NIS2

European Directive to Strengthen the Cybersecurity of Organizations and Essential Services

Contact us

What is the NIS2 Directive?

The European Directive 2022/2555, known as NIS2 (Network and Information Security), strengthens the existing cybersecurity framework for so-called essential entities (EEs) and important entities (IEs) operating within the European Union.

This updated version replaces the original NIS Directive (2016/1148), adopted in 2016, in response to the increasing sophistication and frequency of cyberattacks.

What are the objectives?

By tightening the requirements for businesses and strengthening sanction regimes, this revision aims to:
  • Raise the overall level of cybersecurity across the European Union
  • Harmonize practices among Member States
  • Better protect essential services and critical infrastructures
  • Embed cybersecurity into organizational governance and hold leaders accountable

NIS2 represents a significant shift in scale and introduces a more comprehensive approach, combining technical, operational, and strategic dimensions.

Which entities are affected?

NIS2 has expanded its original scope by harmonizing and broadening the classification of entities subject to its obligations. It distinguishes two categories:

  • Essential entities, considered highly critical as they are vital to the smooth functioning of society
  • Important entities, which are also strategic and whose activities make a significant contribution to economic and societal operations

Key takeaways

Beyond the predominant sector-based criterion, there are additional complementary defining criteria, such as:

  • The size of the company (50+ employees)
  • Turnover (€10+ million in annual revenue)

It is worth noting that there are exceptions regarding company size, particularly for smaller organizations, which may be included if they play a critical or strategic role.

However, if any uncertainty remains, consultations with supervisory ministries, professional federations, or associations and representatives of elected officials are recommended.

What should you do if you are not directly affected?

Even if your company does not formally fall within the scope of NIS2, its impact—though indirect—often remains significant. For instance, if your clients or partners are subject to NIS2, they will likely require your organization to provide security guarantees.

This particularly applies to service providers and suppliers of Essential Entities (EEs) or Important Entities (IEs).

At the same time, market standards are gradually aligning with NIS2 requirements, and compliance is becoming both a trust criterion and a competitive advantage.

By proactively adopting NIS2 requirements, you strengthen your resilience, structure your practices, and reduce cyber risks.

What are the obligations under NIS2?

The NIS2 Directive establishes a set of obligations based on risk management and operational resilience. This begins with the accountability of leadership, including:

  • Training on cybersecurity challenges
  • Supervision and validation of all related measures

In addition, organizations must adopt numerous technical and organizational measures, including:

  • Risk mapping
  • Risk management frameworks, with regular audits and testing
  • An information systems security policy
  • Supply chain security
  • Business continuity and disaster recovery plans, including crisis management protocols

Furthermore, NIS2 now mandates the systematic reporting of high-impact incidents to the competent authorities within strict deadlines.

Why start preparing now?

With NIS2, cybersecurity is now firmly established as a strategic and regulatory priority. It is therefore imperative to start preparing as early as possible to avoid last-minute compliance efforts and, more importantly, to minimize cyber risks in a landscape of increasingly sophisticated and aggressive threats.

Beyond technical aspects, NIS2 often requires changes in governance, risk management, supplier oversight, and employee awareness. These transformations take time and involve mobilizing multiple stakeholders within the organization.

By anticipating these requirements, you can approach this regulation in a gradual and structured manner, while strengthening the long-term digital resilience of your organization and the trust of your partners, clients, and users. In this context, the support of specialized providers like Docaposte can help you understand the requirements, structure your approach, and operationally implement your compliance efforts.

Docaposte: Your Trusted Partner for Compliance

As a digital services provider, we are equally impacted by NIS2 obligations, and we are committed to promoting a safer and more resilient digital world. To anticipate these changes, we have integrated the regulation’s requirements into our internal processes, including risk analyses, supplier assessments, business continuity, and supervision.

Leveraging this expertise, we offer support solutions to help you achieve NIS2 compliance. In this regard, our subsidiary, Docaposte Institute, provides training to help you better understand these requirements.

We also offer a comprehensive approach to support you across all cybersecurity challenges. With our consulting expertise and solutions, we assist you in:

  • Raising awareness among your employees
  • Securing your systems
  • Maintaining your operations
  • Addressing regulatory requirements

Frequently Asked Questions

EU Member States had until October 17, 2024, to transpose the NIS2 Directive into their national laws.


In France, the transposition is still ongoing, as not all dedicated texts have been definitively adopted by Parliament. The draft law on the resilience of critical infrastructures and the strengthening of cybersecurity—known as the Résilience bill—serves as the primary legislative framework.


However, the key principles and obligations of NIS2 are already known, as they stem from the European Directive. Only the national provisions remain uncertain. The ReCyF (French Cybersecurity Framework) is already available to organizations as a working document and outlines initial security objectives applicable to affected entities.


It is therefore possible—and advisable—to start your compliance efforts now.

You must consider several criteria:

  • Your sector of activity
  • The size of your organization
  • Your role in a value chain


Important: If your entity falls within the scope of NIS2, you will not be automatically notified by the competent authorities. It is your responsibility to take the necessary steps and register online with ANSSI (the French National Agency for the Security of Information Systems).


You can also consult the MonEspaceNIS2 website, which will help you assess your situation and complete your registration if required.

NIS2 significantly expands the scope of affected organizations, strengthens obligations, and introduces stricter oversight and sanction mechanisms. It also now holds leadership directly accountable.


These new measures address the limitations observed in the implementation of NIS1, as well as the growing sophistication of cyber threats.

In France, the authority is ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information). It oversees the implementation of NIS2, conducts audits, and can impose corrective measures.


At the European level, ENISA (the European Union Agency for Cybersecurity) coordinates Member States in responding to cyber incidents and sharing information. The Directive also provides for the establishment of CSIRTs (Computer Security Incident Response Teams)—sometimes referred to as CERTs (Computer Emergency Response Teams)—at national and sectoral levels. Their role is to deliver an appropriate response in the event of a cyber incident.


Their responsibilities include:

  • Facilitating information and best practice sharing among Member States
  • Monitoring networks to detect potential threats
  • Issuing alerts in the event of an incident
  • Operationally coordinating cyber response efforts

No, only those with a significant impact. However, the criteria are stringent and require rapid analysis capabilities.


The deadlines are as follows:

  • 24 hours to submit an initial alert
  • 72 hours to provide a more detailed analysis
  • 1 month to deliver a comprehensive report, starting from the date of the first notification

These regulations are complementary and aim to strengthen digital resilience and trust within the European Union.


  • The GDPR (General Data Protection Regulation) establishes a framework for the protection of personal data
  • The CRA (Cyber Resilience Act) focuses on the security of products containing digital elements throughout their lifecycle