Certification is voluntary. And a de facto requirement.
An information security management system (ISMS) under ISO 27001 is officially voluntary, but a de facto requirement for NIS2-regulated organizations, critical infrastructure operators under §8a BSIG, financial institutions (BAIT/VAIT), and suppliers to large enterprise customers. BSI IT-Grundschutz has been mandatory for federal agencies since December 6, 2025. And a recognized security framework for everyone else.
The BSI provides an official mapping table that cross-references ISO 27001 controls and IT-Grundschutz building blocks. That’s the starting point for any parallel implementation. Anyone serving both standards collects evidence once. And maps it to both worlds via the table. In IT-Grundschutz, the asset inventory also serves as the data foundation for the structure analysis.
ISO 27001 and NIS2 aren’t the same thing. NIS2 imposes additional requirements. Particularly around reporting timelines (24h / 72h / 1 month). An ISO certification doesn’t replace NIS2 compliance.