We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity
Advice

NIS2: Will this affect my company in 2026?

NIS2 applies to 15,000 entities in France: sector × size classification table, EE/EI thresholds, requirements, and timeline. Find out your status in 3 questions.

NIS2: Will this affect my company in 2026?

Key Takeaways

  • NIS2 applies to approximately 15,000 entities in France across 18 sectors, compared to 500 under NIS1. The vast majority of SMEs outside the listed sectors are not directly covered by the regulation.
  • Two cumulative criteria: your sector (Annex I or II of the directive) AND your size (≥ 50 employees or revenue > €10 million for a significant entity, ≥ 250 employees or revenue > €50 million for a critical entity).
  • Certain entities are subject to these requirements regardless of their size: DNS providers, telecommunications operators, and qualified trust service providers.
  • Even if you aren't directly affected, your NIS2 customers will impose security requirements on you through the supply chain clause—this is already happening.
  • Registration on MonEspaceNIS2 is now required if you are within the scope (monespacenis2.cyber.gouv.fr).
  • Penalties can reach 10 million euros or 2% of global revenue, and the executives of essential entities are personally liable.
  • IT Systèmes conducts NIS2 qualification assessments and assists small and medium-sized businesses and mid-sized companies with their compliance plans.

NIS2 in France: An Overview in 2 Minutes

The NIS2 Directive (EU 2022/2555) was transposed into French law by the Act on the Resilience of Critical Infrastructure and the Strengthening of Cybersecurity, adopted in 2025. ANSSI is the competent national authority.

France, like most member states, had missed the European deadline of October 17, 2024. The European Commission launched an infringement procedure in late 2024. The law has now been adopted, and ANSSI has announced a transition period of approximately three years to achieve full compliance, starting from the publication of the technical guidelines, with a focus on providing guidance before imposing sanctions.

This deadline does not mean inaction. Registration on MonEspaceNIS2 is an immediate requirement for entities within the scope. And ANSSI’s preventive audits can begin without waiting for an incident to occur.

3 Questions to Help You Determine If This Applies to You

Question 1: Is your industry on the list?

NIS2 applies only to entities operating in the sectors listed in Annexes I and II of the directive. If your sector is not listed there, you are not a critical or important entity, but please read the section on the supply chain anyway.

Question 2: Is your height above the thresholds?

Category Threshold Sectors Maximum Penalties
Essential Entity EE ≥ 250 employees OR Revenue > 50 M€ AND Balance Sheet > 43 M€ Appendix Ionly: Energy, transportation, banking, healthcare… 10 M€ or 2% of global revenue
Significant Entity EI ≥ 50 employees OR Revenue > 10 M€ Appendices I andII: Postal services, digital services, water, space… 7 M€ or 1.4% of global revenue
No minimum size requirement Regardless of the size
DNS TLD Telecom Trusted Qualified OIV / OSE
By category
Not directly affected Below the thresholds, excluding the listed sectors All other sectors

Thresholds defined by Recommendation 2003/361/EC. The calculation is performed on a legal entity-by-legal entity basis, not at the group level.

Question 3: Are you an exception with no threshold?

Certain entities are affected regardless of their size:

  • Public DNS Service Providers
  • Top-Level Domain (TLD) Registries
  • Operators of public electronic communications networks
  • Qualified Trusted Service Providers (electronic signatures, time stamps, etc.)
  • Former OIVs (Operators of Vital Importance) and OSEs (Operators of Essential Services)
  • Entities Designated as Critical Under the REC Directive

The 18 NIS2 sectors: Are you on the list?

Appendix I — Highly Critical Sectors (EE for large-scale projects, EI for medium-scale projects)

Sector Examples of Entities Affected
Energy
Producers, network operators for electricity, gas, oil, hydrogen, and heat
Transportation
Air, rail, inland waterways, maritime, and road — infrastructure and operators
Banking Sector
Credit institutions, payment service providers
Financial Markets
Central securities depositories, clearing houses, trading platforms
Health
Hospitals, laboratories, pharmaceutical R&D, manufacturers of critical medical devices
Drinking water
Drinking Water Suppliers and Distributors
Wastewater
Wastewater Collection, Treatment, and Discharge
Digital Infrastructure
Data centers, CDNs, cloud computing, IXPs, recursive DNS, trusted services
ICT Service Management
Managed IT Service Providers (MSPs),MSSPs Affected
Public Administration
State, regions, departments, municipalities with more than 30,000 residents
Space
Operators of ground-based space infrastructure

Appendix II — Other Critical Sectors (EI if ≥ 50 employees or revenue > 10 M€)

Sector Examples of Entities Affected
Postal and Courier Services
Postal operators, express couriers
Waste Management
Waste Collection, Treatment, and Disposal
Chemistry
Manufacturing, production, and distribution of chemical products
Agri-Food
Production, processing, and distribution of food products
Manufacturing
Medical devices, electronics, machinery, motor vehicles, trailers
Digital Providers
Search engines, marketplaces, social media
Search
Research Organizations

The following are NOT included in the NIS2 list: accounting firms, law firms, architectural firms, real estate agencies, management consulting firms, retail businesses, the hospitality and restaurant industry, and the construction industry (except for manufacturers of relevant materials). These sectors are not directly covered by the scope of the regulation but are indirectly affected (see the following section).

The Case of Suppliers and Subcontractors: The Indirect Impact

This is the most underestimated aspect of NIS2. Supply chain security is one of the ten categories of mandatory measures for essential and important entities. In practical terms: every NIS2 entity must assess and monitor its suppliers’ security practices.

What this means for an accounting firm, a law firm, or an IT service provider that works with a large industrial company, a hospital, or a bank:

Your NIS2 client will ask you to complete a security questionnaire, prove that you have active MFA, tested backups, and an incident management policy, and may require you to sign a security clause in your contract. If you are unable to meet these requirements, you risk losing the contract—not because of a fine, but because your client cannot afford to work with a provider that jeopardizes its own compliance.

The NIS2 supply chain functions like the DPA under the GDPR: it extends throughout the entire supply chain, even to unregulated entities.

IT Systems helps SME suppliers prepare for these contractual requirements before the NIS2 client even raises the issue.

If this applies to you: The 10 NIS2 Requirements

Article 21 of the directive lists ten categories of minimum measures. Here is what that means in practice:

Measurement What ANSSI Specifically Expects
Risk Analysis and Security Policies
Documented PSSI, EBIOS Risk Manager analysis, or equivalent
Incident Management
Procedure for detection, qualification, and notification within 24 hours/ 72 hours
Business Continuity
Documented and tested PCA/PRA, verified backups
Supply Chain Security
Supplier Evaluation, Security Contract Clauses
Development and Procurement Security
Component verification, application security testing
Assessment of the Effectiveness of the Measures
Regular audits, penetration tests (PASSI-certified for EE)
IT Security and Training
Training for Teams and Leaders, Phishing Awareness
Cryptography
Encryption of sensitive data in transit and at rest
Human Resources Security
Pre-employment screenings, exit management, security clearances
Multi-factor authentication (MFA)
MFA for all remote access and privileged accounts

ANSSI sets out these requirements in the Cyber France Framework (ReCyF), published on March 17, 2026. It lists the security objectives for critical entities (20 objectives) and important entities (15 objectives).

Schedule and Penalties

What to Do Now

Immediate Action: Indicate your status (EE / EI / not applicable) and register at monespacenis2.cyber.gouv.fr if you are within the scope of this requirement. ANSSI offers an online self-assessment tool.

Q3–Q4 2026: Map out your IT system and supplier dependencies. This is a prerequisite for any risk analysis.

2027: Implementation of priority measures (MFA, safeguards, detection, business continuity plan), training for executives, crisis drills.

Ongoing: Testing of the notification procedure, annual review of measures, supplier audits.

Penalties for Noncompliance

Entity Type Maximum fine Management Liability
Essential Entity EE 10 M€ or 2% of annual global revenue Yes Temporary ban on holding executive positions in the event of a serious breach
Significant Entity EI 7 M€ or 1.4% of annual global revenue No Possible injunctions and penalty payments

Unlike the GDPR, ANSSI inspections are preventive in nature for employers: document-based and on-site audits, security scans, and requests for information—without waiting for an incident to occur.

IT Systèmes: Your Partner for NIS2 Qualification and Compliance

IT Systèmes supports small and medium-sized businesses and mid-sized companies across two distinct NIS2 areas.

For entities directly affected (manufacturing, healthcare, digital infrastructure, MSPs): qualification audit, IT system mapping, EBIOS risk analysis, prioritized remediation plan, deployment of technical measures (MFA via Microsoft Entra ID, backups, EDR, detection), and support with ANSSI registration.

For NIS2 service providers (accounting firms, law firms, service providers): preparation for your NIS2 clients’ security questionnaires, implementation of the minimum security measures required by contract, and documentation to demonstrate your security level.

La plateforme Hypergérance d'IT Systèmes fournit nativement plusieurs éléments requis par NIS2 : supervision 24/7, alertes en temps réel, MTTA < 1 minute, gestion des incidents avec traçabilité, et rapports exploitables pour vos audits de conformité.

IT Systèmes also offers cybersecurity training for teams and executives—an explicit requirement under Article 20 of the NIS2 Directive.

Explore IT Systèmes' Cybersecurity and Compliance Solutions

FAQ — NIS2 and Entity Qualification

Is my accounting firm affected by NIS2? No, not directly. Accounting firms are not listed in Annexes I or II of the NIS2 Directive. They are therefore neither essential nor significant entities within the meaning of the directive. However, if your clients include industrial companies, healthcare facilities, or banks subject to NIS2, these clients will impose security requirements on you through the supply chain clause—just as the GDPR required you to have a Data Protection Agreement (DPA). Proactive preparation is therefore recommended.

Is a law firm or an IT services company with 30 employees affected? Neither law firms nor IT services companies with fewer than 50 employees fall directly within the NIS2 scope—unless the company provides managed ICT services to NIS2 entities and is designated as such by ANSSI. MSPs (managed service providers) are listed in Annex I under “ICT service management.” IT Systèmes assists MSPs in analyzing their own NIS2 compliance status.

Is the French NIS2 law already in effect? The transposition law was adopted in 2025. Its practical implementation depends on the implementing decrees and ANSSI guidelines. ANSSI has announced a roughly 3-year grace period for achieving full compliance, with a support phase before the first penalties are imposed. Registration on MonEspaceNIS2, however, is an immediate requirement for entities within the scope of the law.

What is the difference between NIS2 and the GDPR for an SME? The GDPR protects the personal data of your customers and employees. NIS2 protects information systems in critical sectors. The technical measures largely overlap (risk analysis, MFA, backups, incident reporting), but the supervisory authorities are different: the CNIL for the GDPR and ANSSI for NIS2. An incident may trigger a dual reporting obligation—to the CNIL within 72 hours if personal data is affected, and to ANSSI within 24 hours if you are a NIS2 entity.

For a group with 300 employees and several subsidiaries, does the threshold apply at the group level or the subsidiary level? At the subsidiary level. The thresholds are calculated on a legal entity-by-legal entity basis. A holding company with 300 employees and subsidiaries with 30 employees each: only the holding company exceeds the threshold, not the subsidiaries. However, if the subsidiaries are in an Annex I or II sector and individually exceed the thresholds, they are classified independently.

What are the personal risks for a senior executive in the event of NIS2 non-compliance? For critical entities only: the senior executive may be held personally liable and subject to a temporary ban on holding executive positions in the event of a serious breach of risk management obligations. This personal liability is new compared to the GDPR, where liability rests with the company. For significant entities, penalties apply to the entity, not directly to the executives.

Is a dedicated CISO required to comply with NIS2? NIS2 does not explicitly require a full-time CISO. It requires that management approve and oversee security measures, and that executives receive training. For an SME or mid-sized company, an outsourced CISO (vCISO) or an MSP provider with cybersecurity expertise, such as IT Systèmes, can fulfill this governance role without hiring a full-time senior executive.

See also

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

In 1996, I took my first steps in computing on an Excel spreadsheet where I filed cheat codes for my favorite video games. 🕹️Le the beginning of a passion for office tools (to each his own 😅 ). There were 3,000 machines connected to the internet! 😶 But what happened next?
July 3, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
June 26, 2026
backup-vs-retention
Cloud & infrastructure

Comparing backup VS retention

Backup VS retention: here's the match everyone's been waiting for!!!! 🥊 (okai not at all but I needed a catchy title..🤫)
July 3, 2026