Where do French and European SMEs really stand facing the AI Act , GDPR , NIS2 , and now DORA and the Cyber Resilience Act? The metrics you won't see in official press releases.
in GDPR fines now hit medium-sized companies for the first time, not just large groups. French SMEs are no longer a low-priority target for the CNIL.
Regulatory compliance for large enterprises is well documented. SME compliance isn't. Available studies stop at declarations of intent, "we are in the process of becoming compliant," without measuring the actual state of practices.
This barometer compiles public data from the CNIL, ENISA, the EDPB, the European Commission, the French General Directorate for Enterprise, and France Num. It doesn't claim to be exhaustive. It gives the most reliable overall diagnostic available today, and invites SMEs to add to it directly through our participatory study. Our team of experts supervises the work.
Themio runs its own parallel study of French and European SMEs. Results publish in the 2027 Barometer.
Participate in the study →Survey hosted on the official European Commission platform. Your data is processed in compliance with GDPR.
Lack of awareness of obligations, or failure to implement. This figure has held since 2022; the CNIL's official 2025 annual report confirms the enforcement pressure behind it has only grown.
83 sanctions, 6,167 breach notifications, 20,150 complaints received. 80% of sanctions used the "simplified procedure" (fines up to €20,000), the mechanism that most directly exposes SMEs.
Ireland (~€531M) and France (~€487M) together account for roughly 89% of the bloc-wide total. France stays the Union's second most active GDPR enforcer.
No compliant cookie banner, an outdated privacy policy, trackers running without consent.
This document is mandatory for any structure processing personal data, which is nearly every company. A Commission proposal (Digital Omnibus) would raise the exemption threshold from 250 to 750 employees, but it remains in trilogue as of September 2026, not yet law.
This figure has doubled in a year. Most of these companies don't know AI use now falls under Regulation (EU) 2024/1689 (AI Act) .
Double extortion (encrypt and exfiltrate) is now the default model, not the exception. Phishing remains the entry point in roughly 60% of cases. ENISA names SMEs directly as high-value targets.
As of 19 August 2026, France, Ireland, Spain and the Netherlands still had no fully notified NIS2 transposition. The European Commission referred all four to the Court of Justice of the EU for failing to notify their transposition measures, and is seeking financial penalties until the Directive is fully transposed. Full detail: NIS2 explainer .
SMEs report the smallest share of the sample and the lowest confidence in their ability to anticipate, withstand and recover from an incident. NIS2 asks every essential and important entity to run a cyber risk management programme; most don't have the headcount to staff one.
| Regulation | SME Awareness Level | Estimated Compliance Level | Next Key Deadline |
|---|---|---|---|
| GDPR (Regulation EU 2016/679) | High, known by 80%+ of managers | Low, roughly 40% compliant on substance; sanctions above €10M now reach mid-sized firms for the first time | Digital Omnibus RoPA simplification (250→750-employee threshold) still in trilogue, not yet law |
| AI Act (Regulation EU 2024/1689) | Low, fewer than 20% of SME AI users have heard of it | Very low, close to no formal compliance | Article 50 transparency: 2 Aug 2026. High-risk Annex III: 2 Dec 2027, confirmed, final law since June/July 2026 |
| NIS2 (Directive EU 2022/2555) | Medium, known in the most exposed sectors | Low, France still without a notified transposition | Four states referred to the CJEU for non-notification; check current status before assuming a grace period |
| DORA (Regulation EU 2022/2554) | Low outside financial services | Mixed, roughly 44% of financial entities short of full compliance | Supervisory operational-resilience testing intensifying through 2026 |
| Cyber Resilience Act (Regulation EU 2024/2847) | Very low among SME manufacturers of connected products | Not yet measured, the regime is new | Vulnerability/incident reporting starts 11 Sept 2026; full compliance by 11 Dec 2027 |
Digital Omnibus on AI: finalised, not provisional. The European Parliament approved the final text on 16 June 2026, the Council of the EU gave final approval on 29 June 2026, and the amending act entered into force in July 2026. The high-risk Annex III deadline is confirmed at 2 December 2027 (Annex I safety components: 2 August 2028). Article 4 (mandatory AI training) and the ban on unacceptable-risk practices remain untouched, in force since February 2025. The Omnibus also adds a new outright ban on AI tools that generate CSAM or non-consensual intimate imagery.
Not every SME carries the same exposure. Here are the sectors where the gap between obligation and compliance runs deepest.
AI drives CV screening, attendance tracking and performance evaluation. These uses fall directly under "high-risk AI systems" in Annex III of the AI Act (Article 6), now confirmed for 2 December 2027. Transparency and human-oversight duties apply even to a 20-person SME running third-party HR software with AI built in.
Advertising trackers, algorithmic personalisation, commercial chatbots: three constant GDPR friction points. The CNIL made cookies and consent an enforcement priority in 2023 and named AI use and data scraping as new 2026 control priorities. E-commerce SMEs are overrepresented in simplified-procedure sanctions, fines up to €20,000.
Entities subject to NIS2 as critical digital service providers, with a duty to report security incidents within 24 hours. 51% of VSEs/SMEs have already suffered a data security incident without reporting it. Source: France Num GDPR 2024.
Health data is a special category under Article 9 GDPR, requiring maximum protection. A sector running structurally behind on digital compliance despite an above-average exposure to penalties.
Any SME manufacturing or selling a "product with digital elements," connected devices, embedded software, IoT, now falls under the Cyber Resilience Act (Regulation EU 2024/2847). From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours (early warning) and 72 hours (detailed report) through ENISA's Single Reporting Platform. Full compliance is required by 11 December 2027; this is a market-access condition, not optional guidance.
Most SMEs think the AI Act only concerns AI developers. It doesn't. The regulation names two roles: the provider , who builds the system, and the deployer , who uses it professionally. As a deployer, an SME has to verify the system is compliant, train its staff (Article 4), and never use AI to monitor employees unlawfully. Using ChatGPT, HR software with automated scoring, or a facial recognition tool puts the SME inside the regulation's scope.
Missing a record of processing activities is a documented infraction, checkable during a CNIL audit, and punishable on its own, no security incident required. 59% of SMEs don't keep one. The record isn't optional: it's the simplest GDPR obligation to build, and the first thing the CNIL checks.
The Digital Omnibus pushed high-risk Annex III obligations to December 2027, and that's now confirmed, final law, not a proposal. Three obligations stay active right now: the ban on unacceptable-risk AI practices (since February 2025), the AI training duty under Article 4 (since February 2025), and rules for general-purpose AI models (since August 2025). SMEs waiting until 2027 to start their compliance work are taking a real risk.
France still has no fully notified NIS2 transposition as of August 2026, 22 months after the October 2024 deadline. Some SMEs read that gap as "nothing applies yet." That reading is risky: sectoral supervisory authorities can already act under existing national security frameworks, and the transposition gap will close, likely with a short transition window once it does. The European Commission has referred France, Ireland, Spain and the Netherlands to the Court of Justice of the EU specifically for failing to notify their transposition measures, and is seeking financial penalties.
Available data on SME compliance is mostly declarative, or comes from large firms working with mid-caps and large enterprises. No systematic, independent, representative study of SMEs under 250 employees exists yet in France and Europe.
We're building it.
The survey takes under 5 minutes, hosted on the official European Commission platform (EUSurvey). Responses are anonymised and processed in compliance with GDPR.
Participate in the Themio Study →This barometer compiles data exclusively from public institutional sources. Every metric carries its own source and date.
| Data | Source | Year |
|---|---|---|
| 60% of SMEs are GDPR non-compliant | RGPDKit, CNIL 2025 Review | 2025 |
| 88% of VSE/SME sites are non-compliant with GDPR | Cartegie, GDPR 7 Years On | 2024 |
| €486.8M in CNIL fines, 83 sanctions, confirmed | CNIL, Rapport annuel 2025 | 2026 |
| €1.15Bn EU-wide GDPR fines (2025) | EDPB, Annual Report 2025 | 2026 |
| 41% of VSEs/SMEs keep a record of processing activities | France Num GDPR 2024 Barometer | 2024 |
| 51% have suffered a data security incident | France Num GDPR 2024 Barometer | 2024 |
| 26% of VSEs/SMEs use an AI tool (doubled in a year) | France Num 2025 Barometer | 2025 |
| 81.1% of EU cybercrime incidents involve ransomware | ENISA, Threat Landscape 2025 | 2025 |
| Digital Omnibus on AI, final law, in force July 2026 | Council of the EU, press release, 29 June 2026 | 2026 |
| 23/27 Member States transposed NIS2 ; France not transposed | European Commission, Digital Strategy | 2026 |
| Four Member States (Ireland, Spain, France, Netherlands) referred to the CJEU for failing to notify NIS2 transposition | European Commission, press release ip_26_1499 | 2026 |
| 10.6% of IT FTEs dedicated to cybersecurity roles | ENISA, NIS Investments 2025 | 2025 |
| GDPR Digital Omnibus (RoPA threshold 250→750), proposed, in trilogue | European Commission, published 19 Nov 2025 | 2025-2026 |
| DORA , roughly 44% of financial entities not fully compliant | Industry survey, ADVISORI 2026 | 2026 |
| Cyber Resilience Act, first reporting deadline 11 Sept 2026 | Regulation (EU) 2024/2847 | 2026 |
Find out if you comply with the European AI Act by evaluating your transparency obligations today.
Or join our study and contribute to the 2027 Barometer:
Answer the Themio survey →