{"id":8483,"date":"2026-04-16T12:04:25","date_gmt":"2026-04-16T10:04:25","guid":{"rendered":"https:\/\/www.bayoosoft.com\/?p=8483"},"modified":"2026-04-16T12:04:28","modified_gmt":"2026-04-16T10:04:28","slug":"nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements","status":"publish","type":"post","link":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/","title":{"rendered":"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left center;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:114px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-padding-left-medium:30px;--awb-padding-top-small:0px;--awb-padding-bottom-small:0px;--awb-padding-left-small:30px;--awb-margin-top:0px;--awb-margin-top-small:-30px;--awb-flex-wrap:wrap;\" ><div class=\"awb-background-mask\" style=\"background-image:  url(data:image\/svg+xml;utf8,%3Csvg%20width%3D%221920%22%20height%3D%22954%22%20fill%3D%22none%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cg%20clip-path%3D%22url%28%23prefix__clip0_58_109%29%22%20fill%3D%22rgba%2844%2C156%2C140%2C1%29%22%3E%3Cpath%20d%3D%22M1020.86%20519.766c6.47-11.566%2022.45-20.942%2035.71-20.942h375.02c30.93%200%2043.77%2021.877%2028.68%2048.863L1204.02%201006H749l271.86-486.234zM1755.66%20419.989c6.47-11.664%2022.45-21.12%2035.7-21.12h391.65c26.5%200%2037.5%2018.912%2024.57%2042.24L1923%20954h-463.62l296.28-534.011z%22%2F%3E%3Cpath%20d%3D%22M1371.86%20126.941c6.47-11.565%2022.46-20.941%2035.71-20.941h376.02c30.93%200%2043.77%2021.877%2028.68%2048.863L1371%20954H914.98l456.88-827.059z%22%2F%3E%3C%2Fg%3E%3Cdefs%3E%3CclipPath%20id%3D%22prefix__clip0_58_109%22%3E%3Cpath%20fill%3D%22%23fff%22%20d%3D%22M0%200h1920v954H0z%22%2F%3E%3C%2FclipPath%3E%3C%2Fdefs%3E%3C%2Fsvg%3E);opacity: 0.23 ;\"><\/div><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:calc( 1200px + 40px );margin-left: calc(-40px \/ 2 );margin-right: calc(-40px \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-left-small:0px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:20px;--awb-margin-bottom-large:0px;--awb-spacing-left-large:20px;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:20px;--awb-spacing-left-medium:20px;--awb-width-small:100%;--awb-order-small:0;--awb-margin-top-small:100px;--awb-spacing-right-small:20px;--awb-spacing-left-small:0px;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-one\" style=\"--awb-margin-top:-50px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h1 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:50;line-height:var(--awb-typography1-line-height);\"><h1><span style=\"color: var(--awb-color2)\">NIS2 and ISO 27001:<br \/>\n<\/span>How companies can make their ISMS fit for the new requirements<\/h1><\/h1><\/div><div class=\"fusion-text fusion-text-1\"><p>The NIS2 Implementation Act (NIS2UmsuCG) has been in force in Germany since December 6, 2025. Compliance and data protection officers who thought they were on the safe side with an existing ISO 27001 certification are now faced with an uncomfortable question: Is that really enough?<\/p>\n<p>The short answer is: No, not completely. The longer answer explains why a well-established ISMS in accordance with ISO 27001 is nevertheless the best starting point and where specific improvements are needed.<\/p>\n<p>&nbsp;<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-padding-bottom-small:25px;--awb-margin-top:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:60px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:3;--awb-margin-top-medium:0px;--awb-spacing-right-medium:0%;--awb-spacing-left-medium:0%;--awb-width-small:100%;--awb-order-small:2;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-margin-bottom-small:0px;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:-20px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\">What the NIS2 directive really requires of companies<\/h2><\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-text-color:var(--awb-color8);--awb-margin-top:;\"><p>The EU&#8217;s NIS2 Directive is not a recommendation, but applicable law. In the German NIS2 Implementation Act, Section 30 BSIG-neu specifies ten minimum measures for risk management that are directly based on Article 21 of the NIS2 Directive. These include concepts for risk analysis, incident response processes, business continuity management including backup strategies, supply chain security and the use of cryptographic procedures and multi-factor authentication.<\/p>\n<p>This is particularly important for compliance officers: The law expressly obliges management to implement and monitor these measures and can be held personally liable in the event of violations. Fines can amount to up to 10 million euros. In addition, &#8220;particularly important&#8221; and &#8220;important&#8221; institutions must register with the BSI. The corresponding portal has been activated since January 6, 2026.<\/p>\n<p>Significant security incidents must be reported within 24 hours, an extended report follows within 72 hours and a final report after one month. This is not a bureaucratic side issue, but an operational requirement that affects processes and documentation in equal measure.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-left-small:0px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:35px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:30px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:1;--awb-spacing-right-small:1.92%;--awb-margin-bottom-small:0px;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-3 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:-20px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>ISO 27001 as a foundation &#8211; but not a free pass<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-3\" style=\"--awb-margin-top:-20px;\"><p>Those who already operate an ISMS in accordance with ISO 27001 have a real head start. Both sets of rules follow a risk-based approach: identify, assess and treat risks and continuously review the effectiveness of the measures. The mapping between NIS2 Article 21 and the ISO 27001 controls is solid. Areas such as risk management, asset management, incident management, supply chain security and business continuity are well anchored in the ISO standard.<\/p>\n<p>Nevertheless, there are structural differences that should not be ignored. ISO 27001 is a voluntary, internationally recognized standard. NIS2 is binding EU law with sectoral requirements, specific reporting deadlines and state supervision by the BSI. While ISO 27001 allows exceptions with justification for certain controls, NIS2 leaves much less leeway. Many requirements are simply mandatory, regardless of the internal risk assessment.<\/p>\n<p>In short: a certified ISMS provides the structure. But it does not automatically cover the NIS2-specific obligations relating to reporting, registration and governance.<\/p>\n<\/div><div class=\"fusion-text fusion-text-4\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:30px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:5;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-4 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:-20px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>Where the gaps typically lie<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-5\" style=\"--awb-margin-top:-20px;\"><p>In practice, a GAP analysis between the existing ISO ISMS and NIS2 repeatedly reveals similar weaknesses. Three of them stand out in particular.<\/p>\n<\/div><ul style=\"--awb-iconcolor:var(--awb-color1);--awb-textcolor:var(--awb-color8);--awb-line-height:27.2px;--awb-icon-width:27.2px;--awb-icon-height:27.2px;--awb-icon-margin:11.2px;--awb-content-margin:38.4px;--awb-circlecolor:var(--awb-color4);--awb-circle-yes-font-size:14.08px;\" class=\"fusion-checklist fusion-checklist-1 fusion-checklist-default type-icons\"><li class=\"fusion-li-item\" style=\"\"><span class=\"icon-wrapper circle-yes\"><i class=\"fusion-li-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><div class=\"fusion-li-item-content\">\n<p><strong>Reporting processes and deadlines:<\/strong> ISO 27001 does not have any statutory reporting deadlines. However, the 24-hour initial notification in accordance with NIS2 requires established, testable processes and a clear assignment of responsibilities in the event of an incident. Anyone who tries to organize this ad hoc in an emergency will fail.<\/p>\n<\/div><\/li><li class=\"fusion-li-item\" style=\"\"><span class=\"icon-wrapper circle-yes\"><i class=\"fusion-li-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><div class=\"fusion-li-item-content\">\n<p><strong>Supply chain security with proof:<\/strong>NIS2 goes much further than ISO 27001 when it comes to the systematic auditing of IT service providers, cloud providers and other third parties. Contractual regulations on information security and reporting obligations, regular due diligence audits, proof of certifications in the supply chain &#8211; all of this must be documented and auditable.<\/p>\n<\/div><\/li><li class=\"fusion-li-item\" style=\"\"><span class=\"icon-wrapper circle-yes\"><i class=\"fusion-li-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><div class=\"fusion-li-item-content\">\n<p><strong>Management governance and evidence:<\/strong> NIS2 requires management to demonstrably fulfill its supervisory duties. Decisions, approvals, management reviews &#8211; all of this must not only take place, but must also be documented with a time stamp and audit trail.<\/p>\n<\/div><\/li><\/ul><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_2_3 2_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:20px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:5;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-5 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>From standard to proof: Why Excel is reaching its limits<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-6\" style=\"--awb-margin-top:-20px;\"><p>Many organizations start their NIS2 compliance journey exactly as they know it from the ISO 27001 implementation: with Excel lists, loose document collections and manually maintained mapping tables. This works to get started, but it doesn&#8217;t scale.<\/p>\n<p>As soon as risk registers, action statuses, supplier assessments, incident logs and management decisions live in different files and directories, versioning problems, responsibility gaps and a nightmare arise with every audit sprint. The BSI expects an &#8220;appropriate documented security level&#8221; &#8211; and that means: traceable, versioned, consistent.<\/p>\n<p>What authorities and auditors want to see is not a folder full of PDFs. It is a living register that shows which risks are known, which measures have been taken, who is responsible for them and when which decision was made. All in one consistent system, not spread across a dozen files.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_1_3 1_3 fusion-flex-column\" style=\"--awb-overflow:hidden;--awb-bg-size:cover;--awb-border-radius:12px 12px 12px 12px;--awb-width-large:33.333333333333%;--awb-margin-top-large:20px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio: 100 \/ 220;--awb-object-position:50% 50%;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none has-aspect-ratio\"><img decoding=\"async\" width=\"1366\" height=\"768\" alt=\"NIS2-und-ISO-27001-Themis\" title=\"SOFT_NIS2-und-ISO-27001-Themis_Absatz\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1.jpg\" class=\"img-responsive wp-image-8478 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1-200x112.jpg 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1-400x225.jpg 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1-600x337.jpg 600w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1-800x450.jpg 800w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1-1200x675.jpg 1200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Absatz-1.jpg 1366w\" sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-top:25px;--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:41px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:5;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-6 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:-50px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>How BAYOOSOFT supports Themis in this process<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-7\" style=\"--awb-margin-top:-20px;\"><p>If you want to use your ISMS in accordance with ISO 27001 as the basis for NIS2 compliance, you face a very specific challenge: the documentation must not only be available, it must be audit-ready. Standard requirements must be linked to actual processes, roles and responsibilities and this must be verifiable, versioned and retrievable at any time.<\/p>\n<p>This is precisely the approach of <b>BAYOOSOFT Themis<\/b>. As a process-led platform for QM and ISMS documentation, Themis closes the gap between the standard and the actual process. The integrated ISO 27001 guide links standard chapters directly with the company&#8217;s SOPs. Roles, responsibilities and approval steps are stored in a structured manner. A complete audit trail documents who decided or approved what and when, without having to manually search through various files.<\/p>\n<p>What this means for NIS2: If you set up and maintain your ISO 27001 ISMS in a structured way with Themis, you have the evidence base that auditors and &#8211; in the NIS2 context &#8211; authorities expect. No gaps between the standard chapter and the actual process, no outdated documents in loose folders, no audit sprint just before the deadline.<\/p>\n<p>Themis deliberately positions itself not as a scanner tool or pure document archive, but as a platform for procedural excellence: the discrepancy between the standard and actual practice is the greatest audit risk and this is precisely where Themis comes in.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-right:0px;--awb-padding-left:0px;--awb-flex-wrap:wrap;--awb-box-shadow: 0px 0px var(--awb-color8);\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-7 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-top:30px;--awb-padding-right:60px;--awb-padding-bottom:30px;--awb-padding-left:60px;--awb-overflow:hidden;--awb-bg-size:cover;--awb-box-shadow:0px 5px 17px 0px var(--awb-custom_color_1);;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-builder-row fusion-builder-row-inner fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"--awb-flex-grow:0;--awb-flex-grow-medium:0;--awb-flex-grow-small:0;--awb-flex-shrink:0;--awb-flex-shrink-medium:0;--awb-flex-shrink-small:0;width:104% !important;max-width:104% !important;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-0 fusion_builder_column_inner_2_3 2_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-text fusion-text-8 sm-text-align-center\" style=\"--awb-content-alignment:left;--awb-font-size:18px;--awb-line-height:var(--awb-typography2-line-height);--awb-letter-spacing:var(--awb-typography2-letter-spacing);--awb-text-transform:var(--awb-typography2-text-transform);--awb-text-color:var(--awb-custom_color_1);--awb-text-font-family:var(--awb-typography2-font-family);--awb-text-font-weight:var(--awb-typography2-font-weight);--awb-text-font-style:var(--awb-typography2-font-style);\"><p>This is how we support you<\/p>\n<\/div><div class=\"fusion-text fusion-text-9 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-text-color:var(--awb-color8);--awb-margin-bottom:25px;\"><p>Are you ready to take your quality management to the next level? Then we would be happy to show you how BAYOOSOFT Themis can support you with documentation, quality management and ISMS. As a validated platform for technical documentation and management systems in regulated industries, Themis combines the requirements of medical technology, pharmaceuticals and critical infrastructures with pragmatic, user-friendly solutions.<\/p>\n<\/div><div ><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" style=\"--button_accent_color:var(--awb-color1);--button_accent_hover_color:var(--awb-color1);--button_border_hover_color:var(--awb-color7);--button_border_width-top:1px;--button_border_width-right:1px;--button_border_width-bottom:1px;--button_border_width-left:1px;--button_gradient_top_color:var(--awb-color3);--button_gradient_bottom_color:var(--awb-color3);--button_gradient_top_color_hover:var(--awb-color7);--button_gradient_bottom_color_hover:var(--awb-color7);\" target=\"_self\" href=\"https:\/\/www.bayoosoft.com\/en\/product\/bayoosoft-themis\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Learn more<\/span><\/a><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-1 fusion_builder_column_inner_1_3 1_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio:1 \/ 1;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-2 hover-type-none has-aspect-ratio\"><img decoding=\"async\" width=\"300\" height=\"300\" alt=\"BAYOOSOFT Themis\" title=\"Themis\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/05\/Themis-300x300.png\" class=\"img-responsive wp-image-1697 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/05\/Themis-200x200.png 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/05\/Themis-400x400.png 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/05\/Themis.png 512w\" sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-4 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-8 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-7 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color4);--awb-margin-top:20px;--awb-margin-bottom:-20px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>Frequently asked questions about NIS2 and ISO-27001:<\/h2><\/h2><\/div><div class=\"accordian fusion-accordian\" style=\"--awb-border-size:1px;--awb-icon-size:30px;--awb-content-font-size:var(--awb-typography4-font-size);--awb-icon-alignment:left;--awb-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-border-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-background-color:var(--awb-color1);--awb-divider-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-divider-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-icon-color:var(--awb-color5);--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color8);--awb-icon-box-color:var(--awb-color7);--awb-toggle-hover-accent-color:var(--awb-color5);--awb-title-font-family:var(--awb-typography1-font-family);--awb-title-font-weight:var(--awb-typography1-font-weight);--awb-title-font-style:var(--awb-typography1-font-style);--awb-title-font-size:13pt;--awb-content-font-family:var(--awb-typography4-font-family);--awb-content-font-weight:var(--awb-typography4-font-weight);--awb-content-font-style:var(--awb-typography4-font-style);\"><div class=\"panel-group fusion-toggle-icon-unboxed\" id=\"accordion-8483-1\"><div class=\"fusion-panel panel-default panel-b9a1841ec6841b309 fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_b9a1841ec6841b309\"><a aria-expanded=\"false\" aria-controls=\"b9a1841ec6841b309\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#b9a1841ec6841b309\" href=\"#b9a1841ec6841b309\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Is ISO 27001 certification sufficient for NIS2 compliance? <\/span><\/a><\/h4><\/div><div id=\"b9a1841ec6841b309\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_b9a1841ec6841b309\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>No. ISO 27001 provides a very good basis, but does not automatically cover NIS2-specific obligations such as reporting obligations (24\/72 hours), BSI registration and sectoral governance requirements. A gap analysis is absolutely essential.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-2698cc8ad8b19adfd fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_2698cc8ad8b19adfd\"><a aria-expanded=\"false\" aria-controls=\"2698cc8ad8b19adfd\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#2698cc8ad8b19adfd\" href=\"#2698cc8ad8b19adfd\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Who is affected by the NIS2 Directive in Germany?<\/span><\/a><\/h4><\/div><div id=\"2698cc8ad8b19adfd\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_2698cc8ad8b19adfd\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>This affects &#8220;particularly important&#8221; and &#8220;important&#8221; institutions in sectors such as energy, healthcare, digital infrastructure, cloud services, public administration and others. The NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 6, 2025. For precise classification, we recommend checking the BSI sector list.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-93bf321dee036d88a fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_93bf321dee036d88a\"><a aria-expanded=\"false\" aria-controls=\"93bf321dee036d88a\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#93bf321dee036d88a\" href=\"#93bf321dee036d88a\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What are the reporting deadlines for security incidents under NIS2? <\/span><\/a><\/h4><\/div><div id=\"93bf321dee036d88a\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_93bf321dee036d88a\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Significant incidents must be reported within 24 hours, a detailed report follows within 72 hours and a final report after one month at the latest. (Source: Article 23 NIS2 Directive \/ \u00a7 32 BSIG-new)<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-dd286ba7d7b35386a fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_dd286ba7d7b35386a\"><a aria-expanded=\"false\" aria-controls=\"dd286ba7d7b35386a\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#dd286ba7d7b35386a\" href=\"#dd286ba7d7b35386a\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What are the consequences of violating NIS2? <\/span><\/a><\/h4><\/div><div id=\"dd286ba7d7b35386a\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_dd286ba7d7b35386a\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Fines can amount to up to 10 million euros or 2 percent of annual global turnover. In addition, the management can be held personally liable for gross breaches of duty.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-0ce557a44cfbed0f0 fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_0ce557a44cfbed0f0\"><a aria-expanded=\"false\" aria-controls=\"0ce557a44cfbed0f0\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#0ce557a44cfbed0f0\" href=\"#0ce557a44cfbed0f0\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">How to perform a mapping between NIS2 and ISO 27001? <\/span><\/a><\/h4><\/div><div id=\"0ce557a44cfbed0f0\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_0ce557a44cfbed0f0\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>The starting point is an identification of the relevant NIS2 requirements (Article 21 \/ \u00a7 30 BSIG-new), followed by a GAP analysis against the existing ISO-ISMS. Gaps are included in the catalog of measures, regularly reviewed and documented in the audit trail. Various providers make prepared mapping tables available (e.g. DataGuard, DQS, Proliance).<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-fab3680e7cd42d21b fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_fab3680e7cd42d21b\"><a aria-expanded=\"false\" aria-controls=\"fab3680e7cd42d21b\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8483-1\" data-target=\"#fab3680e7cd42d21b\" href=\"#fab3680e7cd42d21b\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Does the management have to be actively involved in NIS2? <\/span><\/a><\/h4><\/div><div id=\"fab3680e7cd42d21b\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_fab3680e7cd42d21b\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Yes, NIS2 and the German Implementation Act explicitly require management to approve, implement and monitor cybersecurity measures. Training for management bodies is also provided for.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":40,"featured_media":8481,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[39,47],"tags":[181,110,180,179,111,131],"job-standort":[],"job-bereich":[],"job-arbeitszeit":[],"job-gmbh":[],"class_list":["post-8483","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bayoosoft-themis-en","category-posts","tag-181","tag-bayoosoft-themis","tag-iso","tag-nis2","tag-technical-documentation","tag-themis"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>NIS2 and ISO 27001: Making ISMS fit for NIS2 requirements<\/title>\n<meta name=\"description\" content=\"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements\" \/>\n<meta property=\"og:description\" content=\"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/\" \/>\n<meta property=\"og:site_name\" content=\"BAYOOSOFT\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-16T10:04:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-16T10:04:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1366\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"benjaminossowski\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"benjaminossowski\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/\"},\"author\":{\"name\":\"benjaminossowski\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/1874a19c5cb71ac6d1e56017a9d4c802\"},\"headline\":\"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements\",\"datePublished\":\"2026-04-16T10:04:25+00:00\",\"dateModified\":\"2026-04-16T10:04:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/\"},\"wordCount\":7192,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/03\\\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg\",\"keywords\":[\"27001\",\"BAYOOSOFT Themis\",\"ISO\",\"NIS2\",\"Technical Documentation\",\"themis\"],\"articleSection\":[\"BAYOOSOFT Themis\",\"Posts\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/\",\"name\":\"NIS2 and ISO 27001: Making ISMS fit for NIS2 requirements\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/03\\\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg\",\"datePublished\":\"2026-04-16T10:04:25+00:00\",\"dateModified\":\"2026-04-16T10:04:28+00:00\",\"description\":\"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/03\\\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/03\\\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg\",\"width\":1366,\"height\":768,\"caption\":\"NIS2-und-ISO-27001-Themis\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-themis-en\\\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/www.bayoosoft.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/\",\"name\":\"BAYOOSOFT\",\"description\":\"L\u00f6sungen im Bereich IT-Security und Medical Solutions\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.bayoosoft.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#organization\",\"name\":\"BAYOOSOFT GmbH\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/01\\\/BAYOOSOFT_Logo_Plain.jpg\",\"contentUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/01\\\/BAYOOSOFT_Logo_Plain.jpg\",\"width\":746,\"height\":89,\"caption\":\"BAYOOSOFT GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/bayoosoft\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/1874a19c5cb71ac6d1e56017a9d4c802\",\"name\":\"benjaminossowski\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"caption\":\"benjaminossowski\"},\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"NIS2 and ISO 27001: Making ISMS fit for NIS2 requirements","description":"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/","og_locale":"en_US","og_type":"article","og_title":"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements","og_description":"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.","og_url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/","og_site_name":"BAYOOSOFT","article_published_time":"2026-04-16T10:04:25+00:00","article_modified_time":"2026-04-16T10:04:28+00:00","og_image":[{"width":1366,"height":768,"url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg","type":"image\/jpeg"}],"author":"benjaminossowski","twitter_card":"summary_large_image","twitter_misc":{"Written by":"benjaminossowski","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#article","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/"},"author":{"name":"benjaminossowski","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/1874a19c5cb71ac6d1e56017a9d4c802"},"headline":"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements","datePublished":"2026-04-16T10:04:25+00:00","dateModified":"2026-04-16T10:04:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/"},"wordCount":7192,"commentCount":0,"publisher":{"@id":"https:\/\/www.bayoosoft.com\/#organization"},"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg","keywords":["27001","BAYOOSOFT Themis","ISO","NIS2","Technical Documentation","themis"],"articleSection":["BAYOOSOFT Themis","Posts"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/","url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/","name":"NIS2 and ISO 27001: Making ISMS fit for NIS2 requirements","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#primaryimage"},"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg","datePublished":"2026-04-16T10:04:25+00:00","dateModified":"2026-04-16T10:04:28+00:00","description":"NIS2 directive meets ISO 27001 - what companies really need now, where the gaps are and how a system-supported ISMS can help.","breadcrumb":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#primaryimage","url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg","contentUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/03\/SOFT_NIS2-und-ISO-27001-Themis_Header1.jpg","width":1366,"height":768,"caption":"NIS2-und-ISO-27001-Themis"},{"@type":"BreadcrumbList","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-themis-en\/nis2-and-iso-27001-how-companies-can-make-their-isms-fit-for-the-new-requirements\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.bayoosoft.com\/"},{"@type":"ListItem","position":2,"name":"NIS2 and ISO 27001: How companies can make their ISMS fit for the new requirements"}]},{"@type":"WebSite","@id":"https:\/\/www.bayoosoft.com\/#website","url":"https:\/\/www.bayoosoft.com\/","name":"BAYOOSOFT","description":"L\u00f6sungen im Bereich IT-Security und Medical Solutions","publisher":{"@id":"https:\/\/www.bayoosoft.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bayoosoft.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.bayoosoft.com\/#organization","name":"BAYOOSOFT GmbH","url":"https:\/\/www.bayoosoft.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/01\/BAYOOSOFT_Logo_Plain.jpg","contentUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/01\/BAYOOSOFT_Logo_Plain.jpg","width":746,"height":89,"caption":"BAYOOSOFT GmbH"},"image":{"@id":"https:\/\/www.bayoosoft.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/bayoosoft\/"]},{"@type":"Person","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/1874a19c5cb71ac6d1e56017a9d4c802","name":"benjaminossowski","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","caption":"benjaminossowski"},"url":"https:\/\/www.bayoosoft.com\/en"}]}},"_links":{"self":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8483","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/comments?post=8483"}],"version-history":[{"count":3,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8483\/revisions"}],"predecessor-version":[{"id":8897,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8483\/revisions\/8897"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media\/8481"}],"wp:attachment":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media?parent=8483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/categories?post=8483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/tags?post=8483"},{"taxonomy":"job-standort","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-standort?post=8483"},{"taxonomy":"job-bereich","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-bereich?post=8483"},{"taxonomy":"job-arbeitszeit","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-arbeitszeit?post=8483"},{"taxonomy":"job-gmbh","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-gmbh?post=8483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}