Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›ISO standards
ISO standards

You hold ISO 27001. How much is it worth under the Cybersecurity Act?

The certificate does not release you from the obligation, but it shortens the path considerably. The question is only which measures it covers, which it touches, and which it does not reach at all - and how to prove that without writing a second set of documentation in parallel.

Daniel Bara, PhD3 March 20267 min read

First, to be clear: an ISO 27001 certificate does not substitute for compliance with the Croatian Cybersecurity Act. There is no provision exempting a certified entity from implementing the measures in Annex II. But the relationship is far from useless - on the contrary, an organisation with a working ISMS usually holds most of the required material, just in a different arrangement.

Where the overlap is strong

The standard and the Regulation share the same management logic: know what you have, know what threatens it, decide what to do about it, record it and review it. That shows up in several measures where an ISO organisation typically has nearly everything:

  • Measure 2, asset management. Inventory, ownership, classification - present.
  • Measure 3, risk management. Methodology, risk register, treatment plan, owners - present, with one caveat below.
  • Measure 7, access control. Access policy, least privilege, privileged access - present.
  • Measure 8, supply chain security. Supplier relationship controls - present, usually at a higher level than in organisations without the standard.
  • Measure 12, business continuity. If ISO 22301 is in place alongside 27001, effectively covered.
  • Measure 1, management commitment. Leadership, policy, roles and responsibilities, management review - present as a structure, though the content needs extending.

Where the overlap is partial

This is where most of the misunderstanding arises, because it looks finished and is not.

All-hazards risk assessment

The Regulation requires an assessment covering all categories of hazard - including fire, flood, power loss, failure of communications infrastructure and unauthorised physical access. Many ISMS risk assessments stay within the bounds of information threats. The methodology is the same; the scope is not.

Physical security

Measure 13 is a standalone measure with its own sub-measures. In the standard it is a set of controls inside Annex A. The material exists, but it has to be pulled out and evidenced sub-measure by sub-measure, rather than shown as part of a wider set.

Cryptography

Measure 10 requires rules on use, protection of data in transit and at rest, key management and - proportionate to risk - preparation for quantum-resistant cryptography. The last of these is newer than most ISMS documentation we see.

Where the standard does not help

Three groups of obligations have no equivalent in the standard, because they come from legislation rather than management practice:

  1. Categorisation and everything that follows from it. Level of implementation, competent authority, deadlines.
  2. Incident reporting within prescribed deadlines. The standard requires an incident management process, but knows nothing of 24-hour, 72-hour and 30-day deadlines or notification to a competent CSIRT.
  3. The format and procedure of verification. A self-assessment against a scoring framework, or an independent audit, has nothing to do with a certification audit against the standard.
The practical conclusion

ISO 27001 shortens the path but does not change the destination. A realistic expectation: a working ISMS covers a substantial part of the evidence base, and the remainder is filled in. An ISMS that is not working - built for the certificate and unused since - helps almost not at all, because exactly the records that prove the system is alive are what is missing.

How to do this without duplication

  1. Map before you write. Every sub-measure gets a reference to an existing document, record or control from the Statement of Applicability. The gaps are whatever is left without a reference.
  2. Extend, do not copy. If the existing risk methodology does not cover all hazard categories, widen the scope in the existing document. A second methodology means two risk registers that will diverge.
  3. One asset register. If the ISMS information asset list and the inventory for the Act are maintained separately, one of them will go stale and you will not know which.
  4. Fill what is genuinely missing. Incident reporting, categorisation, self-assessment preparation.

The same approach applies to entities subject to DORA and to organisations with an established GDPR programme. The evidence base overlaps far more than the names of the instruments suggest.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.