Directive (EU) 2022/2555 · NIS 2 · Applicability & Readiness Diagnostic

NIS 2 Diagnostic: are you in scope ,
and where do you stand?

⏱ EU NIS 2 Directive: National transposition ongoing · French ANSSI ReCyF v2.5 framework

Check in 2 minutes whether NIS 2 applies to your company (essential or important entity), then score your cybersecurity readiness against the 10 core measures of Article 21.

2-minute qualification Article 21 maturity score ANSSI ReCyF correspondence 100% anonymous in-browser

Free · No account required · Processed locally in your browser

Scope of application

Who does the NIS 2 Directive apply to?

The directive uses a size-cap rule: it covers primarily medium-sized and large companies in the sectors listed in Annex I (high criticality) and Annex II (other critical sectors). Some activities are covered regardless of size, and a Member State can designate smaller entities (Art. 2).

Category Criteria (Arts. 2 and 3) Examples
● Essential entity Large companies (250 staff or more, or turnover above €50M and balance sheet above €43M) in Annex I. Regardless of size: qualified trust service providers, top-level domain registries, DNS providers. Medium-sized and large public electronic communications providers. Energy supplier, 400-staff private clinic, 300-person cloud host
● Important entity Medium-sized companies (from 50 staff, or turnover and balance sheet above €10M) in Annex I. Medium-sized and large companies in Annex II. 80-staff managed service provider, 150-staff machinery maker, 600-staff food wholesaler
● Out of scope in principle Micro and small enterprises, unless their activity is covered regardless of size or an authority designates them. Many are still affected indirectly through their customers' supply chain security requirements. 30-staff road haulier, IT supplier to a hospital
Detailed obligations

What NIS 2 requires from entities in scope

Entities in scope must implement proportionate technical and organizational cybersecurity risk-management measures and report significant incidents.

Article 20

Management accountability

Management approves cybersecurity measures, oversees their implementation, takes mandatory training, and can be held personally liable for gross negligence.

Article 21

10 Risk-management measures

Security policies, incident handling, business continuity, supply chain security, vulnerability handling, effectiveness testing, basic cyber hygiene, encryption, access control, and MFA.

Article 23 · Reporting
24 h · 72 h · 1 month

Incident reporting deadlines

Early warning within 24 hours, full notification within 72 hours, and a final report within one month to the national CSIRT. GDPR notification also applies if personal data is affected.

Article 34 · Sanctions
Up to €10M · 2% turnover

Maximum fine ceilings

Up to €10M or 2% of global annual turnover for essential entities, and €7M or 1.4% for important entities. National laws determine final schedules.

Transposition Timeline

Where does NIS 2 transposition stand in France & Europe?

As of 29 September 2026, no French transposition law has been promulgated . The loi « Résilience » bill transposes NIS 2 together with the CER Directive and adapts French law to DORA. In the meantime, ANSSI encourages entities to prepare using the ReCyF v2.5 framework and MonEspaceNIS2.

  • The loi « Résilience » bill is presented to the Council of Ministers.

  • Transposition deadline set by the directive (Art. 41) expires.

  • The Senate adopts the bill at first reading.

  • The National Assembly special committee adopts an amended text that notably includes software publishers.

  • The European Commission proposes targeted amendments to the NIS 2 Directive.

  • ANSSI publishes ReCyF v2.5 , a working document: 20 security objectives, 15 of them for important entities.

  • The Commission refers France to the EU Court of Justice (CJEU) for failure to transpose.

  • Plenary reading in the National Assembly, final adoption, promulgation, then implementing decrees.

Methodology & Rigor

How this NIS 2 diagnostic works

A deterministic rules engine based strictly on the official EU directive and the ANSSI ReCyF framework.

  • Scope criteria: The rules in Articles 2 and 3 of the directive, Annexes I and II, and the EU SME definition (Recommendation 2003/361/EC).
  • Most demanding sector principle: The most stringent sector decides the result. Cases that depend on an authority are marked "to be confirmed", never decided for you.
  • Readiness scoring: 23 questions across 12 domains (Arts. 20, 21(2)(a) to (j) and 23), scored 0 to 3. "I don't know" answers score zero and are highlighted.
  • Weights: Higher weights for governance and reporting (×1.5), continuity and MFA (×1.3), incident handling (×1.2).
  • France specific mapping: Mapping to the 20 ReCyF v2.5 objectives based on ANSSI's correspondence table. Objectives 16 to 20 are shown only for essential entities.
  • Versioned rules: Mandatory review when the loi Résilience, its decrees, or EU amendments are finalized.
Frequently asked questions

Frequently asked questions: NIS 2 & SMEs

What is the NIS 2 Directive?
Directive (EU) 2022/2555, known as NIS 2, sets a high common level of cybersecurity across the Union. It replaces the 2016 NIS Directive, extends scope to 18 sectors and imposes three sets of obligations: management accountability (Art. 20), risk-management measures (Art. 21) and reporting of significant incidents (Art. 23).
Does NIS 2 apply to my company?
In principle yes if you are a medium-sized or large company (from 50 staff, or turnover and balance sheet above €10M) active in an Annex I or II sector. Some activities are covered regardless of size, such as DNS providers or qualified trust service providers. The diagnostic above applies these rules to your situation in 2 minutes.
Does NIS 2 already apply in France?
Not yet as a matter of law: as of 29 September 2026 the transposition law has not been promulgated, and the Commission referred France to the CJEU on 8 July 2026. Obligations become enforceable with the law and its decrees. ANSSI recommends preparing now with ReCyF, because compliance takes several months.
What is the difference between essential and important entities?
Both apply the same Article 21 measures and the same reporting rules. The difference is supervision: ex ante for essential entities (Art. 32), ex post for important entities (Art. 33). Fine ceilings also differ. In France, ReCyF adds five objectives that apply only to essential entities.
What are the incident reporting deadlines?
For a significant incident: an early warning within 24 hours, a notification within 72 hours, then a final report within one month (Art. 23). If personal data is affected, GDPR notification to the data protection authority (72 hours, GDPR Art. 33) also applies.
Are SMEs exempt from NIS 2?
Micro and small enterprises are in principle out of scope, except for some digital activities or where designated. In practice many are affected indirectly: their NIS 2 customers must secure their supply chain and impose contractual requirements on them.
Does this diagnostic replace an audit?
No. It gives an indicative classification and a first assessment. Your final status depends on national law and, where relevant, the authority. For an audit, ANSSI qualifies providers in France (PASSI for audits, PACS for advisory).
What happens to my answers?
They stay in your browser unless you request the detailed report. If you do, Themio processes your email and answers to send it, under its privacy policy. Subscribing to news is a separate, optional choice.

Prepare your company for NIS 2 compliance today.

Identify your qualification, audit your security measures, and prepare your remediation roadmap.

🔒 100% GDPR compliant · EU hosted · Anonymous diagnostic with no account required

This page provides general guidance and is not formal legal advice. Themio helps prepare regulatory compliance; interpreting specific situations may require a qualified IT or cybersecurity legal advisor.