NIST CSF vs ISO 27001: which framework fits an EU company

One certifies and one does not, which decides the question faster than any feature comparison.
August 25, 2026
Ivar van Duuren

The short answer for Europe

If a customer, an insurer or a regulator has asked you for proof, you want ISO 27001. It certifies, a European buyer recognises it without a conversation, and it is the one that closes procurement questions.

NIST CSF does not certify. There is no certificate to send anyone. It is a framework for organising security work, published by a United States federal agency, and it is genuinely good at that job.

So the comparison people search for is rarely the choice they face. The real question is whether you need something to show, or something to follow.

And for a growing number of European companies there is a third answer, which is neither, because the decision has already been made for you. If NIS2 applies to your organisation, this stopped being a framework choice. It is law.

Where the two actually differ

ISO 27001 asks for a management system. A scope, a risk method, a set of controls you selected with reasons, evidence that you operate them, and an internal audit and review cycle. An external auditor then checks it and issues a certificate valid for three years with surveillance in between.

NIST CSF asks nothing of you. It offers six functions, Govern, Identify, Protect, Detect, Respond and Recover, and a way to describe your current and target state against them. No scope statement, no auditor, no certificate, no cost beyond your own time.

That difference explains the usual pattern. NIST CSF is excellent at working out what to do next. ISO 27001 is what you need when someone else has to be satisfied. They are not competitors so much as different stages of the same effort.

One practical note for European readers: CSF is written in American regulatory language and maps to American reference catalogues. Nothing stops you using it, and you will translate as you go.

NIS2 is not a framework choice

Both frameworks are voluntary. NIS2 is not.

NIS2 is an EU directive, so it does not bind you directly. Each member state writes it into national law, and that national law is what you answer to. If you are in scope you are not selecting a framework. You are meeting statutory duties, and a supervisor can ask you to show them.

Four duties recur across member states even where the enforcement does not. Take and document risk management measures. Register with a national authority. Report a significant incident on a short clock, usually an early warning inside 24 hours and a fuller notification inside 72. And accept that accountability sits with the management body, which is the part organisations underestimate, because several national laws allow a director to be held personally liable.

Scope splits broadly into essential entities, in sectors such as energy, transport, banking, health, water and digital infrastructure, and important entities, a wider group covering postal services, waste, chemicals, food production and digital providers. Essential entities get proactive supervision, important entities reactive. Most national laws start at around fifty staff or ten million euro in turnover, with some categories in scope at any size.

This is where the framework comparison stops being the interesting question. An ISO 27001 certificate is strong evidence of a working management system. It does not register you, it does not report your incident inside 24 hours, and it does not make your board engaged. Neither does a CSF profile. A framework helps you meet the duties. It does not discharge them.

In the Netherlands it is the Cyberbeveiligingswet

In the Netherlands, NIS2 is implemented as the Cyberbeveiligingswet, and that is the law Dutch organisations are actually held to. It sets out four duties.

Zorgplicht. Assess the risks to your networks and systems and take appropriate measures. The published list is a minimum rather than a complete set, so what counts as appropriate depends on your own risk profile.

Registratieplicht. Organisations in scope register with the government, via mijn.ncsc.nl.

Meldplicht. A significant incident is reported within 24 hours, followed by a fuller report within 72 hours and a final report after that.

Bestuurdersaansprakelijkheid. The management body is ultimately accountable, and the law makes it possible to fine directors personally.

The RDI supervises the law and the NCSC runs the registration portal. Two things catch organisations out. Registration is not a form you fill in once, because changes have to be reported, so it stays a live obligation. And portal access runs through eHerkenning, which is not something you arrange on the day you need it.

The Dutch law does not require certification. It requires appropriate measures and the ability to show them. An ISO 27001 management system is a well-understood way to produce that evidence, and if you already hold NEN 7510 in healthcare you are most of the way there.

One member state went further, and it named ISO 27001

Worth knowing if you sell across the border. Belgium was the first member state to fully implement NIS2, and its Royal Decree makes conformity assessment mandatory for essential entities. It names exactly two reference frameworks that can be used: CyberFundamentals, published by the Centre for Cybersecurity Belgium, and ISO/IEC 27001.

Which is the sharpest fact in this comparison. In none of the national NIS2 laws is NIST CSF a named route. In Belgium, ISO 27001 is written into the law itself.

When NIST CSF earns its place

With the legal picture set out, CSF is easier to place. It is not what you show a European regulator. It is a good way to organise the work a regulator, or a customer, will eventually ask about.

Three situations where reaching for CSF first is the better call.

You have no structure yet and no deadline. CSF gives you a way to see the whole surface and pick an order, without committing to an audit you are not ready for. Pair it with CIS Controls implementation group one and you have a work list rather than a reading list.

You sell into the United States, or your parent does. Then CSF is the vocabulary your counterpart already uses, and describing yourself in it saves a translation on every call.

You already hold ISO 27001 and want a sharper view of detection and response. This is where CSF is genuinely additive: ISO 27001 will pass you with a thin Detect capability, and CSF makes that thinness visible. If you are in NIS2 scope that matters more than it sounds, because Detect, Respond and Recover is the exact ground a 24-hour reporting duty stands on.

CSF 2.0 also promoted Govern to a function in its own right, which is the closest either framework comes to the accountability NIS2 puts on your board.

And the case against, stated plainly. If a prospect is holding a security questionnaire, a CSF profile does not answer it. You cannot send a target state to procurement. And it is not a recognised conformity route under any national NIS2 law.

Running either one in practice

Whichever you pick, the work underneath is the same, and this is the part that decides whether it survives.

An asset inventory. A risk assessment you revisit rather than write once. Controls with evidence attached to them. Suppliers on record. An incident process someone has rehearsed. A review cadence that happens. Both frameworks describe these; neither performs them.

ISOPlanner™ runs inside Microsoft 365, so the register, the evidence and the supplier records sit in the tenant your team already signs into. One control can serve an ISO 27001 requirement and map to a CSF function at the same time, which matters if you use CSF to plan and ISO 27001 to certify.

That matters more once a law is involved. In NIS2 scope, the same register of risks, controls and evidence is what backs your appropriate measures, what you draw on when an incident clock starts, and what you put in front of a supervisor. ISOPlanner™ supports ISO 27001, NIS2, NEN 7510 and CyberFundamentals from the same environment, so a control you have already evidenced does not need evidencing again for the next framework or the next regulator.

That combination is the honest recommendation for most European SMEs. Use CSF to decide what to do next. Certify to ISO 27001 when someone needs proof. Register and report if the Cyberbeveiligingswet applies to you. Keep one set of evidence underneath all three, because maintaining two is how programmes quietly stop being maintained at all.

Not set. No Coffee Sessions clip exists for this topic. Fill when Beat 3 gets its footage.
See how one control serves both

Related Posts