Back to frameworks
Cross-framework crosswalk

Where NIS2 overlaps with GDPR, DORA and ISO 27001

For each of the 10 NIS2 areas find the closest counterpart in GDPR, DORA, ISO/IEC 27001:2022, NIST CSF 2.0 and CIS Controls v8, with a reference to the specific article or control and a qualitative link level.

Matrix NIS2 → GDPR × DORA × ISO 27001

Every NIS2 area is mapped to the closest article or control in the other frameworks together with a qualitative link level.

The AI Act column is qualitative, with no percentages: it shows in which NIS2 area a deployer obligation under the AI Act meets an NIS2 measure and a GDPR duty.

AreaNIS2GDPRDORAISO 27001NIST CSFCIS v8AI Act
Governance & leadershipArt. 20
Partial link
Art. 24, Art. 32(4)
Partial link
Art. 5
Partial link
A.5.1-5.4
Partial link
GV.OC, GV.RR
No link
—
No link
—
Risk managementArt. 21(1)-(2)
Partial link
Art. 32(1), Art. 35
Partial link
Art. 6-16
Partial link
Clause 6.1, A.5.7
Partial link
GV.RM, ID.RA
Partial link
CIS 7
Partial link
Art. 26(9), Art. 27(1), Art. 27(4)
Incident handlingArt. 23
Partial link
Art. 33, Art. 34
Partial link
Art. 17-19
Partial link
A.5.24-5.28
Partial link
DE.CM, DE.AE, RS.MA, RS.CO
Partial link
CIS 17
Partial link
Art. 26(5), Art. 26(6)
Business continuityArt. 21(2)(c)
Partial link
Art. 32(1)(b), Art. 32(1)(c)
Partial link
Art. 11, Art. 12
Partial link
A.5.29-5.30, A.8.13-8.14
Partial link
RC.RP, RC.CO
Partial link
CIS 11
No link
—
Supply chain securityArt. 21(2)(d)
Partial link
Art. 28, Art. 46
Partial link
Art. 28-30
Partial link
A.5.19-5.23
Partial link
GV.SC
Partial link
CIS 15
Partial link
Art. 15(1), Art. 15(5)
Access controlArt. 21(2)(i)-(j)
Partial link
Art. 32(1)(b)
Partial link
Art. 9(4)(c), Art. 9(4)(d)
Partial link
A.5.15-5.18, A.8.2-8.5
Partial link
PR.AA
Partial link
CIS 5, CIS 6
No link
—
CryptographyArt. 21(2)(h)
Partial link
Art. 32(1)(a)
Partial link
Art. 9(4)(d)
Partial link
A.8.24
Partial link
PR.DS
Partial link
CIS 3
No link
—
Awareness & trainingArt. 20(2), 21(2)(g)
Partial link
Art. 39(1)(b)
Partial link
Art. 13(6)
Partial link
Clause 7.3, A.6.3
Partial link
PR.AT
Partial link
CIS 14
Partial link
Art. 4
Human resources securityArt. 21(2)(i)
Partial link
Art. 29, Art. 32(4)
Partial link
Art. 9(4)(c), Art. 13(6)
Partial link
A.6.1-6.8
Partial link
GV.RR, PR.AA
Partial link
CIS 5, CIS 6
No link
—
Asset managementArt. 21(2)(i)
Partial link
Art. 30
Partial link
Art. 8(1)
Partial link
A.5.9-5.14
Partial link
ID.AM
Partial link
CIS 1, CIS 2, CIS 3
No link
—

Area-by-area details

Governance & leadership

NIS2 Art. 20

Board-level accountability, management training, documented security strategy.

GDPRPartial link
Art. 24, Art. 32(4)

Controller accountability for technical and organisational measures; GDPR does not require training of the management body.

DORAPartial link
Art. 5

The management body bears ultimate responsibility for ICT risk management and approves the related policies. Applies to financial entities only.

ISO 27001Partial link
A.5.1-5.4

Policies, roles and responsibilities, segregation of duties, management responsibilities.

NIST CSFPartial link
GV.OC, GV.RR

Govern function: organisational context and roles, responsibilities and authorities.

CIS v8No link
—

CIS Controls v8 are technical safeguards; they contain no control on management-body accountability.

Risk management

NIS2 Art. 21(1)-(2)

Risk assessment methodology, risk register, treatment plans and acceptance criteria.

GDPRPartial link
Art. 32(1), Art. 35

Risk-based security of processing and DPIA for high-risk processing; limited to personal data.

DORAPartial link
Art. 6-16

ICT risk management framework (Chapter II). Applies to financial entities only.

ISO 27001Partial link
Clause 6.1, A.5.7

Information security risk assessment and treatment, threat intelligence.

NIST CSFPartial link
GV.RM, ID.RA

Risk management strategy and risk assessment.

CIS v8Partial link
CIS 7

Continuous vulnerability management covers technical vulnerabilities; CIS v8 has no organisation-wide risk assessment process.

AI ActPartial link
AI Act Art. 26(9), Art. 27(1), Art. 27(4)
NIS2 Art. 21(2)(a)
GDPR Art. 35(1)
Applies from Dec 2, 2027

A deployer of a high-risk AI system uses the information from the provider to carry out its data protection impact assessment under Art. 35(1) GDPR (Art. 26(9) AI Act). A fundamental rights impact assessment (Art. 27(1) AI Act) is required only from bodies governed by public law, private entities providing public services and deployers of systems under Annex III point 5(b) and (c); where a data protection impact assessment already covers part of the obligations, they may cross-reference its sections (Art. 27(4) AI Act as amended by Regulation (EU) 2026/1744). Risk analysis under Art. 21(2)(a) NIS2 concerns network and information systems, not fundamental rights of people.

Incident handling

NIS2 Art. 23

24h early warning, 72h incident report, 1-month final report; detection, containment, recovery.

GDPRPartial link
Art. 33, Art. 34

Notification of a personal data breach to the supervisory authority and to data subjects; triggered only by personal data breaches.

DORAPartial link
Art. 17-19

ICT-related incident management process, classification and reporting of major incidents. Applies to financial entities only.

ISO 27001Partial link
A.5.24-5.28

Incident management planning, assessment, response, learning and collection of evidence; no regulator notification.

NIST CSFPartial link
DE.CM, DE.AE, RS.MA, RS.CO

Detect and Respond functions; no regulator notification deadlines.

CIS v8Partial link
CIS 17

Incident response management; no regulator notification requirement.

AI ActPartial link
AI Act Art. 26(5), Art. 26(6)
NIS2 Art. 23(1)
GDPR Art. 33(1)
Applies from Dec 2, 2027

A deployer of a high-risk AI system keeps the logs the system generates automatically, to the extent they are under its control, for at least six months unless the law provides otherwise (Art. 26(6) AI Act), and informs first the provider, then the importer or distributor and the market surveillance authorities of a serious incident without delay (Art. 26(5) AI Act). NIS2 requires notifying a significant incident to the CSIRT or the competent authority (Art. 23(1) NIS2), GDPR a personal data breach to the supervisory authority (Art. 33(1) GDPR). One incident process, but different triggers and recipients of the notification.

Business continuity

NIS2 Art. 21(2)(c)

BCP, DRP, backup strategy, tested recovery procedures.

GDPRPartial link
Art. 32(1)(b), Art. 32(1)(c)

Resilience of processing systems and timely restoration of availability of personal data; narrower than business continuity and crisis management.

DORAPartial link
Art. 11, Art. 12

ICT business continuity policy, response and recovery plans, backup and restoration. Applies to financial entities only.

ISO 27001Partial link
A.5.29-5.30, A.8.13-8.14

Information security during disruption, ICT readiness for business continuity, backup and redundancy.

NIST CSFPartial link
RC.RP, RC.CO

Recover function: incident recovery plan execution and communication.

CIS v8Partial link
CIS 11

Data recovery and backups; no business continuity or crisis management process.

Supply chain security

NIS2 Art. 21(2)(d)

Vendor risk assessment, contractual security clauses, ICT third-party oversight.

GDPRPartial link
Art. 28, Art. 46

Processor guarantees and contract, safeguards for transfers; only for vendors that process personal data.

DORAPartial link
Art. 28-30

ICT third-party risk management and key contractual provisions. Applies to financial entities only.

ISO 27001Partial link
A.5.19-5.23

Supplier relationships, security in supplier agreements, ICT supply chain, monitoring of supplier services, cloud services.

NIST CSFPartial link
GV.SC

Cybersecurity supply chain risk management.

CIS v8Partial link
CIS 15

Service provider management: inventory, classification, security requirements in contracts, monitoring.

AI ActPartial link
AI Act Art. 15(1), Art. 15(5)
NIS2 Art. 21(2)(d)
Applies from Dec 2, 2027

Accuracy, robustness and cybersecurity of a high-risk AI system, including resilience against exploitation of vulnerabilities, data and model poisoning (Art. 15(1) AI Act, Art. 15(5) AI Act), are design requirements met by the provider. The deployer verifies them with the supplier, in the same process in which it assesses supplier security under Art. 21(2)(d) NIS2.

Access control

NIS2 Art. 21(2)(i)-(j)

MFA, PAM, least-privilege, periodic access review.

GDPRPartial link
Art. 32(1)(b)

Ongoing confidentiality and integrity of processing systems; no explicit access control or multi-factor authentication requirement.

DORAPartial link
Art. 9(4)(c), Art. 9(4)(d)

Policies limiting physical and logical access, management of access rights, strong authentication mechanisms. Applies to financial entities only.

ISO 27001Partial link
A.5.15-5.18, A.8.2-8.5

Access control, identity management, authentication information, access rights, privileged access, secure authentication.

NIST CSFPartial link
PR.AA

Identity management, authentication and access control.

CIS v8Partial link
CIS 5, CIS 6

Account management and access control management, including multi-factor authentication.

Cryptography

NIS2 Art. 21(2)(h)

Encryption of data at rest and in transit, key management, minimum standards.

GDPRPartial link
Art. 32(1)(a)

Pseudonymisation and encryption of personal data, listed as measures to apply where appropriate.

DORAPartial link
Art. 9(4)(d)

Protection of cryptographic keys by which data is encrypted. Applies to financial entities only.

ISO 27001Partial link
A.8.24

Use of cryptography, including key management.

NIST CSFPartial link
PR.DS

Data security, including protection of data at rest and in transit.

CIS v8Partial link
CIS 3

Data protection, including encryption of sensitive data at rest and in transit.

Awareness & training

NIS2 Art. 20(2), 21(2)(g)

Mandatory security training for management and staff, phishing simulations.

GDPRPartial link
Art. 39(1)(b)

The data protection officer monitors awareness-raising and training of staff involved in processing; GDPR does not require training of the management body.

DORAPartial link
Art. 13(6)

ICT security awareness programmes and digital operational resilience training. Applies to financial entities only.

ISO 27001Partial link
Clause 7.3, A.6.3

Awareness and information security awareness, education and training.

NIST CSFPartial link
PR.AT

Awareness and training.

CIS v8Partial link
CIS 14

Security awareness and skills training.

AI ActPartial link
AI Act Art. 4
NIS2 Art. 20(2), Art. 21(2)(g)
Applies from Feb 2, 2025

Art. 4 AI Act as amended by Regulation (EU) 2026/1744 requires measures to support the AI literacy of staff and other persons operating and using AI systems on the company’s behalf; it does not require guaranteeing a particular level for any individual. NIS2 requires training for members of management bodies and encourages similar training for employees (Art. 20(2) NIS2), and cybersecurity training (Art. 21(2)(g) NIS2). An existing training programme can carry an AI module, but it has to cover the AI systems actually in use and the people working with them.

Human resources security

NIS2 Art. 21(2)(i)

Screening, onboarding, exit procedures, role-based security obligations.

GDPRPartial link
Art. 29, Art. 32(4)

Persons acting under the authority of the controller or processor process personal data only on instructions.

DORAPartial link
Art. 9(4)(c), Art. 13(6)

DORA has no dedicated human resources security article; staff-related duties appear as access rights and training. Applies to financial entities only.

ISO 27001Partial link
A.6.1-6.8

People controls: screening, terms of employment, disciplinary process, responsibilities after termination, confidentiality agreements.

NIST CSFPartial link
GV.RR, PR.AA

Cybersecurity in human resources practices and identity management for personnel.

CIS v8Partial link
CIS 5, CIS 6

Account lifecycle only; no screening, terms of employment or disciplinary process.

Asset management

NIS2 Art. 21(2)(i)

Asset inventory, classification, ownership, lifecycle management.

GDPRPartial link
Art. 30

Records of processing activities; covers processing of personal data, not all assets.

DORAPartial link
Art. 8(1)

Identification, classification and documentation of ICT-supported business functions, information assets and ICT assets. Applies to financial entities only.

ISO 27001Partial link
A.5.9-5.14

Inventory of information and other associated assets, acceptable use, return, classification, labelling, information transfer.

NIST CSFPartial link
ID.AM

Asset management.

CIS v8Partial link
CIS 1, CIS 2, CIS 3

Inventory and control of enterprise and software assets, data management and data inventory.

AI ActNo link
NIS2 Art. 21(2)(i)
GDPR Art. 30(1)

The AI system inventory is not linked here to a specific AI Act article; it is a precondition of the other obligations: without it, it is unclear which AI systems the company uses. The NISMap AI inventory therefore builds on the asset register under Art. 21(2)(i) NIS2 and, for systems processing personal data, on the records of processing activities (Art. 30(1) GDPR).

Methodology

The link level is our qualitative comparison of the NIS2 text with the closest provision or control in another framework, not a measurement or the result of a study.

  • Partial link — the other framework addresses the same topic, but with a different scope or depth (e.g. GDPR only for personal data, DORA only for financial entities). Meeting the NIS2 measure does not by itself fulfil it, nor the other way round.
  • No link — the other framework has no counterpart for the topic (e.g. CIS Controls v8 contain no control on management-body accountability).
  • We list no full link for any pair: the equivalence of none of these pairs is documented in a source we could cite.

“Partial link” means the NIS2 or GDPR process is a place to carry out the AI Act obligation, but does not fulfil it on its own. The table has no link where an NIS2 measure alone fulfils an AI Act obligation. Dates of application follow Art. 113 of the AI Act as amended by Regulation (EU) 2026/1744: deployer obligations for high-risk systems under Annex III from 2 December 2027, for Annex I systems from 2 August 2028.

The matrix is an analytical aid, not legal advice. For a precise gap assessment contact a qualified auditor or attorney.

Start with NIS2 scope from your company ID

Find out whether your company falls under NIS2 and run a domain scan. Then compare the result with the mapping above.