NIS2 Directive: Are You Ready? 150,000 Entities Must Comply

NIS2 Directive: Are You Ready? 150,000 Entities Must Comply

1. NIS2: What is it about?

The NIS2 directive, published at the end of 2022 by the European Union, is the new reference framework for the cybersecurity of critical entities. It replaces the NIS1 directive and imposes a uniform level of security across all Member States.

Objective: to strengthen the digital resilience of essential services in the face of the proliferation of cyber threats. Its transposition into French law is expected by October 2024, and will concern more than 150,000 entities in Europe, including nearly 15,000 in France.

NIS2 compliance is not limited to a regulatory obligation. It embodies a cultural shift: that of a cybersecurity that is driven, measurable, and integrated at the highest strategic level of companies.

2. Who is affected by the NIS2 Directive?

The scope of NIS2 is largely extended. It addresses two main categories of organizations:

  • ✅ Essential entities (EE)
    • Medium or large size (>250 employees or >€50M turnover)
    • Highly critical sectors: energy, transport, health, water, digital infrastructure, banking, ICT services, public administration, space…
  • ✅ Important entities (IE)
    • Medium-sized companies (>50 employees or >€10M turnover)
    • Other critical sectors: waste, chemicals, food processing, construction, digital providers, research…

💡 NB: For actors in the financial sector, the DORA directive prevails, but NIS2 may apply in addition.

These entities will have to declare themselves to ANSSI (in France) and implement structured cybersecurity governance, under penalty of sanctions.

3. What obligations does NIS2 impose?

NIS2 compliance is based on a series of clear technical, organizational and strategic obligations. Article 21 details the minimum measures to be implemented:

  • ✅ Risk analysis and cyber governance
  • ✅ Crisis management and business continuity plans
  • ✅ Supply chain security
  • ✅ Team training and cyber culture
  • ✅ Encryption policy, strong authentication
  • ✅ Implementation of a regular NIS2 audit
  • ✅ Notification of major incidents within 24 hours
  • ✅ Assessment of subcontractors and service providers

The major innovation: executives are directly responsible. They must validate the cyber policy, supervise its implementation and train management bodies. In case of breach, fines can reach up to 2% of global turnover, and criminal sanctions are provided for.

4. What impacts for your organization?

The NIS2 directive transforms cybersecurity governance:

  • Companies are no longer designated, they must self-declare.
  • Boards of directors must steer cyber decisions (and assume the consequences).
  • Suppliers, IT service providers, and subcontractors are also affected through extended risk management.
  • Cybersecurity becomes a strategic investment issue, no longer just a technical matter.

This paradigm shift requires:

  • Reviewing your risk analyses, with a comprehensive cybersecurity audit.
  • Assessing your exposure, vulnerabilities, and action plans.
  • Involving your executive committee, in connection with an outsourced CISO or shared CISO if you do not yet have an internal cybersecurity function.

5. How does Data Comply One support you towards NIS2 compliance?

At Data Comply One, we have designed a dedicated NIS2 compliance offering, tailored to SMEs, mid-sized companies, local authorities and critical operators.

Our support will soon include:

  • ✅ NIS2 Audit
  • ✅ Automated assessment of your maturity level
  • ✅ Access to an outsourced CISO or shared CISO
  • ✅ Implementation of your NIS2 cybersecurity roadmap
  • ✅ Dynamic mapping of risks and assets
  • ✅ Easy-to-use and secure management tool to monitor NIS2 compliance
  • ✅ Team awareness and e-learning training
  • ✅ Ongoing monitoring and proof of compliance to export from our platform in case of audit

Our platform and our experts make NIS2 compliance a strategic asset, serving your resilience, your business and your performance.

Conclusion: Bring Your Organization into NIS2 Compliance

Your organization must be ready. NIS2 requires a robust, governed, measured level of cybersecurity, with direct management by executives.

At Data Comply One, we help you transform this obligation into an opportunity and asset for your company. With our platform and our experts, you are supported end-to-end with complete peace of mind.