Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Regulations

NIS2 Directive

NIS2 (Directive (EU) 2022/2555) is the European Union’s cybersecurity directive for essential and important entities across 18 sectors, from energy, transport, banking and health to digital infrastructure, manufacturing and public administration. It requires them to adopt risk-management measures, to report significant incidents on a 24-hour, 72-hour and one-month schedule, and it makes management bodies accountable for approving and overseeing those measures. Member states had until 17 October 2024 to transpose it.

Who is in scope

Scope follows sector and size: medium and large organizations in the sectors of Annexes I and II are in, as essential or important entities depending on sector and size, with some entities in regardless of size (trust service providers, DNS, public administration, entities designated as critical). The distinction matters for supervision and fines: essential entities face proactive supervision and fines up to 10 million euros or 2% of worldwide turnover; important entities face reactive supervision and a lower ceiling.

What it requires

Article 21 lists the minimum measures: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human resources and access control, multi-factor authentication. Article 23 sets the reporting clocks: early warning within 24 hours, notification within 72 hours, final report within one month. Article 20 puts management bodies on the hook and requires their training.

Where France stands

NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. The directive’s obligations are known, so entities that will be essential or important already run the Article 21 measures; what remains pending is the national supervision regime. The practical question for a CISO is therefore not whether NIS2 applies but whether the measures can be shown to operate on the day a supervisor asks.

GO DEEPER

The reference guide.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.