Skip to main content
ApplicableApplication : 2024-10-17

NIS2

Network and Information Security 2, Directive (EU) 2022/2555

EU cybersecurity directive in force since October 2024. Expands scope to SaaS, datacenters, transport, food industry.

01 · Qu'est-ce que c'est ?

NIS2 (directive 2022/2555) is the second European cybersecurity framework, replacing the 2016 NIS directive. It entered into application on 17 October 2024 and was transposed into French law by the law of 21 November 2024.

Goal: harmonize and strengthen the level of cybersecurity in the EU by imposing on entities identified as "essential" or "important" obligations on risk management, incident notification, and governance, with personal liability of executives in case of breach.

The French reference authority is ANSSI (National Information Systems Security Agency). It receives declarations and incident notifications, and conducts controls.

02 · Qui est concerné ?

The scope is defined by Annexes I (essential entities) and II (important entities) of the directive. In summary:

  • Annex I (essential entities): energy, transport, banks, healthcare, water, digital infrastructure, public administrations, space.
  • Annex II (important entities): postal services, waste management, food, manufacturing of chemicals / medical devices / vehicles, digital services (cloud, datacenter, SaaS), R&D.

Thresholds: ≥ 50 employees OR ≥ €10m revenue is enough to fall under "important entity". Beyond 250 employees or €50m revenue, you become "essential entity" with a stricter control regime.

Important: declaration to ANSSI is self-declarative. No notification is sent by the authority, it is up to the entity to identify itself and declare. Absence of declaration is itself an offense.

03 · Calendrier d'application

Applicable since 17 October 2024. Transposed into French law in November 2024. ANSSI self-declaration portal open; targeted controls from 2026.

  • 17 October 2024: entry into application of the directive.
  • November 2024: French transposition voted.
  • 2025: opening of the ANSSI self-declaration portal.
  • From 2026: targeted controls on actors that had a notified incident, were reported via complaint, or were identified as at-risk.

04 · Sanctions

Sanctions are both administrative and personal:

  • Essential entities: fine up to €10m or 2% of global annual revenue (whichever higher).
  • Important entities: fine up to €7m or 1.4% of global annual revenue.
  • Personal liability of executives: possibility of temporary ban from management functions.
  • Complementary sanctions: compliance injunctions, suspension of authorizations, publication of decisions.

05 · Comment s'y conformer

Article 21 of the directive lists 10 categories of minimum technical and organizational measures. In software translation:

  • Tamper-proof and queryable audit log (every sensitive action traced, append-only, timestamped).
  • Incident detection and ANSSI notification workflow within 24h alert / 72h detailed / 1-month final report.
  • Register of technical subcontractors with associated certifications (SOC 2, ISO 27001, NIS2), audit dates, DPO/CISO contacts.
  • Access management with MFA, privilege management, regular reviews.
  • Documented business-continuity plan, tested, reviewed annually.

06 · Questions fréquentes

Is my 60-employee B2B SaaS concerned by NIS2?
Very likely yes, under "digital services" (Annex II). With ≥ 50 employees or ≥ €10m revenue, your SaaS is classified as an important entity. You must declare to ANSSI.
Does SOC 2 Type II suffice for NIS2?
No. SOC 2 and NIS2 are not equivalent. Overlaps exist (encryption, MFA, audit logs) but represent only 60-70% of NIS2 scope. NIS2 notably requires 24h/72h ANSSI notification, supplier register, and continuity exercises, which are not in SOC 2.
How do I notify an incident to ANSSI?
Three steps: early alert within 24h via the ANSSI Mon Service Sécurisé portal, detailed notification within 72h, final report within 1 month. The "significant impact" notion is deliberately broad, when in doubt, notify.
What does NIS2 change for a company's board?
The NIS2 novelty is personal liability of executives. The CEO and CTO can have their civil liability triggered, or even be banned from managerial roles in case of serious breach. NIS2 becomes a board topic, not a CISO topic.

Sources officielles

Réglementations connexes

  • Digital Operational Resilience Act, Règlement (UE) 2022/2554
    In force

    DORA

    Digital Operational Resilience Act, Règlement (UE) 2022/2554

    Règlement européen sur la résilience opérationnelle numérique du secteur financier. Applicable depuis le 17 janvier 2025, avec TLPT en 2026.

    • Banking
    • Finance & VC
  • Règlement (UE) 2024/1689 sur l'intelligence artificielle
    Partially in force

    EU AI Act

    Règlement (UE) 2024/1689 sur l'intelligence artificielle

    Premier cadre horizontal mondial de régulation de l'IA. Obligations IA haut risque applicables le 2 août 2026.

    • B2B SaaS
    • Banking
    • Defense
    • +1

Articles d'analyse

  • NIS2 pour les éditeurs SaaS : six mois pour passer l'audit
    Salle serveur d'un éditeur SaaS avec consoles de supervision sécurité
    SaaS

    NIS2 pour les éditeurs SaaS : six mois pour passer l'audit

    Applicable depuis octobre 2024, la directive NIS2 commence à mordre en 2026. Les éditeurs SaaS classés « entité importante » font face à des exigences techniques nouvelles.

Un projet logiciel NIS2 ?

Quand NIS2 demande un logiciel sur-mesure, nous le livrons en quelques semaines, 3× moins cher qu'un éditeur historique.