Where NIS2 overlaps with GDPR, DORA and ISO 27001
For each of the 10 NIS2 areas find the closest counterpart in GDPR, DORA, ISO/IEC 27001:2022, NIST CSF 2.0 and CIS Controls v8, with a reference to the specific article or control and a qualitative link level.
Matrix NIS2 → GDPR × DORA × ISO 27001
Every NIS2 area is mapped to the closest article or control in the other frameworks together with a qualitative link level.
The AI Act column is qualitative, with no percentages: it shows in which NIS2 area a deployer obligation under the AI Act meets an NIS2 measure and a GDPR duty.
| Area | NIS2 | GDPR | DORA | ISO 27001 | NIST CSF | CIS v8 | AI Act |
|---|---|---|---|---|---|---|---|
| Governance & leadership | Art. 20 | Partial link Art. 24, Art. 32(4) | Partial link Art. 5 | Partial link A.5.1-5.4 | Partial link GV.OC, GV.RR | No link — | No link — |
| Risk management | Art. 21(1)-(2) | Partial link Art. 32(1), Art. 35 | Partial link Art. 6-16 | Partial link Clause 6.1, A.5.7 | Partial link GV.RM, ID.RA | Partial link CIS 7 | Partial link Art. 26(9), Art. 27(1), Art. 27(4) |
| Incident handling | Art. 23 | Partial link Art. 33, Art. 34 | Partial link Art. 17-19 | Partial link A.5.24-5.28 | Partial link DE.CM, DE.AE, RS.MA, RS.CO | Partial link CIS 17 | Partial link Art. 26(5), Art. 26(6) |
| Business continuity | Art. 21(2)(c) | Partial link Art. 32(1)(b), Art. 32(1)(c) | Partial link Art. 11, Art. 12 | Partial link A.5.29-5.30, A.8.13-8.14 | Partial link RC.RP, RC.CO | Partial link CIS 11 | No link — |
| Supply chain security | Art. 21(2)(d) | Partial link Art. 28, Art. 46 | Partial link Art. 28-30 | Partial link A.5.19-5.23 | Partial link GV.SC | Partial link CIS 15 | Partial link Art. 15(1), Art. 15(5) |
| Access control | Art. 21(2)(i)-(j) | Partial link Art. 32(1)(b) | Partial link Art. 9(4)(c), Art. 9(4)(d) | Partial link A.5.15-5.18, A.8.2-8.5 | Partial link PR.AA | Partial link CIS 5, CIS 6 | No link — |
| Cryptography | Art. 21(2)(h) | Partial link Art. 32(1)(a) | Partial link Art. 9(4)(d) | Partial link A.8.24 | Partial link PR.DS | Partial link CIS 3 | No link — |
| Awareness & training | Art. 20(2), 21(2)(g) | Partial link Art. 39(1)(b) | Partial link Art. 13(6) | Partial link Clause 7.3, A.6.3 | Partial link PR.AT | Partial link CIS 14 | Partial link Art. 4 |
| Human resources security | Art. 21(2)(i) | Partial link Art. 29, Art. 32(4) | Partial link Art. 9(4)(c), Art. 13(6) | Partial link A.6.1-6.8 | Partial link GV.RR, PR.AA | Partial link CIS 5, CIS 6 | No link — |
| Asset management | Art. 21(2)(i) | Partial link Art. 30 | Partial link Art. 8(1) | Partial link A.5.9-5.14 | Partial link ID.AM | Partial link CIS 1, CIS 2, CIS 3 | No link — |
Area-by-area details
Governance & leadership
NIS2 Art. 20Board-level accountability, management training, documented security strategy.
Controller accountability for technical and organisational measures; GDPR does not require training of the management body.
The management body bears ultimate responsibility for ICT risk management and approves the related policies. Applies to financial entities only.
Policies, roles and responsibilities, segregation of duties, management responsibilities.
Govern function: organisational context and roles, responsibilities and authorities.
CIS Controls v8 are technical safeguards; they contain no control on management-body accountability.
Risk management
NIS2 Art. 21(1)-(2)Risk assessment methodology, risk register, treatment plans and acceptance criteria.
Risk-based security of processing and DPIA for high-risk processing; limited to personal data.
ICT risk management framework (Chapter II). Applies to financial entities only.
Information security risk assessment and treatment, threat intelligence.
Risk management strategy and risk assessment.
Continuous vulnerability management covers technical vulnerabilities; CIS v8 has no organisation-wide risk assessment process.
A deployer of a high-risk AI system uses the information from the provider to carry out its data protection impact assessment under Art. 35(1) GDPR (Art. 26(9) AI Act). A fundamental rights impact assessment (Art. 27(1) AI Act) is required only from bodies governed by public law, private entities providing public services and deployers of systems under Annex III point 5(b) and (c); where a data protection impact assessment already covers part of the obligations, they may cross-reference its sections (Art. 27(4) AI Act as amended by Regulation (EU) 2026/1744). Risk analysis under Art. 21(2)(a) NIS2 concerns network and information systems, not fundamental rights of people.
Incident handling
NIS2 Art. 2324h early warning, 72h incident report, 1-month final report; detection, containment, recovery.
Notification of a personal data breach to the supervisory authority and to data subjects; triggered only by personal data breaches.
ICT-related incident management process, classification and reporting of major incidents. Applies to financial entities only.
Incident management planning, assessment, response, learning and collection of evidence; no regulator notification.
Detect and Respond functions; no regulator notification deadlines.
Incident response management; no regulator notification requirement.
A deployer of a high-risk AI system keeps the logs the system generates automatically, to the extent they are under its control, for at least six months unless the law provides otherwise (Art. 26(6) AI Act), and informs first the provider, then the importer or distributor and the market surveillance authorities of a serious incident without delay (Art. 26(5) AI Act). NIS2 requires notifying a significant incident to the CSIRT or the competent authority (Art. 23(1) NIS2), GDPR a personal data breach to the supervisory authority (Art. 33(1) GDPR). One incident process, but different triggers and recipients of the notification.
Business continuity
NIS2 Art. 21(2)(c)BCP, DRP, backup strategy, tested recovery procedures.
Resilience of processing systems and timely restoration of availability of personal data; narrower than business continuity and crisis management.
ICT business continuity policy, response and recovery plans, backup and restoration. Applies to financial entities only.
Information security during disruption, ICT readiness for business continuity, backup and redundancy.
Recover function: incident recovery plan execution and communication.
Data recovery and backups; no business continuity or crisis management process.
Supply chain security
NIS2 Art. 21(2)(d)Vendor risk assessment, contractual security clauses, ICT third-party oversight.
Processor guarantees and contract, safeguards for transfers; only for vendors that process personal data.
ICT third-party risk management and key contractual provisions. Applies to financial entities only.
Supplier relationships, security in supplier agreements, ICT supply chain, monitoring of supplier services, cloud services.
Cybersecurity supply chain risk management.
Service provider management: inventory, classification, security requirements in contracts, monitoring.
Accuracy, robustness and cybersecurity of a high-risk AI system, including resilience against exploitation of vulnerabilities, data and model poisoning (Art. 15(1) AI Act, Art. 15(5) AI Act), are design requirements met by the provider. The deployer verifies them with the supplier, in the same process in which it assesses supplier security under Art. 21(2)(d) NIS2.
Access control
NIS2 Art. 21(2)(i)-(j)MFA, PAM, least-privilege, periodic access review.
Ongoing confidentiality and integrity of processing systems; no explicit access control or multi-factor authentication requirement.
Policies limiting physical and logical access, management of access rights, strong authentication mechanisms. Applies to financial entities only.
Access control, identity management, authentication information, access rights, privileged access, secure authentication.
Identity management, authentication and access control.
Account management and access control management, including multi-factor authentication.
Cryptography
NIS2 Art. 21(2)(h)Encryption of data at rest and in transit, key management, minimum standards.
Pseudonymisation and encryption of personal data, listed as measures to apply where appropriate.
Protection of cryptographic keys by which data is encrypted. Applies to financial entities only.
Use of cryptography, including key management.
Data security, including protection of data at rest and in transit.
Data protection, including encryption of sensitive data at rest and in transit.
Awareness & training
NIS2 Art. 20(2), 21(2)(g)Mandatory security training for management and staff, phishing simulations.
The data protection officer monitors awareness-raising and training of staff involved in processing; GDPR does not require training of the management body.
ICT security awareness programmes and digital operational resilience training. Applies to financial entities only.
Awareness and information security awareness, education and training.
Awareness and training.
Security awareness and skills training.
Art. 4 AI Act as amended by Regulation (EU) 2026/1744 requires measures to support the AI literacy of staff and other persons operating and using AI systems on the company’s behalf; it does not require guaranteeing a particular level for any individual. NIS2 requires training for members of management bodies and encourages similar training for employees (Art. 20(2) NIS2), and cybersecurity training (Art. 21(2)(g) NIS2). An existing training programme can carry an AI module, but it has to cover the AI systems actually in use and the people working with them.
Human resources security
NIS2 Art. 21(2)(i)Screening, onboarding, exit procedures, role-based security obligations.
Persons acting under the authority of the controller or processor process personal data only on instructions.
DORA has no dedicated human resources security article; staff-related duties appear as access rights and training. Applies to financial entities only.
People controls: screening, terms of employment, disciplinary process, responsibilities after termination, confidentiality agreements.
Cybersecurity in human resources practices and identity management for personnel.
Account lifecycle only; no screening, terms of employment or disciplinary process.
Asset management
NIS2 Art. 21(2)(i)Asset inventory, classification, ownership, lifecycle management.
Records of processing activities; covers processing of personal data, not all assets.
Identification, classification and documentation of ICT-supported business functions, information assets and ICT assets. Applies to financial entities only.
Inventory of information and other associated assets, acceptable use, return, classification, labelling, information transfer.
Asset management.
Inventory and control of enterprise and software assets, data management and data inventory.
The AI system inventory is not linked here to a specific AI Act article; it is a precondition of the other obligations: without it, it is unclear which AI systems the company uses. The NISMap AI inventory therefore builds on the asset register under Art. 21(2)(i) NIS2 and, for systems processing personal data, on the records of processing activities (Art. 30(1) GDPR).
Methodology
The link level is our qualitative comparison of the NIS2 text with the closest provision or control in another framework, not a measurement or the result of a study.
- Partial link — the other framework addresses the same topic, but with a different scope or depth (e.g. GDPR only for personal data, DORA only for financial entities). Meeting the NIS2 measure does not by itself fulfil it, nor the other way round.
- No link — the other framework has no counterpart for the topic (e.g. CIS Controls v8 contain no control on management-body accountability).
- We list no full link for any pair: the equivalence of none of these pairs is documented in a source we could cite.
“Partial link” means the NIS2 or GDPR process is a place to carry out the AI Act obligation, but does not fulfil it on its own. The table has no link where an NIS2 measure alone fulfils an AI Act obligation. Dates of application follow Art. 113 of the AI Act as amended by Regulation (EU) 2026/1744: deployer obligations for high-risk systems under Annex III from 2 December 2027, for Annex I systems from 2 August 2028.
The matrix is an analytical aid, not legal advice. For a precise gap assessment contact a qualified auditor or attorney.
Start with NIS2 scope from your company ID
Find out whether your company falls under NIS2 and run a domain scan. Then compare the result with the mapping above.