You may fall within the scope of NIS2 and need a practical starting point. This 21-control checklist covers the Directive's essential requirements, translated into operational questions. In France, it should be treated as a preparation tool because transposition is still proceeding through bill PRMD2412608L and its future implementing texts. Allow 45 minutes to work through it with your CIO or CISO.
How to use it
3 minutes to understand, 45 to score
Assign a score to each point:
0
Non-existent
No action taken
1 to 2
Partial
Measure in place but incomplete or undocumented
3
Compliant
Measure documented, tested and audited annually
Block 1: 7 points
Governance & oversight
This is the area SMEs most often neglect, yet it is central to every NIS2 initiative. The Directive significantly strengthens senior management involvement.
- 1. An information systems security policy signed by management exists and has been reviewed within the past 12 months.
- 2. The company leader and executive committee have completed cybersecurity training within the past 24 months.
- 3. A formal, up-to-date risk analysis is available (using EBIOS RM or an equivalent method).
- 4. An annual cybersecurity budget is approved and tracked in the accounts (target: 5% to 10% of the IT budget).
- 5. A named cybersecurity lead, whether internal or an outsourced CISO, has been appointed by written decision.
- 6. The company monitors ANSSI resources and has prepared the information required for future registration, if applicable.
- 7. A monthly dashboard tracks at least five security indicators (incidents, vulnerabilities, backups, training and audits).
Block 2: 7 points
Technical measures
These are the minimum foundations to anticipate. Without these seven measures, no NIS2 readiness programme is credible.
- 8. Multi-factor authentication (MFA) is enabled on 100% of administrator accounts and remote access.
- 9. An EDR (Endpoint Detection & Response) solution is deployed across all workstations and servers.
- 10. 3-2-1 backups include at least one offline or immutable copy and undergo quarterly restoration tests.
- 11. A documented patching policy is in place: critical patches are applied within 14 days and all others within 30 days.
- 12. Sensitive data is encrypted at rest (drives, databases) and in transit (at least TLS 1.2 on all exposed services).
- 13. Effective network segmentation separates workstations, business servers and industrial / IoT systems.
- 14. Security event logs are centralised and retained for at least 12 months (in a SIEM or equivalent solution).
Block 3: 7 points
Organisation & people
Processes and people. Without them, technology will not hold up during a real attack.
- 15. A documented incident notification procedure provides for an alert within 24 hours, notification within 72 hours and a report within one month, to be adjusted to the final French arrangements.
- 16. A business continuity plan (BCP) and disaster recovery plan (DRP) are documented and tested at least once a year.
- 17. 100% of employees have received cybersecurity awareness training within the past 12 months.
- 18. At least one phishing simulation is conducted each year, followed by a debrief and targeted training.
- 19. An up-to-date inventory of assets (hardware, software, data and accounts) records their respective criticality.
- 20. Your five critical IT and SaaS suppliers (cloud, MSPs and business software vendors) have undergone a cybersecurity assessment.
- 21. A cyber crisis management exercise involving senior management has been conducted within the past 24 months.
What next?
From your score to a compliance roadmap
Week 1
Complete the 21-point assessment
Work with your CIO or CISO. Do not massage the figures: the objective is to establish an honest baseline.
Weeks 2 to 4
Prioritise the gaps
Anything scoring below 2 in blocks 1 and 2 (governance and technology) becomes a high priority.
Months 2 to 4
Close the quick gaps
MFA, EDR, immutable backups and management training: 80% of gaps can be closed in 90 days.
Month 6
Third-party audit or penetration test
To confirm that your theoretical posture holds up against a real attacker.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call