Yes. If your organisation falls under NIS2, compliance with the NIS2 directive remains mandatory. Existing standards and frameworks, such as ISO 27001, NEN 7510, DORA, or BIO, can be highly valuable because they already address many technical and organisational security measures.
However, NIS2 introduces additional obligations, including requirements related to management accountability, reporting obligations, and supply chain risk management. A targeted gap analysis shows which components are already covered and where additional measures are required. This enables you to avoid duplication and build efficiently on existing compliance activities.