Information security management system (ISMS)
The management system behind security: risk assessment, approved policy, owned measures and evidence. What eIDAS Article 24 and an audit expect.
The set of policies, processes and responsibilities with which an organisation manages information security as a continuing activity rather than a project: identify risks, decide on measures, assign owners, collect evidence, review, adjust. ISO/IEC 27001 is the frame most organisations use and can be certified against, but the obligation comes first and the certificate second.
For a QTSP the obligation is in eIDAS Article 24(2)(fa): appropriate policies and corresponding measures to manage the legal, business, operational and other risks - directly and indirectly - to the provision of the qualified trust service, explicitly alongside the duty of care in Article 21 of NIS2. The ETSI policy requirements for trust service providers turn that into an auditable shape: a documented risk assessment, a security policy approved by management, and controls that trace back to identified risks.
That is what a conformity assessment body actually audits. Not whether you own a firewall, but whether you can show the chain from risk to measure to evidence, and whether management signed off on the residual risk. Since the Dutch Cyberbeveiligingswet and its decree, in force from 15 August 2026, demand much the same thing in their own words, the sensible move is one management system that answers to both, with a mapping per requirement instead of two parallel binders.