Skip to main content
ISO27001

Who Needs ISO 27001 Certification? 2026 Guide

The NIS2 Implementation Act has been in force since 6 December 2025, but it does not require ISO 27001 certification. This guide shows where obligations actually exist and when certification is worth pursuing voluntarily.

Srdan ManasijevicCEO, fuentis AG10 min readUpdated
Contents
  1. Does NIS2 require ISO 27001 certification?
  2. What applies to KRITIS operators since the BSIG was rewritten?
  3. Which industries and supply chains effectively require ISO 27001?
  4. When is ISO 27001 worth pursuing voluntarily?
  5. ISO 27001 or IT-Grundschutz: Which path fits?
  6. What are the concrete next steps?
  7. What questions come up before the decision?
  8. Does a company without KRITIS status have to show ISO 27001?
  9. How long is an ISO 27001 certificate valid?
  10. Is IT-Grundschutz enough instead of ISO 27001?
  11. Does an ISO 27001 certificate replace NIS2 obligations?

There is no legal obligation to obtain ISO 27001 certification in Germany. The NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025, obliges around 29,500 entities supervised by the BSI (in German) to implement risk management measures, not to hold a certificate. Whether you need one anyway depends on KRITIS (critical infrastructure) evidence requirements, sector-specific law, your customers and your growth plans.

Does NIS2 require ISO 27001 certification?

No. The BSI Act (BSIG) as amended by the NIS2 Implementation Act requires, under § 30 (in German), appropriate risk management measures in line with the state of the art, but no certification. According to the BSI FAQ, certification under ISO/IEC 27001 or IT-Grundschutz can make it easier to provide evidence, but the measures must be checked against the statutory catalogue of measures and supplemented where necessary.

The widespread assumption that "NIS2 means ISO 27001" appears nowhere in the law. The NIS2 Implementation Act was promulgated in Federal Law Gazette 2025 I No. 301 and fundamentally rewrote the BSIG. It distinguishes between "particularly important entities" and "important entities"; operators of critical facilities count as particularly important.

To find out who is affected, read What is NIS2?. For both categories, the BSI names three core obligations: register, report significant security incidents, and implement and document risk management measures.

The catalogue of measures in § 30 (2) BSIG covers at least ten areas, including risk analysis, security incident handling, business continuity management, supply chain security, training and multi-factor authentication. It does not prescribe a specific standard. An ISMS under ISO 27001 does not automatically cover these areas in full, as the BSI FAQ on NIS2 (in German) states.

Particularly important and important entities only have to demonstrate their measures when the BSI orders them to. Operators of critical facilities are exempt from this: under § 39 BSIG they provide evidence even without being asked (more on this in the next section). An ISO 27001 certificate is then one possible piece of evidence, but not a prerequisite. A traceable ISMS is still in demand, however, because of § 38 BSIG (in German): management bodies must implement the measures and oversee their implementation, undergo regular training, and are liable for culpable damage. Anyone who wants to prove this needs documented processes, regardless of the certificate.

The fuentis Suite supports NIS2 and KRITIS in a single platform, with central evidence management and audit readiness, as described on the NIS2 & KRITIS page.

What applies to KRITIS operators since the BSIG was rewritten?

Operators of critical facilities must implement risk management measures in line with the state of the art (§ 31 BSIG (in German), formerly § 8a) and, under § 39 BSIG (in German), demonstrate this every three years through audits, inspections or certifications. An ISO 27001 certificate can be part of the evidence but must cover the KRITIS scope.

The comparison shows what has changed:

Previously (§ 8a BSIG, old version)Since the rewrite (§§ 31, 39 BSIG)
RequirementsMeasures in line with the state of the artMeasures in line with the state of the art, expressly including attack detection systems (§ 31)
Evidence cycleevery two yearsevery three years (§ 39)

It is also new that evidence must be provided even without a request from the BSI. The first evidence is due no earlier than three years after the initial designation as an operator; for existing operators, no earlier than three years after the last evidence under the old law.

The BSI's guidance on evidence under § 39 BSIG (in German) describes which evidence it accepts. It names sector-specific security standards (B3S), ISO 27001 certificates as part of the evidence documents, and IT-Grundschutz as guidance for attack detection. A B3S covers only its sector and must be supplemented by individual measures. The scope of a certificate must fully cover the critical facility, and responsibility for this lies with the operator.

Organisations that already work according to ISO 27001 or IT-Grundschutz save evidence work, but should check whether the scope fully captures the critical facility. Organisations without a certificate yet should follow what the auditors require. The differences between the two paths are explained in BSI IT-Grundschutz vs. ISO 27001. For this evidence, the fuentis Suite combines evidence management and audit readiness (NIS2 & KRITIS). Whether your organisation counts as a critical facility at all is covered in KRITIS identification: Is my organisation part of KRITIS?.

Which industries and supply chains effectively require ISO 27001?

None of these industries requires ISO 27001 by name in law. Financial entities are subject to DORA, which replaces KAIT, VAIT and ZAIT; BAIT expires at the end of 2026. Hospitals must take precautions in line with the state of the art under § 391 SGB V (Fifth Book of the Social Code), automotive suppliers meet customer requirements through TISAX, and an ISO 27001 certificate does not replace any sector-specific requirement.

AreaBasisRole of ISO 27001Further reading
Financial sectorDORA, applicable since 17 January 2025. BaFin repealed KAIT, VAIT and ZAIT as of 16 January 2025; BAIT expires on 31 December 2026.Not a substitute for ICT risk management under DORA, but a usable foundation.BaFin on DORA and the repealed circulars (in German), Bundesbank on BAIT and DORA (in German)
Hospitals§ 391 SGB V (in German) (IT security in hospitals): precautions in line with the state of the art; a sector-specific security standard that the BSI has found suitable can be used for this.Voluntary route, not a legally required proof.Statutory text of § 391 SGB V
AutomotiveCustomer requirement of vehicle manufacturers, assessment under TISAX.ISO 27001 is the basis but does not replace TISAX.ISO 27001 and TISAX compared
Cloud/SaaS and tendersContractual, for example through customer questionnaires or tender documents.Frequently requested evidence; whether it is required is set out in the contract documents of the individual case.Customer contract documents

The difference between law and market determines priority. In the financial sector, DORA directs the effort; ISO 27001 saves work there without meeting the supervisory requirements. In automotive and in supply chains, the customer decides, and the requirement is in the contract, not in the law.

When is ISO 27001 worth pursuing voluntarily?

ISO 27001 is worth pursuing voluntarily when customers, tenders or investors demand independently verified evidence and answering customer questionnaires costs more effort than an audit. The certificate proves a functioning ISMS under ISO/IEC 27001. It guarantees neither security nor fulfilment of NIS2 obligations.

The standard is widespread: the ISO Survey 2024 reports 96,709 valid ISO/IEC 27001 certificates worldwide. It gives no reliable figure for Germany.

A typical situation: a SaaS provider wins its first larger customers. Each one sends its own security questionnaire, each asks slightly differently, and the answers tie up weeks of sales and IT time. An ISO 27001 certificate can supplement these individual proofs with evidence that an external auditor has reviewed.

Not every organisation needs this step. Small entities with no customer pressure and no regulation are often well served by IT-Grundschutz modules or a lean ISMS without certification.

A certificate creates ongoing effort: under the BSI certification scheme for ISO 27001 based on IT-Grundschutz (in German), the certificate is valid for three years and is confirmed annually in surveillance audits. How such a cycle works is described in How long does ISO certification take?. For further effects, see the 9 benefits of ISO 27001 certification.

Management has its own reason as well. § 38 BSIG (in German) obliges the management bodies of affected entities to implement and oversee the risk management measures. A certificate does not replace this duty, but a traceably operated ISMS makes it demonstrable.

"Whether a certificate makes sense is decided by the evidence situation: who demands the proof, and who verifies it? First comes building a functioning ISMS; certification is then the proof of it."

Srdan Manasijevic, CEO of fuentis AG

The ISMS module of the fuentis Suite, which maps ISO 27001, TISAX®, SOC2 and BSI IT-Grundschutz as standards, supports you in the build-up.

ISO 27001 or IT-Grundschutz: Which path fits?

Both paths lead to a verifiable ISMS. ISO 27001 is widely used internationally and leaves room for design; IT-Grundschutz specifies measures more concretely and is frequently used by public authorities in Germany. What matters are the recipients of the evidence, international business and internal resources, not the standard itself.

QuestionLeans IT-GrundschutzLeans ISO 27001
Who demands the evidence?BSI, German authoritiesCustomers abroad, group requirements
Business areapredominantly nationalinternational
Resourcespredefined catalogue of measures that provides guidanceroom for design, own selection of measures
GoalEvidence within the BSI frameworkIn our assessment: customer trust in sales

Choosing one does not rule out combining them. The BSI also certifies ISO 27001 based on IT-Grundschutz (in German), combining both approaches in one certificate. For KRITIS evidence, the BSI guidance (in German) names ISO 27001 certificates as a possible component of the evidence documents and IT-Grundschutz as guidance, for example for attack detection. In both cases, the scope must match the critical facility.

The individual differences in structure and assessment are explained in BSI IT-Grundschutz vs. ISO 27001. Anyone who wants to understand the Grundschutz approach first will find it in What is IT-Grundschutz?. For the tooling question, the comparison of ISMS tools from Germany helps.

What are the concrete next steps?

First clarify who demands evidence from you: the BSI, the sector supervisor or customers. Then define the scope, because a certificate applies only to the area assessed, and check which standard requirements you already meet. Only then decide on a certification audit.

  1. Check whether you are affected: use the BSI applicability check (in German) to find out whether you fall under the BSIG. The result is a non-binding first assessment. What is NIS2? provides background.
  2. Define evidence recipients and scope: record in writing which body demands which evidence for which area.
  3. Carry out a gap analysis: compare your current state with the standard requirements. The path to the audit is described in the guide to ISO 27001 certification.
  4. Choose a tool: the ISMS module of the fuentis Suite offers gap analyses for ISO, BSI and SOC2 and supports ISO 27001 and BSI IT-Grundschutz. The pricing overview shows the packages, and the NIS2 & KRITIS framework covers NIS2 and KRITIS.

Your next action: this week, list every party that demands a security proof from you and assign each one the area it concerns.

What questions come up before the decision?

Does a company without KRITIS status have to show ISO 27001?

Not across the board. The BSIG requires risk management measures in line with the state of the art (in German), but no specific standard. According to the BSI FAQ (in German), particularly important and important entities only have to provide evidence when the BSI orders them to (operators of critical facilities excepted). Otherwise, whether a certificate is needed depends on customers and contracts.

How long is an ISO 27001 certificate valid?

Three years. During this time, annual surveillance audits take place, and recertification follows in the third year, according to the BSI certification scheme (in German). How an audit works and how much lead time to plan in total until the first certificate is described in How long does ISO certification take?.

Is IT-Grundschutz enough instead of ISO 27001?

Towards the BSI, yes, provided scope and measures fit your organisation. Customers abroad, however, frequently ask for ISO 27001. The BSI certificate "ISO 27001 based on IT-Grundschutz" combines both approaches. Where the paths differ is shown in the comparison BSI IT-Grundschutz vs. ISO 27001.

Does an ISO 27001 certificate replace NIS2 obligations?

No. Registration with the BSI, the reporting obligations and the statutory catalogue of measures remain in place whether or not you are certified. A certificate can at most make evidence easier. According to the BSI FAQ, you must still review the measures themselves and supplement them where necessary, even with a certificate.

TISAX® is a registered trademark of the ENX Association. fuentis has no business affiliation with the ENX Association and is not an audit provider approved by ENX. The fuentis Suite supports preparation for TISAX® assessments.

ISO 27001NIS2KRITISIT-Grundschutz

Srdan Manasijevic

CEO, fuentis AG

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI standards and modern risk-analysis methods.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.

Related Articles

General2 min read

The Top 5 ISMS Tools from Germany for 2025

Discover the top 5 German ISMS tools for 2025, offering IT security experts unmatched efficiency and first-class protection.

Read article
NIS24 min read

What is NIS2?

Discover how NIS2 revolutionizes your IT security strategy, helping protect critical infrastructures even more effectively against cyber threats.

Read article
KRITIS2 min read

KRITIS Identification – Does My Organization Fall Under KRITIS?

KRITIS Identification – Does my organization fall under KRITIS? Companies must assess whether they operate critical infrastructure and meet the thresholds defined in the KRITIS Regulation.

Read article
TISAX6 min read

ISO 27001 vs. TISAX®: The Ultimate Comparison for 2025

ISO 27001 or TISAX® - which standard is right for your company? Learn the crucial differences, commonalities, and when you need both standards.

Read article
ISO270017 min read

ISO 27001 Certification: Process, Duration and Checklist 2026

ISO 27001 certification usually takes three to twelve months. This guide covers the process in eight phases, the checklist up to the audit and how to choose a certification body. As of 2026.

Read article
ISO270014 min read

How Long Does ISO Certification Take?

Discover how efficient ISO certification boosts your IT security and unlocks new business opportunities.

Read article
ISO270015 min read

What is the PDCA Cycle? The Complete Guide for ISO 27001 & BSI IT-Grundschutz

The PDCA cycle forms the methodological foundation for continuous improvement in ISO 27001 and BSI IT-Grundschutz. Learn how this iterative four-step approach systematically optimizes your information security and creates a culture of continuous development.

Read article
ISO270017 min read

When Is ISO 27001 Certification Required for Your Business?

There is no legal obligation to obtain ISO 27001 certification. When customers, CRITIS evidence requirements or tenders effectively demand it, and when it is worth pursuing voluntarily. As of 2026.

Read article
ISO270015 min read

The 6 Best ISO 27001 Software Solutions in 2025

The 6 best ISO 27001 software solutions in 2025. Learn what ISO 27001 is, why you need an ISMS tool and which features matter when comparing vendors – from risk and asset management to monitoring and flexible pricing.

Read article