Your SMB is affected by NIS2 if it has at least 50 employees or more than €10 million in annual turnover, and if it operates in one of the eighteen sectors covered: energy, transport, healthcare, food, manufacturing or digital services, among others. And even below these thresholds, your customers can bring you into scope: regulated entities must secure their supply chain, and therefore their subcontractors. One reassuring point: compliance follows a progressive path, steered in France by ANSSI, the national cybersecurity agency.
NIS2: where this directive comes from and who steers it in France
The European NIS2 directive (2022/2555) succeeds the first NIS directive and massively broadens the scope of regulated cybersecurity: from a few hundred operators in France to around fifteen thousand entities according to ANSSI's estimates. It is transposed into French law by the law on the resilience of critical infrastructure and the strengthening of cybersecurity, whose implementing decrees and technical frameworks are being rolled out progressively. ANSSI is the national authority: entity registration, requirement frameworks, inspections and support all go through it, notably via its MonEspaceNIS2 portal. The objective is simple: raise the general level of security across the entire European economic fabric, not just among a handful of large operators.
Who is affected? Sectors and thresholds
Essential entities and important entities
NIS2 distinguishes two categories. Essential entities: as a general rule, companies with at least 250 employees or €50 million in turnover operating in the highly critical sectors (energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, ICT service management, public administration, space). Important entities: from 50 employees or €10 million in turnover, in those same sectors or in the additional critical sectors (postal services, waste management, chemicals, food, manufacturing of medical devices, electronics, machinery and vehicles, digital providers, research). The substantive obligations are similar; the supervision and penalty regime is stricter for essential entities.
Subcontractors are affected by ripple effect
Even outside the scope, an SMB that supplies regulated entities, whether in managed services, software, industrial maintenance or logistics, will see NIS2 requirements flow down into its contracts: security questionnaires, audit clauses, notification obligations. Compliance becomes a commercial argument as much as a regulatory obligation, and anticipating these requests rather than discovering them in the middle of a tender is a real competitive advantage.
Am I affected? The decision tree
- Headcount and turnover: fewer than 50 employees and less than €10 million in turnover? You are in principle outside the direct scope, except for special cases such as DNS providers or trust service providers. Still go to step 4.
- Sector of activity: does your business fall within one of the eighteen sectors listed by the directive? If not, you are not directly in scope.
- Category: at least 250 employees or €50 million in a highly critical sector makes you an essential entity; otherwise, from 50 employees or €10 million, an important entity.
- Supply chain: do your customers include essential or important entities? Then expect equivalent contractual requirements.
- When in doubt: ANSSI's online eligibility test on MonEspaceNIS2 gives a first answer; complex cases, groups, subsidiaries or multiple activities, deserve a dedicated analysis.
The main NIS2 obligations
The directive does not impose a specific technology; it requires proportionate, documented measures across four main areas:
- Risk management: risk analysis, security policy, vulnerability and patch management, multi-factor authentication, encryption, backups, business continuity and supply chain security.
- Incident notification: early warning to ANSSI within 24 hours for any significant incident, detailed notification within 72 hours, then a final report within about one month.
- Registration: entities in scope must register with ANSSI.
- Accountable governance: management bodies approve the risk management measures, train in cybersecurity and can be held liable in the event of a breach.
Compliance checklist
- Determine your status (essential entity, important entity or out of scope) and register with ANSSI if required.
- Involve leadership: appoint an owner, allocate a budget and formalise the programme at executive committee level.
- Map your information system: critical assets, data flows, dependencies and suppliers.
- Run a risk analysis and a gap assessment against ANSSI's framework.
- Deploy the baseline measures: MFA everywhere, tested backups, patch management, logging, endpoint and server detection, network segmentation.
- Formalise incident management: detection, qualification, 24-hour and 72-hour notification, and regular crisis exercises.
- Address the supply chain: security clauses in contracts and assessment of critical suppliers.
- Train executives and staff, then audit regularly to maintain compliance over time.
What penalties for non-compliance?
The orders of magnitude set by the directive: up to €10 million or 2 percent of worldwide turnover for essential entities, €7 million or 1.4 percent for important entities, plus injunction powers, periodic penalty payments and the possibility of holding executives personally liable. In practice, France has announced a progressive ramp-up favouring support and guidance, with an adaptation period in the region of three years for part of the technical measures. That period is an opportunity: better to spread the investment than to face an emergency.
Above all, NIS2 formalises what good cyber hygiene already requires. An initial gap assessment carried out with a seasoned technical partner makes it possible to prioritise high-impact measures, put a figure on the compliance roadmap and turn a regulatory constraint into a mark of trust for your customers.
