NexGenio
Home Academy Insights Contact

Every NIS2 requirement, mapped to eleven frameworks

All 49 requirements of the NIS2 implementing regulation, set against ISO/IEC 27001:2022, NIST CSF 2.0, ETSI EN 319 401, CEN/TS 18026 and the national frameworks of Belgium, Finland, Greece, Spain and France — reproduced from ENISA's own published mapping. Plus two columns of ours that ENISA does not have: ISA/IEC 62443 for operational technology, and ISO 22301 for business continuity.

49 requirements 9 ENISA frameworks + ISA/IEC 62443 for OT + ISO 22301 for continuity Free, no signup
Open the mapping The two columns that are ours
In brief

Does ISO 27001 cover NIS2?

Largely, but not completely — and the useful answer is not a percentage, it is a list. ISO/IEC 27001:2022 addresses the substance of most NIS2 cybersecurity risk-management requirements, and an existing ISMS produces much of the evidence a supervisor will ask for. On the mapping below, 69 of the 93 Annex A controls are referenced against at least one NIS2 requirement.

What ISO 27001 does not give you is the part NIS2 adds on top of security management: the duty to register with your national authority, the 24-hour / 72-hour / one-month incident reporting cascade to a CSIRT, and the personal accountability and training duty Article 20 places on your management body. No ISMS control satisfies those, because they are not security controls — they are legal obligations owed to a regulator. Those are set out below.

ISO 27001 is one of 9 frameworks ENISA correlated. The same 49 requirements are also set against NIST CSF 2.0, ETSI EN 319 401 for trust service providers, CEN/TS 18026, and the national frameworks of Belgium, Finland, Greece, Spain and France. Every column is on this page and you can switch between them in the table — useful if you report into a US parent on NIST, or supply the Spanish public sector under the ENS.

Two things ENISA's table does not have, which we added: an ISA/IEC 62443 column for the OT sectors, and an ISO 22301 column for business continuity. The second matters more than it sounds. Article 21(2)(c) is business continuity and crisis management, and ENISA correlates it to no continuity standard at all — section 4 of the regulation ends up resting on three ISO 27001 controls. ISO 22301 answers it with the whole of clause 8, business impact analysis included.

The nine-framework mapping itself is ENISA's. We have reproduced it faithfully, added the ISO control names, added the Article 21(2) linkage, built the reverse index, and noted the handful of transcription artefacts in the original file. Our two columns are marked ours wherever they appear.

Provenance

Where this mapping comes from

49
requirements in the Annex to Implementing Regulation (EU) 2024/2690
9
frameworks correlated in ENISA's table, all reproduced here
69/93
ISO 27001:2022 Annex A controls referenced at least once
v1.1
ENISA mapping table version, dated 10 July 2025

The source is a regulator, not a consultancy

On 26 June 2025 ENISA published its Technical Implementation Guidance on Commission Implementing Regulation (EU) 2024/2690 — the act that turns the ten headline measures of NIS2 Article 21(2) into 49 concrete requirements. Alongside it ENISA published a mapping table correlating each of those requirements with European, international and national standards and frameworks. Version 1.1 followed on 10 July 2025.

That table is a spreadsheet, and as far as we can find nobody has put all of it on the web. This page is it — every column, every row, with each requirement addressable by its own link.

ENISA is explicit about what the table is not, and that caveat governs everything below:

“The mapping table should not be interpreted as a measure of equivalency among different standards or frameworks. It simply refers to relevant requirements in these standards or frameworks without assessing whether these fully cover the requirements of the regulation.”

It is also advisory rather than binding, and Member States remain free to determine their own approach to supervision. Read it as a navigation aid between documents, not as a compliance claim. Download ENISA's original spreadsheet.

The 9 frameworks in the table

ENISA's column headings, expanded. Four are standards and specifications; five are national frameworks from Member States that have published their own. The last two cards are ours, not ENISA's.

ISO/IEC 27001:2022
The international information security management system standard. ENISA maps to both the management-system clauses and the Annex A controls.
NIST Cybersecurity Framework 2.0
The US National Institute of Standards and Technology framework, organised into the Govern, Identify, Protect, Detect, Respond and Recover functions.
ETSI EN 319 401 V3.1.1 (2024-06)
General policy requirements for trust service providers — directly relevant if you are a qualified or non-qualified TSP under eIDAS.
CEN/TS 18026:2024
A European technical specification published by CEN, referenced by ENISA alongside the international standards.
Belgium — CyberFundamentals (CyFun®)
The framework of the Centre for Cybersecurity Belgium, given a defined role in the Belgian NIS2 transposition. Its BASIC, IMPORTANT and ESSENTIAL assurance levels are shown as ENISA printed them.
Finland — Kybermittari (Cybermeter)
A maturity model from NCSC-FI, built on the Cybersecurity Capability Maturity Model and the NIST framework, used alongside Traficom's national recommendation.
Greece — Ministerial Decision 1689/2025
The Greek national framework of cybersecurity requirements for essential and important entities, together with the Cybersecurity Handbook and the national self-assessment tool.
Spain — ENS, Royal Decree 311/2022
The Esquema Nacional de Seguridad. Mandatory across the Spanish public sector and for the systems private companies use to serve it, which pulls a large supplier population into scope.
France
ENISA heads this column simply “FR” and its annex on national frameworks carries no France entry, so the underlying document is not named in the source. Identifiers carry -IE and -EE suffixes, denoting important entity and essential entity.
ISA/IEC 62443 ours
The OT and industrial control systems series. ENISA does not map to it and no standards body has published a NIS2 to 62443 crosswalk, so this column is NexGenio original work rather than a reproduction. Its derivation is set out below.
ISO 22301:2019 ours
The business continuity management system standard. ENISA maps no continuity standard at all, which leaves the whole of NIS2 section 4 resting on three ISO 27001 controls. This column is NexGenio original work. Its derivation is set out below.

Two things a German or French reader will notice

France has a column but no description. ENISA heads it “FR” and its own annex on national frameworks carries no France entry, so the source document is never named. The identifiers carry -IE and -EE suffixes, which distinguish important entities from essential entities. We have reproduced the references and declined to guess at the document behind them.

Germany has a description but no column. ENISA's annex points to the BSI's state-of-the-art advisory, but no German references appear in the mapping table itself. If you are working to the German transposition, the ISO column is the one that will serve you here.

One scope caveat worth reading before you use this

Implementing Regulation (EU) 2024/2690 is directly binding on a defined subset of NIS2 entities — broadly the digital ones: DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service and managed security service providers, online marketplaces, online search engines, social networking platforms, and trust service providers.

If you are a hospital, a port, a water utility or a manufacturer, the regulation does not bind you directly. It remains the most detailed articulation the Commission has published of what Article 21(2) actually asks for, and national authorities and auditors read it that way. Treat it as the best available reading of the standard of care, and check your own national implementing law for what is legally operative in your case.

The mapping

All 49 requirements, across 9 ENISA frameworks plus 62443 and 22301

Grouped by the thirteen sections of the Annex, each tagged with the Article 21(2) point it implements. The buttons below are live — tick the frameworks you want and the rest are hidden. ISO 27001, NIST and our two columns are on by default; every column is still in the page, so nothing is lost by switching one off. Each requirement has its own anchor link, so you can cite a single row.

Show columns:

1Policy on the security of network and information systemsArt. 21(2)(a)

1.1 Policy on the security of network and information systems 21(2)(a)

A written, management-approved security policy with objectives, scope and roles, reviewed on a set cycle.

NIST CSF 2.0
PR.AT-02 GV.PO-01 GV.PO-02 GV.OC-03 GV.RM-03 GV.OC-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ 6.1-02 REQ 6.1-06 REQ 6.1-07 REQ 6.1-08 Clause 6.3
CEN/TS 18026
ISP-01 ISP-02 OPS-01 OPS-02 OPS-03
Belgium
BASICID.GV-1.1
IMPORTANTID.GV-1.2 PR.IP-5.1 PR.IP-6.1 PR.PT-2.1 PR.AT-4.1
ESSENTIALPR.PT-3.3 PR.PT-4.3
Finland
WORKFORCE-3 PROGRAM-1 PROGRAM-2 Management activities CRITICAL-2 ARCHITECTURE-1
Greece
Ministerial decision 1689/2025articles 6a 6b 6c
Cybersecurity handbookPart A: 2 Part B: 1.1 1.5 2.1 3.1 4.1 5.1 6.1 7.1 8.1 9.1 10.1 11.1 12.1 13.1 14.1 15.1 16.1 17.1 18.1
Self assessment tool1.7 1.8 1.9 1.10 1.11 1.12 1.13 2.1 2.2 3.1 4.1 5.1 6.1 7.1 8.1 9.1 10.1 11.1 12.1 13.1 14.1 15.1 16.1 17.1 18.1 19.1
Spain
Article 5 Article 6 Article 10 Article 12 Article 27
Annex II[org.1] Security policy [org.2] Security regulations [org.3] Security procedures
France
2.B.1-IE/EE
2.B.2-IE/EE
2.B.3-IE/EE
2.B.4-IE/EE
2.B.5-IE/EE
2.C.1-IE/EE
2.C.2-IE/EE
2.C.3-IE/EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
62443-3-2ZCR 7 Asset owner approval
22301 ours
Clauses5.2 Policy 4.3 Determining the scope of the BCMS
1.2 Roles, responsibilities and authorities 21(2)(a)

Named owners for security duties, with the authority and the reporting line to discharge them.

NIST CSF 2.0
GV.RR-02 GV.SC-02 PR.AT-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.1.2-01 REQ-7.2-01X REQ-7.2-03X REQ 7.2-07X REQ 7.2-08X REQ 7.2-09X REQ 7.2-10X REQ 7.2-11X REQ 7.2-12X REQ 7.2-13X REQ-7.2-14X REQ-7.2-15X
CEN/TS 18026
ISP-02 OIS-02
Belgium
BASICRS.RP-1.1
IMPORTANTID.AM-6.1 PR.AT-2.1 PR.AT-4.1 PR.AT-5.1 RS.CO-1.1
Finland
PROGRAM-1 PROGRAM-2 CRITICAL-2 WORKFORCE-2 WORKFORCE-3
Greece
Ministerial decision 1689/2025articles 7a 7b 7c
Cybersecurity handbookPart A: 2 Part B: 1.1 2.1 3.1 4.1 5.1 6.1 7.1 8.1 9.1 10.1 11.1 12.1 13.1 14.1 15.1 16.1 17.1 18.1
Self assessment tool1.1 1.2 1.3 1.4 1.5
Spain
Article 11 Article 13
Annex II[org.1] Security policy
France
2.A.1-IE/EE
2.A.2-EE
2.A.3-IE/EE
2.B.2-IE/EE
4.3-EE
4.4-IE/EE
4.5-IE/EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
22301 ours
Clauses5.3 Roles, responsibilities and authorities

2Risk management policyArt. 21(2)(a)

2.1 Risk management framework 21(2)(a)

A repeatable method for identifying, assessing and treating risk, with a treatment plan management signs off.

ISO 27001
Clauses6.1 Actions to address risks and opportunities 6.1.2 Information security risk assessment 6.1.3 Information security risk treatment 6.2 Information security objectives and planning to achieve them 8.2 Information security risk assessment 8.3 Information security risk treatment
NIST CSF 2.0
ID.RA-01 ID.RA-02 ID.RA-03 ID.RA-04 ID.RA-05 ID.RA-06 GV.RM-03 ID.RM-01 GV.RM-06 GV.RR-03 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 5 Clause 6.3
CEN/TS 18026
OIS-01 RM-01 RM-02 RM-03
Belgium
BASICID.GV-4.1 ID.RA-5.1
IMPORTANTID.BE-4.1 ID.GV-4.2 ID.RA-5.2 ID.RA-6.1 ID.RM-1.1 ID.RM-2.1 ID.RM-3.1 ID.SC-2.1 ID.SC-3.1 PR.AC-7.1 DE.CM-6.2 RS.MI-1.1
ESSENTIALID.RA-5.3 ID.SC-1.1 PR.AC-1.5 DE.AE-4.1
Finland
CRITICAL-2 RISK-1 RISK-2 RISK-3 RISK-4 RISK-5 THIRD-PARTIES-2 WORKFORCE-3 WORKFORCE-4
Greece
Ministerial decision 1689/2025articles 5.1a 5.1b 5.1c 5.1d 5.2
Cybersecurity HandbookPart A: 2
Self assessment tool1.15 1.16 1.17 1.18 1.19
Spain
Article 7 Article 14
Annex II[op.pl.1] Risk analysis [op.mon.2] Metrics system [op.ext.3] Protection of the supply chain
France
3.A.IE/EE
16.1-EE
16.2-EE
16.3-EE
16.4-EE
20.2-EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies ORG 2 Security assessments and reviews
62443-3-2ZCR 1 Identify the SUC ZCR 2 Initial risk assessment ZCR 3 Partition into zones and conduits ZCR 4 Detailed risk assessment ZCR 5 Document the cybersecurity requirements ZCR 7 Asset owner approval
22301 ours
Clauses6.1 Actions to address risks and opportunities 6.2 Business continuity objectives and planning to achieve them 8.2 Business impact analysis and risk assessment
2.2 Compliance monitoring 21(2)(a)

Evidence that you check your own compliance against the policy, not only at audit time.

NIST CSF 2.0
GV.OV-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.13 REQ-6.3-06X REQ-6.3-07X REQ-6.1-08
CEN/TS 18026
CO-01 DOC-03 INQ-01 INQ-02 INQ-03
Belgium
BASICRS.IM-1.1
IMPORTANTID.GV-1.2 ID.GV-3.2 ID.SC-4.1 PR.AT-3.3 PR.IP-9.1 DE.DP-3.1 DE.DP-5.1 RS.IM-1.2 RS.IP-2.1 RC.IM-1.1
ESSENTIALID.SC-4.2 PR.AT-3.4 PR.IP-7.2 PR.IP-9.2 DE.DP-5.2
Finland
PROGRAM-1 PROGRAM-2
Greece
Ministerial decision 1689/2025articles 9a 9b 9c
Cybersecurity HandbookPart A: 2
Self assessment tool1.11 1.12 1.19 1.20
Spain
Article 10 Article 28 Article 31 Article 32
Technical Security Instruction on Safety Status Report.
Technical Security Instruction on Information Systems Security Auditing
ANNEX III - Security audit
France
2.A.1-IE/EE
2.B.2-IE/EE
2.B.4-IE/EE
2.C.1-IE/EE
2.C.2-IE/EE
2.C.3-IE/EE
3.B.1-IE/EE
3.B.2-IE/EE
62443 ours
62443-2-1ORG 2 Security assessments and reviews
22301 ours
Clauses9.1 Monitoring, measurement, analysis and evaluation
2.3 Independent review of information and network security 21(2)(a)

Review by someone independent of the people who run the controls.

NIST CSF 2.0
GV.OV-02 ID.IM-01
ETSI EN 319 401
Clause 7.13 REQ-7.2-11X REQ-7.2-14X (d)
CEN/TS 18026
CO-01 CO-02 CO-03 CO-04
Belgium
ESSENTIALID.SC-4.2 PR.IP-7.2 DE.DP-5.2 DE.CM-2.2
Finland
PROGRAM-2
Greece
Ministerial decision 1689/2025articles 8a 8b 8c 8d
Cybersecurity Handbook-
Self assessment tool15.2
Spain
Article 31
ANNEX III - Security audit National Security Framework Compliance sections V (National Security Framework Compliance) and VI (Requirements of the certifier bodies)
Technical Security Instruction on Information Systems Security Auditing
Technical Security Instruction for compliance with the National Security Framework
France
3.B.2-EI/EE
17.2-EE
62443 ours
62443-2-1ORG 2 Security assessments and reviews
62443-3-2ZCR 6 Verify the cybersecurity requirements
22301 ours
Clauses9.2 Internal audit 9.3 Management review

3Incident handlingArt. 21(2)(b)

3.1 Incident handling policy 21(2)(b)

A documented incident policy setting out roles, classification and escalation before an incident happens.

NIST CSF 2.0
GV.SC-08 RS.MA-01 RS.MA-05 RS.MI-01 RS.MI-02 ID.IM-01 ID.IM-04
ETSI EN 319 401
REQ-7.9.2-12X REQ-7.9.2-01X REQ-7.9.2-04X REQ-7.9.2-05X REQ-7.9.2-12X REQ-7.9.2-06X REQ-7.9.2-08X REQ-7.9.3-01X through 04X REQ-7.9.4-01X and 02X
CEN/TS 18026
ISP-02 IM-01 IM-07
Belgium
BASICRS.RP-1.1
IMPORTANTID.AM-6.1 PR.IP-9.1 RS.CO-1.1 RS.MI-1.1 RC.RP-1.1
Finland
RESPONSE-1 RESPONSE-2 RESPONSE-3 RESPONSE-5 CRITICAL-3
Greece
Ministerial decision 1689/2025articles 24a 24f
Cybersecurity HandbookPart B: 17.1
Self-assessment tool18.1
Spain
Article 12 Article 24 Article 25 Article 33 Article 34
Technical Security Instruction for Notification of Security Incidents
Annex II[op.exp.7] Incident management [op.exp.9] Incident management record [op.mon.1] Intrusion detection [op.mon.2] Metrics system [op.mon.3] Monitoring [op.cont.2] Continuity plan
France
2.C.1-IE/EE
2.C.2-IE/EE
2.C.3-IE/EE
12.1-EE
12.2-EE
12.3-IE/EE
12.4-EE
12.5-EE
12.6-IE/EE
12.7-EE
13.6-EE
13.7-EE
14.1-IE/EE
14.2-IE/EE
14.6-EE
14.8-EE
15.1-IE/EE
15.2-EE
15.3-EE
15.4-EE
62443 ours
62443-2-1EVENT 1 Event and incident management
62443-3-3FR 6 Timely response to events (TRE)
22301 ours
Clauses8.4 Business continuity plans and procedures
3.2 Monitoring and logging 21(2)(b)

Logging and monitoring wide enough to detect the incidents you are obliged to report.

NIST CSF 2.0
RS.AN-06 RS.AN-07 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.9.1-01X REQ-7.9.1-02X REQ-7.9.1-03X REQ-7.9.1-04X REQ-7.9.1-05X REQ-7.9.2-11X REQ-7.10-05 REQ-7.10- 06 REQ-7.10-07 REQ-7.10- 08 REQ-7.10-02
CEN/TS 18026
OPS-10 OPS-11 OPS-12 OPS-13 OPS-14 OPS-15 OPS-16 OPS-23 CS-01 IM-07 PSS-01
Belgium
BASICPR.PT-1.1 DE.AE-3.1
IMPORTANTPR.AC-2.2 PR.AC-4.5 PR.DS-5.1 PR.IP-7.1 PR.MA-1.3 DE.AE-3.2 DE.CM-1.2 DE.CM-6.1 DE.CM-7.1
ESSENTIALID.SC-3.2 PR.PT-1.3 DE.AE-1.1 DE.AE-3.3 DE.CM-1.3 DE.CM-2.2
Finland
SITUATION-1 SITUATION-2 SITUATION-3 ASSET-4
Greece
Ministerial decision 1689/2025articles 24c 24d 24e
Cybersecurity HandbookPart B: 8.1 8.2 8.3 8.4 8.5 8.6 8.7 8.8 8.9 8.10
Self-assessment tool9.1 9.2 9.3 9.4 9.5 9.6 9.7 9.8 9.9 9.10 9.11
Spain
Article 10 Article 21
Annex II[op.mon.1] Intrusion detection [op.mon.3] Monitoring [op.exp.8] Recording of the activity [op.acc.1] Identification
France
5.B.1-EE
12.6-IE/EE
12.7-EE
13.1-IE/EE
16.3-EE
20.1-EE
20.2-EE
20.3-EE
20.4-EE
20.5-EE
62443 ours
62443-2-1EVENT 1.4 Logging EVENT 1.5 Log entries EVENT 1.6 Log access
62443-3-3FR 6 Timely response to events (TRE)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
3.3 Event reporting 21(2)(b)

A route for staff and suppliers to report suspected events quickly, without judgement calls.

NIST CSF 2.0
RS.MI-01 RS.CO-02
ETSI EN 319 401
REQ-7.9.2-12X REQ-7.9.3-01X REQ-7.9.3-02X
CEN/TS 18026
IM-03 IM-04
Belgium
BASICPR.AT-1.1 DE.CM-3.1
IMPORTANTPR.AT-1.2 DE.AE-3.2 DE.AE-5.1 DE.CM-2.1 RS.CO-1.1 RS.CO-5.1
ESSENTIALDE.AE-1.1 DE.AE-3.3 DE.CM-1.3 RS.CO-2.2
Finland
RESPONSE-1 WORKFORCE-2
Greece
Ministerial decision 1689/2025article 21a.g
Cybersecurity HandbookPart B: 17.2 17.7
Self-assessment tool18.3
Spain
Article 32 Article 33
Annex II[op.exp.7] Incident management
France
4.2-IE/EE
4.5-IE/EE
6.2-EE
12.2-EE
14.1-IE/EE
14.2-IE/EE
14.8-EE
62443 ours
62443-2-1EVENT 1 Event and incident management
62443-3-3FR 6 Timely response to events (TRE)
22301 ours
Clauses7.4 Communication
3.4 Event assessment and classification 21(2)(b)

Criteria that decide, consistently, whether an event is an incident and whether it is significant.

NIST CSF 2.0
DE.AE-04 RS.MA-02 RS.MA-03 RS.MA-04 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.9.3-01X REQ-7.9.2-11X REQ-7.9.4-01X REQ-7.9.4-02X REQ-7.9.1-05X
CEN/TS 18026
IM-02
Belgium
BASICRS.IM-1.1
IMPORTANTPR.IP-9.1 DE.AE-1.2 DE.AE-3.2 DE.AE-5.1 DE.DP-3.1 RS.AN-2.1
ESSENTIALPR.PT-1.4 DE.AE-2.2 DE.AE-3.3 DE.AE-4.1 DE.CM-1.3 DE.DP-4.1 RS.AN-2.2 RS.AN-3.2
Finland
RESPONSE-1 RESPONSE-2
Greece
Ministerial decision 1689/2025article 24e
Cybersecurity HandbookPart B: 17.2
Self-assessment tool18.2 18.3
Spain
Article 32 Article 33
Technical Security Instruction for Notification of Security Incidents
Annex II[op.exp.7] Incident management
France
3.A.1-IE/EE
12.2-EE
12.4-EE
12.5-EE
13.6-EE
14.4-EE
20.2-EE
20.4-EE
62443 ours
62443-2-1EVENT 1 Event and incident management
62443-3-3FR 6 Timely response to events (TRE)
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.4 Business continuity plans and procedures
3.5 Incident response 21(2)(b)

Containment, eradication and recovery steps that people have actually rehearsed.

NIST CSF 2.0
RS.MA-01 RS.MA-02 RS.MA-03 RS.MA-04 ID.IM-02 ID.IM-03 ID.IM-04 RS.CO-02 RS.CO-03 RS.AN-03 RS.MI-01 RS.MI-02 RC.CO-03 RC.CO-04.
ETSI EN 319 401
REQ-7.9.2-01X REQ-7.9-09 REQ-7.9-12 Clause 7.9.2 REQ-7.9.1-05X REQ-7.9.2-11X REQ-7.10-01 through 08
CEN/TS 18026
OIS-03 IM-01 IM-05 IM-07 INQ-02 INQ-03
Belgium
BASICRS.RP-1.1
IMPORTANTPR.IP-9.1
ESSENTIALPR.IP-9.2 RS.CO-2.2
Finland
RESPONSE-2 RESPONSE-3
Greece
Ministerial decision 1689/2025articles 24a 24b
Cybersecurity HandbookPart B: 17.2 17.3 17.4 17.5 17.6 17.9 17.10
Self-assessment tool18.2 18.3 18.4 18.5 18.6 18.7 18.8
Spain
Article 32 Article 33
Annex II[op.exp.7] Incident management [op.cont.3] Periodic tests
France
12.1-EE
12.6-IE/EE
13.6-EE
14.1-IE/EE
14.2-IE/EE
14.3-IE/EE
14.4-EE
14.5-EE
14.6-EE
14.7-EE
14.8-EE
14.9-EE
15.1-IE/EE
15.2-EE
15.3-EE
15.4-EE
62443 ours
62443-2-1EVENT 1 Event and incident management AVAIL 1 System availability and intended functionality
62443-3-3FR 6 Timely response to events (TRE) FR 7 Resource availability (RA)
22301 ours
Clauses8.4 Business continuity plans and procedures 8.5 Exercise programme
3.6 Post-incident reviews 21(2)(b)

Lessons captured and fed back into the controls, with the change trail to prove it.

NIST CSF 2.0
ID.IM-01 ID.IM-04 RS.AN-08
ETSI EN 319 401
REQ-7.9.5-01X REQ-7.9.5-03X REQ-7.9.5-04X
CEN/TS 18026
IM-06
Belgium
BASICRS.IM-1.1
IMPORTANTPR.P-7.1 RS.IM-1.2 RS.IM-2.1 RS.CO-1.1 RS.CO-3.2 RC.IM-1.1
Finland
RESPONSE-3 RESPONSE-5
Greece
Ministerial decision 1689/2025article 24f
Cybersecurity HandbookPart B: 17.8
Self-assessment tool18.2 18.3
Spain
Article 32 Article 33
Annex II[op.exp.7] Incident management
France
12.1-EE
12.5-EE
14.1-IE/EE
14.4-EE
15.4-EE
20.2-EE
62443 ours
62443-2-1EVENT 1 Event and incident management ORG 2 Security assessments and reviews
22301 ours
Clauses8.6 Evaluation of business continuity documentation and capabilities 10.1 Nonconformity and corrective action 10.2 Continual improvement

4Business continuity and crisis managementArt. 21(2)(c)

4.1 Business continuity and disaster recovery plan 21(2)(c)

Continuity and recovery plans with tested objectives, not an untested document.

NIST CSF 2.0
ID.IM-02 ID.IM-03 ID.IM-04 GV.OC-04 GV.SC-08 RC.RP-01 RC.RP-02
ETSI EN 319 401
Clause 7.11
CEN/TS 18026
BC-01 BC-02 BC-03 BC-04
Belgium
BASICID.BE-5.1 PR.IP-4.1
IMPORTANTID.SC-5.1 PR.IP-9.1
ESSENTIALID.SC-5.2 PR.IP-4.4 PR.IP-4.5 PR.IP-9.2 RC.RP-1.2
Finland
RESPONSE-4 RESPONSE-5 CRITICAL-3
Greece
Ministerial decision 1689/2025articles 25.1a 25.1b 25.1c
Cybersecurity HandbookPart B: 18.1 18.2
Self-assessment tool19.1 19.2 19.3
Spain
Article 26 Article 27
Annex II[op.cont.1] Impact analysis [op.cont.2] Continuity plan [op.cont.3] Periodic tests [op.cont.4] Alternative means [op.ext.3] Protection of the supply chain
France
12.4-EE
13.1-IE/EE
13.2-IE/EE
13.3-IE/EE
13.4-IE/EE
13.5-EE
13.6-EE
13.7-EE
14.7-EE
14.9-EE
16.1-EE
62443 ours
62443-2-1AVAIL 1 System availability and intended functionality
62443-3-3FR 7 Resource availability (RA)
22301 ours
Clauses8.1 Operational planning and control 8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions 8.4 Business continuity plans and procedures 8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities
4.2 Backup management 21(2)(c)

Backups that are taken, protected, and restored under test.

NIST CSF 2.0
PR.DS-11 RC.RP-01 RC.RP-02 ID.IM-03
ETSI EN 319 401
Clause 7.11.2
CEN/TS 18026
OPS-06 OPS-07 OPS-08 OPS-09
Belgium
BASICPR.IP-4.1 RC.RP-1.1
IMPORTANTPR.IP-4.2 PR.DS-3.3 PR.DS-5.1 PR.DS-6.1 PR.IP-4.3
ESSENTIALID.BE-5.2 PR.DS-8.1 PR.IP-4.4 PR.IP-4.5
Finland
RESPONSE-4 ASSET-1 ASSET-2 CRITICAL-2 ARCHITECTURE-1 ARCHITECTURE-5
Greece
Ministerial decision 1689/2025articles 25.1d 25.1e 25.1f 25.1g
Cybersecurity HandbookPart B: 16.1 16.2 16.3 16.4 16.5 16.6 16.7
Self-assessment tool17.1 17.2 17.3 17.4 17.5 17.6 17.7 17.8
Spain
Annex II[op.cont.1] Impact analysis [op.cont.2] Continuity plan [op.cont.3] Periodic tests [op.cont.4] Alternative means [mp.info.6] Backups
France
12.6-IE/EE
12.7-EE
13.1-IE/EE
13.2-IE/EE
13.3-IE/EE
13.4-IE/EE
13.5-EE
13.6-EE
13.7-EE
20.2-EE
62443 ours
62443-2-1AVAIL 2 Backup, restore and archive
62443-3-3FR 7 Resource availability (RA)
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions 8.4 Business continuity plans and procedures
4.3 Crisis management 21(2)(c)

A crisis structure with decision rights, contacts and communication paths defined in advance.

NIST CSF 2.0
RS.CO-02 RS.CO-03. PR.IR-03 DE.CM-01 ID.AM-03 DE.AE-02 DE.AE-03 DE.AE-04 DE.AE-06 DE.AE-07 DE.AE-08
ETSI EN 319 401
Clause 7.11.3
CEN/TS 18026
BC-03 OIS-03
Belgium
BASICRS.CO-3.1
IMPORTANTPR.IP-8.1 DE.DP-4.1 RS.CO-3.2
ESSENTIALPR.IP-4.4 PR.IP-9.2 RC.CO-2.1 RS.CO-2.2
Finland
RESPONSE-3 THREAT-2 CRITICAL-1 CRITICAL-3
Greece
Ministerial decision 1689/2025articles 25.2a 25.2b
Cybersecurity HandbookPart B: 17.2 17.10 18.1 18.2 18.8
Self-assessment tool18.2 18.3 19.2 19.3 19.8
Spain
Article 26 Article 27
Annex II[op.cont.1] Impact analysis [op.cont.2] Continuity plan [op.cont.3] Periodic tests [op.cont.4] Alternative means [mp.info.6] Backups
France
12.4-EE
12.6-IE/EE
12.7-EE
13.1-IE/EE
13.3-IE/EE
13.4-IE/EE
13.6-EE
13.7-EE
14.1-IE/EE
14.2-IE/EE
14.3-IE/EE
14.4-EE
14.5-EE
14.6-EE
14.7-EE
14.8-EE
14.9-EE
62443 ours
62443-2-1EVENT 1 Event and incident management AVAIL 1 System availability and intended functionality
62443-3-3FR 7 Resource availability (RA)
22301 ours
Clauses8.4 Business continuity plans and procedures 7.4 Communication

5Supply chain securityArt. 21(2)(d)

5.1 Supply chain security policy 21(2)(d)

A supplier security policy that sets requirements by criticality and flows them into contracts.

NIST CSF 2.0
GV.OC-03 GV.OC-05 GV.SC-01 GV.SC-04 GV.SC-06 GV.SC-05 GV.SC-07 GV.SC-09 GV.SC-10 ID.RA-10 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.14.1
CEN/TS 18026
ISP-02 DEV-08 PM-01 PM-02 PM-04 PM-05
Belgium
IMPORTANTID.BE-1.1 ID.GV-1.2 ID.SC-2.1 ID.SC-3.1
ESSENTIALID.SC-1.1 ID.BE-1.2 PR.PT-4.3
Finland
THIRD-PARTIES-1 THIRD-PARTIES-2 CRITICAL-1 CRITICAL-2 CRITICAL-3 WORKFORCE-1 WORKFORCE-3
Greece
Ministerial decision 1689/2025articles 12.1a 12.1c 12.1d 12.1e 12.2a 12.2b
Cybersecurity HandbookPart B: 13.1
Self-assessment tool-
Spain
Article 2 Article 15 Article 16 Article 19 Article 23
Annex II[op.ext.1] Contracting and service level agreements [op.ext.2] Daily management [op.ext.3] Protection of the supply chain [op.ext.4] Interconnection of systems
France
2.B.5-IE/EE
3.A.1-IE/EE
3.A.2-IE/EE
3.B.1-IE/EE
3.B.2-IE/EE
7.B.1-IE/EE
7.B.2-EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
Other parts62443-2-4 Security program requirements for IACS service providers 62443-4-1 SM Security management 62443-4-2 CCSC 4
22301 ours
Clauses4.2 Understanding the needs and expectations of interested parties 8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions
5.2 Directory of suppliers and service providers 21(2)(d)

A maintained register of suppliers and service providers with the services they deliver.

NIST CSF 2.0
GV.OC-05 GV.SC-04 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.14.3-11X REQ-7.14.3-12X Clause 7.14.3
CEN/TS 18026
DEV-02 PM-03
Belgium
BASICID.GV-4.1 ID.RA-5.1
IMPORTANTID.BE-4.1 ID.RA-5.2 ID.RA-6.1 ID.RM-1.1 ID.RM-2.1 ID.RM-3.1 ID.SC-2.1 ID.SC-3.1 ID.SC-4.1 PR.AC-7.1 DE.CM-6.1 DE.CM-6.2
ESSENTIALID.RA-5.3 ID.SC-1.1 ID.SC-2.2 ID.SC-3.2 ID.SC-3.3 ID.SC-4.2
Finland
THIRD-PARTIES-1 CRITICAL-1
Greece
Ministerial decision 1689/2025article 12.1b
Cybersecurity HandbookPart B: 13.2 13.3 13.4 13.5 13.6 13.7
Self-assessment tool14.2 14.3 14.4 14.5 14.6 14.7
Spain
Article 13
Annex II[op.ext] External resources
France
1.1-IE/EE
3.A.1-IE/EE
3.A.2-IE/EE
3.B.1-IE/EE
3.B.2-IE/EE
8.1-IE/EE
16.1-EE
16.2-EE
16.3-EE
16.4-EE
17.2-EE
62443 ours
62443-2-1CM 1 Inventory management of IACS hardware, software and network communications
Other parts62443-2-4 Security program requirements for IACS service providers
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions

6Security in network and information systems acquisition, development and maintenanceArt. 21(2)(e)

6.1 Security in acquisition of ICT services, ICT systems or ICT products 21(2)(e)

Security requirements set before ICT products and services are bought, not after.

NIST CSF 2.0
GV.PO-02 GV.SC-06 ID.RA-09 ID.RA-10 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.7-01 Clause 7.14.2
CEN/TS 18026
OIS-04 AM-03 DEV-02 DEV-07 PM-01
Belgium
BASICID.GV-4.1
IMPORTANTID.RM-1.1 ID.GV-4.2 ID.SC-3.1 ID.SC-4.1 PR.IP-2.1 DE.CM-6.2
ESSENTIALID.SC-2.2 ID.SC-3.2 ID.SC-4.2 ID.SC-3.3
Finland
THIRD-PARTIES-1 THIRD-PARTIES-2 ARCHITECTURE-4
Greece
Ministerial decision 1689/2025articles 12.1a 12.1c 12.1d 12.1e 12.2a 12.2b
Cybersecurity HandbookPart B: 13.1 13.2 13.4 13.5
Self-assessment tool14.1 14.2 14.4 14.5
Spain
Article 19
Annex II[op.pl.3] Acquisition of new components [op.pl.5] Certified components [op.ext.1] Contracting and service level agreements [op.ext.2] Daily management [op.exp.4] Security maintenance and updates
France
3.A.1-IE/EE
5.A.1-EE
5.B.1-EE
16.1-EE
8.5-EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
62443-3-2ZCR 5 Document the cybersecurity requirements
62443-4-1SR Specification of security requirements
Other parts62443-4-2 Technical security requirements for IACS components 62443-2-4
22301 ours
Clauses8.3 Business continuity strategies and solutions
6.2 Secure development life cycle 21(2)(e)

Security built into the development lifecycle rather than tested at the end.

NIST CSF 2.0
ID.AM-08 PR.PS-06 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.7-01 REQ-7.7-02 REQ-7.7-03 REQ-7.7-04 REQ-7.8-10
CEN/TS 18026
OIS-04 CCM-04 CCM-06 DEV-01 DEV-03 DEV-04 DEV-05 DEV-06
Belgium
IMPORTANTID.GV-1.2 PR.IP-2.1
ESSENTIALPR.DS-7.1 PR.IP-2.2
Finland
ARCHITECTURE-4 THIRD-PARTIES-2
Greece
Ministerial decision 1689/2025articles 15a 15b 15c 15d
Cybersecurity HandbookPart B: 9.1 9.2 9.3 9.4 9.5 9.6 9.7 9.8 9.9 9.10 9.11 9.12 9.13 9.14 9.15 9.16
Self-assessment tool10.1 10.2 10.3 10.4 10.5 10.6 10.7 10.8 10.9 10.10 10.11 10.12
Spain
Article 36
Annex II[mp.sw.1] IT Applications development [mp.sw.2] Acceptance and commissioning [mp.info.1] Personal data
France
2.B.5-IE/EE
5.B.1-EE
62443 ours
62443-4-1SM Security management SR Specification of security requirements SD Secure by design SI Secure implementation SVV Security verification and validation testing SG Security guidelines
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.3 Configuration management 21(2)(e)

Secure baselines applied and enforced across systems.

NIST CSF 2.0
PR.PS-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-6.3-08X REQ-7.7-03 REQ-6.3-09X REQ-7.7-08X REQ-7.7-09X REQ-7.7-10X
CEN/TS 18026
OPS-21 PSS-03 PSS-04
Belgium
BASICPR.IP-4.1
IMPORTANTID.AM-3.2 PR.IP-1.1
ESSENTIALID.SC-3.2 PR.DS-1.1 PR.IP-1.2 PR.IP-2.2 DE.CM-7.2
Finland
ASSET-3 ASSET-4 ARCHITECTURE-3 ARCHITECTURE-4
Greece
Ministerial decision 1689/2025articles 14a 14b 14c 14d 19h
Cybersecurity HandbookPart B: 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 2.9 2.10 2.12 2.15
Self-assessment tool3.1 3.2 3.3 3.4 3.5 3.6 3.7 3.8 3.9 3.10 3.12 3.13
Spain
Article 10 Article 20 Article 21 Article 30
Annex II[op.exp.2] Security Configuration [op.exp.3] Security Configuration Management
France
10.B.2-IE/EE
11.B.7-EE
17.2-EE
19.1-EE
19.2-EE
19.3-EE
62443 ours
62443-2-1CM 1 Inventory management of IACS hardware, software and network communications
62443-3-3FR 3 System integrity (SI)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.4 Change management, repairs and maintenance 21(2)(e)

Changes, repairs and maintenance assessed for security impact and authorised.

ISO 27001
Clauses6.3 Planning of changes 8.1 Operational planning and control
NIST CSF 2.0
ID.RA-07 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.7-03 REQ-7.7-04 REQ-7.7-07X
CEN/TS 18026
ISP-03 CCM-01 CCM-02 CCM-03 CCM-04 CCM-05 CCM-06
Belgium
BASICID.AM-1.1 ID.AM-2.1; ID.GV-1.1
IMPORTANTID.AM-1.2 ID.AM-2.2 ID.AM-4.1 ID.GV-1.2 PR.DS-6.1 PR.MA-1.2 PR.MA-1.3 PR.IP-3.1 RS.IM-2.1
ESSENTIALID.AM-3.3 ID.AM-4.2 PR.IP-2.2 PR.IP-3.2 DE.CM-7.2
Finland
ASSET-4
Greece
Ministerial decision 1689/2025articles 16a 16b
Cybersecurity HandbookPart B: 2.12
Spain
Annex II[op.exp.5] Change Management
France
2.C.2-IE/EE
5.A.1-EE
62443 ours
62443-2-1CM 1 Inventory management COMP 3 Patch management
62443-3-3FR 3 System integrity (SI)
Other parts62443-2-3 Patch management in the IACS environment
22301 ours
Clauses6.3 Planning of changes
6.5 Security testing 21(2)(e)

Testing that verifies the controls work, on a defined schedule.

NIST CSF 2.0
ID.RA-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.8-10 REQ-7.8-13 REQ-7.8-14X REQ-7.8-17X REQ-7.8-18X REQ-7.8-19X
CEN/TS 18026
ISP-02 OPS-19 DEV-01 DEV-04 DEV-06
Belgium
IMPORTANTID.BE-5.1 ID.SC-4.1 PR.IP-3.1 PR.P-4.2 PR.IP-7.3 PR.MA-1.3 RS.CO-1.1 RS.IM-1.2 RC.IM-1.1
ESSENTIALID.RA-1.3 ID.SC-3.2 ID.SC-4.2 PR.DS-7.1 PR.IP-2.2 PR.IP-3.2 DE.DP-5.2
Finland
THREAT-1 THIRD-PARTIES-2
Greece
Ministerial decision 1689/2025articles 8a 8b 8c 8d 18.1a 18.1b 18.1c 18.1d 18.2a 18.2b
Cybersecurity HandbookPart B: 14.4 14.5 9.13 9.14
Self-assessment tool15.6 15.7 15.8 15.9 10.10 10.11
Spain
Annex II[op.nub.1] Cloud Service Protection [op.cont.2] Continuity plan [op.cont.3] Periodic tests [op.exp.4] Security maintenance and updates [op.exp.5] Change Management
France
3.B.2-IE/EE
13.2-IE/EE
13.3-IE/EE
13.4-IE/EE
17.3-EE
62443 ours
62443-2-1ORG 2 Security assessments and reviews
62443-3-2ZCR 6 Verify the cybersecurity requirements
62443-4-1SVV Security verification and validation testing
22301 ours
Clauses8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities
6.6 Security patch management 21(2)(e)

Patches assessed, prioritised and applied within stated timeframes.

NIST CSF 2.0
PR.PS-02 DE.CM-09 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.7-07X
CEN/TS 18026
CCM-03 CCM-04 CCM-05 OPS-18
Belgium
BASICPR.MA-1.1
IMPORTANTPR.MA-1.2 PR.IP-1.1
ESSENTIALID.SC-3.2 PR.MA-1.7
Finland
ASSET-4 THREAT-1
Greece
Ministerial decision 1689/2025articles 17c 17d
Cybersecurity HandbookPart B: 2.8
Self-assessment tool3.5 3.6 15.4
Spain
Article 21
Annex II[op.exp.4] Security maintenance and updates
France
5.A.1-EE
5.B.1-EE
5.B.2-IE/EE
5.B.3-IE/EE
5.B.4-IE/EE
5.B.5-EE
5.B.6-IE/EE
5.B.7-IE/EE
5.B.8-IE/EE
5.B.9-IE/EE
5.B.10-IE/EE
5.B.11-IE/EE
62443 ours
62443-2-1COMP 3 Patch management
62443-3-3FR 3 System integrity (SI)
62443-4-1SUM Security update management
Other parts62443-2-3 Patch management in the IACS environment
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.7 Network security 21(2)(e)

Network controls that limit exposure and detect abnormal traffic.

NIST CSF 2.0
DE.CM-01 PR.IR-01 PR.PS-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.8
CEN/TS 18026
PS-04 CS-01 CS-02 CS-03 CS-06 CS-07 CS-08 PSS-02
Belgium
BASICID.RA-1.1 PR.AC-2.1 PR.AC-3.1 PR.AC-3.2 PR.AC-5.1 PR.AC-5.2 DE.CM-1.1 DE.CM-3.1
IMPORTANTPR.AC-2.2 PR.AC-3.3 PR.AC-5.3 PR.AC-5.4 PR.AT-1.2 DE.CM-1.2 DE.CM-3.2
ESSENTIALID.BE-1.2 PR.AC-2.4 PR.AC-5.5 DE.CM-1.3
Finland
ACCESS-1 ACCESS-2 ARCHITECTURE-1 ARCHITECTURE-2
Greece
Ministerial decision 1689/2025articles 19a 19b 19c 19d 19f 19g 19h 19i 19j 19k
Cybersecurity HandbookPart B: 6.1 6.2 6.3 6.8 6.9 6.10 6.11 6.12 6.13 6.14 6.15 6.16 6.17 6.18 6.19 6.20 6.21 6.22 6.23
Self-assessment tool7.1 7.2 7.3 7.8 7.9 7.11 7.12 7.13 7.14 7.16 7.17 7.18 7.19 7.20 7.21
Spain
Article 9 Article 10 Article 27
Annex II[mp.com.1] Secure perimeter [mp.com.2] Protection of confidentiality [mp.com.3] Protection of integrity and authenticity
France
3.A.1-IE/EE
5.B.3-IE/EE
7.A.2-EE
8.1-IE/EE
8.2-IE/EE
8.3-EE
8.5-EE
9.1-IE/EE
9.2-EE
9.3-IE/EE
9.4-EE
11.B.5-EE
19.10-EE
62443 ours
62443-2-1NET 1 System segmentation NET 2 Secure wireless access NET 3 Secure remote access
62443-3-3FR 5 Restricted data flow (RDF) FR 1 Identification and authentication control (IAC)
62443-3-2ZCR 3 Partition into zones and conduits
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.8 Network segmentation 21(2)(e)

Segmentation that contains an intrusion instead of letting it spread.

NIST CSF 2.0
PR.IR-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.8-02 REQ-7.8-03 REQ-7.8-04 REQ-7.8-05 REQ-7.8-06 REQ-7.8-07 REQ-7.8-08 REQ-7.8-09X REQ-7.8-10
CEN/TS 18026
IAM-09 CS-02 CS-04 CS-05
Belgium
BASICPR.AC-3.1 PR.AC-5.2
IMPORTANTPR.AC-5.3 PR.AC-5.4 PR.IP-4.3
ESSENTIALID.BE-5.2 PR.DS-7.1 PR.IP-3.2 PR.IP-4.5
Finland
ARCHITECTURE-1 ARCHITECTURE-2
Greece
Ministerial decision 1689/2025articles 19e 19f 19k
Cybersecurity HandbookPart B: 6.4 6.5 6.6 6.7 6.15
Self-assessment tool7.4 7.5 7.6 7.7 7.15
Spain
Annex II[mp.com.4] Separation of information flows on the network
France
7.A.1-IE/EE
7.A.2-EE
7.A.3-EE
7.A.4-EE
7.A.5-EE
7.A.6-EE
7.A.7-IE/EE
62443 ours
62443-2-1NET 1 System segmentation
62443-3-3FR 5 Restricted data flow (RDF)
62443-3-2ZCR 3 Partition into zones and conduits ZCR 4 Detailed risk assessment of the zones and conduits
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.9 Protection against malicious and unauthorised software 21(2)(e)

Malware protection plus control over what software may run.

NIST CSF 2.0
DE.CM-01 DE.CM-09 PR.PS-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.7-05 REQ-7.8-15X REQ-7.8-16X
CEN/TS 18026
OPS-04 OPS-05 CS-03
Belgium
BASICID.AM-2.1 ID.RA-1.1 PR.PT-4.1 DE.CM-4.1
IMPORTANTID.AM-2.4 DE.CM-5.1
ESSENTIALID.AM-2.5 PR.MA-1.6 PR.PT-2.3 DE.CM-4.2 DE.DP-5.2
Finland
ARCHITECTURE-2 ARCHITECTURE-3
Greece
Ministerial decision 1689/2025articles 20a 20b 20c 20d 20e
Cybersecurity HandbookPart B: 6.9 6.10 7.1 7.2 7.3 7.4 7.5 7.6 7.7 7.8 7.9 7 10
Self-assessment tool7.9 7.10 7.11 8.1 8.2 8.3 8.4 8.5 8.6 8.7 8.8 8.9 8.10
Spain
Article 24
Annex II[op.exp.6] Protection against harmful code
France
5.B.1-EE
5.B.2-IE/EE
5.B.3-IE/EE
9.1-IE/EE
9.2-EE
9.3-IE/EE
9.4-EE
9.5-IE/EE
9.6-IE/EE
9.7-IE/EE
20.1-EE
62443 ours
62443-2-1COMP 2 Malware protection COMP 1 Components and portable media
62443-3-3FR 3 System integrity (SI)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
6.10 Vulnerability handling and disclosure 21(2)(e)

A vulnerability handling process, including how you receive and act on external reports.

NIST CSF 2.0
ID.RA-01 ID.RA-02 ID.RA-04 ID.RA-05 ID.RA-06 PR.PS-02 PR.PS-03 ID.RA-08 ID.RA-06 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.8-13 REQ-7.8-14X REQ-7.9.2-09X REQ-7.9.2-10X REQ-7.9.5-01X REQ-7.9.5-02X
CEN/TS 18026
OIS-03 OPS-17 OPS-18 OPS-19 OPS-20 OPS-21 DEV-06
Belgium
BASICID.RA-1.1
IMPORTANTID.RA-1.2 ID.RA-2.1 DE.CM-8.1 DE.CM-8.2 DE.DP-4.1 RS.AN-5.1
ESSENTIALID.AE-3.3 DE.DP-5.2 RS.AN-5.2
Finland
THREAT-1
Greece
Ministerial decision 1689/2025articles 5.2 17a 17b 17e 17f 17g
Cybersecurity HandbookPart B: 14.1 14.2 14.3
Self-assessment tool15.1 15.3 15.4 15.5
Spain
Article 8 Article 10 Article 21 Article 34
Annex II[op.mon.3] Monitoring [mp.s.2] Protection of web services and applications
France
5.B.1-EE
5.B.2-IE/EE
5.B.3-IE/EE
5.B.4-IE/EE
5.B.5-EE
5.B.6-IE/EE
5.B.7-IE/EE
5.B.8-IE/EE
5.B.9-IE/EE
5.B.10-IE/EE
5.B.11-IE/EE
17.2-EE
17.3-EE
17.4-EE
17.5-EE
18.4-EE
62443 ours
62443-2-1COMP 3 Patch management
62443-4-1DM Defect management SUM Security update management
Other parts62443-2-3 Patch management in the IACS environment
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system

7Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresArt. 21(2)(f)

7.1 Policies and procedures to assess the effectiveness of cybersecurity risk-management measures 21(2)(f)

Measurement of whether the measures work, feeding management review.

ISO 27001
Clauses6.2 Information security objectives and planning to achieve them 9.1 Monitoring, measurement, analysis and evaluation 9.3 Management review
NIST CSF 2.0
ID.IM-03 GV.RM-06 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 5, ref. to ISO/IEC 270052022 REQ-7.9.5-03X REQ-7.9.5-04X
CEN/TS 18026
ISP-02 OPS-20 CO-04
Belgium
BASICRS.IM-1.1
IMPORTANTPR.IP-7.1 PR.IP-8.1 PR.IP-8.2 PR.IP-9.1 DE.DP-3.1 RS.IM-1.2 RC.IM-1.1
ESSENTIALPR.IP-7.2 PR.IP-7.3 PR.IP-9.2
Finland
CRITICAL-2 RISK-4 RISK-5 Management activities
Greece
Ministerial decision 1689/2025articles 18.1a 18.1b 18.1c 18.1d 18.2a 18.2b
Cybersecurity HandbookPart B: 14.1 14.2 14.3 14.4 14.5
Self assessment tool15.1 15.2 15.3 15.4 15.5 15.6 15.7 15.8 15.9
Spain
Article 7 Article 10 Article 27 Article 31 Article 32
Technical Security Instruction on Safety Status Report.
Annex II [org.3] Security procedures [op.pl.1] Risk Analysis
[op.mon.2] Metrics System
ANNEX III - Security audit
France
2.B.2-IE/EE
2.B.5-IE/EE
15.3-EE
16.1-EE
16.2-EE
16.3-EE
16.4-EE
62443 ours
62443-2-1ORG 2 Security assessments and reviews Annex C maturity levels ML1–ML4
62443-3-2ZCR 6 Verify the cybersecurity requirements
22301 ours
Clauses8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities 9.1 Monitoring, measurement, analysis and evaluation 9.3 Management review

8Basic cyber hygiene practices and security trainingArt. 21(2)(g)

8.1 Awareness raising and basic cyber hygiene practices 21(2)(g)

Cyber hygiene reaching everyone, including non-technical staff.

NIST CSF 2.0
PR.AT-01 PR.AT-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.2-01X REQ-7.2-02 REQ-7.2-03X REQ-7.2-04X REQ-7.2-05X
CEN/TS 18026
HR-04 DOC-01
Belgium
BASICPR.AT-1.1
IMPORTANTPR.AT-1.2
ESSENTIALPR.AT-1.3
Finland
WORKFORCE-2 WORKFORCE-3 WORKFORCE-4 PROGRAM-2
Greece
Ministerial decision 1689/2025articles 4b.e 21a 21c
Cybersecurity HandbookPart B: 10.4 10.5 10.6 10.7 10.8 10.9 10.10 10.11 10.12 10.13 10.14 10.15 12.1
Self-assessment tool11.1 11.5 11.6 13.1
Spain
Article 6
Annex II [mp.per.3] Awareness
France
4.1-IE/EE
4.2-IE/EE
4.3-EE
4.4-IE/EE
4.5-IE/EE
15.1-IE/EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
22301 ours
Clauses7.3 Awareness
8.2 Security training 21(2)(g)

Role-appropriate training, with records of who was trained and when.

NIST CSF 2.0
PR.AT-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.2-04X REQ-7.2-02 REQ-7.2-05X REQ-7.2-07X REQ-7.2-09X REQ-7.2-12X
CEN/TS 18026
HR-04 PM-01
Belgium
BASICPR.AT-1.1
IMPORTANTPR.AT-1.2 PR.AT-5.1 RC.IM-1.1
ESSENTIALPR.AT-1.3
Finland
WORKFORCE-1 WORKFORCE-2 WORKFORCE-3 WORKFORCE-4
Greece
Ministerial decision 1689/2025articles 21b 21c
Cybersecurity HandbookPart B: 12.1 12.2 12.3 12.4 12.5
Self-assessment tool13.1 13.2 13.3 13.4 13.5 13.6
Spain
Article 15 Article 16
Annex II [mp.per.4] Training
France
4.2-IE/EE
4.3-EE
4.4-IE/EE
15.1-IE/EE
15.2-EE
15.3-EE
15.4-EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
Other parts62443-2-4 Solution staffing functional area
22301 ours
Clauses7.2 Competence 7.3 Awareness

9CryptographyArt. 21(2)(h)

9.1 Cryptography 21(2)(h)

A cryptography policy covering algorithms, key management and where encryption is required.

NIST CSF 2.0
PR.DS-01 PR.DS-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.5, ref. to clause 8.24 of ISO/IEC 270022022
CEN/TS 18026
ISP-02 CKM-01 CKM-02 CKM-03 CKM-04
Belgium
IMPORTANTPR.DS-6.1
ESSENTIALPR.AC-3.4 PR.DS-8.1
Finland
ARCHITECTURE-5
Greece
Ministerial decision 1689/2025articles 22a 22b 22c 22d 22e
Cybersecurity HandbookPart B: 5.5 6.22 9.10 9.16 11.1 11.2 11.3 11.4 11.5 11.6 11.7 11.8
Self-assessment tool6.7 10.7 12.1 12.2 12.3 12.4 12.5 12.6 12.7
Spain
Article 10 Article 27
Annex II[op.exp.10] Cryptographic key protection [mp.si.2]. Cryptography
France
2.B.4-IE/EE
8.1-IE/EE
8.2-IE/EE
8.3-IE/EE
8.4-EE
8.5-EE
19.10-EE
19.11-EE
19.12-EE
62443 ours
62443-2-1DATA 1 Protection of data
62443-3-3FR 4 Data confidentiality (DC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system

10Human resources securityArt. 21(2)(i)

10.1 Human resources security 21(2)(i)

Security duties written into employment terms and understood from day one.

NIST CSF 2.0
PR.AT-02 GV.RR-04 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.2
CEN/TS 18026
HR-01 HR-02 HR-03
Belgium
BASICID.GV-1.1 PR.AC-1.1 PR.AC-4.3 PR.IP-11.1
IMPORTANTID.AM-6.1 ID.GV-1.2 ID.SC-3.1 PR.AC-2.2 PR.AC-4.6 PR.IP-11.2 DE.CM-6.2
ESSENTIALID.BE-1.2 ID.SC-3.2 ID.SC-3.3
Finland
WORKFORCE-1 WORKFORCE-2 WORKFORCE-3 THIRD-PARTIES-1 THIRD-PARTIES-2 Management activities
Greece
Ministerial decision 1689/2025articles 4b.c 7c
Spain
Article 15
Annex II[mp.per.1] Job characterization [mp.per.2] Duties and obligations [mp.per.3] Awareness [mp.per.4] Training [org.4] Authorization process
France
1.1-IE/EE
2.A.1-IE/EE
2.A.2-EE
2.A.3-IE/EE
3.A.1-IE/EE
3.A.2-IE/EE
3.B.1-IE/EE
3.B.2-IE/EE
62443 ours
62443-2-1ORG 1 Security-related organization and policies
22301 ours
Clauses7.2 Competence
10.2 Verification of Background 21(2)(i)

Background verification proportionate to the role, where the law permits.

ISO 27001
NIST CSF 2.0
GV.RR-04 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.2-09X REQ-7.2-17
CEN/TS 18026
HR-02
Belgium
BASICPR.IP-11.1
IMPORTANTPR.IP-11.2
Finland
WORKFORCE-1
Greece
Ministerial decision 1689/2025articles 10.1a 10.2
Spain
Article 15 Article 16
Annex II[mp.per.1] Job characterization
France
4.4-IE/EE
62443 ours
No 62443 equivalent — 62443 does not address human resources security
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
10.3 Termination or change of employment procedures 21(2)(i)

Access, assets and duties dealt with cleanly when someone leaves or changes role.

NIST CSF 2.0
GV.RR-04
ETSI EN 319 401
REQ-7.3.2-07X REQ-7.4-08X
CEN/TS 18026
HR-05 HR-06
Belgium
BASICID.GV-3.1 PR.AC-4.3 PR.IP-11.1
IMPORTANTPR.IP-11.2
Finland
WORKFORCE-1 ACCESS-1 ACCESS-2 ACCESS-3
Greece
Ministerial decision 1689/2025article 10.1b
Spain
Annex II[org.2] Security regulations
France
2.B.2-IE/EE
4.3-EE
4.4-IE/EE
62443 ours
62443-2-1USER 2 Authorization and access control
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
10.4 Disciplinary process 21(2)(i)

A disciplinary route for security breaches that is known in advance and applied consistently.

NIST CSF 2.0
ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.2-06X
CEN/TS 18026
HR-01
Belgium
BASICID.GV-3.1
IMPORTANTID.GV-3.2
Finland
WORKFORCE-1
Greece
Ministerial decision 1689/2025article 10.1c
Spain
Annex II3.2 Annex II: [org.2] Security regulations
France
2.C.2-IE/EE
3.B.1-IE/EE
3.B.2-IE/EE
4.1-IE/EE
62443 ours
No 62443 equivalent — 62443 does not address human resources security
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system

11Access controlArt. 21(2)(i), (j)

11.1 Access control policy 21(2)(i)

An access control policy grounded in least privilege and need to know.

NIST CSF 2.0
PR.AA-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.4-02X REQ-7.4-09X REQ-7.4-13X REQ-7.4-01 REQ-7.4-06X REQ-7.4-11X REQ-7.4-20X
CEN/TS 18026
OIS-02 ISP-02 IAM-01
Belgium
BASICID.AM-5.1 ID.GV-1.1 PR.AC-4.1 PR.IP-11.1
IMPORTANTID.AM-6.1 ID.GV-1.2 PR.AC-2.2 PR.AC-4.6 PR.AC-5.4 PR.AC-6.1 PR.AT-3.2 PR.DS-3.3 PR.DS-5.1 PR.IP-11.2 PR.MA-2.1 DE.AE-3.2 DE.CM-3.3 DE.CM-6.1 DE.CM-7.1
ESSENTIALPR.DS-1.1 PR.DS-3.3 DE.CM-2.2
Finland
ACCESS-1 ACCESS-2 ACCESS-3 ACCESS-4 ARCHITECTURE-3
Greece
Ministerial decision 1689/2025articles 13a 13h
Cybersecurity HandbookPart B: 4.1
Spain
Article 12 Article 17 Article 18 Article 20
Annex II[op.acc] Access control [org.1] Security policy [org.2] Security regulations [org.3] Security procedures [org.4] Authorization process
France
2.B.5-IE/EE
2.C.1-IE/EE
2.C.2-IE/EE
4.4-IE/EE
62443 ours
62443-2-1USER 1 Identification and authentication USER 2 Authorization and access control
62443-3-3FR 1 Identification and authentication control (IAC) FR 2 Use control (UC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.2 Management of access rights 21(2)(i)

Access granted, reviewed and revoked through a controlled process.

NIST CSF 2.0
PR.AA-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.4 REQ-7.9.1-04X
CEN/TS 18026
OIS-02 IAM-04 IAM-05 PSS-03 HR-05
Belgium
BASICID.AM-5.1 ID.GV-1.1 PR.AC-1.1 PR.AC-4.3 PR.IP-11.1
IMPORTANTID.AM-6.1 ID.GV-1.2 PR.AC-2.2 PR.AC-6.1 PR.AT-3.2 PR.DS-5.1 PR.IP-11.2 PR.MA-2.1 DE.CM-6.1 DE.CM-7.1
ESSENTIALPR.DS-1.1
Finland
ACCESS-1 ACCESS-2 ACCESS-3 ACCESS-4 ARCHITECTURE-3 WORKFORCE-1 SITUATION-1 SITUATION-2
Greece
Ministerial decision 1689/2025articles 13b 13c 13e 13h
Cybersecurity HandbookPart B: 4.3 4.6 4.7 4.8 2.11 2.14 9.9
Self-assessment tool5.3 5.4 5.5 5.6 5.7 5.8 5.9 5.13 5.14
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.2] Access requirements [op.acc.3] Segregation of functions and tasks [op.acc.4] Access rights management process [op.acc.5] Authentication mechanism (external users) [op.acc.6] Authentication mechanism (organization users)
France
6.1-IE/EE
6.2-EE
6.3-EE
6.4-EE
6.5-IE/EE
10.A.1-IE/EE
10.1.2-IE/EE
10.A.3-IE/EE
10.A.4-IE/EE
10.A.5-IE/EE
10.B.1-IE/EE
10.B.2-IE/EE
10.B.3-IE/EE
10.B.4-IE/EE
10.B.5-IE/EE
10.B.6-IE/EE
10.B.7-EE
10.C.1-IE/EE
10.C.2-IE/EE
10.C.3-IE/EE
10.C.4-IE/EE
11.A.7-EE
62443 ours
62443-2-1USER 2 Authorization and access control
62443-3-3FR 2 Use control (UC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.3 Privileged accounts and system administration accounts 21(2)(i)

Privileged accounts identified, restricted, and monitored more closely than the rest.

NIST CSF 2.0
ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.4-10X
CEN/TS 18026
ISP-02 IAM-05 IAM-06
Belgium
BASICPR.AC-1.1 PR.AC-4.3
IMPORTANTPR.AC-4.7 PR.AT-2.1
ESSENTIALPR.AC-4.9
Finland
ACCESS-1 ACCESS-2 ACCESS-3 ACCESS-4 ARCHITECTURE-3
Greece
Ministerial decision 1689/2025articles 13b 13d 13h
Cybersecurity HandbookPart B: 4.4 4.5 4.7
Self-assessment tool5.10 5.11 5.12 5.13
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.3] Segregation of functions and tasks
France
4.5-IE/EE
11.A.1-IE/EE
11.A.2-IE/EE
11.A.3-IE/EE
11.A.4-EE
11.A.5-EE
11.A.6-EE
11.A.7-EE
11.B.3-EE
11.B.4-EE
19.2-EE
19.3-EE
19.4-EE
19.6-EE
62443 ours
62443-2-1USER 2 Authorization and access control
62443-3-3FR 1 Identification and authentication control (IAC) FR 2 Use control (UC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.4 Administration systems 21(2)(i)

Administration systems hardened and separated from general-purpose use.

NIST CSF 2.0
-
ETSI EN 319 401
REQ-7.4-10X REQ-7.4-02X REQ-7.4-03X REQ-7.4-04X REQ-7.4-05X REQ-7.8-08 REQ-7.8-09X
CEN/TS 18026
OIS-02 IAM-06 IAM-09
Belgium
BASICPR.AC-4.4
IMPORTANTPR.AC-5.4
Finland
ACCESS-1 ACCESS-2 ACCESS-3 ACCESS-4 ARCHITECTURE-2 ARCHITECTURE-3 ARCHITECTURE-5
Greece
Ministerial decision 1689/2025articles 13a 13d
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.3] Segregation of functions and tasks
France
7.A.1-IE/EE
7.A.4-EE
7.B.1-IE/EE
7.B.4-IE/EE
11.A.1-IE/EE
11.A.2-IE/EE
11.A.3-IE/EE
11.A.4-EE
11.A.5-EE
11.A.6-EE
11.A.7-EE
62443 ours
62443-2-1USER 2 Authorization and access control NET 1 System segmentation NET 3 Secure remote access
62443-3-3FR 2 Use control (UC) FR 5 Restricted data flow (RDF)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.5 Identification 21(2)(i)

Unique identities, with shared accounts controlled by exception.

NIST CSF 2.0
PR.AA-01 PR.AA-05 PR.AC-02
ETSI EN 319 401
REQ-7.4-11X REQ-7.4-08X REQ-7.4-12X REQ-7.7-06X REQ-7.9.1-04X
CEN/TS 18026
IAM-02 IAM-03 IAM-06
Belgium
BASICPR.AC-1.1 PR.AC-4.1
IMPORTANTPR.AC-1.2 PR.AC-3.3 PR.AC-4.5 PR.AC-4.7 PR.AC-6.1
ESSENTIALPR.AC-4.9 PR.AC-6.2
Finland
ACCESS-1
Greece
Cybersecurity HandbookPart B: 4.2 4.3 4.7
Self-assessment tool5.2 5.6 5.7 5.13
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.2] Access requirements [op.acc.3] Segregation of functions and tasks [op.acc.4] Access rights management process [op.acc.5] Authentication mechanism (external users) [op.acc.6] Authentication mechanism (organization users); [mp.if.2] Identification of persons
France
4.4-IE/EE
10.A.1-IE/EE
10.A.2-IE/EE
10.A.3-IE/EE
10.A.4-IE/EE
10.A.5-IE/EE
11.A.4-EE
11.A.5-EE
11.B.3-EE
11.B.4-EE
62443 ours
62443-2-1USER 1 Identification and authentication
62443-3-3FR 1 Identification and authentication control (IAC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.6 Authentication 21(2)(i)

Authentication strong enough for the risk, with credential handling rules.

NIST CSF 2.0
PR.AA-05 PR.AA-03 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.4-02X REQ-7.4-05X REQ-7.7-06X REQ-7.4-11X
CEN/TS 18026
IAM-07 IAM-08
Belgium
BASICPR.AC-3.2
IMPORTANTPR.AC-1.2 PR.AC-1.4 PR.MA-2.2
ESSENTIALPR.AC-6.2
Finland
ACCESS-1 ACCESS-2 ACCESS-3 ACCESS-4 ARCHITECTURE-2 ARCHITECTURE-3 ARCHITECTURE-5
Greece
Ministerial decision 1689/2025articles 13a 13f 13g 13h
Cybersecurity HandbookPart B: 5.1 5.2 5.3 5.4 5.5 5.8 5.10
Self-assessment tool6.1 6.2 6.6 6.7 6.8 6.10
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.2] Access requirements [op.acc.3] Segregation of functions and tasks [op.acc.4] Access rights management process [op.acc.5] Authentication mechanism (external users) [op.acc.6] Authentication mechanism (organization users) [op.exp.2] Security Configuration
France
4.4-IE/EE
8.1-IE/EE
8.2-IE/EE
8.3-EE
8.4-EE
8.5-EE
10.B.1-IE/EE
10.B.2-IE/EE
10.B.3-IE/EE
10.B.4-IE/EE
10.B.5-IE/EE
10.B.6-IE/EE
10.B.7-EE
19.10-EE
62443 ours
62443-2-1USER 1 Identification and authentication
62443-3-3FR 1 Identification and authentication control (IAC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
11.7 Multi-factor authentication 21(2)(j)

Multi-factor or continuous authentication where the risk warrants it.

NIST CSF 2.0
PR.AA-03
ETSI EN 319 401
REQ-7.4-05X REQ-7.4-06X ref. to clause 2 of CA/Browser Forum network security guide
CEN/TS 18026
OPS-23 IAM-06 IAM-07
Belgium
BASICPR.AC-3.2
IMPORTANTPR.AC-1.2 PR.AC-1.4
Finland
ACCESS1
Greece
Ministerial decision 1689/2025article 13g
Cybersecurity HandbookPart B: 5.6 5.7 5.9 10.3
Self-assessment tool6.3 6.4 6.5 6.9 11.3
Spain
Article 20
Annex II[op.acc.1] Identification [op.acc.2] Access requirements [op.acc.3] Segregation of functions and tasks [op.acc.4] Access rights management process [op.acc.5] Authentication mechanism (external users) [op.acc.6] Authentication mechanism (organization users)
France
8.1-IE/EE
8.2-IE/EE
8.3-EE
8.4-EE
8.5-EE
10.B.1-IE/EE
19.10-EE
62443 ours
62443-2-1USER 1 Identification and authentication
62443-3-3FR 1 Identification and authentication control (IAC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system

12Asset managementArt. 21(2)(i)

12.1 Asset classification 21(2)(i)

Assets classified so protection matches sensitivity.

NIST CSF 2.0
ID.AM-05
ETSI EN 319 401
REQE-7.3.2-01X REQ-7.3.2-02X REQ-7.3.2-03X REQ-7.3.2-04X REQ-7.3.2-05X REQ-7.3.2-06X REQ-7.3.2-07X
CEN/TS 18026
AM-05
Belgium
BASICID.AM-5.1
Finland
CRITICAL-1 CRITICAL-2 ASSET-1 ASSET-2 RESPONSE-4 THIRD-PARTIES-1
Greece
Ministerial decision 1689/2025article 11b
Cybersecurity HandbookPart B: 1.4
Self assessment tool2.5 2.6
Spain
Article 40
Annex II[op.pl.1] Risk analysis [op.exp.1] Asset inventory [op.pl.2] Security Architecture
France
5.A.1-EE
62443 ours
62443-2-1CM 1 Inventory management of IACS hardware, software and network communications
62443-3-2ZCR 1 Identify the System under Consideration
22301 ours
Clauses8.2 Business impact analysis and risk assessment
12.2 Handling of assets 21(2)(i)

Handling rules that follow the classification through storage, transfer and disposal.

NIST CSF 2.0
ID.IM-01
ETSI EN 319 401
REQ-7.3.2-06X REQ-7.3.3-01X REQ-7.3.3-02X REQ-7.3.3-03X
CEN/TS 18026
ISP-02 AM-02 AM-03
Belgium
BASICID.AM-1.1 ID.AM-3.1 ID.GV-4.1
IMPORTANTID.AM-1.2 ID.AM-6.1 ID.RA-6.1 PR.DS-3.2 PR.DS-3.3
Finland
PROGRAM-2 ASSET-1 ASSET-2 ASSET-5 ARCHITECTURE-5 ARCHITECTURE-6 WORKFORCE-1
Greece
Ministerial decision 1689/2025article 11c
Cybersecurity HandbookPart B: 1.1 1.3 1.6 1.7 1.8
Self assessment tool2.1 2.2 2.4 2.7 2.8 2.9 2.10
Spain
Article 40
Annex II[op.pl.1] Risk analysis
France
1.1-IE/EE
2.A.3-IE/EE
3.A.1-IE/EE
5.A.1-EE
16.1-EE
16.3-EE
62443 ours
62443-2-1CM 1 Inventory management DATA 1 Protection of data
62443-3-3FR 4 Data confidentiality (DC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
12.3 Removable media policy 21(2)(i)

Control over removable media, including when it may be used at all.

NIST CSF 2.0
PR.DS-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.3.3-01X REQ-7.3.3-02X REQ-7.3.3-03X
CEN/TS 18026
ISP-02 AM-02 PS-04
Belgium
BASICPR.DS-3.1
IMPORTANTID.GV-1.2 PR.PT-1.1 PR.PT-2.2
ESSENTIALPR.DS-1.1 PR.DS-3.4
Finland
ARCHITECTURE-3g ARCHITECTURE-5g ARCHITECTURE-6c
Greece
Ministerial decision 1689/2025article 11d
Cybersecurity HandbookPart B: 1.5
Self assessment tool2.2 3.11
Spain
Annex II[mp.eq.3] Protection of portable devices [mp.sI.2] Cryptography
France
2.8.1-IE/EE
9.5.IE/EE
9.6-IE/EE
62443 ours
62443-2-1COMP 1 Components and portable media
62443-3-3FR 3 System integrity (SI)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
12.4 Asset inventory 21(2)(i)

A current inventory of assets with owners.

NIST CSF 2.0
ID.AM-01 ID.AM-02 ID.AM-03 ID.AM-04 ID.AM-07 ID.AM-08 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.3
CEN/TS 18026
AM-04
Belgium
BASICID.AM-1.1 ID.AM-2.1
IMPORTANTID.AM-1.2 ID.AM-1.3 ID.AM-2.2 ID.AM-2.4 PR.DS-3.3 DE.CM-7.1
Finland
ASSET-1 ASSET-4
Greece
Ministerial decision 1689/2025article 11a
Cybersecurity HandbookPart B: 1.2 1.9 1.10
Self assessment tool2.3 2.11
Spain
Annex II[op.exp.1] Asset inventory [mp.eq.3] Protection of portable devices
France
5.A.1-EE
62443 ours
62443-2-1CM 1 Inventory management of IACS hardware, software and network communications
62443-3-2ZCR 1 Identify the System under Consideration
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions
12.5 Deposit, return or deletion of assets upon termination of employment 21(2)(i)

Assets and access recovered or removed when employment ends.

NIST CSF 2.0
-
ETSI EN 319 401
REQ-7.3.2-07X REQ-7.3.3-01X REQ-7.3.3-02X REQ-7.3.3-03X REQ-7.4-08X
CEN/TS 18026
AM-01
Belgium
BASICPR.IP-11.1
IMPORTANTPR.AT-3.2 PR.IP-11.2
Finland
WORKFORCE-1
Greece
Ministerial decision 1689/2025article 11c
Spain
Annex II[mp.si.5] Erasure and destruction
France
4.1-IE/EE
4.2-IE/EE
4.3-EE
4.4-IE/EE
4.5-IE/EE
62443 ours
62443-2-1CM 1 Inventory management USER 2 Authorization and access control DATA 1 Protection of data
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system

13Environmental and physical securityArt. 21(2)(c), (e), (i)

13.1 Supporting utilities 21(2)(c)

Power, cooling and other utilities protected so they do not become the outage.

NIST CSF 2.0
DE.CM-02 DE.CM-06 GV.OC-03 GV.OC-05 GV.OC-07 ID.RA-10 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
REQ-7.6-03 REQ-7.6-05 REQ-7.11.2-01X REQ-7.11.2-02X For network connections REQ-7.8-12
CEN/TS 18026
PS-05
Belgium
BASICID.GV-3.1 RS.IM-1.1
IMPORTANTID.BE-1.1 ID.GV-3.2 PR.IP-7.1 PR.IP-9.1 DE.CM-2.1 DE.CM-6.1 DE.CM-6.2 DE.DP-3.1 DE.DP-5.1 RS.IM-1.2 RS.IM-2.1 RC.IM-1.1
ESSENTIALID.BE-1.2 PR.IP-7.2 PR.IP-7.3 PR.IP-9.2 DE.CM-2.2 DE.DP-5.2
Finland
RESPONSE-4 CRITICAL-3
Greece
Ministerial decision 1689/2025articles 23a 23e 23f
Cybersecurity HandbookPart B: 15.5
Self-assessment tool16.6
Spain
Article 2
Annex II[mp.if.1]. Separate areas with access control [mp.if.2] Identification of persons [mp.if.3] Fitting-out of premises [mp.if.4] Power supply [mp.if.5] Fire protection [mp.if.6] Flood protection [mp.if.7] Recording of entries and exits of equipment
France
2.B.2-IE/EE
3.A.1-IE/EE
3.A.2-IE/EE
12.1-EE
12.4-EE
12.5-EE
13.6-EE
14.1-IE/EE
14.4-EE
62443 ours
62443-2-1ORG 3 Security of physical access AVAIL 1 System availability and intended functionality
62443-3-3FR 7 Resource availability (RA)
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions
13.2 Protection against physical and environmental threats 21(2)(e)

Protection against fire, flood and comparable physical and environmental threats.

NIST CSF 2.0
PR.IR-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04
ETSI EN 319 401
Clause 7.6
CEN/TS 18026
PS-05
Belgium
BASICRS.IM-1.1
IMPORTANTPR.IP-5.1 PR.IP-7.1 PR.IP-9.1 DE.DP-3.1 DE.DP-5.1 RS.IM-1.2 RS.IM-2.1 RC.IM-1.1
ESSENTIALPR.IP-5.2 PR.IP-7.2 PR.IP-7.3 PR.IP-9.2 DE.DP-5.2
Finland
RISK-1 RISK-2 RISK-3 RISK-4 THREAT-2 RESPONSE-3
Greece
Ministerial decision 1689/2025articles 23a 23d 23f
Cybersecurity HandbookPart B: 15.5
Self-assessment tool16.6
Spain
Article 2
Annex II[mp.if.1]. Separate areas with access control [mp.if.2] Identification of persons [mp.if.3] Fitting-out of premises [mp.if.4] Power supply [mp.if.5] Fire protection [mp.if.6] Flood protection [mp.if.7] Recording of entries and exits of equipment
France
12.5-EE
14.4-EE
16.1-EE
20.2-EE
62443 ours
62443-2-1ORG 3 Security of physical access
62443-3-3FR 7 Resource availability (RA)
22301 ours
Clauses8.2 Business impact analysis and risk assessment 8.3 Business continuity strategies and solutions
13.3 Perimeter and physical access control 21(2)(i)

Physical perimeters, entry control and monitoring of secure areas.

NIST CSF 2.0
PR.AA-06 DE.CM-02
ETSI EN 319 401
Clause 7.6
CEN/TS 18026
PS-01 PS-02 PS-03 PS-04
Belgium
BASICID.GV-1.1 PR.AC-2.1 PR.AC-3.1 PR.AC-4.1 PR.AC-4.2 PR.AC-4.3 PR.IP-11.1
IMPORTANTID.AM-6.1 ID.GV-1.2 PR.AC-2.2 PR.AC-3.3 PR.AC-4.6 PR.AC-6.1 PR.AT-3.2 PR.DS-3.3 PR.DS-5.1 PR.IP-11.2 PR.MA-2.1 DE.CM-2.1 DE.AE-3.2 DE.CM-6.1 DE.CM-7.1
ESSENTIALPR.AC-2.3 PR.AC-2.4 PR.AC-3.4 PR.AC-4.8 PR.DS-1.1 DE.CM-2.2
Finland
RISK-1 RISK-2 RISK-3 ARCHITECTURE-3 ACCESS-3
Greece
Ministerial decision 1689/2025articles 23a 23b 23c 23f
Cybersecurity HandbookPart B: 15.1 15.2 15.3 15.4 15.6
Self-assessment tool16.1 16.2 16.3 16.4 16.5 16.7
Spain
Article 18
Annex II[mp.if.1]. Separate areas with access control [mp.if.2] Identification of persons [mp.if.7] Recording of entries and exits of equipment
France
2.B.2-IE/EE
6.1-IE/EE
6.2-EE
6.3-EE
6.4-EE
6.5-IE/EE
16.1-EE
17.3-EE
62443 ours
62443-2-1ORG 3 Security of physical access
62443-3-3FR 1 Identification and authentication control (IAC)
22301 ours
No ISO 22301 equivalent — outside the scope of a business continuity management system
The two columns that are ours

Where ENISA stops, and what we added

ENISA's nine columns leave two holes that matter to anyone actually running the programme. Nothing in them is written for a plant, and nothing in them is a continuity standard. So we added two columns of our own: ISA/IEC 62443 for operational technology, and ISO 22301 for business continuity. Both are NexGenio's work rather than a regulator's, both are marked ours wherever they appear, and the derivation of each is set out here so you can disagree with it specifically.

ISA/IEC 62443 — the OT column

Eight of the nine ENISA columns are IT frameworks and the ninth is a trust-service specification. None of them is written for a plant. Several NIS2 sectors are materially operational technology — energy, drinking water, waste water, chemicals, manufacturing, transport — and for those the relevant standard is the ISA/IEC 62443 series. ENISA does not map to it. Neither does anyone else.

Nobody has published this, so we wrote it

We checked directly against the publications of every body that might have: ENISA, the German BSI, the Austrian NIS authority, ISA and its Global Cybersecurity Alliance, and the IEC itself. None has published a clause-level crosswalk between NIS2 and the 62443 series. What circulates instead is vendor and certification-body marketing asserting that the two are “complementary”, without a table behind it.

ISA's own alliance came closest. Its June 2025 white paper Applying ISO/IEC 27001, ISO/IEC 27002 and the ISA/IEC 62443 Series for Operational Technology Environments works a single example — 62443-2-1's NET 3 Secure remote access against four ISO/IEC 27002 controls — and then says in its own “next steps” that a full element-by-element mapping could be developed. It does not exist yet.

So the column below is NexGenio's work, not a regulator's, and we have kept it visually separate from ENISA's nine for exactly that reason. It carries none of ENISA's authority. It carries our reasoning, which you can check.

The granularity is deliberate, and it is coarser than the ISO column

We map to requirement families and foundational requirementsORG 1, NET 3, FR 5, ZCR 3 — and not to individual system requirements, component requirements or SP.XX.YY service-provider requirements.

Two reasons, and the second is the honest one. First, the 62443 parts are paywalled, and the individual requirement titles are not ours to reproduce. Second, when we had those titles researched, two separate passes returned fabricated ones — invented SR names under FR3 and FR4, a mislabelled ZCR 4 and ZCR 5, and an SPE 5 that does not exist. Every identifier on this page was subsequently read off a standard's own table of contents, and anything that could not be was left out rather than guessed. A coarser mapping that is correct beats a granular one that is decorated with plausible fiction.

Parts used: 62443-2-1:2024 Edition 2.0 (asset owner security programme, the eight SPEs), 62443-3-3:2013 (the seven foundational requirements), 62443-3-2:2020 (ZCR 1–7, zones and conduits), 62443-4-1:2018 (the eight secure development practices), with 62443-2-3, 62443-2-4:2023 and 62443-4-2:2019 cited at part level where the duty falls on a service provider or a component supplier rather than on you.

A note on 62443-2-1's ISO 27001 annex, because it gets repeated wrongly

Edition 2.0 of 62443-2-1 was published on 7 August 2024 and its foreword says the requirements were revised to “eliminate duplication of an information security management system”. It ships an informative Annex A.4 cross-referencing ISO/IEC 27001. You will hear this summarised as “the new standard was built to map to ISO 27001”.

Two corrections. The foreword never names ISO/IEC 27001, and ISA's own announcement of the edition does not mention it either. And the annex maps to ISO/IEC 27001:2013 — the superseded edition, not the 2022 control set your certificate is against and not the edition ENISA mapped NIS2 to. We therefore did not route this column through that annex. Mapping NIS2 to ISO 2022 to 62443 via a 2013 crosswalk would have been quicker and quietly wrong.

Where 62443 stops

47 of the 49 requirements have a 62443 reference. Requirements 10.2 and 10.4 — background verification and the disciplinary process — have none, because 62443 is a technical and programme standard and does not reach into human resources. ISO 27001 does, via A.6.1 and A.5.28. For those two, the ISO column is the one to use.

Beyond the table, 62443 is silent on the same regulator-facing duties ISO 27001 is silent on, and for the same reason: Article 23's reporting cascade, Article 20's management body accountability and training duty, and the Article 27 registration obligation are legal obligations, not control objectives. A 62443 certificate closes none of them.

The practical three-layer framing for a plant: 62443 for the technical and programme layer, your governance function for the management body duties, and your legal or compliance function for the regulator interface. Nothing on this page collapses those three into one.

ISO 22301 — the business continuity column

Article 21(2)(c) is business continuity, backup management, disaster recovery and crisis management. The Implementing Regulation turns it into section 4 — three requirements on business continuity and disaster recovery, plus crisis management. ENISA maps no continuity standard whatsoever. Every one of its nine columns answers section 4 out of an information security framework.

Three controls against a whole management system

Look at what section 4 gets from the ISO column: A.5.29 information security during disruption, A.5.30 ICT readiness for business continuity, A.8.13 information backup. Three Annex A controls, roughly a paragraph each, and clause 8.1 for operational planning. That is the entire continuity apparatus ENISA's mapping offers.

ISO 22301:2019 answers the same three requirements with 7 clauses, because in 22301 continuity is the management system rather than one control theme inside it: 8.2 business impact analysis and risk assessment, 8.3 business continuity strategies and solutions, 8.4 business continuity plans and procedures, 8.5 exercise programme, 8.6 evaluation of documentation and capabilities, on top of 8.1.

The difference is not academic and it is where NIS2 continuity programmes usually fail an inspection. A.5.30 tells you to plan ICT readiness against business continuity objectives. It does not tell you how those objectives were derived. 8.2 does: a business impact analysis that produces prioritised activities, recovery time objectives and recovery point objectives, with the disruption tolerances written down and the dependencies identified. Requirement 4.1 of the Implementing Regulation asks for continuity plans based on the results of a business impact analysis. The word is in the regulation. It is not in ISO 27001.

The granularity is deliberate here too

We map at clause x.y and no deeper. The clause 8 titles used here were verified against the published structure of ISO 22301:2019. The sub-sub-clause titles — 8.2.2, 8.4.2 and so on — were not, so they are not used. Same discipline as the 62443 column, same reason.

Clauses 4 to 7, 9 and 10 are the Annex SL harmonised management-system clauses, shared verbatim in structure with ISO 27001, ISO 42001 and the rest. If you already hold an ISO 27001 certificate, those clauses are largely satisfied by the system you are already running. The work that is genuinely new is clause 8.

Where 22301 stops

26 of the 49 requirements have an ISO 22301 reference and 23 have none. That is the correct result, not a defect. A BCMS has nothing to say about cryptography, multi-factor authentication, network segmentation or vulnerability handling, and a column that claimed otherwise would be padding.

Read it the other way round: the clusters where 22301 lights up are section 4 in full, the impact side of section 2's risk assessment, section 3's incident handling and communication, section 12's asset criticality, and section 13's environmental and physical threats. Those are the places where an information security framework answers thinly and a continuity framework answers properly.

And as with 62443, a 22301 certificate closes none of the Article 23 reporting duties, the Article 20 management body duties or the Article 27 registration obligation. Continuity is a capability. Those are legal obligations.

Reverse index

From your Annex A control, to your NIS2 duty

If you already run an ISMS, this is the direction you actually need. Every one of the 93 ISO/IEC 27001:2022 Annex A controls, with the NIS2 requirements it serves. Controls shown in grey are not referenced anywhere in ENISA's mapping — which does not make them optional under ISO 27001, only absent from this correlation.

5A.5 Organizational31 of 37 referenced

A.5.1
Policies for information security
A.5.2
Information security roles and responsibilities
A.5.3
Segregation of duties
A.5.4
Management responsibilities
A.5.5
Contact with authorities
not referenced
A.5.6
Contact with special interest groups
not referenced
A.5.7 new in 2022
Threat intelligence
A.5.8
Information security in project management
not referenced
A.5.9
Inventory of information and other associated assets
A.5.10
Acceptable use of information and other associated assets
A.5.11
Return of assets
A.5.12
Classification of information
A.5.13
Labelling of information
A.5.14
Information transfer
A.5.15
Access control
A.5.16
Identity management
A.5.17
Authentication information
A.5.18
Access rights
A.5.19
Information security in supplier relationships
A.5.20
Addressing information security within supplier agreements
A.5.21
Managing information security in the ICT supply chain
A.5.22
Monitoring, review and change management of supplier services
A.5.23 new in 2022
Information security for use of cloud services
A.5.24
Information security incident management planning and preparation
A.5.25
Assessment and decision on information security events
A.5.26
Response to information security incidents
A.5.27
Learning from information security incidents
A.5.28
Collection of evidence
A.5.29
Information security during disruption
A.5.30 new in 2022
ICT readiness for business continuity
A.5.31
Legal, statutory, regulatory and contractual requirements
A.5.32
Intellectual property rights
A.5.33
Protection of records
not referenced
A.5.34
Privacy and protection of personally identifiable information (PII)
not referenced
A.5.35
Independent review of information security
A.5.36
Compliance with policies, rules and standards for information security
A.5.37
Documented operating procedures
not referenced

6A.6 People6 of 8 referenced

A.6.1
Screening
A.6.2
Terms and conditions of employment
A.6.3
Information security awareness, education and training
A.6.4
Disciplinary process
A.6.5
Responsibilities after termination or change of employment
A.6.6
Confidentiality or non-disclosure agreements
not referenced
A.6.7
Remote working
not referenced
A.6.8
Information security event reporting

7A.7 Physical9 of 14 referenced

A.7.1
Physical security perimeters
A.7.2
Physical entry
A.7.3
Securing offices, rooms and facilities
A.7.4 new in 2022
Physical security monitoring
A.7.5
Protecting against physical and environmental threats
A.7.6
Working in secure areas
not referenced
A.7.7
Clear desk and clear screen
A.7.8
Equipment siting and protection
not referenced
A.7.9
Security of assets off-premises
not referenced
A.7.10
Storage media
A.7.11
Supporting utilities
A.7.12
Cabling security
not referenced
A.7.13
Equipment maintenance
A.7.14
Secure disposal or re-use of equipment
not referenced

8A.8 Technological23 of 34 referenced

A.8.1
User endpoint devices
not referenced
A.8.2
Privileged access rights
A.8.3
Information access restriction
A.8.4
Access to source code
not referenced
A.8.5
Secure authentication
A.8.6
Capacity management
not referenced
A.8.7
Protection against malware
A.8.8
Management of technical vulnerabilities
A.8.9 new in 2022
Configuration management
A.8.10 new in 2022
Information deletion
not referenced
A.8.11 new in 2022
Data masking
not referenced
A.8.12 new in 2022
Data leakage prevention
not referenced
A.8.13
Information backup
A.8.14
Redundancy of information processing facilities
A.8.15
Logging
A.8.16 new in 2022
Monitoring activities
A.8.17
Clock synchronization
A.8.18
Use of privileged utility programs
A.8.19
Installation of software on operational systems
not referenced
A.8.20
Networks security
A.8.21
Security of network services
A.8.22
Segregation of networks
A.8.23 new in 2022
Web filtering
not referenced
A.8.24
Use of cryptography
A.8.25
Secure development life cycle
A.8.26
Application security requirements
not referenced
A.8.27
Secure system architecture and engineering principles
not referenced
A.8.28 new in 2022
Secure coding
not referenced
A.8.29
Security testing in development and acceptance
A.8.30
Outsourced development
A.8.31
Separation of development, test and production environments
A.8.32
Change management
A.8.33
Protection of test information
A.8.34
Protection of information systems during audit testing
The source measures

The ten measures in Article 21(2)

The Annex requirements above exist to give these ten measures operational content. This is the directive's own wording.

Text of Directive (EU) 2022/2555, Article 21(2), as published on EUR-Lex.

The gaps

What an ISO 27001 certificate does not give you

These are the NIS2 obligations with no Annex A equivalent — not because the mapping is incomplete, but because they are duties owed to a regulator rather than security controls. A perfect ISMS leaves every one of them open, and no other column in the table closes them either.

No ISO equivalent

Registration with your national authority

In-scope entities must register, provide and maintain a defined set of details, and keep them current. ISO 27001 has no concept of registering with a regulator at all.

No ISO equivalent

The incident reporting cascade

An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month, to a named CSIRT or competent authority.

  • A.5.24–A.5.28 govern internal incident handling
  • None of them sets an external clock
  • None of them names an external recipient
No ISO equivalent

Personal accountability of the management body

Article 20 requires the management body to approve the risk management measures, oversee their implementation, and be capable of being held liable for failing to do so. ISO 27001 clause 5 asks for leadership and commitment. It creates no personal liability.

No ISO equivalent

A training duty on directors themselves

Members of the management body must undergo training to acquire sufficient knowledge and skills to identify risks and assess management practices. A.6.3 covers staff awareness. It does not reach the board as a legal obligation on the individuals.

Partly covered

Supply chain security

A.5.19–A.5.22 cover supplier relationships well. Article 21(3) adds something ISO does not contemplate: entities must take into account the results of EU-level coordinated security risk assessments of critical supply chains.

Partly covered

Scope itself

An ISMS protects the scope you define. NIS2 defines your scope for you, by sector and size, and adds entities regardless of size. An ISO 27001 scope statement drawn too narrowly is a common and expensive finding.

On the “ISO 27001 gets you 70% of the way there” figure

You will see that number, or something near it, on a lot of vendor pages. We looked for the calculation behind it. There isn't one. The figure recurs across at least eight vendors and consultancies, several of which describe it themselves as a rule of thumb, and no regulator or standards body has published a percentage at all. ENISA, which is the only body to have published an actual mapping, explicitly declines to assess coverage.

So we are not going to give you a number. The list above is the honest version of the same answer, and it is more useful, because you can act on a list.

Editor's notes

Where we departed from the original file

Reproducing a regulator's table means saying exactly what you changed. Four things, and then two additions:

  • Typography, normalised. ENISA's spreadsheet renders several control references with a Greek capital alpha in place of a Latin A (Α.5.19, Α.8.2 and others), and prints some with stray spaces — “A.5 .24”, “A. 7.11”, “A5.7”. These are transcription artefacts. We have normalised them; no reference was changed.
  • One bare reference, resolved. Requirement 10.4, disciplinary process, lists “5.28, A.6.4”. There is no clause 5.28 in ISO/IEC 27001:2022, and A.5.28 is Collection of evidence, which fits a disciplinary process. We read it as A.5.28 and flag it here.
  • One reference we left alone. Requirement 12.5, deposit, return or deletion of assets on termination, lists A.8.24 Use of cryptography. A.8.10 Information deletion would appear to be the closer fit. We have reproduced ENISA's reference as published rather than substitute our own judgement.
  • Control names, added. ENISA's file gives reference numbers only. The ISO Annex A control titles shown here are the standard's own short titles, added so the table can be read without the standard open beside you. ISO/IEC 27001:2022 is a copyrighted document and its full control text is not reproduced. For the other eight frameworks ENISA's own reference strings are reproduced as printed, without expansion.

Two columns are additions, not reproductions. ENISA's table has nine framework columns. This page has eleven. The ISA/IEC 62443 and ISO 22301 columns are NexGenio's own work — no regulator or standards body has published either mapping — and they are marked ours on every row, rendered in a separate tinted block, and listed separately in the framework legend. They carry none of ENISA's authority, and the reasoning behind both, including where each stops, is set out in full above.

The Article 21(2) linkage in each requirement header is ours, derived from the Annex's own wording — each requirement opens “For the purpose of Article 21(2), point (x) of Directive (EU) 2022/2555”. The plain-language line under each requirement title is ours too, and is a summary rather than a substitute for the requirement text.

Found something wrong? Tell us and we will correct it and say so here.

Questions

Common questions about this mapping

Does ISO 27001 certification make us NIS2 compliant?
No, but it takes you a long way. ISO/IEC 27001:2022 addresses the substance of most of the 49 requirements and produces the documentation a supervisor will ask to see. It does not address the registration duty, the incident reporting timelines to your national CSIRT, or the personal accountability and training duty Article 20 places on your management body. Those four sit outside any ISMS control. The practical route for most organisations is to keep the ISMS as the engine and bolt the regulatory duties on as a defined, evidenced layer.
Which frameworks does ENISA's mapping table cover?
Nine, and all nine are on this page. Four are standards or specifications — ISO/IEC 27001:2022, the NIST Cybersecurity Framework 2.0, ETSI EN 319 401 V3.1.1 for trust service providers, and CEN/TS 18026:2024. Five are national frameworks published by Member States: Belgium's CyberFundamentals (CyFun®), Finland's Kybermittari, Greece's Ministerial Decision 1689/2025, Spain's Esquema Nacional de Seguridad under Royal Decree 311/2022, and a French column that ENISA labels only “FR”. Use the framework buttons above the table to show the columns you need side by side.
Is there a NIS2 to ISA/IEC 62443 mapping for OT?
There is now, on this page, and as far as we can establish it is the first one published. We checked ENISA, the German BSI, the Austrian NIS authority, ISA and its Global Cybersecurity Alliance, and the IEC directly — none has published a NIS2 to 62443 crosswalk. ISA's own alliance white paper of June 2025 works one example and then says a full mapping “could be developed”. So the 62443 column here is NexGenio's work rather than a regulator's, it is marked as such throughout, and how we derived it is set out in full, including why it is mapped at requirement-family level rather than to individual system requirements.
Why is there an ISO 22301 column when ENISA does not have one?
Because Article 21(2)(c) is business continuity, backup management, disaster recovery and crisis management, and ENISA correlates it to no continuity standard at all. Every one of its nine columns answers section 4 of the implementing regulation out of an information security framework. From ISO 27001 that means three Annex A controls — A.5.29, A.5.30 and A.8.13 — of roughly a paragraph each. ISO 22301:2019 answers the same requirements with the whole of clause 8, including the business impact analysis that produces your recovery time and recovery point objectives. Requirement 4.1 asks for continuity plans based on the results of a business impact analysis; that term appears in ISO 22301 and not in ISO 27001. How we built the column is set out in full.
Who produced this mapping — ENISA or NexGenio?
Both, and the page keeps them apart. The correlation between each NIS2 requirement and ENISA's nine frameworks is ENISA's, published as version 1.1 of its mapping table on 10 July 2025. We reproduced every column, added the ISO Annex A control titles, added the Article 21(2) linkage from the Annex's own wording, wrote the plain-language summaries, built the reverse index, and documented where we departed from the original file. Two further columns — ISA/IEC 62443 and ISO 22301 — are entirely ours; ENISA maps neither. They carry an ours badge everywhere they appear. Anything you would want to check independently is linked to source.
We are a hospital, not a cloud provider. Does the implementing regulation apply to us?
Not directly. Commission Implementing Regulation (EU) 2024/2690 binds a defined set of digital entities — cloud, data centre, CDN, DNS, TLD registries, managed service and managed security service providers, online marketplaces and search engines, social platforms and trust service providers. For every other sector it is the most detailed reading the Commission has published of what Article 21(2) requires, and authorities and auditors treat it as the reference point. Your legally operative text is your national implementing law.
Why are some Annex A controls not referenced at all?
Because ENISA mapped in one direction: from each NIS2 requirement to the references that speak to it. Controls with no NIS2 requirement pointing at them simply did not come up. It says nothing about whether the control is necessary for your ISMS — that follows from your own risk assessment and Statement of Applicability, not from this table.
Can we use this as evidence for a supervisor?
Use it as a navigation aid, not as evidence. ENISA states plainly that the table is not a measure of equivalency and does not assess whether the referenced standards fully cover the regulation, and that it is advisory rather than binding. What a supervisor will want is your own gap assessment against the requirements that apply to you, with the evidence behind each one. This page is a good place to start that work and a poor place to end it.
What about OT and industrial environments?
None of ENISA's nine columns is an OT standard. ISO 27001 was written for information security management and carries real limitations in plant and process environments, where availability and safety outrank confidentiality and where you cannot patch a running line. Several NIS2 sectors are materially OT — energy, drinking water, waste water, manufacturing, transport. The ISA/IEC 62443 series is the relevant standard there, and the 62443 column on this page is our attempt at it. If that is your situation, say so on the call and we will route it accordingly.

Sourced from ENISA's mapping table version 1.1 (10 July 2025) and Commission Implementing Regulation (EU) 2024/2690. This page is reviewed when either source is revised. Last reviewed 16 September 2026.

Knowing the mapping is not the same as closing the gap

A short call establishes which of the 49 requirements actually apply to you, what your existing framework already covers, and what is genuinely missing. From there the Baseline Check gives you something you can take to your board.

Book a scoping call