All insights

Controls and evidence

Zero Trust, NIS2 and ISO 27001: connect them without overclaiming

Zero Trust, NIS2 and ISO/IEC 27001 are not the same thing. Their useful connection emerges when access risk, the control, its owner and evidence are described in one decision chain.

Learners First 19 July 2026 9 min

Three perspectives on the same risk

Zero Trust provides an architecture principle: network location does not create trust, and access is decided from explicit conditions. NIS2-based regulation emphasizes organizational risk management, accountability, continuity and supply chains. ISO/IEC 27001 provides a management system for governing risks and controls.

Managed access is the common denominator, but terms from different frameworks should not be presented as direct mappings without an organization-specific scope.

Build a control chain

For each critical access path, document the following.

  • Business risk and the protected service
  • Permitted identities, devices, purposes and time limits
  • Technical and administrative control with a named owner
  • Evidence from approvals, changes, logs and reviews
  • Exception process, continuity method and remediation tracking

Keep the compliance boundary clear

A Zero Trust assessment can produce a risk view and define evidence needs for access controls. It is not a certification, regulator assessment or legal opinion.

Final scope and sufficiency must be evaluated through the organization's own management system, legal obligations and competent assessors. A clear boundary strengthens credibility and avoids false assurance.

Start with an assessment

Turn one critical access path into a decision-ready control

In a 30-minute discussion, we scope the risk, ownership and a verifiable next step.