The essentials

NIS2 sharply broadens the number of sectors and organisations concerned. Qualification is not just a threshold: it requires looking at the entity, its activity, its size, the services provided and the specific designation cases.

1. Start by qualifying the entity

The analysis must be carried out at the level of the legal person and document four dimensions: sector of activity, size, nature of the service and location. Some categories can be in scope regardless of their size; conversely, a trading name close to a listed sector is not enough to conclude.

Never freeze a conclusion without a date.

In France, ANSSI publications and the transposition texts are the operational reference. An analysis must state the sources consulted and the state of the law on the day of the study.

2. Treat NIS2 as a governance matter

The framework puts leadership at the centre of cyber risk management. The programme therefore cannot be handed to a purely technical project. It must connect business risks, assets, suppliers, continuity, incidents, skills and investment decisions.

The first workstreams that will not be wasted

  • Map the critical services, the assets and the dependencies.
  • Assign risk owners and operational responsibilities.
  • Evaluate the suppliers who contribute to essential services.
  • Prove backup, restore and continuity.
  • Formalise detection, escalation and incident management.
  • Build a chain of evidence produced by real operations.

3. Use ANSSI publications as a working reference

The NIS2 portal and the frameworks published by ANSSI are a preparation base to be articulated with the controls already in place, the state of the French transposition and the other applicable frameworks.

4. Prepare the evidence at the same time as the control

Installing a control without organising its evidence postpones the problem to the day of the audit or the incident. For each measure, identify the owner, the frequency, the expected results, the retention and the review of deviations.

5. Avoid three shortcuts

  • Confusing ISO 27001 alignment with automatic NIS2 compliance.
  • Reducing the programme to buying cyber tools.
  • Waiting for the last regulatory step before treating risks that are already known.

Next step

A short framing exercise should answer three questions: are we probably in scope, which services and entities fall within the perimeter, and which priority actions immediately improve our resilience?

Assess your NIS2 situation Frame your scope