Cybersecurity is no longer a technical defence declared by IT but a verifiable condition for continuity, compliance, contracting and institutional trust. The change is not that there are more attacks. It lies in who is asking: clients, regulators, insurers, auditors and supply chains have begun demanding evidence before signing, insuring or supervising — approved governance, treated risks, tested controls, recorded incidents, rehearsed recovery, third parties under control and documented improvement.


The signal

Four frameworks push in the same direction, and none asks for an opinion. NIST CSF 2.0 made the shift visible by incorporating Govern alongside Identify, Protect, Detect, Respond and Recover: governance ceased to be context and became a framework function. NIS2 brought the obligation to implement risk management measures with management accountability to Europe’s critical sectors. DORA, applicable since 17 January 2025, turned financial-sector ICT risk into regulated digital operational resilience. The Cyber Resilience Act brings the same logic to digital products: risk, technical documentation, vulnerabilities and conformity assessment.

The most useful classification is an emerging requirement with an established core. The core has been published for years: ISO/IEC 27001 for the management system, ISO/IEC 27002 for controls, ISO/IEC 27005 for risk, the ISO/IEC 27035 series for incidents, ISO 22301 for continuity, ISO 31000 for enterprise risk, ISO 9001 for leadership, processes, documented information and improvement. What is emerging is not new technology: it is regulatory and contractual pressure. Demonstration is no longer good practice but a condition for access to markets, contracts, insurance and supervision.

Cybersecurity is not demonstrated by saying “we have antivirus”. It is demonstrated through governance, risk, controls, records, tests, response and improvement.

The framework map that organises the evidence

No standard covers the whole problem, and those seeking a single standard often end up buying the wrong one. Frameworks are read by function: some organise the system, others the controls, others continuity, others independent assessment, and others regulatory obligations. The auditor’s mistake is to look only at the technical tool; management’s mistake is to believe that a certificate replaces operational evidence.

FrameworkWhat it providesWhat the organisation should be able to show
ISO/IEC 27001Information security management system.ISMS scope, risk assessment and treatment, statement of applicability, objectives, internal audits, management review and corrective actions.
ISO/IEC 27002 and 27005Security controls and a security risk management method.Controls with owners, implementation evidence, risk criteria, a living matrix, treatment plans and periodic review.
ISO/IEC 27035 seriesPrinciples, preparation, response operations and incident coordination.Incident procedure, reporting channels, escalation, playbooks, RCA, lessons learned and coordination with third parties.
ISO/IEC 27701:2025Privacy management system for PII controllers and processors.Records of processing activities, responsibilities for personal data, privacy controls, accountability and data incident response.
ISO 22301Business continuity management system.BIA, critical processes, continuity strategies, plans, tests, recovery times and post-exercise improvement.
NIST CSF 2.0Executive architecture in six functions: Govern, Identify, Protect, Detect, Respond and Recover.Roles, risk appetite, inventories, data protection, monitoring, response, recovery, communication and supply chain risk.
NIS2, DORA and CRARegulatory obligations concerning risk management, incidents, third parties, resilience and digital product conformity.Evidence of measures, incident records, ICT contracts, tests, technical documentation, conformity assessment and management oversight where applicable.

What has changed in the auditor’s seat

Mature auditing can no longer stop at “do you have a security policy?” or “is there a firewall?”. It must ask where critical information resides, who owns it, how it is classified, which supplier supports it, when the last actual restoration took place, which privileged access rights remain active, what incidents occurred, what was learned and what changed afterwards. Evidence is no longer solely documentary or solely technical: it is systemic.

01

Management enters the actual scope

NIST CSF 2.0 places governance at the forefront of the framework, NIS2 requires management bodies to approve and oversee measures, and DORA establishes the management body's responsibility for ICT risk. Three different frameworks, one shared reading: cybersecurity that does not reach the decision-making table is operations without governance.

02

Continuity has become inseparable from security

A digital incident no longer affects infrastructure alone: it affects customer care, production, data, billing, contracts, public services, health, education and trust. ISO 22301 and NIST's Recover function structure recovery; DORA turns it into regulated digital resilience for the financial sector.

03

The supplier is part of the perimeter

Supply chain risk is no longer a contractual annex. NIST devotes a specific category to supply chain risk; DORA builds a framework for critical ICT third parties; NIS2 extends requirements to the supply chains of critical sectors. The supplier contract is already security evidence, and the auditor will ask for it.

The expected evidence matrix

Supporting a cybersecurity claim requires an evidence file spanning four dimensions. None is sufficient on its own: documentation without technical evidence is narrative, technical evidence without contractual evidence leaves the perimeter open, and all three without competence describe a system no one knows how to operate. Together, they allow the auditor to assess governance, operations and effectiveness in the same file.

Type of evidenceConcrete examples
DocumentaryApproved policy, ISMS scope, asset inventory, information classification, risk methodology, statement of applicability, treatment plan, BIA, continuity plan, internal audits, management review and corrective actions.
TechnicalAccess records, logs, MFA, monitoring alerts, vulnerabilities and patches, restoration tests, availability metrics, encryption evidence, cloud and endpoint reports, drills and incident records.
ContractualSupplier due diligence, security, privacy and continuity clauses, service level agreements, notification obligations, data processing annexes, exit criteria and performance reviews.
CompetenceCompetence matrix, role-based training, effectiveness evaluation, response exercises, simulations, key personnel profiles, professional certifications where applicable and verifiable auditor competence.

Questions a serious audit should ask

Useful questions are not decorative. They distinguish a living system from a technical narrative, and each has a minimum set of evidence that supports or disproves it.

DimensionCritical questionMinimum evidence
GovernanceHas top management approved the policy, roles, resources and measurable objectives?Minutes, current policy, assigned responsibilities, management review and metrics.
RiskIs digital risk integrated into enterprise risk, or does it live in an IT spreadsheet?Methodology, criteria, matrix, risk owners, treatment plans and follow-up.
AccessWho can gain access, with what privileges, and when was this last reviewed?Account creation, removal and changes, periodic review, MFA, logs and traceability of privileged accounts.
IncidentsWhat was recorded, how was it escalated, what root cause was identified and what changed afterwards?Event and incident register, playbooks, communications, RCA and corrective actions.
ContinuityWhen was a backup restored in a real test, and against what objective?BIA, RTO/RPO, exercise minutes, restoration results and subsequent improvement.
Third partiesWhich critical suppliers support services or data, and what happens if they fail?Third-party inventory, criticality, contracts, notification clauses, monitoring and alternative plan.

Three notes that change how the standards are read

First. ISO/IEC 27701 is now read in its 2025 version. The 2019 edition is listed as withdrawn in the ISO catalogue, and the current version should no longer be described solely as an extension of 27001/27002: it is presented as a privacy management system with its own requirements and guidance. Citing the old edition in a contract or scope is a nonconformity waiting for a date.

Second. ISO/IEC 27035 is read as a series, not as a standalone document. Incident management is not limited to a procedure: it includes principles and process, preparation, response operations and coordination between organisations. Anyone who has only the procedure has the cheapest part of the problem.

Third. ISO/IEC 17024 was updated in 2026. For cybersecurity, auditing and conformity assessment, this brings the question of people's certifiable competence into sharper focus: a course is not enough; the scheme, assessment, impartiality and monitoring of competence over time matter.

The evidence file before the tool

Priority · next twelve months

Build the evidence file before buying another tool. A reliable inventory, information classification, dependency map, digital risks integrated into enterprise risk, controls with owners, access review, incident register, tested restoration, strengthened third-party contracts, metrics and management review. That investment sequence is one an auditor can read.

ISO/IEC 27001 certification does not promise invulnerability. It demonstrates that a formal system exists to manage security risks under verifiable requirements. Accreditation of the certification body adds confidence in competence, consistency and impartiality; it does not turn the certificate into an absolute shield.

The underlying point is operational. Auditors in the coming cycle will need to understand both management systems and digital resilience. If they cannot read a log, a restoration, an ICT contract, a risk matrix and a management review within the same file, they will audit the surface and leave the blind spot intact.

Limitation of this analysis

This report draws on official sources, public standards and regulation pages, and available institutional guidance. It does not reproduce copyrighted standards text or replace a local legal review. Outside the European Union, specific obligations vary by jurisdiction, sector, contract and type of data processed.