You set the ISMS boundary once, and every asset, risk, control and task inherits it. NIS2 is the exception: its scope is set by law, so the job is making sure your boundary covers it rather than defining it. Nothing gets re-scoped per framework.
A risk is assessed once. Its treatment maps across Annex A, the NIS2 Article 21 measures, NEN 7510-2 and the BIO2 government measures, so adding a framework is a mapping exercise rather than a second project.
Records accumulate from the work itself rather than being assembled before an audit. That matters most for NIS2, which never tells you to keep records but lets a supervisor demand your audit results and the evidence underneath them.
Internal audits, management reviews and corrective actions run on one schedule serving every framework in scope, instead of one cycle per certificate.
Tasks land with the people who do the work, in the tools they already use. Adoption outside the compliance team is where multi-framework programmes usually fail, and a better framework map cannot fix it.
The boundary. Which parts of the organisation, which systems and which information the ISMS covers.
Clause 4.3. You set it, and you defend it.
As ISO 27001, within government scoping rules.
Clause 4.3, as ISO 27001.
Set by law, not by you. Sector and size decide (Articles 2 and 3, Annexes I and II).
A named owner senior enough to decide, who approves the measures and answers for them.
Clause 5. Commitment, policy, assigned roles.
As ISO 27001.
Clause 5, as ISO 27001.
Article 20. Management bodies approve the measures, oversee implementation, can be held liable, and must follow training.
A current view of what could go wrong, how likely it is, and what it would cost.
Clause 6.1.2. Identify, analyse, evaluate.
As ISO 27001.
Clause 6.1.2, plus healthcare-specific risk.
Article 21(2)(a). Policies on risk analysis and information system security, on an all-hazards basis.
The measures you put in place, and the recorded reasoning for the ones you did not.
Clause 6.1.3 and the Statement of Applicability, against Annex A.
ISO 27002 plus mandatory BIO2 government measures.
Clause 6.1.3, with the NEN 7510-2 control set.
Article 21(2)(b) to (e) and (g) to (j). Ten named measures, from incident handling to multi-factor authentication.
Records showing the system is running, available when somebody asks rather than assembled afterwards.
Clause 7.5, documented information.
As ISO 27001.
Clause 7.5, as ISO 27001.
No records clause exists. The words "documented information", "records" and "documentation" do not appear as obligations anywhere in the Directive. Supervisors may still demand audit results and the underlying evidence.
A regular check that it still works, and a route to fix it when it does not.
Clause 9.2 internal audit, 9.3 management review.
As ISO 27001.
Clauses 9.2 and 9.3.
Article 21(2)(f). Policies and procedures to assess the effectiveness of the measures. Article 21(4) requires corrective action once a gap is found.
ISO 27001 is the reference standard. It defines what a management system for information security must contain, in clauses 4 to 10, and the other three either build on it or describe the same machine in different words.


BIO2 works by having you apply NEN-EN-ISO/IEC 27001 to establish the management system, then NEN-EN-ISO/IEC 27002 plus the mandatory government measures to select controls. A government body complying with BIO2 is, by definition, running an ISO 27001 ISMS. BIO2 became legally binding on 15 August 2026 through the Cyberbeveiligingswet, and BIO 1.04zv has lapsed.
NEN 7510 is the same move for healthcare. NEN 7510-1:2024 contains the normative provisions for the management system according to ISO 27001, with sector additions in NEN 7510-2. It is not a parallel standard. It is ISO 27001's management system with healthcare requirements layered on.


NIS2 is the interesting one, because it is not a management system standard at all. It is a set of obligations. But its obligations describe the same machine: management that approves and oversees, risk analysis, a named set of measures, and a way to assess whether they work. What NIS2 never does is tell you to keep records. It simply assumes a supervisor can ask for the results of a security audit and the evidence underneath it.
01.
What does ISMS stand for?
Information Security Management System.
02.
Is an ISMS the same as ISO 27001?
No. The ISMS is the system; ISO 27001 is the standard that says what it must contain and against which it can be certified.
03.
Do I need a separate ISMS for NIS2?
No. NIS2 is a set of obligations rather than a management system standard, and its obligations are met by the ISMS you already run.
04.
Does NEN 7510 require its own management system?
No. NEN 7510-1:2024 contains the normative provisions for the management system according to ISO 27001, with healthcare additions in NEN 7510-2.
05.
What changed with BIO2?
BIO2 became legally binding on 15 August 2026 through the Cyberbeveiligingswet, and it requires an ISO 27001 ISMS by reference. BIO 1.04zv has lapsed.
06.
Is a CSMS the same as an ISMS?
No. CSMS is the term used for industrial systems under IEC 62443-2-1 and for vehicle type approval under UN Regulation No. 155. An ISMS manages information security; a CSMS covers operational technology or vehicle platforms.
07.
How long does it take to set one up?
Yes. Documents are already in SharePoint and identity in Entra ID, so the ISMS becomes a management layer over records you are already producing.
08.
Can an ISMS live in Microsoft 365?
With Instant 27001, about three months, starting from roughly 80% of the work already done.
Log in to your ISOPlanner™ workspace, or start a free trial.
Log in Start your free trial