How does ISVS certification relate to the new Cybersecurity Act?

18. 7. 2025


With the introduction of the new Cybersecurity Act (based on NIS2), there is now a strong connection between ISVS requirements and cybersecurity regulations.

In practice, if an ISVS also falls under the scope of the Cybersecurity Act (e.g., it ensures the provision of essential services), then the certification process must also reflect the cybersecurity requirements from that law.

Even today, ISVS certification routinely includes evaluating areas such as:

  • Access management

  • Backups

  • Change management

  • Incident response

  • Operational security

These areas overlap with the requirements of NIS2 and the Cybersecurity Act.

Therefore, we recommend planning ISVS certification in the context of broader cybersecurity requirements and ideally linking it with a compliance assessment based on ZoKB/NIS2.