helpful | Required |
| EU AI Act | Limited relevance | Required |
ISO 27001's main value beyond regulation:
- Market credibility — enterprise customers trust ISO 27001 certificates
- Audit rights — customers can satisfy audit rights by accepting the certificate in lieu of on-site audit
- Disciplined security programme — the certification process forces good security hygiene
EU regulation compliance beyond ISO 27001:
- Privacy governance (GDPR)
- Incident reporting timelines (NIS2, DORA)
- Regulatory registration
- Board-level governance and accountability
- Sector-specific technical requirements (DORA)