What an ISMS is, and why you only need one

An ISMS is how you manage information security on purpose.
Build one, not four. ISO 27001, NIS2, NEN 7510 and BIO2 all read from the same system.
All inside your own Microsoft 365 environment
✓ Evidence builds as you work, not the week before the audit
✓ Your evidence stays in your tenant, nothing on our servers
✓ 87% first-time audit pass rate

See how one ISMS covers four frameworks

ISOPlanner™ wordt vertrouwd door 600+ bedrijven

Ondersteuning voor 50+ normen
Where the work gets shared, not repeated

How ISOPlanner™ Runs One ISMS Across Frameworks

Sharing an ISMS across frameworks only works if the sharing is structural. If scope, risk and evidence exist once and are read many times, adding a framework is a mapping exercise. If they are copied, you have four systems wearing one name and four times the maintenance. These five are where that difference actually lives.

Principle

How this works in an ISMS

One scope, inherited everywhere

You set the ISMS boundary once, and every asset, risk, control and task inherits it. NIS2 is the exception: its scope is set by law, so the job is making sure your boundary covers it rather than defining it. Nothing gets re-scoped per framework.

One risk register, many mappings

A risk is assessed once. Its treatment maps across Annex A, the NIS2 Article 21 measures, NEN 7510-2 and the BIO2 government measures, so adding a framework is a mapping exercise rather than a second project.

Evidence as a by-product

Records accumulate from the work itself rather than being assembled before an audit. That matters most for NIS2, which never tells you to keep records but lets a supervisor demand your audit results and the evidence underneath them.

One audit calendar

Internal audits, management reviews and corrective actions run on one schedule serving every framework in scope, instead of one cycle per certificate.

Ownership that holds outside the compliance team

Tasks land with the people who do the work, in the tools they already use. Adoption outside the compliance team is where multi-framework programmes usually fail, and a better framework map cannot fix it.

Whichever of the four brought you here, the system underneath is the same one. Build it once and the next framework is a mapping exercise. Build it four times and you will spend years keeping four copies in agreement.
Where the four agree, and where they don't.

What Every ISMS Needs

Six things, whichever framework brought you here. The columns show what each one calls them and where they differ, because the differences are the part worth knowing.

The boundary. Which parts of the organisation, which systems and which information the ISMS covers.

ISO 27001

Clause 4.3. You set it, and you defend it.

BIO2

As ISO 27001, within government scoping rules.

NEN 7510

Clause 4.3, as ISO 27001.

NIS2

Set by law, not by you. Sector and size decide (Articles 2 and 3, Annexes I and II).

A named owner senior enough to decide, who approves the measures and answers for them.

ISO 27001

Clause 5. Commitment, policy, assigned roles.

BIO2

As ISO 27001.

NEN 7510

Clause 5, as ISO 27001.

NIS2

Article 20. Management bodies approve the measures, oversee implementation, can be held liable, and must follow training.

A current view of what could go wrong, how likely it is, and what it would cost.

ISO 27001

Clause 6.1.2. Identify, analyse, evaluate.

BIO2

As ISO 27001.

NEN 7510

Clause 6.1.2, plus healthcare-specific risk.

NIS2

Article 21(2)(a). Policies on risk analysis and information system security, on an all-hazards basis.

The measures you put in place, and the recorded reasoning for the ones you did not.

ISO 27001

Clause 6.1.3 and the Statement of Applicability, against Annex A.

BIO2

ISO 27002 plus mandatory BIO2 government measures.

NEN 7510

Clause 6.1.3, with the NEN 7510-2 control set.

NIS2

Article 21(2)(b) to (e) and (g) to (j). Ten named measures, from incident handling to multi-factor authentication.

Records showing the system is running, available when somebody asks rather than assembled afterwards.

ISO 27001

Clause 7.5, documented information.

BIO2

As ISO 27001.

NEN 7510

Clause 7.5, as ISO 27001.

NIS2

No records clause exists. The words "documented information", "records" and "documentation" do not appear as obligations anywhere in the Directive. Supervisors may still demand audit results and the underlying evidence.

A regular check that it still works, and a route to fix it when it does not.

ISO 27001

Clause 9.2 internal audit, 9.3 management review.

BIO2

As ISO 27001.

NEN 7510

Clauses 9.2 and 9.3.

NIS2

Article 21(2)(f). Policies and procedures to assess the effectiveness of the measures. Article 21(4) requires corrective action once a gap is found.

Why one ISMS is the way

One ISMS, Four Frameworks

The reason one ISMS can carry four frameworks is not that we are clever about it. It is that two of the four say so themselves.

ISO 27001 Defines the System

ISO 27001 is the reference standard. It defines what a management system for information security must contain, in clauses 4 to 10, and the other three either build on it or describe the same machine in different words.

1
Embedded ML
API Calling ML
2

BIO2 Requires it by Name

BIO2 works by having you apply NEN-EN-ISO/IEC 27001 to establish the management system, then NEN-EN-ISO/IEC 27002 plus the mandatory government measures to select controls. A government body complying with BIO2 is, by definition, running an ISO 27001 ISMS. BIO2 became legally binding on 15 August 2026 through the Cyberbeveiligingswet, and BIO 1.04zv has lapsed.

NEN 7510 is It, Plus Healthcare

NEN 7510 is the same move for healthcare. NEN 7510-1:2024 contains the normative provisions for the management system according to ISO 27001, with sector additions in NEN 7510-2. It is not a parallel standard. It is ISO 27001's management system with healthcare requirements layered on.

3
ML Platform
API Calling ML
4

NIS2 Asks for It without Saying So

NIS2 is the interesting one, because it is not a management system standard at all. It is a set of obligations. But its obligations describe the same machine: management that approves and oversees, risk analysis, a named set of measures, and a way to assess whether they work. What NIS2 never does is tell you to keep records. It simply assumes a supervisor can ask for the results of a security audit and the evidence underneath it.

Three starting points

Where to Start

If you have no ISMS yet
Instant 27001 delivers a complete, auditor-tested ISMS into ISOPlanner™ with roughly 80% of the work already done, controls mapped and requirements structured. Certification inside three months, without a full compliance team.

If you have one and it has outgrown its spreadsheets
The usual state is a real ISMS that lives in one person's files. Moving it into ISOPlanner™ makes it survivable when that person is on holiday, and auditable without three weeks of preparation.

If a second framework just landed on you
This is the situation this page is written for. Do not start again. Map what you already have.
Boek een demo
Answered

Frequently Asked Questions