NIS2 is coming. Are you affected?
The EU NIS2 directive extends cybersecurity obligations to thousands of French SMEs, with heavy sanctions and personal liability for executives. Check your status in 30 seconds — then turn the obligation into a roadmap.
Check your NIS2 status
Two questions are enough for a first orientation. Our interactive eligibility simulator currently runs in French only — no data leaves your browser.
Answer two questions (sector, company size) to get an indicative NIS2 status — essential entity, important entity, or out of scope.
Open the simulator (French) →From qualification to compliance
Four steps to approach NIS2 proactively rather than reactively: qualify, register, achieve compliance, maintain it.
1. Qualify
Determine whether you are an essential entity, an important entity, or out of scope — sector (Annexes I/II) cross-referenced with your size. That's what the eligibility check above covers.
2. Register
Affected entities register with ANSSI via the MonEspaceNIS2 platform (open for pre-registration). Identity, sector, point of contact.
3. Achieve compliance
Deploy the Article 21 measures (risk governance, MFA, encryption, backup, continuity, supply-chain security) and the incident notification procedure (24h / 72h / 1 month).
4. Maintain compliance
NIS2 is an ongoing regime: risk management, restoration testing, incident exercises, and documented evidence in case of an ANSSI audit.
You're not alone in financing your upgrade
The French government funds and structures SME security upgrades. We build your project so it fits these schemes when you're eligible — the real cost isn't always what you'd expect.
Cyber PME (France 2030)
France 2030 scheme operated by Bpifrance: support for securing SMEs with partial cost coverage (diagnostic, roadmap, first measures).
francenum.gouv.fr (opens in a new tab)MesServicesCyber (ANSSI)
ANSSI platform: free cyber diagnostic (≈1h30) with referral to complementary schemes. A no-cost starting point to scope your exposure.
francenum.gouv.fr (opens in a new tab)Mon ExpertCyber label
National label (Cybermalveillance.gouv.fr / AFNOR) distinguishing audited local cybersecurity providers. KOLOSALTech has engaged in the process.
cybermalveillance.gouv.fr (opens in a new tab)Eligibility and amounts depend on each scheme and your situation (size, sector, location). Public information — official sources linked above, to verify at the time of your project.
Frequently asked questions
Is NIS2 already applicable in France?
The EU NIS2 directive entered into force in October 2024. Its French transposition (the “Resilience law”) is currently being adopted: its entry into force will trigger the obligations and registration deadlines. Planning ahead now avoids being caught out by the timeline.
Is my SME of fewer than 50 employees affected?
As a general rule, micro and small businesses (fewer than 50 employees AND under €10M in revenue) fall outside the direct scope. Two exceptions: certain critical activities remain covered regardless of size (DNS, registries, telecoms, trust service providers, public administration); and if you are a subcontractor to an affected entity, it will impose security requirements on you by contract.
What's the difference between an essential and an important entity?
The substantive obligations (Article 21, incident notification) are the same. The difference lies in oversight — proactive supervision (audits, inspections) for essential entities, ex-post control for important entities — and in the sanction cap (up to €10M or 2% of worldwide turnover for essential entities, €7M or 1.4% for important entities).
Where should I actually start?
With an honest baseline assessment. Our free cyber diagnostic (2 minutes) maps your real maturity level, then we scope an NIS2 roadmap proportionate to your risk and budget — drawing on public financing schemes when you're eligible.
Turn NIS2 into an advantage, not a chore.
Free diagnostic, roadmap proportionate to your risk, public financing schemes mobilized. We start by measuring, not selling.