Key Takeaways
- NIS2 applies to approximately 15,000 entities in France across 18 sectors, compared to 500 under NIS1. The vast majority of SMEs outside the listed sectors are not directly covered by the regulation.
- Two cumulative criteria: your sector (Annex I or II of the directive) AND your size (≥ 50 employees or revenue > €10 million for a significant entity, ≥ 250 employees or revenue > €50 million for a critical entity).
- Certain entities are subject to these requirements regardless of their size: DNS providers, telecommunications operators, and qualified trust service providers.
- Even if you aren't directly affected, your NIS2 customers will impose security requirements on you through the supply chain clause—this is already happening.
- Registration on MonEspaceNIS2 is now required if you are within the scope (monespacenis2.cyber.gouv.fr).
- Penalties can reach 10 million euros or 2% of global revenue, and the executives of essential entities are personally liable.
- IT Systèmes conducts NIS2 qualification assessments and assists small and medium-sized businesses and mid-sized companies with their compliance plans.
NIS2 in France: An Overview in 2 Minutes
The NIS2 Directive (EU 2022/2555) was transposed into French law by the Act on the Resilience of Critical Infrastructure and the Strengthening of Cybersecurity, adopted in 2025. ANSSI is the competent national authority.
France, like most member states, had missed the European deadline of October 17, 2024. The European Commission launched an infringement procedure in late 2024. The law has now been adopted, and ANSSI has announced a transition period of approximately three years to achieve full compliance, starting from the publication of the technical guidelines, with a focus on providing guidance before imposing sanctions.
This deadline does not mean inaction. Registration on MonEspaceNIS2 is an immediate requirement for entities within the scope. And ANSSI’s preventive audits can begin without waiting for an incident to occur.
3 Questions to Help You Determine If This Applies to You
Question 1: Is your industry on the list?
NIS2 applies only to entities operating in the sectors listed in Annexes I and II of the directive. If your sector is not listed there, you are not a critical or important entity, but please read the section on the supply chain anyway.
Question 2: Is your height above the thresholds?
Thresholds defined by Recommendation 2003/361/EC. The calculation is performed on a legal entity-by-legal entity basis, not at the group level.
Question 3: Are you an exception with no threshold?
Certain entities are affected regardless of their size:
- Public DNS Service Providers
- Top-Level Domain (TLD) Registries
- Operators of public electronic communications networks
- Qualified Trusted Service Providers (electronic signatures, time stamps, etc.)
- Former OIVs (Operators of Vital Importance) and OSEs (Operators of Essential Services)
- Entities Designated as Critical Under the REC Directive
The 18 NIS2 sectors: Are you on the list?
Appendix I — Highly Critical Sectors (EE for large-scale projects, EI for medium-scale projects)
Appendix II — Other Critical Sectors (EI if ≥ 50 employees or revenue > 10 M€)
The following are NOT included in the NIS2 list: accounting firms, law firms, architectural firms, real estate agencies, management consulting firms, retail businesses, the hospitality and restaurant industry, and the construction industry (except for manufacturers of relevant materials). These sectors are not directly covered by the scope of the regulation but are indirectly affected (see the following section).
The Case of Suppliers and Subcontractors: The Indirect Impact
This is the most underestimated aspect of NIS2. Supply chain security is one of the ten categories of mandatory measures for essential and important entities. In practical terms: every NIS2 entity must assess and monitor its suppliers’ security practices.
What this means for an accounting firm, a law firm, or an IT service provider that works with a large industrial company, a hospital, or a bank:
Your NIS2 client will ask you to complete a security questionnaire, prove that you have active MFA, tested backups, and an incident management policy, and may require you to sign a security clause in your contract. If you are unable to meet these requirements, you risk losing the contract—not because of a fine, but because your client cannot afford to work with a provider that jeopardizes its own compliance.
The NIS2 supply chain functions like the DPA under the GDPR: it extends throughout the entire supply chain, even to unregulated entities.
IT Systems helps SME suppliers prepare for these contractual requirements before the NIS2 client even raises the issue.
If this applies to you: The 10 NIS2 Requirements
Article 21 of the directive lists ten categories of minimum measures. Here is what that means in practice:
ANSSI sets out these requirements in the Cyber France Framework (ReCyF), published on March 17, 2026. It lists the security objectives for critical entities (20 objectives) and important entities (15 objectives).
Schedule and Penalties
What to Do Now
Immediate Action: Indicate your status (EE / EI / not applicable) and register at monespacenis2.cyber.gouv.fr if you are within the scope of this requirement. ANSSI offers an online self-assessment tool.
Q3–Q4 2026: Map out your IT system and supplier dependencies. This is a prerequisite for any risk analysis.
2027: Implementation of priority measures (MFA, safeguards, detection, business continuity plan), training for executives, crisis drills.
Ongoing: Testing of the notification procedure, annual review of measures, supplier audits.
Penalties for Noncompliance
Unlike the GDPR, ANSSI inspections are preventive in nature for employers: document-based and on-site audits, security scans, and requests for information—without waiting for an incident to occur.
IT Systèmes: Your Partner for NIS2 Qualification and Compliance
IT Systèmes supports small and medium-sized businesses and mid-sized companies across two distinct NIS2 areas.
For entities directly affected (manufacturing, healthcare, digital infrastructure, MSPs): qualification audit, IT system mapping, EBIOS risk analysis, prioritized remediation plan, deployment of technical measures (MFA via Microsoft Entra ID, backups, EDR, detection), and support with ANSSI registration.
For NIS2 service providers (accounting firms, law firms, service providers): preparation for your NIS2 clients’ security questionnaires, implementation of the minimum security measures required by contract, and documentation to demonstrate your security level.
La plateforme Hypergérance d'IT Systèmes fournit nativement plusieurs éléments requis par NIS2 : supervision 24/7, alertes en temps réel, MTTA < 1 minute, gestion des incidents avec traçabilité, et rapports exploitables pour vos audits de conformité.
IT Systèmes also offers cybersecurity training for teams and executives—an explicit requirement under Article 20 of the NIS2 Directive.
Explore IT Systèmes' Cybersecurity and Compliance Solutions
FAQ — NIS2 and Entity Qualification
Is my accounting firm affected by NIS2? No, not directly. Accounting firms are not listed in Annexes I or II of the NIS2 Directive. They are therefore neither essential nor significant entities within the meaning of the directive. However, if your clients include industrial companies, healthcare facilities, or banks subject to NIS2, these clients will impose security requirements on you through the supply chain clause—just as the GDPR required you to have a Data Protection Agreement (DPA). Proactive preparation is therefore recommended.
Is a law firm or an IT services company with 30 employees affected? Neither law firms nor IT services companies with fewer than 50 employees fall directly within the NIS2 scope—unless the company provides managed ICT services to NIS2 entities and is designated as such by ANSSI. MSPs (managed service providers) are listed in Annex I under “ICT service management.” IT Systèmes assists MSPs in analyzing their own NIS2 compliance status.
Is the French NIS2 law already in effect? The transposition law was adopted in 2025. Its practical implementation depends on the implementing decrees and ANSSI guidelines. ANSSI has announced a roughly 3-year grace period for achieving full compliance, with a support phase before the first penalties are imposed. Registration on MonEspaceNIS2, however, is an immediate requirement for entities within the scope of the law.
What is the difference between NIS2 and the GDPR for an SME? The GDPR protects the personal data of your customers and employees. NIS2 protects information systems in critical sectors. The technical measures largely overlap (risk analysis, MFA, backups, incident reporting), but the supervisory authorities are different: the CNIL for the GDPR and ANSSI for NIS2. An incident may trigger a dual reporting obligation—to the CNIL within 72 hours if personal data is affected, and to ANSSI within 24 hours if you are a NIS2 entity.
For a group with 300 employees and several subsidiaries, does the threshold apply at the group level or the subsidiary level? At the subsidiary level. The thresholds are calculated on a legal entity-by-legal entity basis. A holding company with 300 employees and subsidiaries with 30 employees each: only the holding company exceeds the threshold, not the subsidiaries. However, if the subsidiaries are in an Annex I or II sector and individually exceed the thresholds, they are classified independently.
What are the personal risks for a senior executive in the event of NIS2 non-compliance? For critical entities only: the senior executive may be held personally liable and subject to a temporary ban on holding executive positions in the event of a serious breach of risk management obligations. This personal liability is new compared to the GDPR, where liability rests with the company. For significant entities, penalties apply to the entity, not directly to the executives.
Is a dedicated CISO required to comply with NIS2? NIS2 does not explicitly require a full-time CISO. It requires that management approve and oversee security measures, and that executives receive training. For an SME or mid-sized company, an outsourced CISO (vCISO) or an MSP provider with cybersecurity expertise, such as IT Systèmes, can fulfill this governance role without hiring a full-time senior executive.
See also
- Ransomware: What to Do in the First 24 Hours? — The crisis response protocol and NIS2 notification requirements
- Microsoft Defender for Cloud: SMB Guide 2026 — Securing Your Azure Resources Under NIS2



