NIS2 is the European Union's major cybersecurity directive of the decade. Many SME leaders still think it will not apply to them. That is a misreading of the text.
The framework
NIS2 explained on one page
NIS2 (Network and Information Security 2) is EU Directive 2022/2555. It replaces the first NIS Directive of 2016, which was considered too narrow. It has three objectives:
18
Sectors covered
Compared with 7 under NIS1
≈ 100,000
Companies affected in the EU
Including tens of thousands in France
2025
French transposition
Bill PRMD2412608L is being adopted
In France, transposition is being carried out through the bill on the resilience of critical infrastructure and stronger cybersecurity, referenced as PRMD2412608L. The text was presented to the Council of Ministers on 15 October 2024 and adopted at first reading by the Senate on 12 March 2025. ANSSI is preparing the operational implementation of NIS2 and supporting the entities that will fall within its scope.
Am I affected?
The two-gate rule
To determine whether NIS2 could apply to your SME, you need to pass through two successive gates.
Yes
I move to gate 2 (size).
No
I am outside the scope unless ANSSI designates my company individually.
Yes
I am potentially within the scope of NIS2 (as an essential or important entity).
No
I am outside the scope, except for sector-specific exceptions (DNS, trust services, etc.).
The two categories of entities
Annex I
Essential entities
- Energy, transport, banking
- Healthcare, drinking water
- Digital infrastructure (cloud, data centres, DNS)
- MSPs / MSSPs (business-to-business ICT services)
- Public administration, space
Annex II
Important entities
- Postal and courier services, waste management
- Chemicals, food production
- Manufacturing (medical devices, electronics, automotive)
- Digital providers (online marketplaces, social networks)
- Research
The size thresholds to remember
≥ 250
Employees (essential entity)
or €50m revenue and €43m balance sheet total
≥ 50
Employees (important entity)
or €10m revenue and €10m balance sheet total
< 50
Outside the scope
Except for sector-specific exceptions
When
The actual timetable for a French SME
October 2024
EU transposition deadline
France fell behind schedule.
15 October 2024
Bill presented
Bill PRMD2412608L was presented to the Council of Ministers.
12 March 2025
Adopted at first reading by the Senate
An important parliamentary step, but not the enactment of final legislation.
2026
Operational preparation
ANSSI is providing resources, including MonEspaceNIS2 and the ReCyF working document.
After adoption
Implementing texts
Decrees, frameworks and supervisory arrangements will clarify the French requirements.
Plan ahead
Inspections and penalties
The maximum penalties provided for by the Directive and incorporated through transposition will apply under the final framework.
What to do
The 10 minimum requirements, in practical terms
The NIS2 Directive provides for technical and organisational measures. Here is a practical interpretation for SMEs, to be adjusted once the final French texts are available:
- A risk analysis policy approved by management (updated annually)
- An incident management procedure with a 24/7 point of contact
- A business continuity plan: tested backups and a disaster recovery plan
- A cybersecurity assessment of your critical suppliers (cloud, MSPs)
- Security in development and patch management
- Regular technical audits or penetration tests
- Annual awareness training for all employees
- Encryption policies for sensitive data
- MFA, least privilege and an up-to-date asset inventory
- Secure communications during crisis management
Penalties
What you actually risk
€10m
Directive ceiling: essential entity
Or 2% of annual worldwide revenue, whichever is higher
€7m
Directive ceiling: important entity
Or 1.4% of annual worldwide revenue
€420,000
Ceiling for an SME with €30m revenue
Important entity category
Beyond the fine: senior leaders on the front line
- Enhanced supervisory measures depending on the entity's category
- Formal orders to remedy identified shortcomings
- Possible publication of certain decisions under the final framework
- Loss of contracts: large companies and the public sector will demand more cybersecurity evidence
Action plan
Where to start if this is new to you
The priority is not to overhaul everything. It is to secure the next three quarters in this order:
Week 1
Confirm your eligibility in writing
NAF business code, employee count, revenue. Document the decision.
Week 2
Monitor ANSSI resources
MonEspaceNIS2, ReCyF and transposition updates will help you anticipate the framework.
Weeks 3 to 10
Gap assessment
Current posture against the 10 minimum measures. Six to eight weeks is enough.
Month 3
12-month roadmap
Prioritised by risk, approved by management and traceable.
Month 4
Train senior management
Essential for demonstrating active cybersecurity governance.
If you want a precise assessment of your situation, request a free NIS2 diagnostic: 30 minutes to clarify your category, obligations and exposure.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call