Michael Aim
Founder & CEO
The NIS2 directive was due for transposition by 17 October 2024. France missed the deadline, to the point that on 8 July 2026 the Commission decided to refer it to the EU Court of Justice alongside Spain, Ireland and the Netherlands, requesting financial sanctions. The so-called Resilience law, meant to transpose the text, is not on July's parliamentary agenda: its examination slips to the autumn. The European obligation, meanwhile, has been running since October 2024.
One detail changes everything for anyone wanting to move: the technical framework is already public. In March 2026 ANSSI published its Référentiel Cyber France, translating NIS2 requirements into security objectives, twenty for essential entities and fifteen for important ones. Most of what will be asked is therefore known before the law is even voted. Waiting for the text means waiting for the formatting of obligations whose substance is already available.
The change of scale is the real subject: from a few hundred operators under NIS1, France moves to 15,000 to 18,000 covered entities, split between “essential” and “important” entities. Industrial mid-caps, local authorities, health, transport or agrifood players will discover they are in scope, with risk management obligations, incident reporting duties, and ANSSI supervision.
From good practice to auditable arrangement
The conceptual shift is the same as GDPR in its time: cybersecurity stops being a subject of experts and good intentions and becomes an arrangement whose existence and operation you must be able to demonstrate. Governance, risk analysis, supply-chain security, incident management, continuity: every requirement of the directive implies evidence.
And the asymmetry of sanctions concentrates minds: up to 10 million euros or 2% of worldwide turnover for essential entities, with proactive controls; 7 million or 1.4% for important entities, controlled after incidents. In both cases, on control day, improvisation shows.
What the directive concretely requires
NIS2 imposes a minimal base of measures: security policies and risk analysis, incident handling, business continuity and crisis management, supply-chain security, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, multi-factor authentication. Ten families of requirements which, in effect, draw a framework.
Add the mechanics of significant incident notification, in tight steps: early warning within 24 hours, notification within 72 hours, final report within a month. Meeting those deadlines cannot be improvised on incident day: it presupposes detection, qualification and a decision chain already in place, and already tested.
The supply-chain effect
The real scope exceeds the 15,000 designated entities: the directive requires them to master their supply chain's security, and that requirement trickles down contractually. A software subcontractor, an industrial maintainer or a logistics provider outside the scope will receive its regulated clients' questionnaires and clauses.
For those suppliers, the smart reading is commercial: the one who shows up with a measured, demonstrable cyber maturity turns an endured constraint into a listing argument. In the tenders of 2027, it will be a sorting criterion, not a bonus.
Where to start
For an organisation discovering the subject, the reasonable order holds in three gestures: determine whether you are in scope, and in which category; measure your real maturity against the directive's requirements, entity by entity, rather than collecting one-off audits; and convert the gaps into a dated action plan, because the upgrade will take months and the calendar will not wait.
Our catalogue holds 11 cybersecurity frameworks to equip that measurement, and the logic holds for groups: each subsidiary assessed on the same base, a consolidation that shows where to concentrate the effort. NIS2 compliance will be an administered marathon; better to enter it with an instrument.