We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

+33 1 70 83 20 91
Phone

NIS2 Support for Small and Medium-Sized Enterprises (SMEs) and Mid-Sized Companies: Assessment, Action Plan, and Compliance

NIS2 is the European cybersecurity directive (EU 2022/2555) that extends security obligations to 18 sectors and thousands of French companies, including small and medium-sized enterprises (SMEs) and mid-sized companies. It mandates risk management measures, incident reporting, and personal liability for executives.

IT Systèmes supports small and medium-sized businesses (SMEs) and mid-sized companies throughout the entire process: determining whether you are affected, assessing the gap between your current practices and the requirements, implementing technical and organizational measures, and then maintaining compliance over time. We handle detection and response from France, and we apply the ISO 27001 certification process—which we have initiated—to our own services.

NIS2 in France: What's the Status of the Law?

The directive was to be transposed by Member States by October 17, 2024. In France, the bill on the resilience of critical infrastructure and the strengthening of cybersecurity was adopted by the Senate on March 12, 2025, and then by the National Assembly’s special committee on September 10, 2025. As of the date this page was written (September 2026), the law has not been enacted, and the European Commission referred the matter to the Court of Justice of the European Union on July 8, 2026, for failure to transpose the directive in a timely manner.

ANSSI, the designated national authority, published a draft framework on March 17, 2026—the Cyber France Framework (ReCyF)—which outlines the measures expected of significant entities. ANSSI presents this document as a working document: the obligations will not become enforceable until the law and its decrees are enacted.

This timeline does not excuse inaction. Critical entities are already imposing requirements on their suppliers as part of the supply chain, and insurers are making their contracts contingent on concrete measures. The measures required by NIS2 are standard security practices that every small and medium-sized enterprise would be wise to implement, with or without a legal obligation.

Our NIS2 Support

Qualification Assessment

Are you affected, and in what capacity? We’ll assess your industry sector based on the annexes to the directive, your size (number of employees and revenue), and your position in your customers’ supply chain. You’ll receive a written response indicating whether you are a critical entity, a significant entity, a supplier to a covered entity, or outside the scope of the directive.

Gap Analysis and Compliance Plan

We compare your current situation with the expected standards in the following areas: risk management, access security, backup and business continuity, incident detection, supply chain security, and training. The deliverable is a prioritized action plan that specifies, for each gap, the measure to be implemented, the person responsible, and the estimated budget.

Technical Measures

Deployment and operation of the expected components: multi-factor authentication, endpoint and server protection (EDR/XDR), privileged access management, configuration hardening, tested backups, and patch management. These measures can be integrated into our managed services or deployed within a limited scope.

Log Detection, Response, and Retention

NIS2 requires organizations to detect incidents, respond to them, and be able to demonstrate what happened. Our managed SOC, operated from France, collects and retains logs, detects attack scenarios, and triggers a response. For a more limited scope, our MDR service covers endpoints, email, and identities.

Governance and Executive Accountability

NIS2 holds executives personally liable. We formalize security policies, roles, incident management and reporting procedures, and provide training to management and teams. Employee awareness is part of the framework.

Maintaining Compliance

Compliance is maintained through periodic risk reviews, recovery tests, incident management drills, and monitoring of regulatory changes (transposition laws, decrees, ANSSI guidelines). Regular reporting enables you to provide evidence-based responses to clients, insurers, or auditors.

Why should you entrust your NIS2 compliance to IT Systèmes?

  • A single point of contact for diagnostics, technical measures, detection, and governance, rather than a consulting firm for advice and a service provider for operations.
  • Monitoring conducted from France, with log retention, which meets the requirement to document an incident.
  • We have been providing IT outsourcing services since 2010 to small and medium-sized enterprises (SMEs) and mid-sized companies in sectors covered by the directive: manufacturing, healthcare, digital services, and regulated firms.
  • We have initiated an ISO 27001 implementation process for our own services.
  • No long-term commitment required—just like all of our services.

Learn more:

NIS2: Does this apply to my company?

NIS2: What Is It? Directive, Compliance, and Requirements

NIS2 Compliance: A Practical Guide and Technical Measures for SMEs

Managed SOC and MDR

Privileged Access Management (PAM)

IT Security Audit

Contact us

A clear, rapid and personalized approach

Make an appointment
01

Qualification

Analysis of your industry, company size, and customer relationships to determine whether you are subject to NIS2, either directly or through the supply chain.
02

Variance Analysis

Review of current technical and organizational practices in light of the expected measures, including a prioritized and costed action plan.
03

Implementation of Measures

Deployment of technical components (MFA, EDR/XDR, PAM, backups, patches) and drafting of policies and procedures.
04

Detection and Response

Implementation of the managed SOC or MDR, depending on the scope, including log retention and incident reporting procedures.
05

Maintenance and Evidence

Periodic reviews, exercises, regulatory monitoring, and reporting—to maintain compliance over time and demonstrate it.

Your IT experts

Contact an expert
Amine
Computer technician
Amine
Amine
Laure
RH
Laure
Laure
Guillaume
Modern Workplace Consultant
Guillaume
Guillaume
Julien
Computer engineer
Julien
Julien
Anaïs
ADV
Anaïs
Anaïs
Amir
Developer
Amir
Amir
Nadia
Accountant
Nadia
Nadia
Thomas
Computer engineer
Thomas
Thomas
Christian
Computer engineer
Christian
Christian
Florent
Chief Executive Officer
Florent
Florent
Mohamed
Account manager
Mohamed
Mohamed
Johana
Computer technician
Johana
Johana
William
Technical Lead at ModernWork
William
William
Samuel
Project Manager
Samuel
Samuel
Emmanuel
Operations Manager
Emmanuel
Emmanuel
Bruno
Infrastructure Business Unit Director
Bruno
Bruno
Anthony
Outsourcing Manager
Anthony
Anthony
Kevin
Development Director
Kevin
Kevin
Olivier
Technical Manager
Olivier
Olivier
Yann
Computer engineer
Yann
Yann
Laudine
Computer engineer
Laudine
Laudine
Adrien
Computer engineer
Adrien
Adrien
Mathis
Developer
Mathis
Mathis
Samir
President
Samir
Samir

NIS2 FAQ

No items found.