Antonio Tejeda Encinas CEO META Channel corp. President of the Comité Euro Americano de Derecho Digital –CEA Digital Law.
LET’S NOT CONFUSE!
Parallelism and Complementarity between NIS2, ISO/IEC 27001 and NIST CSF 2.0: A Comprehensive Framework for Cybersecurity in Europe
With the growing importance of cybersecurity in Europe, it is essential to understand the differences and complementarities between these three frameworks:
NIS2 (European Network and Information Systems Security Directive)
– Nature: Legal and regulatory directive of the European Union.
– Aim: Guarantee a minimum level of cybersecurity in critical infrastructures and essential sectors (energy, health, transportation, etc.).
– Mandatory: Mandatory compliance for all member states and companies in critical sectors.
– Coverage: Protecting the security of essential infrastructure and digital services.
– Applicable: Starting in October 2024.
ISO/IEC 27001 (Information Security Management System)
– Nature: VOLUNTARY international standard.
– Aim: Create a security management system that guarantees the confidentiality, integrity and availability of information.
– Mandatory: Voluntary, based on certification.
– Coverage: Applicable to any type of organization that wants to structure its security based on its specific risks.
– Applicable: Last update in October 2022.
NIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework)
– Nature: Cybersecurity management framework developed in the US.
– Aim: Provide good practices to manage risks and improve the security posture in organizations.
– Mandatory: Voluntary, adopted by many companies as a reference standard.
– Coverage: Adaptable approach for all types of organizations, from small businesses to large corporations.
– Applicable: Draft version 2.0 presented in October 2024.
Why is it important? 🔍👇
Although they all address cybersecurity, NIS2 establishes a mandatory legal framework to protect critical infrastructure in Europe. While ISO 27001 and NIST CSF 2.0 are voluntary guidelines that allow companies to structure their security according to their own risks and objectives.
💡 Together, these frameworks do not replace each other, but rather complement each other to build a comprehensive cybersecurity environment in the region.

