RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

ISO/IEC 27001 and how it relates to the law

If you already run a management system to the standard, much of what the law asks is covered. We show exactly what counts and what is missing, so the work is not done twice.

LEGAL FRAMEWORKISO/IEC 27001:2022REGULATION NN 135/2024, ANNEX IIZKS NN 14/2024

The standard and the Regulation are not the same thing

They overlap substantially, but not in what the Regulation measures and puts deadlines on.

ISO/IEC 27001:2022 requires an information security management system, with 93 controls in Annex A grouped into organisational, people, physical and technological. The Regulation requires the thirteen measures of Annex II, broken into 99 sub-measures, which an audit checks through a control catalogue of 137 controls and a set of scoring thresholds.

The overlap is greatest where both frameworks ask for the same thing: risk management, access control, cryptography, human resources security and asset management. The difference appears where the Regulation sets specific deadlines and specific recipients, incident reporting within 24 and 72 hours for instance, or where it requires a record of annual reporting to management.

An existing certificate does not replace the scoring. The auditor still scores every catalogue control, and your certificate, statement of applicability and internal audit reports feed into that scoring as evidence. The same holds for ISO 22301, which covers the business continuity measure well.

Our work here is not certification but joining the two frameworks so that one record serves both. Without that, you end up running two systems and writing the same things twice.

Where they match and where they do not

The eight measures where the difference is felt most, from experience preparing entities that already hold the standard. The standard covers the other five evenly, so they are not singled out here.

MEASURE FROM ANNEX IICOVERAGE BY THE STANDARDWHAT IS USUALLY MISSING
1. Commitment and accountabilityHighThe record of annual reporting to management on the state of cyber security, and the appointment of an operationally responsible person
2. Asset managementHighA separate identification of critical assets and critical data against the Regulation’s criteria
3. Risk managementHighThe all hazards principle, meaning physical threats and failures too, not only cyber ones
4. People and digital identitiesHighDisciplinary measures for breaking the rules, and evidence of regular training with attendance lists
5. Cyber hygieneMediumSpecific password length requirements, mandatory multi-factor sign-in and 90-day log retention
8. Supply chainMediumA right to audit the supplier written into the contract, and a register of direct suppliers and service providers
11. Incident handlingLowDeadlines towards the competent CSIRT, notification of service recipients, and triage rules with an internal deadline
12. Business continuityHigh with ISO 22301With ISO 27001 alone, the business impact analysis and the plan testing records are missing

The coverage rating is our practical assessment, not an official statement. The official correlation review is produced and published by the central state authority for cyber security, under Article 49 of the Regulation. That obligation lies with the authority, not with the entity, and no auditor will ask you to produce a correlation review of your own.

How we join the two frameworks

Six steps to a state where one record serves both the standard and the Regulation.

01

Mapping your records to the catalogue controls

We match each catalogue control to an Annex A control and to a record you already hold. We take the published correlation review as a starting point and then tie it to your actual documents.

MAPPING TABLEINVENTORY OF EXISTING RECORDS
02

The list of requirements the standard does not cover

Whatever stays unmatched is the work ahead. It is usually incident reporting deadlines, supplier clauses and the records of annual reporting to management.

GAP LISTPRIORITIESEFFORT ESTIMATE
03

Extending the statement of applicability

The statement is extended with the controls the Regulation requires and the standard does not cover, with a justification for each. We do not write a new statement but extend the existing one, so it stays usable for the certification body.

EXTENDED STATEMENTJUSTIFICATIONSLINK TO MEASURES
04

A single risk register

One register for both frameworks, extended to all the hazard types the Regulation requires, so fire, failure and human error as well. Two registers in practice mean one of them is not maintained.

SINGLE RISK REGISTEREXTENSION TO ALL HAZARDS
05

Shared records instead of duplicate ones

Internal audit, management review, access rights reviews and plan testing can cover both frameworks with a single record, provided you decide up front what that record has to contain.

RECORDS PLANTEMPLATESOBLIGATIONS CALENDAR
06

Preparing for both reviews

A certification audit and an audit under the Act need the same material, but in a different order and with different emphases. We arrange the evidence so that it serves both.

EVIDENCE SETTWO VIEWS OF THE SAME MATERIAL

Frequently asked questions

The questions we are asked most often before we start.

Does the certificate prove compliance with the Act?

It does not, but it is strong evidence for a large part of the measures. The certificate, the statement of applicability and internal audit reports feed into the scoring as evidence. The gap has to be closed and documented separately.

How much of the thirteen measures does ISO/IEC 27001 already cover?

A large part, but not all of it and not to the same depth. The standard covers risk management, access control, cryptography, asset management and human resources security well. It is weaker where the Regulation sets specific deadlines and recipients, incident handling for instance.

What is the correlation review?

A mapping of the measures and sub-measures of Annex II onto the main European and international standards. It is produced and published by the central state authority for cyber security, under Article 49 of the Regulation. The obligation lies with that authority, not with you, and it serves you as a tool for faster gap analysis.

Do we have to produce our own correlation review?

No. No auditor will ask for one and no non-conformity of that kind exists. What we do is an internal mapping of your records to the controls, which is a different thing: help in finding evidence faster, not a regulatory obligation.

Do we have to change the statement of applicability?

As a rule yes, but only by extension. The statement is extended with the controls the Regulation requires and the standard does not cover, with a justification for each. The existing certification scope is untouched.

Does ISO 22301 help us?

For the business continuity measure it helps considerably, because the business impact analysis, the recovery plans and the testing records directly cover part of that measure. With ISO 27001 alone, that is exactly what is usually missing.

Is certification worth it if the Act binds us anyway?

It depends on whether your clients ask for the certificate. For the Act itself it is not required; for tenders and customer questionnaires it often is. That is a commercial decision, not a regulatory one.

Do you carry out certification?

No. The certificate is issued by an accredited certification body, and a body that built the system may not also assess it. We do the preparation and close the gap.

How long does joining the two frameworks take?

Mapping the records to the controls takes two to three weeks. Closing the gap depends on how much of it needs a new cycle, an annual review or a contract amendment for example, so anywhere from a few weeks to a few months.

Do other frameworks count, NIST for example?

They count as supporting evidence of implementation maturity. The published correlation review covers the NIST and CIS frameworks alongside the ISO standards, so self-assessments against them can be used, but they do not replace the scoring of the catalogue controls.

Where to go next

What the Regulation actually requires and what the check looks like.

You hold the standard but do not know what it is worth here?

Half an hour, no obligation. We compare your statement of applicability against the thirteen measures and see how large the gap is.

Book a callINFO@RISKORIA.EU · +385 97 737 1345