Network and Information Security (NIS2) Directive
Cybersecurity is no longer a technical decision. It’s a governance one.
What Is NIS2?
NIS2 (Directive (EU) 2022/2555) is the EU directive that sets a common cybersecurity baseline for essential and important entities across 18 critical sectors. It replaces the original 2016 NIS Directive and expands its scope roughly tenfold, from around 15,000 entities under NIS1 to an estimated 160,000 across the EU.
France, like several Member States, has not yet completed its national transposition. National transposition is expected by the end of 2026. The ANSSI nonetheless recommends starting compliance work now: the substance of the requirements is already settled, even where the exact enforcement date isn’t.
Who is affected?
NIS2 covers 18 critical sectors, split into two tiers, and applies based on your organisation’s size within those sectors.
Highly critical sectors
Annex I — 11 sectors
Other critical sectors
Annex II — 7 sectors
Size determines your obligations
250+ employees or €50M+ turnover
Large entities
Generally classified as essential entities, the strictest supervision tier.
50 to 250 employees or €10M to €50M turnover
Medium entities
Generally classified as important entities, with lighter obligations.
Under 50 employees
Small entities
Generally out of scope, except for specific sectors regardless of size.
Estimates for France range from roughly 10,000 to 18,000 entities, essential and important combined. Check your own eligibility directly on ANSSI’s registration portal, MonEspaceNIS2.
Sanctions and personal liability
Non-compliance carries serious consequences. Essential entities face fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%.
Beyond the financial penalty, NIS2 introduces personal liability for management bodies: executives can be held accountable for failing to implement adequate risk-management measures, including a duty to approve and oversee cybersecurity measures under Article 20.
The baseline measures NIS2 requires
Article 21 sets out ten categories of minimum security measures every essential and important entity must implement: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in system acquisition and development, policies to assess the effectiveness of measures, basic cyber hygiene and training, cryptography and encryption, human resources security and access control, and the use of multi-factor authentication.
France's technical reference: the ReCyF
Ahead of the law’s final adoption, the ANSSI published a technical reference, the Référentiel Cyber France (ReCyF): 20 security objectives for essential entities, 15 for important entities, organised around four pillars: Governance, Protection, Defence and Resilience. It isn’t legally binding yet, but it is already the de facto benchmark auditors and clients use to judge readiness.
How our four practices answer NIS2
- Governance → Cyber Advisory & GRC — CISO as a Service and a governance framework that satisfies Article 20’s management training and oversight duties.
- Protection → Offensive Security — penetration testing and vulnerability management that directly fulfil Article 21(2)(e)’s obligation to test the effectiveness of your security measures.
- Defence → Managed Cyber Defense — 24/7 detection and response, covering the continuous monitoring and incident notification duties of Articles 21 and 23.
- Resilience → Cyber Crisis Management — crisis plans and exercises that satisfy Article 21’s business continuity requirement.
Two further obligations run across all four: ICT Third-Party Risk Management answers Article 21(2)(d)’s supply chain security requirement, and Training answers Article 21(2)(g)’s staff cyber hygiene obligation.
Questions
Frequently Asked Questions
General questions about regulatory compliance
NIS2 is the EU directive (2022/2555) that sets a common cybersecurity baseline for essential and important entities across 18 critical sectors, replacing the original 2016 NIS Directive with a far broader scope and stricter enforcement.
Organisations operating in one of NIS2’s 18 critical sectors, above the size thresholds, broadly 50 or more employees or €10 million or more in annual turnover, plus a small number of entities subject regardless of size. Check your own eligibility on ANSSI’s MonEspaceNIS2 portal.
The rules determining whether an entity falls within the scope of NIS2 are intended to be consistent across countries. It is therefore very likely that an entity will be subject to the Directive in all countries where it is established.
Under Article 26, each entity is subject to the legislation of the country in which it is established, except for specific cases concerning digital services, telecommunications, and public administration. Applicability will therefore depend on the nature of the establishments operating in the different countries.
The companies concerned are subject to the regulation when they meet the criteria defining them as medium-sized or large enterprises (in most cases) and operate in one of the sectors listed in the annexes to the European legislation. Regarding the size and revenue criteria, both must be met cumulatively.
NIS2 applies broadly across 18 critical sectors, while DORA applies specifically to financial entities and their ICT providers. A financial institution can fall under both at once, and where they do, the two sets of obligations overlap substantially, particularly on incident reporting and third-party risk.
Article 21 sets ten categories of measures for both tiers, covering risk analysis, incident handling, business continuity, supply chain security, secure system development, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. The categories are identical, but the expected depth isn’t: essential entities face stricter supervision, while important entities can prioritise progressively. In France, ANSSI’s ReCyF reflects this directly, 20 security objectives for essential entities, 15 for important entities.
Yes, on both counts. Under Article 21(2)(d), outsourcing a function never transfers your own compliance liability, French courts have already confirmed that a regulated entity remains fully responsible for its subcontractors’ security failures. In practice, this makes the wording of your security clauses matter: vague references to “applicable standards and international usages” have already been challenged in French courts, providers have been ordered to pay damages for breaching explicit secure-development clauses, and courts have separately treated cybersecurity as an implicit essential quality of an IT contract even without one. For groups, NIS2 applies subsidiary by subsidiary and activity by activity, never automatically at group level: one subsidiary can fall into scope while another, in the same group, doesn’t.
