This table shows the 24 compliance areas where ISO 27001 and NIS2 controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaISO 27001NIS2
EncryptionA.8.24nis2-cr-01
Key ManagementA.8.24nis2-cr-02
Access ControlA.5.15nis2-hr-02
Identity ManagementA.5.16nis2-hr-02
Authentication & MFAA.5.17, A.8.5nis2-mf-01
Access Rights ReviewA.5.18nis2-hr-04
Privileged Access ManagementA.8.2nis2-hr-04
Network SecurityA.8.20, A.8.21, A.8.22nis2-ch-01
Vulnerability ManagementA.8.8nis2-ss-02
Logging & MonitoringA.8.15, A.8.16nis2-ea-02
Incident ManagementA.5.24, A.5.25, A.5.26nis2-ih-01
Post-Incident ReviewA.5.27nis2-ih-04
Business ContinuityA.5.29, A.5.30nis2-bc-01
Backup & RestorationA.8.13nis2-bc-02
Third-Party Risk ManagementA.5.19, A.5.20nis2-sc-01
Supplier Due DiligenceA.5.21nis2-sc-02
Supplier ContractsA.5.20nis2-sc-03
Supplier MonitoringA.5.22nis2-sc-04
Risk AssessmentA.5.7nis2-ra-02, nis2-ra-03
Information Security PolicyA.5.1nis2-ra-01
Security Awareness & TrainingA.6.3nis2-ch-02
Change ManagementA.8.32nis2-ss-04
Secure DevelopmentA.8.25, A.8.28nis2-ss-03
Security TestingA.5.35nis2-ea-01
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.