NIS 2 checklist
Where do you stand on the 20 ReCyF security objectives?
The French cybersecurity agency’s referential for NIS 2, turned into 156 control points to tick, objective by objective, so you can see where you stand.
Governance of information systems (objectives 1 to 5)
Protection of information systems (objectives 6 to 11)
Defence of information systems (objective 12)
Resilience of information systems (objectives 13 to 15)
The 5 objectives reserved for essential entities (16 to 20)
What ISO 27001 and ANSSI-qualified services already cover
Based on ReCyF v2.5 of 17 March 2026, published by ANSSI as a working document. France has not completed the transposition of NIS 2: this checklist is there to prepare, not to attest compliance.