Where the law stands
The NIS2 directive was due to be transposed in every country by October 2024. France, like most member states, is late: the law on the resilience of critical infrastructure and the strengthening of cybersecurity is going through Parliament in 2026. It designates ANSSI as the national authority and subjects about 15,000 entities, against 500 under the first directive, to risk-management, registration and incident-notification duties.
The expected timeline: risk analysis and security policy by the end of 2026, deployment of measures and exercises in 2027. Planned penalties go up to 10 million euros or 2% of worldwide turnover for essential entities.
Am I in scope?
Three cases:
- Directly, if you are in one of the eighteen targeted sectors and above the size thresholds, generally fifty employees or ten million euros of revenue. You will be an "important" or "essential" entity, with graduated duties.
- Indirectly, if one of your customers is regulated: they must verify the security of their supply chain, and will ask you through a questionnaire, a contract clause or an audit. This is the most common case for an SME.
- Not at all, which is no reason to do nothing: NIS2's measures are the ones that stop ransomware, and ransomware does not read the directive before attacking.
The measures that do 80% of the work
- Strong authentication on e-mail, VPN, server administration and online tools.
- Backups encrypted, offline or off-site, checked nightly and tested by a restore every quarter.
- Scheduled updates of workstations, servers and network equipment.
- Logging of access and administrative actions, kept long enough to understand an incident.
- Access management: who is entitled to what, accounts of former employees and suppliers closed.
- A written continuity and recovery plan, known and exercised once a year.
What we saw at a client
An accounting server whose backup had been frozen for more than two years, while the upload mechanism sent an old image every night without any alert. A restore would have taken the company two years back. This is exactly the kind of flaw a risk analysis reveals in a day, and that NIS2 requires to fix.
References
- ANSSI and the NIS2 directive: the official status of the transposition, with the self-assessment space MonEspaceNIS2.
- The NIS2 directive on the European Commission's site.
- ANSSI's IT hygiene guide: the 42 basic measures, still valid.