The time for discovering the text has passed. In 2026, the questions raised in security committees are about execution: which controls are actually in place, who owns them, and how to demonstrate them to the authority. NIS2 compliance is decided there, in the translation of legal requirements into traceable technical and organisational measures.
This guide follows the order in which the workstreams are actually triggered: status, current state, prioritisation, deployment, evidence.
Identifying your organisation’s regulatory status
Everything starts with qualifying your exposure. The directive separates two categories of players, whose reporting obligations and level of scrutiny differ.
Telling Essential Entities from Important Entities
Classification depends on the sector (high criticality or other critical sectors), headcount and turnover. An Essential Entity falls under both ex ante and ex post supervision: the national authority can carry out checks on its own initiative, without waiting for an incident.
An Important Entity falls mainly under ex post supervision, triggered by an incident, a report or a complaint. The difference has a direct effect on your documentation budget.
The impact on the supply chain
You can stay below the size thresholds and still fall within scope through your commercial relationships. Regulated entities must ensure the security of their suppliers, and that requirement flows down through contracts.
Many subcontractors now answer audit questionnaires aligned with NIS2 in order to keep their contracts. Compliance trickles down, and it often reaches you through the customer’s procurement department before it reaches you through the regulator.
The case of digital service providers
Cloud providers, data centre operators, online marketplaces: their position in the digital economy places them automatically among the most closely supervised players. If you run shared infrastructure, your level of segregation and availability also determines your customers’ compliance.

The directive’s concrete obligations, beyond the text
The NIS2 directive imposes a baseline of minimum measures, documented and operational. Let us go through the three blocks that consume the most effort.
Governance and risk management
Every measure deployed must be tied back to a risk analysis. You demonstrate that you have identified your threats, assessed their impact and responded proportionately: the text refers to an all-hazards approach.
This assumes an up-to-date map of data flows and of the dependencies between your essential services and their technical supports. Without that foundation, the justification for your choices will not hold up in front of an auditor.
Incident management and business continuity
The reporting timeline is strict: 24 hours for the early warning, 72 hours for the incident notification, one month for the final report. Those deadlines assume detection and response procedures that are already written, already tested, with named roles.
In parallel, the business continuity plan must guarantee the survival of essential functions after ransomware or a major infrastructure failure. A plan that has never been exercised is worth nothing on the day.
Cyber hygiene and staff training
Awareness programmes become an obligation, on the same footing as technical training for administrators. Patch management, authentication policy, MFA, logging: IT hygiene moves out of the realm of recommendation and into that of legal requirement.
Establishing the initial baseline
Before opening new workstreams, capture an accurate picture of your maturity. That assessment becomes your zero point: the whole trajectory will be measured against it.
Asset mapping and scope definition
The map covers hardware, applications, sensitive data and third-party access. Scope is defined by the essential services delivered, not by geography or by IP addressing plan.
This is often the longest step, and the one that reveals the most blind spots: forgotten test environments, supplier VPNs that were never revoked, business applications outside IT’s remit.
Auditing the current state against expected measures
Compare your practices against ANSSI’s ReCyF framework. The gap analysis identifies shortfalls domain by domain and produces a list of actions that can be ranked.
Share that result with executive management without smoothing it over. A gap that is documented and budgeted can be defended; a gap that is hidden is paid for at the first inspection.
Identifying third-party dependencies
Go back through your contracts. How many suppliers have direct access to your information system, with which rights, under what monitoring?
The directive holds you responsible for the security of your ecosystem. A weakness at a maintenance provider becomes your incident, and your non-compliance.
The compliance plan: execution phases
Four phases, in this order. The temptation to start with the third one explains most of the projects that get stuck.
Phase 1: organisation and appointment of owners
Appoint a lead. The role usually falls to the CISO, with formal backing from legal and procurement, without which the contractual workstream will never move forward.
Set up a monthly steering body: arbitration of priorities, tracking of action plans, budget decisions. The minutes of that body are part of your evidence.
Phase 2: risk analysis and prioritisation
Do not treat everything at once. Start from the map to isolate the risks with major impact on the availability or confidentiality of your essential services.
Document every arbitration, including deferrals. A measure postponed on the basis of a written risk analysis can be defended in front of the authority; a measure that was forgotten cannot.
Phase 3: technical and organisational deployment
MFA, encryption, network segmentation, SIEM/EDR monitoring, privileged access management: the visible phase of the project. In parallel, update your information security policy so that it describes what is actually practised.
A policy that describes an ideal way of working, never applied, will be used against you during an audit. The gap between the document and the field will be the first point raised.
The vulnerability lifecycle
Quarterly scanning is no longer enough. Set up threat intelligence monitoring and a patching schedule with firm deadlines, shorter for internet-facing assets.
Track exceptions: every server not patched within the deadline must have a justification and a date for remediation.
Phase 4: the documentation lifecycle
Compliance is proven in writing. Audits, penetration tests, incident reports, training records: every deliverable has an owner, a review date and a single storage location.
This is where a GRC platform changes daily life. No more parallel spreadsheets, no more manual chasing, no more evidence that cannot be found the day before an inspection.
How the responsibility of management bodies has changed
The directive directly involves management bodies. Cybersecurity moves out of the IT department’s remit and onto the board’s agenda.
The training obligation for directors
Members of management bodies must undergo training that allows them to understand cyber risks and their impact on the business. Pleading technical ignorance no longer protects anyone in the event of a failure to supervise.
Keep records of those sessions: dates, attendees, content. That is the first piece of evidence you will be asked for.
Sanctions and governance liability
National authorities can hold directors liable in the event of serious breaches of risk management obligations. The arrangements vary between Member States, but the direction of travel is stable: negligence in security is becoming a civil, and potentially criminal, liability risk.
Building cyber into strategy
Put security on the board’s agenda, with indicators that stay consistent from one session to the next. A service launch, an acquisition or an outsourcing decision must be handled with security by design, not after go-live.
Evidence management: the pillar of lasting compliance
Compliance has to be maintained. A file put together for one audit and then left aside for six months loses its demonstrative value.
A scope that changes every month
New servers, new employees, new partners: your cybersecurity compliance keeps up with that pace or falls behind. A control that was effective in January can be bypassed in June by a new attack technique.
Plan periodic reviews of scope and of the risk analysis, at a frequency written into your ISMS.
Centralising and timestamping evidence
During an inspection, the authority will ask for artefacts: scan reports, logs, proof of awareness training, crisis exercise reports, security committee minutes. Centralise them in a dedicated tool, timestamped and versioned.
A single source of truth: the same risks, third parties, actions and evidence shared between teams, never re-entered.
Preparing for supervisory audits
An action plan that is up to date, even with actions still in progress, shows a managed approach. The authority quickly tells apart the organisation that knows its weaknesses and is addressing them from the one that asserts without demonstrating.
Prepare a permanent audit file: scope, risk analysis, security policy, control plan, incident register, third-party monitoring.
Timeline and sequencing mistakes to avoid
Time is the most constrained resource in a NIS2 project. Poor sequencing produces wasted spend and teams that disengage.
A 12 to 18 month trajectory
Deploying a PAM solution or a new backup policy takes several months of testing before it can be generalised. Break the project into quarterly sequences with identified deliverables and a checkpoint in committee.
Working habits change slowly. Build change management into the schedule, not at the end of the project.
The “all technical” approach
Buying licences before defining governance produces underused tools. A detection engine without a trained team or an alert handling procedure delivers no real capability.
Tooling comes after governance and risk analysis. In that order, it serves a purpose.
Overloading procurement and legal
Reviewing supplier contracts is a heavy workload spread over time. Your legal team will have to build security clauses, notification commitments and audit rights into every sensitive contract.
With several hundred suppliers, that workstream starts in the first month. It determines the date at which you will be able to declare your ecosystem under control.
Key takeaways
- Qualify your status: Essential or Important Entity, the level of scrutiny is not the same.
- Make management accountable: training for directors is an obligation, with evidence to back it up.
- Steer by risk: every measure answers an identified and documented threat.
- Document continuously: evidence counts as much as the technical control.
- Address the supply chain early: your suppliers are an extension of your information system.
- Maintain the system: periodic reviews, exercises, updated analyses, in a PDCA logic.
Frequently asked questions
How large are the penalties for NIS2 non-compliance?
The directive sets high ceilings. For Essential Entities: 10 million euros or 2% of annual worldwide turnover, whichever is higher. For Important Entities: 7 million euros or 1.4%. Member States supplement that baseline with injunction and suspension measures.
Does NIS2 apply to the foreign subsidiaries of a French company?
A subsidiary located in the European Union and exceeding the thresholds falls under the directive in its host country, with the corresponding national authority. Subsidiaries outside the EU are not directly covered, but they enter the scope contractually as soon as they provide services to the European group. The parent company then imposes its own security requirements on them.
Can you be NIS2 compliant if you are already ISO 27001 certified?
ISO 27001 is a solid foundation: the ISMS, the risk analysis and the improvement cycle are already in place. Equivalence is not automatic, however. NIS2 adds reporting obligations with short deadlines and supply chain requirements that often go beyond the certification scope. A gap analysis between your statement of applicability and the ReCyF framework will measure the real distance.
How will ANSSI supervise companies?
Several levers coexist: documentation audits, on-site audits carried out by its own staff or by PASSI-qualified providers, technical checks. Important Entities will mainly be inspected following an incident or a report. Essential Entities can be subject to scheduled inspections. The quality of your documentation largely determines how those inspections unfold.
Are small companies exempt?
Not systematically. A small organisation identified as critical by the State, for example the sole supplier of a component essential to an Essential Entity, can be designated regardless of its size. Beyond that, contractual pressure from large customers effectively imposes a level of requirement on SMEs that want to keep their contracts.
Going further
Three actions to launch this quarter: formally appoint the NIS2 lead, have the scope of essential services validated by executive management, start the gap analysis against the ReCyF framework. That last one gives the clearest view of the ground to cover, and serves as the basis for budget arbitration.
Involve procurement and legal immediately. Bringing supplier contracts into compliance will be your longest workstream, and it conditions the rest.
Make IT Safe centralises your risk analyses, your action plans and your document management in a collaborative platform. Map your security controls onto several frameworks at once (NIS2, ISO 27001, GDPR, DORA): no duplicate data entry, no silos. Your dashboards give management the visibility it needs to shoulder its responsibilities.
To see how these requirements translate into a tool, request a demonstration.