How should we prioritize NIS2 readiness when we already have ISO 27001 certification?

0
3
Asked By MellowCedar42 On

We recently came into scope for NIS2, and with the October deadline approaching, I'm trying to decide how to focus our remaining effort. We already hold ISO 27001 certification, so many areas—such as access control, audit logging, supplier management, and our Statement of Applicability—provide a useful foundation. However, NIS2 appears to require more operational evidence than our ISMS currently produces, particularly around supply-chain security and incident reporting.

The biggest gap is incident response. Our ISO process was not designed around NIS2's more prescriptive 24-hour early-warning and 72-hour notification timelines, so we need to confirm that we can detect, escalate, document, and report an incident within those windows. Supplier assurance is another concern: while we have a documented supplier-management process, smaller vendors may have reasonable security practices without the formal evidence needed to demonstrate them quickly.

Our strongest existing evidence concerns credentials and privileged access. Shared and administrative accounts are stored in a password vault that can export per-user access logs, giving us records of who could access which systems and when. However, those records are only reliable if our joiner-mover-leaver process is accurate, and that process has been inconsistent enough that I want to improve it before relying heavily on the logs.

I'm deciding between making a smaller set of controls genuinely audit-ready while documenting remediation timelines for the rest, or spreading our effort across more requirements with less depth. I'm leaning toward the first approach, but I haven't been assessed against NIS2 before. How would you prioritize the work, and how much credit should we expect ISO 27001 to provide?

5 Answers

Answered By QuietLantern64 On

The exact expectations vary by member state, and some countries recognize existing certifications or map them to national cybersecurity frameworks more directly than others. Confirm which authority you report to, whether your organization has any sector-specific rules, and whether ISO 27001 can be used as formal evidence or only as supporting documentation. A focused independent gap assessment could help turn the remaining work into a defensible prioritized plan.

Answered By VioletKite88 On

Treat the 24-hour early warning and 72-hour notification requirements as urgent, even if you otherwise use a risk-based plan. Update the incident-response procedure, assign clear decision-makers and alternates, define the information required at each stage, and run a tabletop exercise. That is the area most likely to expose a real operational weakness rather than just a documentation gap.

Answered By NorthHarbor7 On

Your instinct is sound: prioritize a smaller number of areas that you can actually demonstrate and defend, rather than creating shallow documentation for everything. ISO 27001 gives you a useful governance and evidence base, but it does not automatically prove that every NIS2 obligation is being met. The regulator and implementation details in your country will matter, so it is worth checking the applicable national framework or having an experienced assessor perform a gap review.

Answered By SilverMaple5 On

The access logs are useful, but first validate the process that feeds them. Reconcile current employees and contractors against vault access, review privileged accounts, test a recent joiner and leaver, and confirm that movers lose permissions that no longer match their role. That gives you stronger evidence than simply exporting a log and assuming it is complete.

Answered By BriskOak31 On

Start supplier evidence requests now instead of waiting until the deadline is close. Ask vendors for practical proof such as security certifications, independent assessments, incident-notification commitments, vulnerability-management information, and relevant contractual assurances. For smaller suppliers that cannot provide formal reports, document a proportionate risk assessment, the compensating controls, and a remediation deadline rather than leaving the gap unexplained.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.