Information Security 2 min read

Applying NIS2 and ISO 27001 standards in Europe

An overview of NIS2 directive and ISO/IEC 27001 requirements, alongside solutions from Ukrainian IT companies to ensure compliance with new security standards.

New EU cybersecurity requirements and the role of ISO/IEC 27001

In October 2024, the NIS2 Directive came into force in the EU, significantly expanding cybersecurity requirements. It directly affects companies working with European clients or integrated into their supply chains. At the same time, the international ISO/IEC 27001 standard remains the foundational tool for building information security management systems (ISMS).

The NIS2 Directive requires businesses to manage risks effectively, respond quickly to incidents, ensure business continuity, and secure supply chains. Building an ISMS in accordance with ISO/IEC 27001 helps meet most NIS2 requirements without duplicating efforts.

What is at stake for the industry

For companies operating within or exporting to the European market, non-compliance with the NIS2 Directive poses severe regulatory risks and can lead to the loss of key European partners. Integrating these standards is crucial for maintaining trust, securing supply chains, and ensuring uninterrupted business operations in the EU ecosystem.

Practical solutions from Ukrainian IT companies

Market players, including member companies of the Intecracy Group consortium, offer ready-made solutions to comply with the new security standards:

  • Softline implements comprehensive information security systems (CISS) and supports certification processes.
  • SL Global Service ensures cloud security by implementing IAM, SIEM, and DLP systems.
  • IQusion provides IT consulting and information security services for the public and defense sectors.
  • Softengi applies ISO/IEC 27001 standards in developing enterprise software, AI systems, and IoT.
  • Nectain ensures compliance with SOC 2, ISO/IEC 27001, and HIPAA standards in its document management systems.

Integrating NIS2 and ISO/IEC 27001 standards helps minimize regulatory risks and build trust with European partners.

Steps for businesses

To align with the new EU requirements and secure your business, follow these practical steps:

  • Implement or upgrade your Information Security Management System (ISMS) based on the ISO/IEC 27001 framework to cover NIS2 requirements.
  • Deploy essential security measures, including Identity and Access Management (IAM), Data Loss Prevention (DLP), and robust cloud security.
  • Collaborate with specialized IT partners to conduct security audits, implement comprehensive information security systems, and navigate the certification process.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Materials and sources used in this article.

  1. Original publication — intecracy.com