Many companies that fall under NIS 2 already run a management system certified to ISO/IEC 27001:2022, or are building one. The question that reaches the leadership team is always the same: how much work is left? This guide answers it from the official texts: D.Lgs. 138/2024, the determination of Italy's National Cybersecurity Agency (ACN, Agenzia per la Cybersicurezza Nazionale) on the baseline measures, and ENISA's technical guidance.
In brief
- None of the reference official texts treats ISO 27001 certification as a presumption of NIS 2 compliance: not D.Lgs. 138/2024, not ACN determination 379907/2025, not ENISA's technical guidance.
- The management system already covers most of the method: risk assessment and treatment, policies, roles, internal audit, management review and improvement.
- NIS 2 adds obligations the standard does not have: registration on the ACN platform, the accountability of the management bodies, and notification of significant incidents to CSIRT Italia within 24 hours, 72 hours and one month.
- The ACN baseline measures set specific requirements (management body approvals, review intervals, minimum plan contents) that must be checked one by one, even where an ISO control already exists.
- One management system is the better route, with its scope extended to the systems relevant to NIS 2 and a mapping that links each ACN requirement to the control and the evidence that meets it.
What ISO 27001 certification already covers
ISO/IEC 27001 sets the requirements for an information security management system, the ISMS (ISO/IEC 27001:2022). Clauses 4 to 10 describe the system: context and scope, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists the controls, grouped in four themes: organizational, people, physical and technological.
For a company entering NIS 2 this is a real head start. Article 24 of D.Lgs. 138/2024 requires appropriate and proportionate technical, operational and organizational measures, and lists their minimum areas. They run from risk analysis to incident handling, and from business continuity to the supply chain. Then come secure development, assessment of effectiveness, training, cryptography, access control and multi-factor authentication (D.Lgs. 138/2024, art. 24). Almost every area already has one or more matching controls in Annex A.
The structure of the ACN measures is also familiar to anyone who works with frameworks. ACN determination no. 379907 of 19 December 2025 describes them as developed in line with the Italian national framework and organized in functions, categories, subcategories and requirements (ACN determination 379907/2025, art. 1). The six functions carry the same codes as NIST CSF 2.0: GV (govern), ID (identify), PR (protect), DE (detect), RS (respond) and RC (recover). For a wider comparison of the schemes, see our guide to cybersecurity frameworks compared.
ENISA's technical guidance on Commission Implementing Regulation (EU) 2024/2690 links each requirement to ISO/IEC 27001:2022 in a mapping table (ENISA, Technical implementation guidance, June 2025). Regulation 2024/2690 binds only some digital entities, including DNS, cloud, data centre, managed service and managed security service providers. For everyone else the guidance is a reference for method, not an obligation.
What NIS 2 adds: the obligations the standard does not have
ISO/IEC 27001 is voluntary and leaves the choice of scope and controls to the organization. NIS 2 is a legal obligation, with addressees, deadlines and a supervisory authority. Five differences matter more than the rest.
Registration on the ACN platform
From 1 January to 28 February each year, entities in scope register, or update their registration, on ACN's digital platform. They give at least their company name, contact details and a point of contact. Entities notified of their inclusion in, or continued presence on, the list then provide further data from 15 April to 31 May, such as public IP addresses and domain names. Any change must be reported within fourteen days (D.Lgs. 138/2024, art. 7). No certification audit checks these steps.
Accountability of the management bodies
Clause 5 of ISO/IEC 27001 asks for top management commitment. Article 23 of D.Lgs. 138/2024 goes further: the management bodies approve how the article 24 measures are implemented, oversee their implementation and are responsible for breaches of the decree. They must take cybersecurity training, promote regular training for employees and be kept informed of incidents and notifications (D.Lgs. 138/2024, art. 23).
The baseline measures turn these rules into specific approvals. The management bodies approve (ACN determination 379907/2025, Annex 1):
- the security policies (GV.PO-01);
- the risk assessment (ID.RA-05);
- the treatment plan, including acceptance of residual risks (ID.RA-06);
- the training plan (PR.AT-01) and the remediation plan (ID.IM-01);
- the continuity, disaster recovery and crisis management plans (ID.IM-04);
- the incident management plan (RS.MA-01).
Under ISO/IEC 27001 the treatment plan and residual risks are approved by the risk owners (clause 6.1.3), who in many companies are not the board. The detail is in our guide to article 23 obligations for management bodies.
Incident notification to CSIRT Italia
Annex A controls A.5.24 to A.5.28 cover incident management, but set no recipient and no deadline towards an authority. Article 25 does: entities notify CSIRT Italia, without undue delay, of every incident with a significant impact on the provision of their services, in this sequence (D.Lgs. 138/2024, art. 25):
- early warning within 24 hours of becoming aware of the significant incident;
- incident notification within 72 hours, with an initial assessment of severity and impact and, where available, the indicators of compromise;
- intermediate report, if CSIRT Italia requests one;
- final report within one month of the notification; if the incident is still ongoing, monthly progress reports and a final report within one month of its closure.
The baseline measures require a plan for incident management and notification to CSIRT Italia, approved by the management bodies and reviewed at least every two years (RS.MA-01). The cybersecurity organization includes the point of contact, the CSIRT contact person and their deputies (GV.RR-02). Which incidents count as significant is set by Annexes 3 and 4 of the same determination, separately for important and essential entities. Timing and content are explained in our guide to incident notification under article 25.
The ACN baseline measures and their evidence
With determination 379907/2025, which replaced determination 164179/2025 from 15 January 2026, ACN set the baseline security measures: 37 for important entities (Annex 1) and 43 for essential entities (Annex 2). Each measure is broken down into specific requirements: minimum document contents, review intervals, approvals (ACN, baseline specifications). Some examples that a certified ISMS does not guarantee on its own:
- documented policies for at least sixteen areas, reviewed at least once a year (GV.PO-01, GV.PO-02);
- a risk assessment repeated at least every two years and after a significant incident (ID.RA-05);
- an up-to-date list of the relevant network and information systems (GV.OC-04);
- multi-factor authentication at least on the relevant systems, based on the risk assessment (PR.AA-03);
- defined and documented expected service levels, also to detect significant incidents in time (DE.CM-01).
The deadlines run from the notice of inclusion in the list: nine months for the notification obligation and eighteen months for the measures (ACN determination 379907/2025, art. 3). For entities added to the list for the first time in 2026, the ACN determination of 13 April 2026 applies: notification from 1 January 2027, measures by 31 July 2027 (ACN determination 127434/2026). The differences between the two categories are in our guide to essential and important entities in the baseline specifications. A first reading of the obligations is in our article on the baseline measures set by ACN.
Supply chain
Annex A covers suppliers in controls A.5.19 to A.5.23. NIS 2 requires entities to take into account the specific vulnerabilities of each direct supplier, the overall quality of its products and its secure development practices (art. 24, paragraph 3). The baseline measures say what to document (GV.SC-01, GV.SC-04, GV.SC-05, GV.SC-07):
- an inventory of suppliers with a potential impact on security, with the contact person and the type of supply;
- security requirements in requests for quotation, tenders, contracts and agreements;
- a risk assessment of each supply covering at least access to systems, access to data and intellectual property, the impact of a disruption, recovery time and cost, and the supplier's role;
- periodic, documented checks that supplies meet the requirements.
The cybersecurity organization must be involved in purchasing from the design of the supply onwards (GV.SC-01).
Control mapping
The table links ISO/IEC 27001 clauses and Annex A themes to the obligations of D.Lgs. 138/2024 and to the ACN baseline measures of Annex 1; the prefix of each code gives the function. Where available, the ISO references follow ENISA's mapping table (ENISA, mapping table version 1.2). ENISA states that its mapping is not a measure of equivalence between standards and does not assess whether a control fully covers a requirement: it shows where to look, not whether the requirement is met.
| ISO/IEC 27001:2022 | D.Lgs. 138/2024 | ACN baseline measures | What to check |
|---|---|---|---|
| Clause 4, context and scope (4.3) | Art. 24, paragraph 1 | GV.OC-04 | The certified scope includes every network and information system relevant to the NIS activities and services |
| Clause 5, leadership, policy and roles; A.5.1 to A.5.4 | Art. 23, paragraph 1 | GV.RR-02, GV.PO-01, GV.PO-02 | Policies on the sixteen areas approved by the management bodies; point of contact and CSIRT contact person in the organization; review at least yearly |
| Clause 6, risk assessment and treatment (6.1.2, 6.1.3) | Art. 24, paragraph 2, letter a) | GV.RM-03, ID.RA-05, ID.RA-06 | Assessment at least every two years, approved by the management bodies; treatment plan and residual risks approved by the management bodies |
| Clause 7, competence and awareness (7.2, 7.3); A.6.3 | Art. 23, paragraph 2; art. 24, paragraph 2, letter g) | PR.AT-01 | Training plan that includes the management bodies and is approved by them; register of trained staff |
| A.5.19 to A.5.23, suppliers | Art. 24, paragraph 2, letter d), and paragraph 3 | GV.SC-01, GV.SC-02, GV.SC-04, GV.SC-05, GV.SC-07, ID.AM-04 | Supplier inventory, contract clauses, risk assessment per supply, periodic checks |
| A.5.9, inventory; A.8.8, vulnerabilities | Art. 24, paragraph 2, letters e) and i) | ID.AM-01, ID.AM-02, ID.RA-01, ID.RA-08 | Hardware, software and service inventories; a process to receive and handle vulnerability disclosures |
| A.5.15 to A.5.18, A.8.2, A.8.5, access and authentication | Art. 24, paragraph 2, letters i) and l) | PR.AA-01, PR.AA-03, PR.AA-05, PR.AA-06 | Multi-factor authentication on the relevant systems, according to the risk assessment |
| A.8.13, backup; A.8.24, cryptography; A.8.15 and A.8.16, logging and monitoring | Art. 24, paragraph 2, letters c) and h) | PR.DS-01, PR.DS-02, PR.DS-11, PR.PS-04, DE.CM-01, DE.CM-09 | Documented expected service levels; detection tools on the relevant systems |
| A.8.20 to A.8.22, networks; A.8.25 to A.8.28, secure development | Art. 24, paragraph 2, letter e) | PR.IR-01, PR.PS-02, PR.PS-06 | Network protection, software maintained according to risk, secure development practices |
| A.5.24 to A.5.28, A.6.8, incidents | Art. 25 | RS.MA-01, RS.CO-02, RC.RP-01 | Incident management and CSIRT Italia notification plan approved by the management bodies; procedures for early warning, notification and reports |
| A.5.29 and A.5.30, continuity | Art. 24, paragraph 2, letter c) | ID.IM-04 | Continuity, disaster recovery and crisis management plans approved by the management bodies, reviewed at least every two years |
| Clauses 9 and 10, internal audit, management review and improvement | Art. 24, paragraph 2, letter f), and paragraph 4 | GV.PO-02, ID.IM-01 | Check that policies comply with the law; remediation plan approved by the management bodies, with periodic reports to them |
| No matching clause | Art. 7 | No measure: it is a platform obligation | Annual registration, data updates, changes reported within fourteen days |
Essential entities apply Annex 2, which adds six measures: ID.AM-03, PR.AT-02, PR.PS-01, PR.PS-03, PR.IR-03 and RC.CO-03 (ACN determination 379907/2025, Annex 2).
Where certification helps as evidence and where it does not
D.Lgs. 138/2024 contains no provision that gives ISO 27001 certification the value of a presumption of compliance. Article 27 allows ACN to require ICT products, services and processes certified under European cybersecurity certification schemes, provided for by Regulation (EU) 2019/881: that is a different thing from certifying a management system (art. 27). Article 28 asks ACN to promote European and international technical specifications, without naming any standard (art. 28). ENISA, too, writes that implementing its guidance partly or in full does not in itself mean compliance with the regulation.
The certificate is still a solid starting point, if you know where to use it.
Where it helps. The risk register, the statement of applicability, management review minutes, internal audit reports and corrective actions are already dated, versioned documents. Many ACN requirements ask for exactly that: a defined, documented and reviewed process. An Annex A control already in place is often the basis of the evidence for the matching measure.
Where it falls short.
- Scope. The certificate applies to the declared scope, which may leave out sites, services or systems relevant to NIS 2.
- Approvals. Where a measure requires approval by the management bodies, the signature of a risk owner or of the ISMS manager does not replace it.
- Intervals and minimum contents. The standard leaves review frequency to the organization; the ACN measures set it, for example every year for policies and every two years for the risk assessment.
- Obligations towards the authority. Registration, platform updates and notifications to CSIRT Italia are outside the certification audit.
- Exclusions. A control excluded in the statement of applicability may correspond to a mandatory measure. For some requirements, if they are not implemented for justified and documented legal or technical reasons, compensating measures must be described in the treatment plan (ID.RA-06).
If you are still building the system or preparing for ISO 27001 certification, it pays to draw the scope around the systems relevant to NIS 2 from the start.
UNI/PdR 174:2025: the Italian bridge between the two
The reference practice UNI/PdR 174:2025 has been in force since 30 April 2025. It sets the requirements for a cybersecurity and information security management system, harmonized with UNI CEI EN ISO/IEC 27001 and with NIST CSF 2.0 (UNI catalogue). ACN, which supported its development, presents it as a way to extend a system already certified to ISO/IEC 27001 towards the NIST CSF controls linked to the NIS baseline measures. The document can be downloaded from the UNI website after registration (ACN, 15 May 2025). Neither UNI nor ACN presents it as a presumption of compliance. We covered it in our article on UNI/PdR 174:2025 for ISO 27001 certified NIS entities.
Where to start: a three-step path
- Align the scope. Start from the list of relevant network and information systems required by GV.OC-04 and compare it with the scope of the certificate. If the NIS perimeter is wider, extend the ISMS rather than opening a second system.
- Map requirement by requirement. Take the annex for your category, Annex 1 for important entities and Annex 2 for essential ones. For each requirement record the ISO control, the document that serves as evidence, who approved it and when it was last reviewed. The empty rows become the remediation plan required by ID.IM-01.
- Add what the standard does not cover. Registration and updates on the ACN platform, the CSIRT contact person, notification procedures within the article 25 deadlines, training and approvals by the management bodies. Then add the ACN measures to the internal audit programme, so that one cycle covers both certification and NIS 2.
If you want to start from your ISMS without doing the work twice, we support you on NIS 2 compliance, from reading the requirements to the remediation plan.