Article at a glance: NIS 2 affects between 15,000 and 18,000 French companies, with penalties of up to €10 million and Accountability for executives. The French implementation is expected in July 2026, but preparing now is the best strategy. This guide explains everything you need to know. 

NIS 2 Directive: cybersecurity and data protection in Europe

Introduction

Cyberattacks are on the rise in Europe, and their impact is becoming increasingly severe: service disruptions, data breaches, and financial losses. In light of this, the European Union has decided to raise cybersecurity standards for organizations that support the economy and citizens’ daily lives.

This is the purpose of the NIS 2 Directive, which was adopted in December 2022 and will take effect in October 2024. It replaces the NIS 1 Directive, which covered only about 500 entities in France. Under the NIS 2 Directive, between 15,000 and 18,000 French organizations are now subject to enhanced cybersecurity requirements. Are you a business leader, DPO, CIO, or CISO in a potentially affected sector? This guide provides a comprehensive overview of what NIS 2 means for your organization.

1. What is the NIS 2 NIS 2 Directive? Definition, objectives, and implementation

The NIS 2 Directive (Network and Information Security 2) is the European framework for cybersecurity, published as Directive (EU) 2022/2555. It marks a paradigm shift: cybersecurity is now a strategic imperative, rather than merely a technical choice.

NIS 2 in a nutshell: European legislation that requires companies in critical sectors to implement robust cybersecurity measures for their systems and report on them to the relevant authorities. This overview actually covers a set of fundamental requirements for your organization.

1.1. Why did NIS 2 replace NIS 1?

The first NIS Directive, also known as the Network and Information Systems Security Directive, which took effect in 2016, applied to only about 500 entities in France, primarily operators of critical infrastructure in the energy, transportation, and healthcare sectors. In the face of the surge in cyberattacks, the rise of ransomware, and increasingly sophisticated threats.

1.2 What are the objectives of NIS 2?

The NIS 2 Directive has three objectives, under the supervision of the European Commission:

  • Strengthen oversight and Accountability governing bodies, thereby building greater trust in the European digital society.
  • Harmonize cybersecurity standards across the EU through national digital security strategies and cooperation among Member States on incident response.
  • Expand the scope to include medium- and large-sized companies in a wide range of sectors, particularly in the manufacturing of industrial and food products.

Good to know: The NIS 2 Directive, along with the DORA Regulation (financial sector) and the CER Directive (critical physical infrastructure), forms part of a coherent set of European regulations designed to complement one another.

Cyberattacks and cybercrime: targeted threats to information systems

2. Does NIS 2 apply to your company?

To fall within the scope of the NIS 2 Directive, your organization must operate in one of the 18 sectors defined by the directive and exceed certain size thresholds.

2.1 Which 18 sectors are covered by the NIS 2 Directive?

The NIS 2 Directive distinguishes between two categories of sectors, which are listed in the annex to the directive.

  • Critical sectors (Annex II): Postal and shipping services, waste management, manufacturing, production and distribution of chemicals, production, processing, and distribution of food, industrial manufacturing (medical devices, electronic equipment, vehicles, machinery), digital service providers, research.
  • Highly critical sectors (Annex I): energy, transportation, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

In practice: ANSSI provides a self-assessment tool on its website—Mon Espace NIS 2—that allows you to check your eligibility in just a few minutes.

2.2 What is the difference between a material entity and a significant entity?

The NIS 2 Directive classifies organizations into two categories based on their size and sector, which determines both the level of obligations and the amount of applicable penalties.

Critical entities (CE): large organizations in the sectors listed in Annex I (more than 250 employees or revenue exceeding 50 million euros), subject to proactive oversight by ANSSI. Significant Entities (SE): medium-sized organizations (50 to 249 employees, revenue between €10 million and €50 million) in Annex I and II sectors, subject to reactive monitoring.

Key figures: Between 15,000 and 18,000 French entities fall under the scope of the NIS 2 Directive, compared to approximately 500 under NIS 1.

2.3 Are processors suppliers affected?

Yes. The NIS 2 Directive requires the management of supply chain risks. If you are a service provider to an entity subject to the NIS 2 Directive, you will be required to demonstrate your security level through contractual provisions or audits. These new rules are among the most significant for SMB .

3. What are the requirements under the NIS 2 Directive?

NIS 2 establishes a set of requirements regarding risk management measures, incident response, and Accountability .

3.1 What cybersecurity measures does NIS 2 require?

Article 21 of the directive covers ten categories of measures: vulnerability management, business continuity, supply chain security, encryption, access control, strong authentication, and the use of appropriate monitoring solutions. Incident detection and response capabilities are central to these requirements, alongside the management of cybersecurity risks specific to each organization.

Dipeeo Tip: These measures, which include raising awareness among staff, largely align with the security requirements of GDPR, particularly Article 32. An organization already working toward GDPR compliance GDPR already laid a solid foundation for NIS 2.

3.2 What are the deadlines for reporting incidents?

This is one of the most stringent requirements of the NIS 2 Directive. Any significant incident must be reported to ANSSI within 24 hours (early notification), 72 hours (initial notification), and one month (final report).

An incident is considered significant if it causes a serious disruption of services, significant financial losses, or an impact on other organizations.

3.3 Does NIS 2 hold Accountability ?

This is the most significant change in the NIS 2 Directive compared to NIS 1. The management bodies of the entities concerned are personally responsible for ensuring compliance with the Directive’s requirements. In practical terms, this means:

  • Approve cybersecurity policies
  • Oversee their implementation
  • Take regular training courses on cyber risks

In the event of a serious breach, individuals in management positions may be held personally liable and may face a temporary ban on holding management positions. Cybersecurity is no longer solely a technical matter; it is a matter of trust and Accountability highest levels of the organization.

European Union and cybersecurity regulations: NIS Directive 2

4. What are the penalties for non-compliance with NIS 2?

NIS 2 introduces a penalty system aligned with that of GDPR. Fines vary depending on the type of entity:

  • For large entities: Up to €7 million or 1.4% of global revenue. In addition to fines, ANSSI may issue injunctions, require corrective measures, and order a temporary suspension of operations.
  • For critical entities: Up to 10 million euros or 2% of global annual revenue, whichever is higher.

Good to know: NIS 2 and GDPR penalties GDPR be cumulative. If an incident results in a personal data breach, your organization may face penalties from both ANSSI and the CNIL (National Commission for Information Technology and Civil Liberties) at the same time. This is yet another reason to address both compliance requirements in a coordinated manner.

5. What is the status of the implementation of NIS 2 in France?

Compliance checklist for the implementation of the NIS Directive 2

France has failed to meet the October 17, 2024, deadline for transposing NIS 2 into national law. This delay in transposition creates legal uncertainty for the organizations concerned.

5.1 What is the Resilience Bill? What is the timeline for its implementation?

The government has chosen to implement NIS 2 through the Resilience Bill, which also incorporates the CER Directive and the DORA Regulation. Passed by the Senate in March 2025, it is expected to be adopted by the National Assembly no earlier than July 2026, at which point the European Commission will suspend its infringement proceedings against France.

5.2 What is ANSSI’s ReCyF?

While awaiting the law, ANSSI has not been idle. On March 17, 2026, it published the Référentiel Cyber France (ReCyF), a technical framework that lists the recommended management measures for achieving the security objectives set by NIS 2. This framework corresponds to Article 14 of the Resilience Bill. ReCyF is not mandatory by default, but stakeholders who apply it can cite it during ANSSI inspections. Aligning with ReCyF—whose official source is available on MesServicesCyber—means getting a head start on the formal implementation of these requirements.

Legal sanctions and compliance with the NIS Directive 2

5.3 Should we wait for the law to be enacted before we start preparing for NIS2?

No. Once the law is enacted, deadlines will be set and service providers’ resources will be stretched thin. To prepare, you need to assess your scope and implement initial measures before the requirement becomes formally enforceable.

6. How can you comply with the NIS 2 Directive?

NIS 2 compliance can’t be winged—it requires a structured approach. Here are the steps to follow to move forward in a gradual and well-documented manner.

6.1 How can you tell if you are within the NIS 2 scope?

Three cumulative criteria: your sector is listed in Annex I or II, you exceed the thresholds (50 employees or €10 million in revenue), and you operate in at least one EU Member State.

6.2 What are the specific steps for NIS 2 compliance?

  • Step 1: Confirm your category (essential or significant entity) and your associated obligations.
  • Step 2: Conduct a cybersecurity maturity assessment based on the ten measures outlined in Section 21.
  • Step 3: Implement priority measures: access segmentation, backups, strong authentication, encryption.
  • Step 4: Appoint a CISO, train senior management, and formalize security policies.
  • Step 5: Establish an incident response procedure that adheres to the 24-hour, 72-hour, and 1-month response times.
  • Step 6: Document and demonstrate your compliance: traceability and continuous improvement are just as important as compliance itself.

6.3 Is ISO 27001 sufficient to ensure compliance with NIS 2?

ISO 27001 is a catalyst, not a substitute. It does not cover statutory notification deadlines, the Accountability of executives, or the requirements of the ReCyF.

Tip from Dipeeo: Your GDPR compliance often GDPR 50 to 60% of the work required to achieve NIS 2 compliance. Data processing inventories, risk assessments, and incident management: these foundational elements can be directly reused.

Complementarity between the NIS 2 Directive and GDPR strengthen cybersecurity for businesses

7. NIS 2 and GDPR How to Align the Two Regulations?

The NIS 2 Directive and GDPR common objectives and requirements that overlap significantly.

7.1 How do NIS 2 and GDPR complement each other GDPR

Both regulations require security measures commensurate with the risk, incident reporting within specified timeframes (72 hours under the GDPR, 24 hours under NIS 2), and documentation of compliance activities. An organization that GDPR already GDPR a foundation that can be directly leveraged for NIS 2

The main difference: The GDPR on the protection of personal data, while NIS 2 covers the security of networks and information systems as a whole, including the sharing of information among competent authorities.

In practice, an organization that has already conducted its data protection impact assessment (DPIA), kept its record of processing date, and established a data breach response procedure has a foundation that can be directly leveraged for NIS 2.

7.2 NIS 2 and DORA: Which regulations take precedence?

For organizations in the financial sector (banks, insurance companies, asset managers, payment service providers), both regulations may apply simultaneously.

DORA is the lex specialis for the financial sector: it takes precedence over NIS 2. An organization that complies with DORA largely meets the requirements of NIS 2

8. FAQ: Your Questions About the NIS 2 Directive

What is the NIS 2 Directive?

A European regulation requiring companies to better protect themselves against cyberattacks.

Which companies are affected by NIS 2?

SMB large companies in critical sectors such as healthcare, transportation, energy, and digital technology.

What are the main requirements of NIS 2?

Ten categories of cybersecurity measures, reporting incidents to ANSSI within strict deadlines, executive involvement, and securing the supply chain.

What are the penalties for non-compliance with NIS 2?

Up to €10 million or 2% of global revenue for critical entities, up to €7 million or 1.4% for significant entities, with the possibility of Accountability executives Accountability .

When does the NIS 2 Directive apply?

It took effect in 2023 and is being phased in gradually across each European country.

Has France implemented NIS 2?

Not yet. The Resilience Act is not expected until July 2026 at the earliest. ANSSI has published the ReCyF to help organizations start preparing now.

GDPR NIS 2 and GDPR related?

They complement each other. An organization that is already GDPR already laid much of the groundwork required for NIS 2.

8. How does Dipeeo help you ensure compliance and guide you toward NIS 2?

Managing GDPR compliance GDPR running your business is exhausting. That’s exactly why Dipeeo exists.

With Dipeeo, a legal expert in data protection gets to know your business, its unique characteristics, and its constraints, becoming your trusted daily point of contact. They handle everything that weighs on you: the initial audit, mandatory documentation, monitoring your service providers, managing data deletion requests, and those unexpected issues that always seem to pop up at the worst possible time.

Here's what you'll actually get:

  • A dedicated legal professional who understands your business and your industry
  • Unlimited, personalized support
  • Documents that are compliant and always up to date
  • An intuitive platform to help you manage your compliance with peace of mind

Many executives tell us they wish they had addressed this sooner. The best time to do so is now.

👉 I’m scheduling an appointment with Dipeeo – outsourced DPO

Conclusion

The NIS 2 directive should be seen as an opportunity to strengthen your organization's digital resilience and overall security. Anticipating its implementation means protecting your activities, building trust with your partners, and raising your level of cybersecurity. Don't just comply with the regulation: turn it into a strategic lever. Conduct an audit now.

François Lemarié
François Lemarié

Co-founder & COO - GDPR Expert