Sovereignty & Compliance

NIS2 — Becoming Compliant Before the Deadline

A practical guide for French SMEs and mid-sized companies: who is affected, what the directive really requires, and how to structure compliance without dedicating a full-time team.

September 2026

NIS2 is no longer reserved for large groups: around 15,000 French entities will be affected, compared to around 500 under the former NIS1 regime — a thirtyfold increase in scope.

Penalties are sized to be dissuasive: up to €10 million or 2% of worldwide turnover for an essential entity in default, with liability that can reach up to the executives themselves.

Am I affected? Sectors, thresholds, categories

Three combined criteria determine whether an entity is subject to the directive: its sector of activity (18 sectors split into two criticality levels), its size, and the resulting criticality level.

An SME with fewer than 50 employees can still be affected if it is the sole identified critical supplier of an essential entity.

What NIS2 actually requires

Documented risk analysis, an incident notification procedure within 24h then 72h, a tested continuity plan, and an assessment of supplier security.

Direct involvement of governing bodies in cyber risk management, with formal approval of the measures.

Key takeaways

  • Check whether the sector appears in one of the directive's two annexes
  • Check whether headcount or turnover exceeds the applicable thresholds
  • Have a formalized incident detection and notification procedure within 24h
  • Have tested the business continuity plan within the last twelve months
  • Have trained executives on their cyber risk management responsibilities

YOUR GUIDE TO KEEP

NIS2 — Becoming Compliant Before the Deadline

Get the complete guide to explore the topic further and share best practices with your team.

Download the PDF

Free PDF · Direct access

Ready to put it into practice?

Our experts help you move your cloud projects forward.

Go further

Cloud Sovereignty in Europe: SecNumCloud, AWS European Sovereign Cloud, and Choosing the Right FitCloud

Cloud Sovereignty in Europe: SecNumCloud, AWS European Sovereign Cloud, and Choosing the Right Fit

Between the arrival of AWS European Sovereign Cloud, the rise of Bleu and S3ns, and the upcoming European EUCS certification scheme, cloud sovereignty has become a central decision criterion for French CIOs. An overview of the offerings and a decision framework.

Zero Trust in Cloud Environments: Architecture and Practical ImplementationCloud

Zero Trust in Cloud Environments: Architecture and Practical Implementation

The Zero Trust model replaces perimeter security with continuous control: never implicit trust, always verify. How to implement it concretely on AWS, Azure, and GCP.

Engie ITCase Study

Engie IT

Modernize aging WordPress sites hosted on Azure virtual machines, held back by weak scalability and cost inefficiency.