Skip to content
KOLOSALTech
NIS2 Compliance · SMEs

NIS2 is coming. Are you affected?

The EU NIS2 directive extends cybersecurity obligations to thousands of French SMEs, with heavy sanctions and personal liability for executives. Check your status in 30 seconds — then turn the obligation into a roadmap.

French transposition (the “Resilience law”) is underway — plan ahead for the timeline.
≈15,000
entities affected in France
18
sectors covered (Annexes I & II)
€10M
max. sanction (essential entity)
Executives
personal liability at stake

Check your NIS2 status

Two questions are enough for a first orientation. Our interactive eligibility simulator currently runs in French only — no data leaves your browser.

Answer two questions (sector, company size) to get an indicative NIS2 status — essential entity, important entity, or out of scope.

Open the simulator (French) →
Timeline & steps

From qualification to compliance

Four steps to approach NIS2 proactively rather than reactively: qualify, register, achieve compliance, maintain it.

1. Qualify

Determine whether you are an essential entity, an important entity, or out of scope — sector (Annexes I/II) cross-referenced with your size. That's what the eligibility check above covers.

2. Register

Affected entities register with ANSSI via the MonEspaceNIS2 platform (open for pre-registration). Identity, sector, point of contact.

3. Achieve compliance

Deploy the Article 21 measures (risk governance, MFA, encryption, backup, continuity, supply-chain security) and the incident notification procedure (24h / 72h / 1 month).

4. Maintain compliance

NIS2 is an ongoing regime: risk management, restoration testing, incident exercises, and documented evidence in case of an ANSSI audit.

Financing & public schemes

You're not alone in financing your upgrade

The French government funds and structures SME security upgrades. We build your project so it fits these schemes when you're eligible — the real cost isn't always what you'd expect.

Co-financed diagnostic + action plan

Cyber PME (France 2030)

France 2030 scheme operated by Bpifrance: support for securing SMEs with partial cost coverage (diagnostic, roadmap, first measures).

francenum.gouv.fr (opens in a new tab)
Free first-level diagnostic

MesServicesCyber (ANSSI)

ANSSI platform: free cyber diagnostic (≈1h30) with referral to complementary schemes. A no-cost starting point to scope your exposure.

francenum.gouv.fr (opens in a new tab)
Choose a trusted provider

Mon ExpertCyber label

National label (Cybermalveillance.gouv.fr / AFNOR) distinguishing audited local cybersecurity providers. KOLOSALTech has engaged in the process.

cybermalveillance.gouv.fr (opens in a new tab)

Eligibility and amounts depend on each scheme and your situation (size, sector, location). Public information — official sources linked above, to verify at the time of your project.

Frequently asked questions

Is NIS2 already applicable in France?

The EU NIS2 directive entered into force in October 2024. Its French transposition (the “Resilience law”) is currently being adopted: its entry into force will trigger the obligations and registration deadlines. Planning ahead now avoids being caught out by the timeline.

Is my SME of fewer than 50 employees affected?

As a general rule, micro and small businesses (fewer than 50 employees AND under €10M in revenue) fall outside the direct scope. Two exceptions: certain critical activities remain covered regardless of size (DNS, registries, telecoms, trust service providers, public administration); and if you are a subcontractor to an affected entity, it will impose security requirements on you by contract.

What's the difference between an essential and an important entity?

The substantive obligations (Article 21, incident notification) are the same. The difference lies in oversight — proactive supervision (audits, inspections) for essential entities, ex-post control for important entities — and in the sanction cap (up to €10M or 2% of worldwide turnover for essential entities, €7M or 1.4% for important entities).

Where should I actually start?

With an honest baseline assessment. Our free cyber diagnostic (2 minutes) maps your real maturity level, then we scope an NIS2 roadmap proportionate to your risk and budget — drawing on public financing schemes when you're eligible.

Turn NIS2 into an advantage, not a chore.

Free diagnostic, roadmap proportionate to your risk, public financing schemes mobilized. We start by measuring, not selling.