“Act Now: From SRA to ISO/IEC 27001, A Smarter Path to NIS 2 Compliance”
Daniella Vendramini
Cyber Risk & Compliance Consultancy Services Team Lead
ISO/IEC 27001:2022 Lead Auditor
🡪 Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (December 14, 2022)
Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information security across the Union” (“NIS”)
🡪 NIS 2 replaces the old NIS and came into effect on October 18, 2024
The NIS 2 Directive could become for cybersecurity what the EU GDPR has become for privacy: a worldwide standard that other countries use as a best practice for their own legislation.
What is the old NIS, and how is NIS 2 different?
NIS 1:
Cybersecurity for critical infrastructure
NIS 2:
Same level of cybersecurity across all Member States
A wider and deep pool of entities
Better cooperation between the Member States
New timelines for reporting incidents
More focus on supply chains
The responsibility on the top management of entities
Stricter penalties
Why is NIS 2 important?
It sets very strict cybersecurity requirements for many companies in European Union.
+ 100,000 companies in the EU will have to become NIS 2 compliant!
You can find the official text here: https://eur-lex.europa.eu/eli/dir/2022/2555
NIS 2 Directive: The New Reality
Annex I: Sectors of high criticality
Annex II: Other critical sectors
Drinking water
Wastewater
Space
ICT service management
Public administration
Digital infrastructures (including ISP and cloud)
Energy
Transport
Financial market institutions
Banking
Health
Waste management
Food production & distribution
Postal & courier services
Manufacture, production and distribution of chemicals
Digital providers
Manufacturing
Research
“Essential entities” are as follows:
“Essential entities”
“Important entities”
NEW SECTORS
DORA PRIORITY
NIS 1 SECTORS
NIS2 makes provision to impose administrative fines for infringements
A maximum of at least 10,000,000 EUR or up to 2% of the total worldwide annual turnover of the undertaking to which the ESSENTIAL ENTITY belongs in the preceding financial year, whichever is higher.
A maximum of at least 7,000,000 EUR or 1,4% of the total worldwide annual turnover of the undertaking to which the IMPORTANT ENTITY belongs in the preceding financial year, whichever is higher.
NIS 2 Directive Overview
*For financial market infrastructures, the Digital Operational Resilience Act (DORA) will take priority.
Annex I: Sectors of high criticality
Annex II: Other critical sectors
Drinking water
Wastewater
Space
ICT service management
Public administration
Digital infrastructures (including ISP and cloud)
Energy
Transport
Financial market institutions
Banking
Health
Waste management
Food production & distribution
Postal & courier services
Manufacture, production and distribution of chemicals
Digital providers
Manufacturing
Research
“Essential entities” are as follows:
“Essential entities”
“Important entities”
NEW SECTORS
DORA PRIORITY
NIS 1 SECTORS
NIS2 makes provision to impose administrative fines for infringements
A maximum of at least 10,000,000 EUR or up to 2% of the total worldwide annual turnover of the undertaking to which the ESSENTIAL ENTITY belongs in the preceding financial year, whichever is higher.
A maximum of at least 7,000,000 EUR or 1,4% of the total worldwide annual turnover of the undertaking to which the IMPORTANT ENTITY belongs in the preceding financial year, whichever is higher.
NIS 2 Directive Overview
*For financial market infrastructures, the Digital Operational Resilience Act (DORA) will take priority.
Not enough time…
NIS 2 Framework – Article 1
Responsibilities of the Member States
Cybersecurity Strategies (Government) Reporting Obligations
Competent Authorities for Crisis Management, Contact Points for Communication and for CSIRTs Role
Exchange of Cybersecurity Information
Supervisory and Enforcement Obligations
Responsibilities of the Entities
Management Commitment
Managing Cyber Security Risks
Reporting Obligations
Source: L_2022333EN.01008001.xml
The Most Important NIS 2 Requirements for Entities
Chapter I — General provisions
Chapter II — Coordinated cybersecurity frameworks
Chapter III — Cooperation at union and international level
Chapter IV — Cybersecurity risk-management measures and reporting obligations
Article 20 - Governance
Article 21 - Cybersecurity risk-management measures
Article 22 - Union level coordinated security risk assessments of critical supply chains
Article 23 - Reporting obligations
Article 24 - Use of European cybersecurity certification schemes
Article 25 - Standardisation
Chapter V — Jurisdiction and registration
Chapter VI — Information sharing
Chapter VII — Supervision and enforcement
Chapter VIII — Delegated and implementing acts
Chapter IX — Final provisions
Annex I — Sectors of high criticality
Annex II — Other critical sectors
Annex III — Correlation table between NIS 2 and NIS
NIS 2 Cybersecurity & Reporting Obligations
🡪 Articles 20, 21, 23: Governance, Cybersecurity risk-management measures, Reporting obligations
Reporting Obligations
Cybersecurity Obligations
Member States can add extra local rules on top of NIS 2 through national legislative transposition
01
08
02
07
03
06
04
05
02. Importance of Training
According to Article 20, top management must complete and approve regular cybersecurity training covering risks and security practices.
01. Responsibilities of Senior Management
According to Article 20, senior management must approve and oversee cybersecurity measures and can be held liable if they are not properly implemented.
0.4 Cybersecurity Measures
According to Article 21, companies must apply technical, operational, and organizational measures to manage risks and reduce impacts.
03. Risk-Based Approach to Cybersecurity
According to Article 21, cybersecurity measures must match the level of risk, considering factors such as expousure, company size, incident likelihood and severity and economic impact.
07. Using Certified IT Products and Services
The NIS 2 directive does not require certification but allows authorities to demand the use of certified IT products and services, which may become mandatory in the future.
08. Fines
According to Article 34, non-compliance may lead to fines up to €10 million or 2% of turnover for essential entities, and €7 million or 1.4% for important ones.
0.5 Supply Chain Security
According to Article 21, companies must manage supply chain risks by addressing supplier vulnerabilities, ensuring product quality, and securing development processes.
06. Reporting of Significant Incidents
According to Article 23, companies must report significant incidents to CSIRTs through early warnings, incident notifications, and follow-up reports. A final report is due within one month, plus updates if needed.
Most Important Cybersecurity & Reporting Requirements in NIS 2
06. Reporting of Significant Incidents
🡪 NIS 2 Chapter IV, Article 23 – Reporting obligations
(6) ‘incident’ means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;
(a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned;
(b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
Source: NCSC: NIS2, NCSC: CSIRT-IE
To report only ‘significant’ incidents to the CSIRT or competent authority and to affected recipients through:
EARLY WARNING
Is it a suspected malicious act with potential cross-border impacts?
OFFICIAL INCIDENT NOTIFICATION
Assessment of the incident, severity and impact, plus indicators of compromise.
INTERMEDIATE STATUS REPORT
At the resquest of CSIRT or relevant competent authority.
FINAL REPORT
Or if incident ongoing at time of final report a progress report and final report 1 month after end.
Once you implement all cybersecurity measures required by NIS2, you will significantly lower the chances of an incident, especially for significant incidents.
Hope for the best; prepare for the worst.
Once you implement all cybersecurity measures required by NIS 2, you will significantly lower the chances of an incident, especially for significant incidents.
If your institution is asked to comply with NIS 2, where do you start?
I don’t like the sound of all that…
Am I in Scope of the Directive?
NIS 2 Transposition Tracker
Last update: 15 October 2025
November 2025 – NIS 2 not yet in national law (NCSB still legislative process); EU infringement procedure ongoing; NCSC provide draft guidance + FAQs; NIS 1 still apply until NCSB pass
The Irish Approach: NCSC RMM & CyFun*
Draft law
National Cyber Security Act 2025?
Entities in scope should prepare by ensuring they have appropriate governance controls & readiness measures in place.
Source: NCSC: NIS2, DECC
Organisations can use various frameworks, like ISO 27001, COBIT, NIST or their own Information Security Management System to meet these requirements.
Certification or self-assessment under CyFun is optional
“CyFun is one recognised way to organise and evidence your controls, not a statutory presumption of compliance”
The Role of CyFun in Ireland’s Compliance Framework:
“Perform a Risk Assessment” to Select your Assurance Level (CyFun Selection)
Complete your Self-Assessment, and Implement Corrective Actions/ Measures
Submit your responses to an authorised CAB for a Conformity Assessment
Request your label on the national website/ portal of
your country
*The Cybersecurity Fundamentals Framework
NIS 2 in Ireland - Key Takeaways
CyFun® for NIS 2 in
Ireland
CyFun® for NIS 2 in
Belgium
Ireland
Belgium
15 Implementation Steps for NIS 2 Cyber Risk Measures
01. Obtain Senior Management Support
02. Set up Project Management
03. Perform Initial Training
04. Write a Top-Level Policy on Information System Security
05. Define the Risk Management Methodology
06. Perform Risk Assessment and Treatment
07. Write and Approve the Risk Treatment Plan
08. Implement Cybersecurity Measures
09. Set up Supply Chain Security
10. Set up the Assessment of Cybersecurity Effectiveness
11. Set up Incident Reporting
12. Set up Continual Cybersecurity Training
13. Conduct Periodic Internal Audits
14. Conduct Periodic Management Review
15. Execute Corrective Actions
“All these best practices are applicable for both essential and important entities”
15 Implementation Steps for NIS 2 Cyber Risk Measures
01. Obtain Senior Management Support
02. Set up Project Management
03. Perform Initial Training
04. Write a Top-Level Policy on Information System Security
05. Define the Risk Management Methodology
06. Perform Risk Assessment and Treatment
07. Write and Approve the Risk Treatment Plan
08. Implement Cybersecurity Measures
09. Set up Supply Chain Security
10. Set up the Assessment of Cybersecurity Effectiveness
11. Set up Incident Reporting
12. Set up Continual Cybersecurity Training
13. Conduct Periodic Internal Audits
14. Conduct Periodic Management Review
15. Execute Corrective Actions
12 of 15 steps can be implemented using ISO 27001.
Processes
Output
Stakeholders’ Expectations and Wishes
Contracts
Goals, Mission, Vision and Values of the Organisation
Managed Information Security According to Objectives
Input
Plan
Do
Check
Act
Managed Information Security According to Objectives
Confidentiality
Integrity
Availability
ISO Information Security Management System s)
Processes
Output
Stakeholders’ Expectations and Wishes
Contracts
Goals, Mission, Vision and Values of the Organisation
Managed Information Security According to Objectives
Input
Plan
Do
Check
Act
Managed Information Security According to Objectives
Confidentiality
Integrity
Availability
ACTIVITIES THAT ARE CONTINUOUSLY ASSESSED AND IMPROVED
Controls
ISO Information Security Management System s)
Mapping ISO 27001 with NIS 2 Relevant Articles
Article 20
Management Commitment
Article 21
Cybersecurity Measures
Article 23
Incident Reporting
Completely map ISO 27001 Clauses/ Controls
One exception about Crisis Management
Since NIS 2 Article 23 “Reporting obligations” mandates very specific reporting requirements, the fact is that they cannot be addressed using ISO 27001.
🡪 Relevant Articles for companies that need to become compliant
Out of 26 cybersecurity requirements specified by NIS 2, ISO 27001 can address 25 of them; only Crisis Management is not really covered by the standard.
Request the complete version from us: ictsecurityservices@heanet.ie
Request the complete version from us: ictsecurityservices@heanet.ie
Request the complete version from us: ictsecurityservices@heanet.ie
Cybersecurity Risk Management Policy
Cybersecurity Governance and Oversight Policy
Security Awareness and Training Policy
Information Security Policy
Incident Management Policy
Business Continuity Policy
Backup Policy
Supplier Risk Management Policy
Change Management Policy
Secure Development Lifecycle (SDLC) Policy
Cyber Hygiene Guidelines
Cryptography Policy
NDAs and Confidentiality Agreements
Access Control Policy
Asset Management Policy
Authentication Policy
Information Transfer Policy
Communication Security Policy
Policy Review and Development (ictsecurityservices@heanet.ie)
If your company is compliant with ISO 27001, then the best thing is really to do a gap analysis and see what documents you are missing. You must also slightly adapt these existing documents so that they have references to NIS 2. And basically, this would be it. | If you are not compliant with ISO 27001, keep in mind that this standard is not a legal requirement of NIS 2. However, adopting ISO 27001 can simplify and accelerate compliance, since many controls align directly with NIS 2. It also brings extra benefits like stronger security, better governance and more trust. |
“To be or not to be… ISO Certified”
Key Benefits of ISO/IEC 27001
1. Demonstrates external validation of your security practices; building credibility and trust
2. Aligns all departments under a single framework, ensuring shared responsibility.
3. Provides a structured way to identify and address the most significant security risks.
4. Turns policies into action; closing gaps and enabling proactive risk management.
5. Demonstrates governance, reducing organisational risk and insurance costs.
5 Reasons IT Managers Say “Yes” to ISO 27001
1. Accountability & Trust
2. One Security Standard
3. Clear IT Security Risk Focus
4. Stronger Policies and Actions
5. Lower Cyber Insurance Premiums
Confidentiality Assurance
Secure data Exchange
Regulatory Compliance
Data Protection
Competitive Advantage
Enhanced Trust
Consistent Delivery
Risk Reduction
Security Culture
Organisational Protection
Strong Internal Processes
Continual Improvement
Global Compliance
Lower Costs
Vulnerability Detection
Build Security. Inspire Trust – Together for the Future
🡪 Supporting education and research through practical security and compliance services.
NIS 2 Readiness Self-Assessment
🡪 Scan to access our excusive NIS 2 Self Assessment tool
Get a high-level view of your institution’s compliance NIS 2 Directive through a quick self-assessment form.
Security & Risk Assessment
🡪 Schedule your SRA with us (Security Consultancy Services)
Receive a clear snapshot of your security posture based on best practices, including ISO 27001 and NIS 2.
Policy Review & Development
🡪 Request the creation, review, or adoption of policies
Ensure your policies are aligned with your needs, NIS 2 requirements, and industry best practices.
Schedule with us: ictsecurityservices@heanet.ie
THANK YOU
Daniella Vendramini