Knowella

Information Security Risk Assessment Template

Two things have changed the character of this assessment for operational businesses. NIS2 requires an all-hazards approach covering physical, environmental and human threats rather than only digital ones, and it makes the management body personally accountable, with the possibility of executives being temporarily barred from management functions.

KnowComplyAssessmentCMP-035Full guide
ISO 27001:2013
Invalid since 31 October 2025
NIS2 Article 21
All-hazards, not just cyber

Summary

In short

  • ISO 27001:2013 certificates became invalid on 31 October 2025. Organisations that missed the transition now require full recertification with Stage 1 and Stage 2 audits rather than a transition audit.
  • The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, which changes the statement of applicability substantially.
  • NIS2 required transposition by 17 October 2024. Very few member states met it, the Commission opened infringement proceedings against most, and by mid-2026 the great majority had transposed with several still in process.
  • Where you operate across borders you are governed by the transposition status of each member state in which you provide services, not by your home state alone.
  • NIS2 Article 20 places accountability on the management body, and competent authorities can order audits at the entity's expense and, for essential entities, temporarily ban executives from management functions.
  • Article 21's all-hazards approach reaches beyond IT into physical, environmental and human threats, which is where operational businesses are usually least assessed.

What it is

What it is

What is an information security risk assessment?

A structured assessment of risks to the confidentiality, integrity and availability of information, identifying assets and their exposure, credible threats, existing controls and residual risk. Under ISO 27001 clause 6.1.2 the methodology must be defined, applied consistently and produce comparable results.

Does it cover operational technology?

It should, and increasingly must. NIS2 Article 21 requires an all-hazards approach covering cyber, physical, environmental and human threats to network and information systems, which for a manufacturer includes control systems, connected machinery and the operational technology that a purely IT-scoped assessment omits.

When to use it

When to use it, and when not to

This assessment covers risks to information and to network and information systems. Adjacent regimes address related but distinct obligations.

Use it for

  • Establishing the ISMS risk picture under ISO 27001, and reviewing it at planned intervals
  • Assessing operational technology and connected machinery alongside IT systems
  • Following a significant change: new system, new supplier, acquisition, or a change in processing
  • After an incident or a near miss, including at a supplier
  • Where NIS2 or an equivalent regime applies and the all-hazards scope must be demonstrated

Not for

  • Data protection impact assessment, which addresses risks to individuals from processing personal data
  • Business continuity and disaster recovery planning, which respond to disruption rather than assessing likelihood
  • Penetration testing and vulnerability scanning, which are technical assurance activities feeding this
  • Supplier due diligence, which applies the assessment's conclusions to a specific third party
  • Physical security assessment of the site, which this should reference where systems depend on it

Standards

What it is built against

Information security combines a management system standard undergoing transition with an EU directive whose enforcement machinery is arriving unevenly.

ClauseRequirementWhere it lands
ISO 27001 cl.6.1.2Information security risk assessment process with defined criteria, applied consistently and producing comparable resultsHeader
ISO 27001 cl.6.1.3Risk treatment, statement of applicability and risk treatment plan approved by risk ownersControls
ISO 27001:2022 Annex A93 controls across organisational, people, physical and technological themesControls
NIS2 Article 21All-hazards risk management measures covering cyber, physical, environmental and human threatsThreats
NIS2 Article 20Management body approval of measures, oversight of implementation and accountability for breachesOutcome
NIS2 Article 23Incident reporting cascade with early warning, incident notification and final report timescalesOutcome
GDPR Article 32Security of processing appropriate to risk, where personal data is involvedAssets and exposure
ISO 27001 cl.8.2Risk assessment performed at planned intervals and when significant changes occurHeader

What it does not cover

  • Data protection impact assessment, which addresses risk to individuals from processing rather than risk to the organisation.
  • Business continuity planning, which addresses recovery rather than assessing exposure.
  • Penetration testing and vulnerability management, which provide technical input to this assessment.
  • Supplier due diligence, applying the assessment's conclusions to specific third parties.
  • The incident reporting process, which under NIS2 has a specific cascade with defined timescales.

Filling it in

Filling it in well

Four things determine whether this assessment reflects the organisation rather than its IT department.

Scope to network and information systems, not to IT

Include operational technology, control systems, connected equipment, building management systems and anything with a network interface on the production floor. For most operational businesses the largest availability exposure sits there, and a scope drawn around corporate IT will not find it.

Cover physical, environmental and human threats

NIS2's all-hazards approach is explicit about this and it is where assessments are usually thinnest. Loss of power or cooling, water ingress, physical access to a control cabinet, an engineer with standing remote access, and a supplier's technician with a laptop are all in scope and none are conventional cyber threats.

Establish where each member state's rules apply

NIS2 transposition has been uneven. Only a small number of member states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Where you provide services across borders, each state's transposition governs your obligations there.

Record management body approval

Article 20 places accountability on the management body for approving measures and overseeing implementation, with the possibility for essential entities of executives being temporarily barred from management functions. Approval therefore needs to be evidenced rather than assumed from a governance structure.

Audit findings

Common audit findings

Findings here concentrate on scope and on evidence of governance.

FindingClauseWhat fixes it
Scope limited to corporate IT, excluding operational technology.NIS2 Article 21Include control systems and connected equipment; the availability exposure usually sits there.
Physical, environmental and human threats not assessed.NIS2 Article 21All-hazards is explicit; power, cooling, access and insider exposure belong in the assessment.
Operating under an expired ISO 27001:2013 certificate.IAF transition rules2013 certificates became invalid on 31 October 2025; full recertification is now required.
Statement of applicability not updated for the 2022 Annex A structure.ISO 27001:202293 controls across four themes replaced 114 across 14 domains; the mapping is substantial.
Management body approval not evidenced.NIS2 Article 20Record approval and oversight; accountability sits with the management body personally.
Cross-border obligations assessed against the home state only.NIS2Each member state where you provide services governs your obligations there.
Supply chain security not assessed.NIS2 Article 21Supplier and service provider security is an explicit measure, not an optional extension.
Risk assessment not repeated after a significant change.ISO 27001 cl.8.2Assess at planned intervals and on change; acquisitions and new systems both qualify.
Incident reporting timescales not built into the response process.NIS2 Article 23The cascade has defined stages and timings; discovering them during an incident is too late.
Risk owners not identified for treatment decisions.ISO 27001 cl.6.1.3Name risk owners; unowned residual risk has not been accepted by anyone.

Worked case

Case in point: the standard expired and the directive arrived unevenly

Two things happened in parallel. The International Accreditation Forum set a three-year window for transition from ISO 27001:2013 to the 2022 revision, ending 31 October 2025. After that date a certificate referencing the 2013 standard is invalid, and organisations that missed the window face full recertification with Stage 1 and Stage 2 audits rather than the shorter transition path.

Meanwhile NIS2 required transposition into national law by 17 October 2024. Very few member states met the deadline. The Commission opened infringement proceedings against most of them in November 2024, issued reasoned opinions in May 2025, and by 2026 had escalated the slowest cases further. By mid-2026 the large majority of member states had transposed, with a handful still in legislative process.

For an operator with sites in several member states, that produced a period in which the same directive imposed different obligations in different places, with the applicable rules depending on each state's transposition rather than on the directive alone.

Definitions

Definitions and key terms

All-hazards approach
The NIS2 Article 21 requirement to protect network and information systems against cyber, physical, environmental and human threats.
Essential and important entities
The two NIS2 categories, differing in supervisory regime and in the sanctions available.
Statement of applicability
The ISO 27001 document recording which Annex A controls apply, why, and their implementation status.
Operational technology
Control systems, connected machinery and instrumentation, frequently outside the scope of IT-drawn assessments.
Risk owner
The person accountable for a risk and for accepting residual risk after treatment.
Management body accountability
The NIS2 Article 20 requirement that management approves measures and oversees implementation, with personal consequences.
Transposition
A member state enacting a directive into national law, which for NIS2 has proceeded unevenly and at different speeds.
Incident reporting cascade
The NIS2 sequence of early warning, incident notification and final report, each with its own timescale.

FAQ

Frequently asked questions

What happened to ISO 27001:2013 certificates?+

They became invalid on 31 October 2025, at the end of the three-year transition window set by the International Accreditation Forum. Organisations that completed a transition audit before then hold a 2022 certificate. Those that did not now require full recertification against the 2022 standard, involving Stage 1 and Stage 2 audits rather than the shorter transition route.

What changed in the 2022 revision?+

The management system clauses saw relatively modest change. Annex A was restructured substantially: 114 controls across 14 domains became 93 controls across four themes covering organisational, people, physical and technological controls. The practical consequence is that the statement of applicability requires remapping rather than editing.

Does NIS2 apply to us?+

It depends on sector, size and, critically, on which member states you operate in, because obligations are set by each state's transposing law. Transposition has been uneven: very few states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Reported counts vary between sources and change as legislation progresses.

What does the all-hazards approach require?+

Under Article 21, protection of network and information systems against cyber, physical, environmental and human threats rather than digital threats alone. For an operational business that means power and cooling, physical access to control cabinets, environmental exposure, standing remote access held by engineers and suppliers, and operational technology generally.

What is the significance of management accountability?+

NIS2 Article 20 requires the management body to approve cybersecurity risk management measures and oversee their implementation, and makes it accountable for breaches. Competent authorities can order audits at the entity's expense and, for essential entities, temporarily prohibit individuals from exercising management functions. Approval therefore needs to be evidenced.

The agents

What the agents do with it

The assessment defines the ISMS risk picture. What fails is the scope that stopped at the IT boundary and the approval nobody evidenced.

KnowComply

Holds the assessment against the asset inventory including operational technology, and tracks the statement of applicability against the current Annex A structure.

KnowMaintain

Brings control systems, connected machinery and building systems into the asset picture, which IT-drawn inventories consistently omit.

Ella

Flags changes, acquisitions and new suppliers as assessment triggers, and tracks obligations by the jurisdiction in which services are provided.

KnowContractor

Covers supplier and service provider security, including standing remote access held by engineering partners.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

  • ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3 and 8.2, and Annex A
  • IAF transition requirements for ISO/IEC 27001:2022, transition ending 31 October 2025
  • Directive (EU) 2022/2555 (NIS2), particularly Articles 20, 21 and 23
  • ENISA technical guidance on NIS2 implementation and control mappings
  • GDPR Article 32, security of processing
Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.