NIS2 Support for Small and Medium-Sized Enterprises (SMEs) and Mid-Sized Companies: Assessment, Action Plan, and Compliance
NIS2 is the European cybersecurity directive (EU 2022/2555) that extends security obligations to 18 sectors and thousands of French companies, including small and medium-sized enterprises (SMEs) and mid-sized companies. It mandates risk management measures, incident reporting, and personal liability for executives.
IT Systèmes supports small and medium-sized businesses (SMEs) and mid-sized companies throughout the entire process: determining whether you are affected, assessing the gap between your current practices and the requirements, implementing technical and organizational measures, and then maintaining compliance over time. We handle detection and response from France, and we apply the ISO 27001 certification process—which we have initiated—to our own services.
NIS2 in France: What's the Status of the Law?
The directive was to be transposed by Member States by October 17, 2024. In France, the bill on the resilience of critical infrastructure and the strengthening of cybersecurity was adopted by the Senate on March 12, 2025, and then by the National Assembly’s special committee on September 10, 2025. As of the date this page was written (September 2026), the law has not been enacted, and the European Commission referred the matter to the Court of Justice of the European Union on July 8, 2026, for failure to transpose the directive in a timely manner.
ANSSI, the designated national authority, published a draft framework on March 17, 2026—the Cyber France Framework (ReCyF)—which outlines the measures expected of significant entities. ANSSI presents this document as a working document: the obligations will not become enforceable until the law and its decrees are enacted.
This timeline does not excuse inaction. Critical entities are already imposing requirements on their suppliers as part of the supply chain, and insurers are making their contracts contingent on concrete measures. The measures required by NIS2 are standard security practices that every small and medium-sized enterprise would be wise to implement, with or without a legal obligation.
Our NIS2 Support
Qualification Assessment
Gap Analysis and Compliance Plan
Technical Measures
Log Detection, Response, and Retention
Governance and Executive Accountability
Maintaining Compliance
Why should you entrust your NIS2 compliance to IT Systèmes?
- A single point of contact for diagnostics, technical measures, detection, and governance, rather than a consulting firm for advice and a service provider for operations.
- Monitoring conducted from France, with log retention, which meets the requirement to document an incident.
- We have been providing IT outsourcing services since 2010 to small and medium-sized enterprises (SMEs) and mid-sized companies in sectors covered by the directive: manufacturing, healthcare, digital services, and regulated firms.
- We have initiated an ISO 27001 implementation process for our own services.
- No long-term commitment required—just like all of our services.
Learn more:
→ NIS2: Does this apply to my company?
→ NIS2: What Is It? Directive, Compliance, and Requirements
→ NIS2 Compliance: A Practical Guide and Technical Measures for SMEs










-2-2.webp)


-2-3.webp)
-6.webp)



-5.webp)





.webp)