Annual Report · Themio · Digital Compliance Office 2026 Edition — updated September 2026

SME Digital Compliance Barometer
France & Europe 2026

Where do French and European SMEs really stand facing the AI Act , GDPR , NIS2 , and now DORA and the Cyber Resilience Act? The metrics you won't see in official press releases.

>€10 M

in GDPR fines now hit medium-sized companies for the first time, not just large groups. French SMEs are no longer a low-priority target for the CNIL.

Five-part visual showing different SME compliance maturity across GDPR, AI Act, NIS2, DORA and the Cyber Resilience Act
Why This Barometer?

What institutional reports don't say

Regulatory compliance for large enterprises is well documented. SME compliance isn't. Available studies stop at declarations of intent, "we are in the process of becoming compliant," without measuring the actual state of practices.

This barometer compiles public data from the CNIL, ENISA, the EDPB, the European Commission, the French General Directorate for Enterprise, and France Num. It doesn't claim to be exhaustive. It gives the most reliable overall diagnostic available today, and invites SMEs to add to it directly through our participatory study. Our team of experts supervises the work.

Themio Participatory Study

Themio runs its own parallel study of French and European SMEs. Results publish in the 2027 Barometer.

Participate in the study →

Survey hosted on the official European Commission platform. Your data is processed in compliance with GDPR.

Key Metrics 2025-2026

What the data shows

60%

of French SMEs are not GDPR compliant

Lack of awareness of obligations, or failure to implement. This figure has held since 2022; the CNIL's official 2025 annual report confirms the enforcement pressure behind it has only grown.

€486.8 M

in CNIL fines confirmed for 2025

83 sanctions, 6,167 breach notifications, 20,150 complaints received. 80% of sanctions used the "simplified procedure" (fines up to €20,000), the mechanism that most directly exposes SMEs.

€1.15 Bn

in GDPR fines across the EU in 2025

Ireland (~€531M) and France (~€487M) together account for roughly 89% of the bloc-wide total. France stays the Union's second most active GDPR enforcer.

Four key SME compliance metrics: 60%, €486.8M, 26% and 23 of 27
88%

of French VSE/SME websites fail GDPR requirements

No compliant cookie banner, an outdated privacy policy, trackers running without consent.

41%

of VSEs/SMEs keep a record of processing activities

This document is mandatory for any structure processing personal data, which is nearly every company. A Commission proposal (Digital Omnibus) would raise the exemption threshold from 250 to 750 employees, but it remains in trilogue as of September 2026, not yet law.

26%

of VSEs/SMEs use at least one AI tool

This figure has doubled in a year. Most of these companies don't know AI use now falls under Regulation (EU) 2024/1689 (AI Act) .

81.1%

of cybercrime incidents affecting EU organisations involve ransomware

Double extortion (encrypt and exfiltrate) is now the default model, not the exception. Phishing remains the entry point in roughly 60% of cases. ENISA names SMEs directly as high-value targets.

23 / 27

EU Member States now report full NIS2 transposition. France is not one of them.

As of 19 August 2026, France, Ireland, Spain and the Netherlands still had no fully notified NIS2 transposition. The European Commission referred all four to the Court of Justice of the EU for failing to notify their transposition measures, and is seeking financial penalties until the Directive is fully transposed. Full detail: NIS2 explainer .

10.6%

of IT FTEs at EU organisations in NIS2-covered sectors are dedicated to cybersecurity roles

SMEs report the smallest share of the sample and the lowest confidence in their ability to anticipate, withstand and recover from an incident. NIS2 asks every essential and important entity to run a cyber risk management programme; most don't have the headcount to staff one.

Overview Table

Five regulations, five levels of maturity

Regulation SME Awareness Level Estimated Compliance Level Next Key Deadline
GDPR (Regulation EU 2016/679) High, known by 80%+ of managers Low, roughly 40% compliant on substance; sanctions above €10M now reach mid-sized firms for the first time Digital Omnibus RoPA simplification (250→750-employee threshold) still in trilogue, not yet law
AI Act (Regulation EU 2024/1689) Low, fewer than 20% of SME AI users have heard of it Very low, close to no formal compliance Article 50 transparency: 2 Aug 2026. High-risk Annex III: 2 Dec 2027, confirmed, final law since June/July 2026
NIS2 (Directive EU 2022/2555) Medium, known in the most exposed sectors Low, France still without a notified transposition Four states referred to the CJEU for non-notification; check current status before assuming a grace period
DORA (Regulation EU 2022/2554) Low outside financial services Mixed, roughly 44% of financial entities short of full compliance Supervisory operational-resilience testing intensifying through 2026
Cyber Resilience Act (Regulation EU 2024/2847) Very low among SME manufacturers of connected products Not yet measured, the regime is new Vulnerability/incident reporting starts 11 Sept 2026; full compliance by 11 Dec 2027
Update

Digital Omnibus on AI: finalised, not provisional. The European Parliament approved the final text on 16 June 2026, the Council of the EU gave final approval on 29 June 2026, and the amending act entered into force in July 2026. The high-risk Annex III deadline is confirmed at 2 December 2027 (Annex I safety components: 2 August 2028). Article 4 (mandatory AI training) and the ban on unacceptable-risk practices remain untouched, in force since February 2025. The Omnibus also adds a new outright ban on AI tools that generate CSAM or non-consensual intimate imagery.

Sector Focus

Most Exposed Sectors

Not every SME carries the same exposure. Here are the sectors where the gap between obligation and compliance runs deepest.

HR, Recruitment, Payroll Management

AI drives CV screening, attendance tracking and performance evaluation. These uses fall directly under "high-risk AI systems" in Annex III of the AI Act (Article 6), now confirmed for 2 December 2027. Transparency and human-oversight duties apply even to a 20-person SME running third-party HR software with AI built in.

E-commerce and Digital Marketing

Advertising trackers, algorithmic personalisation, commercial chatbots: three constant GDPR friction points. The CNIL made cookies and consent an enforcement priority in 2023 and named AI use and data scraping as new 2026 control priorities. E-commerce SMEs are overrepresented in simplified-procedure sanctions, fines up to €20,000.

Accounting, Legal, and Consulting Firms

Entities subject to NIS2 as critical digital service providers, with a duty to report security incidents within 24 hours. 51% of VSEs/SMEs have already suffered a data security incident without reporting it. Source: France Num GDPR 2024.

Healthcare, Social Work, and Well-being

Health data is a special category under Article 9 GDPR, requiring maximum protection. A sector running structurally behind on digital compliance despite an above-average exposure to penalties.

Manufacturing & Connected Products

Any SME manufacturing or selling a "product with digital elements," connected devices, embedded software, IoT, now falls under the Cyber Resilience Act (Regulation EU 2024/2847). From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours (early warning) and 72 hours (detailed report) through ENISA's Single Reporting Platform. Full compliance is required by 11 December 2027; this is a market-access condition, not optional guidance.

4 Most Underestimated Risks

What most SMEs don't know yet

01

Using AI software isn't the same as AI Act compliance

Most SMEs think the AI Act only concerns AI developers. It doesn't. The regulation names two roles: the provider , who builds the system, and the deployer , who uses it professionally. As a deployer, an SME has to verify the system is compliant, train its staff (Article 4), and never use AI to monitor employees unlawfully. Using ChatGPT, HR software with automated scoring, or a facial recognition tool puts the SME inside the regulation's scope.

02

An incomplete GDPR record can cost as much as a data breach

Missing a record of processing activities is a documented infraction, checkable during a CNIL audit, and punishable on its own, no security incident required. 59% of SMEs don't keep one. The record isn't optional: it's the simplest GDPR obligation to build, and the first thing the CNIL checks.

03

The AI Act postponement isn't a pause

The Digital Omnibus pushed high-risk Annex III obligations to December 2027, and that's now confirmed, final law, not a proposal. Three obligations stay active right now: the ban on unacceptable-risk AI practices (since February 2025), the AI training duty under Article 4 (since February 2025), and rules for general-purpose AI models (since August 2025). SMEs waiting until 2027 to start their compliance work are taking a real risk.

04

« NIS2 isn't transposed in France yet » is not a compliance holiday

France still has no fully notified NIS2 transposition as of August 2026, 22 months after the October 2024 deadline. Some SMEs read that gap as "nothing applies yet." That reading is risky: sectoral supervisory authorities can already act under existing national security frameworks, and the transposition gap will close, likely with a short transition window once it does. The European Commission has referred France, Ireland, Spain and the Netherlands to the Court of Justice of the EU specifically for failing to notify their transposition measures, and is seeking financial penalties.

Participatory Study

Help us produce the first primary barometer on SME compliance

Available data on SME compliance is mostly declarative, or comes from large firms working with mid-caps and large enterprises. No systematic, independent, representative study of SMEs under 250 employees exists yet in France and Europe.

We're building it.

What you gain by participating:

  • Full study results in preview, as soon as they publish
  • A benchmark for your sector: where does your company stand?
  • Priority access to Themio at launch

The survey takes under 5 minutes, hosted on the official European Commission platform (EUSurvey). Responses are anonymised and processed in compliance with GDPR.

Participate in the Themio Study →
FAQ

Frequently Asked Questions on SME Regulatory Compliance

Is my company affected by the AI Act if it isn't a tech company?
Yes. The AI Act (EU Regulation 2024/1689) names two types of actors: providers, who build AI systems, and deployers, who use them professionally. An SME using recruitment software with automated scoring, a content-generation tool, or a customer chatbot counts as a deployer and carries legal obligations. Article 4 requires AI training for anyone involved in using an AI system, in force since February 2, 2025. Since the Digital Omnibus became final law in June/July 2026, high-risk Annex III obligations apply from December 2, 2027, but Article 4 training and the ban on unacceptable-risk practices were never delayed. Most French and European SMEs using AI tools already fall inside the regulation without realising it.
Does GDPR really apply to a business with fewer than 10 employees?
Yes, with no size exception. GDPR (EU Regulation 2016/679) applies to any entity processing personal data, regardless of size. The one limited exception: companies under 250 employees don't have to keep a record of processing activities, unless processing is regular, risky, or touches sensitive data. A Commission proposal (Digital Omnibus, published November 2025) would raise that threshold to 750 employees and make it risk-based, but as of September 2026 it remains in trilogue, not yet law. The CNIL has actively targeted VSEs/SMEs since 2023 through its simplified procedure, fines up to €20,000, and its 2025 annual report confirms sanctions above €10 million now hit medium-sized companies for the first time.
What is NIS2 and does it affect my SME?
The NIS2 Directive (EU 2022/2555) sets cybersecurity obligations for entities the law treats as essential or important to the economy and society. It applies from 50 employees or €10 million turnover, across 18 sectors including energy, transport, health, water, digital infrastructure, public administration and digital service providers. Covered entities must run a cyber risk management programme, notify incidents within 24 hours, and name a security officer. As of August 2026, four Member States, Ireland, Spain, France and the Netherlands, still have no fully notified transposition, 22 months after the October 2024 deadline; the European Commission has referred all four to the Court of Justice of the EU for failing to notify their transposition measures and is seeking financial penalties. ENISA's NIS Investments 2025 report puts cybersecurity staffing at just 10.6% of IT FTEs across covered organisations, with SMEs reporting the smallest share. See our full NIS2 guide for sector thresholds and obligations.
What's the real cost of GDPR non-compliance for an SME?
CNIL fines for SMEs through the simplified procedure run €3,000 to €20,000. The CNIL's official 2025 annual report confirms 83 sanctions totalling €486.8 million, 80% through this simplified procedure targeting small structures. New in 2025: several sanctions topped €10 million against medium-sized enterprises, the first time a fine at this scale has hit a company below the large-enterprise bracket. The real cost goes beyond the fine: reputation damage, lost customers, emergency compliance spend, and the risk of complaints from data subjects. Reactive compliance runs an estimated 5 to 15 times the cost of proactive compliance.
The AI Act was postponed. Can I wait before preparing for it?
No. The Digital Omnibus, finalised by the European Parliament (16 June 2026) and the Council of the EU (29 June 2026), in force since July 2026, only postponed obligations tied to high-risk systems under Annex III, from August 2026 to December 2, 2027 (Annex I safety-component systems: August 2, 2028). Three obligations stay active right now: the ban on unacceptable-risk AI practices (since February 2, 2025), the Article 4 AI training duty (since February 2, 2025), and rules for general-purpose AI models (since August 2, 2025). The Omnibus also added a new ban on AI tools that generate CSAM or non-consensual intimate imagery. Waiting until 2027 exposes SMEs deploying AI today to real non-compliance risk on these active points.
Do DORA and the Cyber Resilience Act apply to my SME too, or only to large companies?
Both can apply well below large-enterprise size. DORA (Regulation EU 2022/2554) , in force since January 17, 2025, covers financial entities and their ICT third-party providers, including small fintechs and any SME contracted to provide IT services to a bank, insurer or investment firm; industry surveys put roughly 44% of financial institutions short of full compliance. The Cyber Resilience Act (Regulation EU 2024/2847) reaches further: any SME manufacturing or selling a product with digital elements must report actively exploited vulnerabilities within 24 hours from September 11, 2026, and reach full compliance by December 11, 2027. Neither regulation carries a GDPR-style size exemption; only DORA offers a lighter regime for genuine microenterprises under Article 16.
How does Themio produce this barometer, and how often is it updated?
This barometer compiles data exclusively from public institutional sources, updated on a quarterly cycle: CNIL, EDPB, ENISA, the European Commission and Council of the EU, and France Num. The September 2026 edition reflects the final adoption of the Digital Omnibus on AI, the CNIL's confirmed 2025 enforcement figures, and the current NIS2 transposition gap. Every metric carries its own source and date in the methodology table below. Themio also runs its own primary survey of French and European SME executives on the European Commission's EUSurvey platform, feeding the 2027 edition.
Methodology

Methodology and sources

This barometer compiles data exclusively from public institutional sources. Every metric carries its own source and date.

Data Source Year
60% of SMEs are GDPR non-compliant RGPDKit, CNIL 2025 Review 2025
88% of VSE/SME sites are non-compliant with GDPR Cartegie, GDPR 7 Years On 2024
€486.8M in CNIL fines, 83 sanctions, confirmed CNIL, Rapport annuel 2025 2026
€1.15Bn EU-wide GDPR fines (2025) EDPB, Annual Report 2025 2026
41% of VSEs/SMEs keep a record of processing activities France Num GDPR 2024 Barometer 2024
51% have suffered a data security incident France Num GDPR 2024 Barometer 2024
26% of VSEs/SMEs use an AI tool (doubled in a year) France Num 2025 Barometer 2025
81.1% of EU cybercrime incidents involve ransomware ENISA, Threat Landscape 2025 2025
Digital Omnibus on AI, final law, in force July 2026 Council of the EU, press release, 29 June 2026 2026
23/27 Member States transposed NIS2 ; France not transposed European Commission, Digital Strategy 2026
Four Member States (Ireland, Spain, France, Netherlands) referred to the CJEU for failing to notify NIS2 transposition European Commission, press release ip_26_1499 2026
10.6% of IT FTEs dedicated to cybersecurity roles ENISA, NIS Investments 2025 2025
GDPR Digital Omnibus (RoPA threshold 250→750), proposed, in trilogue European Commission, published 19 Nov 2025 2025-2026
DORA , roughly 44% of financial entities not fully compliant Industry survey, ADVISORI 2026 2026
Cyber Resilience Act, first reporting deadline 11 Sept 2026 Regulation (EU) 2024/2847 2026

Where does your company stand compared to these statistics?

Find out if you comply with the European AI Act by evaluating your transparency obligations today.

Take the Article 50 compliance benchmark now →

Or join our study and contribute to the 2027 Barometer:

Answer the Themio survey →