Skip to content
NIS2 Compliance · SMEs

NIS2 is coming. Are you affected?

The EU NIS2 directive extends cybersecurity obligations to thousands of French SMEs, with heavy sanctions and personal liability for executives. Check your status in 30 seconds · then turn the obligation into a roadmap.

French transposition (the “Resilience law”) is underway: plan ahead for the timeline.
≈15,000
entities affected in France
18
sectors covered (Annexes I & II)
€10M
max. sanction (essential entity)
Executives
personal liability at stake

Check your NIS2 status

Two questions are enough for a first orientation. Our interactive eligibility simulator currently runs in French only: no data leaves your browser.

Answer two questions (sector, company size) to get an indicative NIS2 status: essential entity, important entity, or out of scope.

Open the simulator (French) →
Timeline & steps

From qualification to compliance

Four steps to approach NIS2 proactively rather than reactively: qualify, register, achieve compliance, maintain it.

1. Qualify

Determine whether you are an essential entity, an important entity, or out of scope, sector (Annexes I/II) cross-referenced with your size. That's what the eligibility check above covers.

2. Register

Affected entities register with ANSSI via the MonEspaceNIS2 platform (open for pre-registration). Identity, sector, point of contact.

3. Achieve compliance

Deploy the Article 21 measures (risk governance, MFA, encryption, backup, continuity, supply-chain security) and the incident notification procedure (24h / 72h / 1 month).

4. Maintain compliance

NIS2 is an ongoing regime: risk management, restoration testing, incident exercises, and documented evidence in case of an ANSSI audit.

Funding & French public schemes

Check which public funding schemes apply

Some French public schemes can help eligible small businesses assess or improve cybersecurity. Check the current rules on the official service before including any funding in your budget.

Co-financed diagnostic and action plan

Cyber PME (France 2030)

France 2030 scheme operated by Bpifrance: support for securing small and mid-sized companies with part of the cost covered (diagnostic, roadmap, first measures).

francenum.gouv.fr (opens in a new tab)
Free first-level diagnostic

MesServicesCyber (ANSSI)

ANSSI platform: a free cyber diagnostic (about 1 h 30) and referral to complementary schemes. A no-cost starting point to scope your exposure.

francenum.gouv.fr (opens in a new tab)
Choose a trusted provider

Mon ExpertCyber label

National label run by Cybermalveillance.gouv.fr and AFNOR for audited local providers. Check the current public directory before choosing a provider.

cybermalveillance.gouv.fr (opens in a new tab)

Eligibility, scope and funding amounts can change. Confirm the current rules with the organisation running the scheme before you commit to a project.

Frequently asked questions

Is NIS2 already applicable in France?

The EU NIS2 directive entered into force in October 2024. Its French transposition (the “Resilience law”) is currently being adopted: its entry into force will trigger the obligations and registration deadlines. Planning ahead now avoids being caught out by the timeline.

Is my SME of fewer than 50 employees affected?

As a general rule, micro and small businesses (fewer than 50 employees AND under €10M in revenue) fall outside the direct scope. Two exceptions: certain critical activities remain covered regardless of size (DNS, registries, telecoms, trust service providers, public administration); and if you are a subcontractor to an affected entity, it will impose security requirements on you by contract.

What's the difference between an essential and an important entity?

The substantive obligations (Article 21, incident notification) are the same. The difference lies in oversight, proactive supervision (audits, inspections) for essential entities, ex-post control for important entities, and in the sanction cap (up to €10M or 2% of worldwide turnover for essential entities, €7M or 1.4% for important entities).

Where should I actually start?

With an honest baseline assessment. Our free cyber diagnostic (2 minutes) maps your real maturity level, then we scope an NIS2 roadmap proportionate to your risk and budget: drawing on public financing schemes when you're eligible.

Turn NIS2 into an advantage, not a chore.

Free diagnostic, roadmap proportionate to your risk, public financing schemes mobilized. We start by measuring, not selling.