certifications8 min read

Is ISO 27001 mandatory? GDPR, NIS2, French HDS and tenders

“Are you ISO 27001 certified?” The question lands in tenders, supplier questionnaires and due-diligence reviews. Many conclude that certification has become mandatory. The reality is more nuanced — and more interesting: no general law requires it, but several legal and commercial mechanisms make it, depending on your situation, hard to avoid. Let us go through each case.

What is voluntary: the certification itself

ISO/IEC 27001 is a voluntary standard. No French or European text of general application obliges a company to hold the certificate. Certifying is a business decision: structuring your security, reassuring clients, standing out. That is the scheme’s status, as summarised in the ISO 27001 certification profile.

But “voluntary” does not mean “optional in practice”. Three families of mechanisms change the picture.

GDPR: an obligation of security, not an obligation to certify

GDPR requires appropriate technical and organisational measures to guarantee the security of personal data — its security-of-processing requirement. It does not require ISO 27001, and the certificate does not amount to compliance: the regulation carries a whole legal side (lawful bases for processing, informing individuals, handling their rights) foreign to the standard’s scope.

The complementarity, on the other hand, is real and documented: the work of Diamantopoulou, Tsohou and Karyda, published in 2019 in Lecture Notes in Computer Science, maps precisely the synergies between GDPR requirements and ISO 27001 controls, and shows that an ISMS covers a substantial share of the regulation’s security side (see the study). In short: the ISMS is an excellent vehicle for GDPR’s security requirement, to be completed by the legal work. For a feel of what the standard does not cover, our guide to GDPR obligations for training providers gives a good picture of that legal side.

NIS2: cybersecurity obligations, with ISO 27001 as a good vehicle

The European NIS2 directive considerably widens the reach of cybersecurity regulation: it targets essential and important entities across many sectors (energy, transport, health, digital infrastructure, digital services, and their supply chains) and imposes cyber risk-management measures along with notification of significant incidents. Legal scholar Niels Vandezande, in an analysis published in 2024 in Computer Law & Security Review, highlights the widened scope and stiffened requirements compared with the first NIS directive.

Two honest caveats. First, NIS2 does not require ISO 27001 certification: it requires measures — which the standard precisely helps structure, document and demonstrate, international standards being a natural point of support. Second, the French rollout runs through transposition and implementing texts whose arrangements and timetable rest with the authorities: if you think you fall within scope, verify your situation and deadlines directly with ANSSI (the French cybersecurity agency), which provides tooling for that check. Do not base your compliance plan on second-hand summaries.

Where certification becomes a genuine entry condition

Tenders and contracts. The most frequent mechanism: a buyer requires the certificate as a selection criterion or contractual clause, notably in IT, finance and industry. Legally voluntary, commercially eliminatory — no certificate, no shortlist.

Hosting health data in France. Hosting personal health data on behalf of third parties in France requires HDS certification (hébergement de données de santé — health-data hosting), a distinct regulated scheme that builds on ISO 27001. If you are concerned, it is a subject in its own right: see the HDS certification profile.

Supply chains. Large groups pass their own obligations (NIS2, financial sector, defence) down to their suppliers through questionnaires and security requirements. Even without being in a regulation’s scope yourself, you can inherit its effects contractually — which is often how the ISO 27001 question reaches SMEs.

Deciding: the three-question grid

  1. Does a legal text impose a specific scheme on you? (health data → HDS; entity within NIS2’s scope → measures to verify with ANSSI). If so, that scheme comes first.
  2. Do your clients or prospects require the certificate? Re-read your last three lost tenders and your pending security questionnaires: the answer is in there.
  3. Absent any obligation, does the ISMS make economic sense? Internal structuring, differentiation, readiness for future requirements — and possibly pairing with a SOC 2 report if your market spans the Atlantic: our comparison ISO 27001 vs SOC 2 helps you decide.

Take action

ISO 27001 is not mandatory in law, but it has become the standard answer to security obligations that are, themselves, multiplying. Clarify your situation with the grid above, then frame your project with the ISO 27001 certification profile — the free ebook that comes with it walks the whole journey, from scope to audit.

FAQ

Frequently asked questions

+Is ISO 27001 certification required by law in France?

No: it is a voluntary certification, and no general legal text requires holding it. Legal security obligations (GDPR, cybersecurity regulation) impose outcomes and measures, not this certificate. It does become mandatory in practice when a client, a tender or a sector scheme requires it contractually.

+Does being ISO 27001 certified make you GDPR compliant?

Not automatically. The standard covers information security broadly and strongly supports the security-of-processing requirement, but GDPR carries its own legal requirements — lawful bases, informing individuals, access and erasure rights — which remain outside the standard's scope.

+Does the NIS2 directive require ISO 27001?

No: NIS2 imposes cybersecurity risk-management measures and incident-notification duties on in-scope entities, without requiring any particular certification. An ISO 27001-conformant ISMS is, however, a solid foundation for structuring and demonstrating those measures. The precise French arrangements depend on transposition and implementing texts: check the scheme in force with ANSSI, the French cybersecurity agency.

Read next