ISO 27001, NIS 2, DORA: what cyber frameworks really prove, and how to sustain them over time
In 2025, 40 % of French companies suffered at least one significant cyberattack. The figure comes from the 2026 barometer of CESIN, the French club of information security and digital experts, which brings together several hundred CISOs from French companies and public bodies. It is falling year after year (47 % a year earlier, 65 % in 2019), and CESIN credits the improvement to stronger detection and response capabilities.
Meanwhile, European law is changing the nature of the subject. DORA, the regulation on the digital operational resilience of the financial sector, has applied since 17 January 2025. NIS 2, the directive on the security of network and information systems, will take France from roughly 500 regulated entities to some 15,000, spread across 18 sectors. Formalised security is ceasing to be the choice of a prudent manager and becoming, in a growing number of cases, a legal obligation backed by sanctions.
Facing this wave, the same question comes up in every boardroom: what are these frameworks actually for? Does a certificate on the wall protect anything? And above all, how do you sustain these requirements over time without dedicating an entire team to them?
Three frameworks, three logics
People often talk about "the standards" as a single block. That is a misreading. This article takes three frameworks as examples, because they concern the largest number of organisations in Europe today, but the landscape is much wider: sector certifications such as TISAX in automotive or HDS in healthcare, qualifications such as SecNumCloud for trusted cloud, good-practice frameworks such as the NIST CSF or ANSSI's IT hygiene guide, and obligations such as the GDPR or the upcoming European regulation on connected products (CRA).
Our three examples share neither the same legal status, nor the same audience, nor the same philosophy.
ISO/IEC 27001 is a voluntary standard. No one is forced to comply: an organisation chooses to build an information security management system (ISMS) and, if it wishes, to have it certified by an accredited body. The standard does not prescribe a shopping list of products but a governance discipline: assess your risks, select controls (Annex A of the 2022 version offers 93 of them), document them, audit them and improve them continuously.
It is the most widespread framework in the world: the ISO Survey counts 96,709 valid certificates at the end of 2024. The geography of those certificates is telling: China alone holds a third of them, far ahead of India and Japan, and within Europe both Italy (6th) and Germany (8th) sit ahead of France, which ranks 15th with 1,728 certificates, a modest figure relative to the size of its economy. One calendar detail also matters: since 31 October 2025, certificates issued against the old 2013 version have expired; only the 2022 version stands.
| Rank | Country | Valid certificates |
|---|---|---|
| 1 | China | 33,359 |
| 2 | India | 6,758 |
| 3 | Japan | 6,644 |
| 4 | United Kingdom | 4,455 |
| 5 | United States | 4,260 |
| 6 | Italy | 3,284 |
| 7 | Turkey | 3,202 |
| 8 | Germany | 2,444 |
| … | … | … |
| 15 | France | 1,728 |
NIS 2 is an obligation, not a label. The name stands for Network and Information Security: it is the second version of the European directive on the security of network and information systems, Directive (EU) 2022/2555. It imposes cyber risk management measures on "essential" and "important" entities across 18 sectors, with explicit involvement of management bodies and fines of up to 10 million euros or 2 % of worldwide turnover for essential entities.
The French transposition, carried by the resilience bill, is still being debated in Parliament. But ANSSI already published its requirements framework, the ReCyF, in March 2026, with 20 security objectives for essential entities and 15 for important ones. Companies in scope therefore already know what to prepare for, and waiting for the implementing decree would be a poor bet.
DORA is a regulation, directly applicable. DORA stands for Digital Operational Resilience Act: Regulation (EU) 2022/2554 on the digital operational resilience of the financial sector. No transposition, no national delay: it has applied as-is since 17 January 2025 to more than 22,000 financial entities and ICT service providers across the Union, under the supervision of financial authorities (in France, the ACPR and the AMF). Its logic: an ICT risk management framework, incident reporting, resilience testing and tight oversight of technology providers.
| Framework | Nature | Who is covered | Where things stand |
|---|---|---|---|
| ISO/IEC 27001 | Voluntary international standard, certifiable by a third party | Any organisation, any sector, any size | Only the 2022 version has been valid since 31 October 2025 |
| NIS 2 | European directive, legal obligation | Around 15,000 entities in France, 18 sectors | French transposition still under debate; ANSSI requirements framework (ReCyF) published in March 2026 |
| DORA | European regulation, directly applicable | Over 22,000 financial entities and ICT providers across the EU | Applicable since 17 January 2025 |
What a certification demonstrates, and what it does not
An ISO 27001 certification does not prove that a company is impenetrable. It proves something else, which matters: a structured effort exists, management has committed, a risk assessment process is running, and an external auditor comes back every year to check the whole thing has not collapsed. Academic research describes certification in exactly those terms: a 2025 study in Computers & Security, covering 128 countries over twelve years, analyses ISO 27001 as a strategic signal of capability sent to the market.
That signal has blind spots, though. The first is scope: a certification covers a declared perimeter, which may span the whole company or a single service line or datacentre. An organisation can therefore state "we are ISO 27001 certified" on the strength of a narrow scope. Before relying on a partner's certificate, read what it actually covers.
The second is temporal: an audit is a photograph. What happens between two audits, nobody certifies. We will come back to this, because that is precisely where everything is decided.
What compliance changes for your customers
The most immediate benefit of a compliance framework is not measured in your SOC but in your commercial relationships. We documented it in our article Third-Party Security: Now One of the Leading Entry Points for Attackers: a third party is now involved in nearly one breach in three, and buyers have drawn the consequences. Supplier security questionnaires are getting longer, cyber clauses are getting tougher, and certifications serve as verifiable guarantees: they do not guarantee invulnerability, but they prove that a structured, audited effort exists.
Concretely, a company able to present a certification or documented compliance wins on three fronts.
It shortens sales cycles: a recognised certificate replaces dozens of questionnaire pages and rounds of exchanges with the customer's security team. It secures its place in the supply chain: NIS 2 (article 21.2 (d)) and DORA (article 28) explicitly require regulated entities to oversee their suppliers' security, which means your own regulated customers will have to ask you the question. It eases insurability: cyber insurers increasingly condition underwriting on the demonstration of specific controls, and a documented ISMS speeds up that conversation.
A word of caution on this last point: the "10 to 30 %" premium reductions found in sales pitches come from firms selling certification services, not from public actuarial studies. The real gain lies mostly in eligibility and smoother underwriting.
Certified, therefore less attacked? What the data actually says
It is the question every executive asks, and it deserves an honest answer: no solid study demonstrates that an ISO 27001-certified company suffers fewer attacks than another. No insurer, no national agency, no peer-reviewed journal has published a rigorous comparison between certified and non-certified organisations. The only figure circulating in that direction, the "92 % fewer claims" of Cyber Essentials-certified organisations in the UK, comes from the very body that issues the certification, with an obvious selection bias: organisations that get certified are already the most mature.
What is demonstrated sits one level lower, at the level of the controls these frameworks impose. Marsh McLennan, by crossing its policyholders' questionnaires with their actual losses, measures clear effects: running regular crisis exercises is associated with a 13 % lower probability of a material cyber event, each additional 25 % increment of EDR deployment with a 10 % reduction, and phishing-resistant multi-factor authentication with 9 %.
These controls are precisely the ones Annex A of ISO 27001:2022 requires you to consider: malware protection, logging and monitoring, incident management, technical vulnerability management. The link between standard and loss experience is thus mechanically plausible, if not statistically isolated.
Two further lessons complete the picture. The first comes from the payments industry: Verizon reports that since 2010, none of the organisations it assessed after a data breach was fully PCI DSS compliant at the time of the breach, while more than half had been at their latest audit. The most useful reading of that figure is not "compliance protects" but "compliance erodes": the value lies not in passing the audit but in continuously maintaining the practices.
The second comes from breach economics: the IBM Cost of a Data Breach Report 2026 puts the global average cost of a breach at 4.99 million dollars, up 12 % year on year, and the 2025 edition noted that 32 % of breached organisations had also paid a regulatory fine. Compliance maturity matters less for the probability of being attacked than for the residual bill: faster detection, organised response, avoided sanctions.
Finally, we should say what the certificate does not promise: Equifax, Okta, SolarWinds and Fidelity Investments all held recognised certifications at the time of their compromise. The certificate is a marker of practices; it is the practices that protect, and only for as long as they last.
Where tooled-up intelligence strengthens and ticks precise requirements
Look closely at the three frameworks and one transversal requirement stands out: all of them demand an up-to-date knowledge of threats and vulnerabilities. ISO 27001:2022 made it a control in its own right with threat intelligence (A.5.7) and technical vulnerability management (A.8.8); NIS 2 expects risk analysis policies and vulnerability handling (article 21.2); DORA requires identifying threats (article 8) and learning continuously from incidents (article 13).
On paper, this is reasonable. In practice, it means reading, sorting, cross-checking and recording a considerable flow of information, every day, including in August. That is exactly the work a structured intelligence service takes on, and that is what our intelligence offers: each feature of the platform feeds precise requirements of the three frameworks.
| Intelligence input | ISO/IEC 27001:2022 | NIS 2 | DORA |
|---|---|---|---|
| Daily intelligence and victimology alerts | ✓ Control A.5.7 (threat intelligence) | ✓ Art. 21.2 (b), incident handling | ✓ Art. 8, threat identification |
| Exploited-vulnerability tracking (KEV filter) | ✓ Control A.8.8 (technical vulnerability management) | ✓ Art. 21.2 (e), vulnerability handling | ✓ Art. 13, continuous learning and remediation |
| Factual threat data (TTPs, indicators) | ✓ Clause 6.1.2 (risk assessment) | ✓ Art. 21.2 (a), risk analysis policies | ✓ Art. 6, ICT risk management framework |
| Monthly summaries and activity reports | ✓ Clause 9.3 (management review) | ✓ Art. 20, governance and management oversight | ✓ Art. 5, governance and organisation |
| Sector and third-party threat mapping | ✓ Controls A.5.19 and A.5.21 (supplier relationships) | ✓ Art. 21.2 (d), supply-chain security | ✓ Art. 28, ICT third-party risk |
The gain goes beyond daily comfort. When the audit or inspection comes, the auditor's question will be: "show me how you track threats and vulnerabilities". An organisation relying on formalised intelligence already has the answer: timestamped alerts, archived monthly summaries, patching priorities grounded in vulnerabilities that are actually exploited (the KEV filter) rather than theoretical severity alone.
The evidence builds up as you go, instead of being reconstructed in a rush the week before the audit. That is team time handed back to real work, and a source of serenity that counts as the deadline approaches.
Integrating intelligence into the ISMS: cadence makes compliance
A point of honesty, which is also a piece of method: subscribing to an intelligence feed, ours included, does not "make" anyone compliant. For intelligence to count in an auditor's eyes, it must be read, recorded and turned into decisions at a documented cadence. It is the integration into the management system that turns an information flow into evidence.
That integration runs through complementary channels, each with its audience and its rhythm: daily intelligence and real-time alerts through the app, for the operational team; threat trends and sector mapping, to feed the risk assessment; the newsletter, to keep informed those who do not live in the tool; and the monthly report with its slides, ready to be presented at the management review and then archived as evidence.
Concretely, four habits are enough to turn this flow into living compliance:
- Write the cadence down: who reads the daily alerts, who processes the monthly summary, within what timeframe.
- Feed the risk assessment (clause 6.1.2) with facts observed in the field, sector by sector, rather than with theoretical scenarios frozen from one year to the next.
- Make exploited vulnerabilities a formal trigger: a KEV catalogue entry affecting your estate becomes a tracked remediation ticket (control A.8.8).
- Bring a periodic summary to the management review (clause 9.3), so that the executive involvement required by NIS 2 and DORA rests on something more than a mood slide.
There is no shortage of material, and that is precisely the problem. Over the past six months, our intelligence captured around 83,500 major reports, weak signals excluded. That figure is itself the result of a triage: upstream, more than one million raw reports were analysed. No in-house team can absorb such a volume; extracting the essential information from that noise is precisely what LuksMentis does.
Among those major reports, 44,321 concern vulnerability exploitation and 5,123 ransomware. Over the same period, 144 vulnerabilities joined the catalogue of actively exploited flaws, one every thirty hours, and 3,225 ransomware attack claims were published by criminal groups.
The photograph and the film
A certificate is a photograph: it freezes, on a given day, the state of a management system. Security is a film, and attackers only work in the interval between two frames. That is why the data quoted above converges on a single conclusion: compliance frameworks are worth the continuous discipline they install, not the logo they deliver.
NIS 2 and DORA have settled part of the debate: for tens of thousands of European entities, the question is no longer "should we get structured?" but "at what cost, and with what load on the teams?". The reasonable answer is to turn the obligation into an instrument of maturity, and to tool up whatever can be tooled up so the discipline holds over time.
Threat intelligence is part of that: it is a requirement common to all three frameworks, one of the most time-consuming to sustain by hand, and one of the simplest to formalise properly. Compliance is demonstrated through continuity; continuity might as well cost as little effort as possible.
Sources
- Marsh McLennan, Cybersecurity Signals: Connecting Controls and Incident Outcomes (2025): marsh.com
- IBM, Cost of a Data Breach Report 2026 (global average cost $4.99M): ibm.com
- Verizon, Payment Security Report (PCI DSS compliance at the time of breaches): verizon.com
- ISO, The ISO Survey 2024 (96,709 valid ISO/IEC 27001 certificates; country breakdown via IAF CertSearch): iso.org
- ANSSI, MonEspaceNIS2, scope and transposition of the directive: monespacenis2.cyber.gouv.fr
- ANSSI, Panorama de la cybermenace 2025: cyber.gouv.fr
- CESIN / OpinionWay, Barometer of French corporate cybersecurity, 11th edition (2026): opinion-way.com
- Regulation (EU) 2022/2554 (DORA) and Directive (EU) 2022/2555 (NIS 2): eur-lex.europa.eu
- Certification as a compensation mechanism for weak regulation? Exploring the diffusion of ISO/IEC 27001, Computers & Security (2025): sciencedirect.com
- LuksMentis, Third-Party Security: Now One of the Leading Entry Points for Attackers: luksmentis.com/blog
- Primary data: LuksMentis intelligence (~83,500 major reports retained out of over one million analysed, February-August 2026)