A risk management framework is a repeatable method for finding risks, rating them, deciding what to do about each one, and showing your work later. That last part is what turns a framework from a good habit into something an auditor or a customer accepts.
For a European SME the real choice is narrower than the literature suggests. Three options cover almost every case.
Pick ISO 27001 if a customer, an insurer or a regulator wants proof. It is certifiable, it is recognised across the EU, and its companion standard ISO 27005 gives you the risk method itself. This is the usual answer when someone has asked you for a certificate.
Pick NIST CSF if you want structure without an audit. It is free to use, it organises security work into six functions, and nobody issues a certificate for it. Good for getting your bearings, weak as an answer to a procurement questionnaire.
Pick NIS2 if it applies to you. It arrives as an obligation in law rather than a standard you buy, and it is worked in practice as a framework: a defined set of risk management measures you implement, evidence and can be inspected against. Supply chain security is one of those duties, which is why supplier records, processing agreements and supplier assessments belong inside the same system as the rest of your risk work rather than in a separate folder.
Pick NIS2 Supply Chain if you are the supplier rather than the in-scope entity. This is the one most comparisons miss. It is a certifiable scheme with independent audit, aimed at NIS2 in-scope organisations and at the far larger group of companies that supply them, and it comes in three risk-tiered levels. SC10 BASIC is sized for SMEs, SC20 SUBSTANTIAL for higher risk, SC30 HIGH for critical suppliers. If your customer is in scope for NIS2 and has started sending you questionnaires, this is the framework built for your side of that conversation.
Two clarifications that save wasted effort. ISO 31000 comes up in every search on this topic and is genuinely the standard about risk management, but it gives you principles and a process rather than a control list, and nobody certifies you against it. Treat it as the umbrella above a security framework, not as an alternative to one. And if you already hold ISO 9001, its clause on risk-based thinking is the cheapest place to start, because the habit and the review cadence already exist.
Compare frameworks on two axes and the field thins out quickly. Scope is what the framework covers. Effort is what it costs you to run, which is the axis most vendor comparisons skip.
ISO 27001 covers information security management. Its scope is the ISMS you define, which can be one product line rather than the whole company. Effort is the highest of the three: a risk assessment, a treatment plan, a set of controls with evidence, an internal audit, a management review, then an external audit in two stages. Recertification runs on a three-year cycle with surveillance visits between. In return it is the one an EU buyer recognises without explanation.
NIS2 covers the risk management measures the directive requires of in-scope organisations, including incident handling, business continuity and supply chain security. Effort depends on where you start: an organisation already running ISO 27001 is most of the way there, and one starting from nothing is not. It is enforced rather than optional, so for in-scope companies it is not really a choice.
NIS2 Supply Chain covers the supplier side of the directive. Scope is your own security posture as a supplier to an in-scope customer. Effort is tiered on purpose: SC10 is the entry level for an SME and SC30 is for critical suppliers, so the cost scales with the risk you actually carry rather than with the size of the standard. It is certifiable with an independent audit, which is the difference between answering a questionnaire and being able to point at a certificate.
ISO 9001 covers quality management and carries risk-based thinking as a requirement rather than a full risk framework. Effort is low if you already hold it, because you are extending an existing management system rather than starting one. Worth naming because many EU SMEs already have it and do not realise they have somewhere to put risk work.
ISO 31000 covers risk anywhere in the organisation. Effort is moderate and mostly intellectual: there is no control set to implement and no audit to pass, so the cost is the discipline of actually running the process. It will not satisfy a customer asking for security assurance, and no certificate exists, which is why it belongs in this comparison as context rather than as a candidate.
NIST CSF covers cyber security activity, organised under Govern, Identify, Protect, Detect, Respond and Recover. Effort is low to start because you can self-assess against it in a workshop. There is no certificate, so the effort buys you clarity rather than proof.
CIS Controls is worth knowing even though it is not a risk method. It is a prioritised list of technical controls in three implementation groups, and the first group is deliberately sized for organisations without a security team. Many SMEs get more security per hour from CIS than from any framework, then adopt a framework later when someone asks for one.
Two more come up in searches and rarely fit an SME. COSO ERM is built for boards and financial reporting. FAIR expresses risk in money, which is genuinely useful and needs loss data plus a trained analyst.
Then there are sector overlays that sit on top rather than replacing your choice. IEC 62443 for industrial and OT environments. NEN 7510 for Dutch healthcare. ISO 42001 for AI management systems.
Four mistakes account for most of the wasted money we see.
Picking the largest framework because it looks the most thorough. Scope is a decision you make, not a size you inherit.
Treating a framework as software. No tool implements a framework for you. Tools reduce the administrative cost of running one, which is a real saving and a different claim.
Confusing an obligation with a framework, then trying to get certified against NIS2. You cannot. You demonstrate that your risk management meets its requirements, usually by pointing at a framework.
Buying a tool before setting scope. Scope determines the size of your risk register, and the register is the thing you will live with.
The honest version of the effort question is this. The framework is not the work. The risk register, the evidence and the review cadence are the work, and they continue after the certificate arrives.
Framework documents describe a process. Here is what the process looks like at the size most readers are actually working at, using the ISO 27001 route because it is the one with an audit at the end.
Start with what you are protecting. A first asset inventory for a 40 person company usually lands between 60 and 120 entries once you count systems, data stores, suppliers and the laptops. It is smaller than people fear and larger than the spreadsheet they started with.
Name risks against those assets, specifically. "Risk of a data breach" cannot be treated because it cannot be tested. "Unauthorised access to the customer database through a shared administrator account" can: you can see the account, you can see who knows the password, and you can close it this week.
Rate each risk on likelihood and impact using a scale you write down. The scale matters less than using the same one every time, because comparability is what makes the register useful in a year.
Decide a treatment for each risk, and accept that accepting a risk is a legitimate treatment when the owner records why. Auditors object to unrecorded decisions far more often than to accepted risks.
Assign an owner and a review date. This is the step that separates a live register from a document written for an audit, and it is the step most often skipped.
Review on a cadence you can sustain. Quarterly for the top risks and annually for the rest is achievable without a dedicated hire.
A first pass at this takes a few working days spread over a few weeks, and the second pass takes hours because the structure already exists. The recurring cost is the review, not the setup.
Answer these in order and stop at the first yes.
Has a customer, insurer or regulator asked you for proof? Choose ISO 27001, and use ISO 27005 for the risk method. This covers most SMEs who are reading about frameworks in the first place, because the search usually starts with a questionnaire.
Are you a supplier to a company in scope for NIS2, and getting questionnaires because of it? Look at NIS2 Supply Chain, starting at the SC10 level. It is the only certifiable answer on this list built for the supplier side rather than the in-scope entity, which is where most EU SMEs actually sit.
Are you in scope for NIS2 yourself? Then the measures are not optional, and the practical route is to run NIS2 as your framework, with supplier records and assessments held in the same place as the rest of the risk work rather than alongside it.
Do you already hold ISO 9001? Start there. Its risk-based thinking clause gives you a home for risk work inside a management system your team already runs, which is cheaper than standing up a second one.
Do you need risk coverage beyond IT, for example financial or operational risk the board watches? ISO 31000 is the umbrella for that, kept above a security framework rather than instead of it.
Do you want structure now with no audit and no budget? Start with NIST CSF for the shape and CIS Controls implementation group one for the actual work. Revisit in a year.
Are you in a regulated sector? Add the overlay that applies, IEC 62443, NEN 7510 or ISO 42001, on top of the answer above rather than in place of it.
If your answer was ISO 27001, the next thing to look at is not another framework comparison. It is a risk assessment in the shape an auditor expects, with assets linked to risks, owners named and treatments recorded against the controls they satisfy. ISOPlanner™ runs that inside Microsoft 365, so the register lives in the SharePoint your team already uses and the review tasks land in Outlook instead of a system nobody opens between audits.
See a worked ISO 27001 risk assessment, then decide whether the framework question is really still open.
Log in to your ISOPlanner™ workspace, or start a free trial.
Log in Start your free trial