A management system, not a checklist
The standard’s core clauses ask for context and scope, leadership commitment, a risk assessment and treatment process, resources and competence, operational planning, performance evaluation and continual improvement. Annex A is the catalog the risk treatment draws from, and the Statement of Applicability records which controls apply and why. An organization can be certified with controls excluded, provided the exclusion is justified by the risk assessment. That is why two certificates can cover very different realities.
What auditors actually look at
Evidence that the process runs: risk assessments with dates and owners, management reviews with decisions, internal audit results, corrective actions closed, and for each applicable control the records that it operates (access reviews, change records, supplier evaluations, awareness sessions). Certification audits sample; the risk for the certified organization is evidence that exists for the audit week and nowhere else in the year.
Where it meets the European texts
ISO 27001 does not make an organization NIS2 or DORA compliant, but its control set overlaps heavily with the NIS2 risk-management measures and the DORA ICT risk framework, and a mapped control set lets one program serve all three. The value of the certificate in a supply chain is precisely that: a supplier’s ISO 27001 scope and Statement of Applicability tell a buyer which controls are claimed, and a buyer’s own assessment tells it whether to believe them.