NIS2 for SMEs: in scope, and where to startThe directive targets 15,000 entities in France. Many SMEs will discover it through a customer's questionnaire.

NIS2 is the European directive raising the cybersecurity level of essential and important sectors. Its French transposition, the resilience law, is going through Parliament in 2026 and puts ANSSI, the national cybersecurity agency, in charge. Even if your SME is not directly targeted, your regulated customers must verify the security of their supply chain, and that is often how the topic lands on your desk.

Your situations

How NIS2 reaches an SME

A large customer sends a forty-question security questionnaire, due back within two weeks.

A public tender now requires a security policy and a recovery plan.

You are in one of the eighteen targeted sectors, transport, food, health, water, energy, digital, and you do not know whether the size threshold applies to you.

Your backups exist, but nobody has ever tested a restore.

Two-factor authentication is only enabled on the manager's mailbox.

The IT provider says everything is secure, with no document to prove it.

What we deliver

What we put in place

A readable risk analysis

What is critical for you, what can happen, what it would cost. Following ANSSI's EBIOS Risk Manager method, scaled to an SME: a ten-page document, not a hundred.

The measures that matter, in order

Strong authentication everywhere, encrypted and tested backups, scheduled updates, logging, network segmentation, supplier access management.

Proof for your customers

A security policy, a business continuity and recovery plan, an incident register: the documents a regulated customer or an auditor will ask for.

Operations that last

Compliance is not a yearly audit, it is a daily practice. We run it as part of our managed services, with a monthly report.

How it works

A realistic timeline

  1. 01

    Week 1: am I in scope?

    Sector, size, revenue, regulated customers: we answer the question in one meeting, and document it.

  2. 02

    Month 1: risk analysis

    Map of your information system, risk scenarios, priorities. The document everything else builds on.

  3. 03

    Months 2 and 3: priority measures

    Strong authentication, tested backups, updates, logging. What reduces risk the most for the least effort.

  4. 04

    Then: operations and proof

    Monthly report, incident-handling exercise, answers to customer questionnaires. Compliance becomes routine.

Where the law stands

The NIS2 directive was due to be transposed in every country by October 2024. France, like most member states, is late: the law on the resilience of critical infrastructure and the strengthening of cybersecurity is going through Parliament in 2026. It designates ANSSI as the national authority and subjects about 15,000 entities, against 500 under the first directive, to risk-management, registration and incident-notification duties.

The expected timeline: risk analysis and security policy by the end of 2026, deployment of measures and exercises in 2027. Planned penalties go up to 10 million euros or 2% of worldwide turnover for essential entities.

Am I in scope?

Three cases:

  • Directly, if you are in one of the eighteen targeted sectors and above the size thresholds, generally fifty employees or ten million euros of revenue. You will be an "important" or "essential" entity, with graduated duties.
  • Indirectly, if one of your customers is regulated: they must verify the security of their supply chain, and will ask you through a questionnaire, a contract clause or an audit. This is the most common case for an SME.
  • Not at all, which is no reason to do nothing: NIS2's measures are the ones that stop ransomware, and ransomware does not read the directive before attacking.

The measures that do 80% of the work

  • Strong authentication on e-mail, VPN, server administration and online tools.
  • Backups encrypted, offline or off-site, checked nightly and tested by a restore every quarter.
  • Scheduled updates of workstations, servers and network equipment.
  • Logging of access and administrative actions, kept long enough to understand an incident.
  • Access management: who is entitled to what, accounts of former employees and suppliers closed.
  • A written continuity and recovery plan, known and exercised once a year.

What we saw at a client

An accounting server whose backup had been frozen for more than two years, while the upload mechanism sent an old image every night without any alert. A restore would have taken the company two years back. This is exactly the kind of flaw a risk analysis reveals in a day, and that NIS2 requires to fix.

References

Proof

What we already operate

  • Backup takeover of a Windows accounting server for a Gironde SME: 784 missed backups found at audit, none since, encrypted backups hosted in France and a quarterly restore test.

  • Operations of a Kubernetes cluster hosting the websites and CMS of a construction group, with versioned deployments and rollback.

  • A health platform designed with no personal data, read-only access by default, encrypted secrets, tested backups: security as a design property.

Frequently asked questions

Questions we are asked about NIS2

We have twenty employees, are we in scope?

Directly, rarely: NIS2's thresholds generally target companies with more than fifty employees in the listed sectors. Indirectly, often: if one of your customers is regulated, they will ask you for guarantees. We check your case in one meeting and document it, which will serve as your answer to those requests.

Should we wait for the French law to pass?

No. The measures required, strong authentication, tested backups, risk analysis, are the same ones that protect you from ransomware today. Waiting means running the risk without benefiting from the delay. What can wait is the formal registration with ANSSI.

How much does compliance cost for an SME?

The risk analysis and security policy represent a few engineer days. Technical measures depend on what exists: enabling strong authentication costs almost nothing, rebuilding a backup chain takes days. We price after the analysis, never before, and spread the work over the law's timeline.

Do we have to report incidents?

Regulated entities will have to notify ANSSI within 24 hours of a significant incident, with a report within 72 hours. For a non-regulated SME there is no legal duty, but an incident register is what your customers and your insurer will ask for. We keep it for you as part of managed services.

What if we already have an IT provider?

We work with them. The risk analysis and documentation are independent of who runs the systems, and an outside view is exactly what a regulated customer asks for. If you later wish to entrust us with operations, the transition happens without interruption.

Find out in thirty minutes whether NIS2 applies to you

A no-commitment call, a documented answer, and if needed a realistic timeline to get compliant.

Book a free diagnostic

Nous utilisons des cookies pour analyser le trafic et améliorer votre expérience. En savoir plus