Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

REFERENCE GUIDE · Directive (EU) 2022/2555 (NIS2)

NIS2: who is in scope in France

NIS2 applies to organizations that are medium-sized or larger (50 employees or more, or over 10 million euros in both annual turnover and balance sheet) in one of the 18 sectors of its two annexes, plus entities in scope whatever their size. Sector and size then decide the label, essential or important, which sets the supervision and the fines. NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. This guide runs the test in four questions.

Published on · Facts reviewed by

The test in one sentence

Article 2 of the directive gives the rule: a public or private entity is in scope when it belongs to a type listed in Annex I or Annex II and qualifies as a medium-sized enterprise, or exceeds the ceilings for one, under the European SME definition (Recommendation 2003/361/EC). Everything else in the directive, the measures, the reporting clocks, the accountability of the management body, follows from that one sentence. The test is therefore sector first, size second, and a short list of exceptions third.

Size is read the SME way, which surprises many companies. An enterprise is small when it employs fewer than 50 persons and its annual turnover or its balance sheet total stays at or under 10 million euros. Cross either line, 50 staff or more, or both turnover and balance sheet above 10 million, and the enterprise is medium-sized or larger, hence in scope if its sector is listed. The headcount counts annual work units, so part-time staff and seasonal workers weigh in proportion.

The SME definition also aggregates partner and linked enterprises: a subsidiary is generally sized with its group. The directive lets member states weigh how independent the entity’s network and information systems are from those of its group, so a small French subsidiary of a large foreign group should not assume it is out. It should assume it is in, then check with the authority.

Question 1: is the sector listed?

Annex I lists the sectors of high criticality, Annex II the other critical sectors. The words matter less than the activity: a hospital is in the health sector whatever its legal form, a food wholesaler is in the food sector, a company that makes medical devices or machinery is in manufacturing. The 18 sectors are listed below; each one is refined by sub-sectors and entity types in the annexes themselves, which is where the edge cases live.

  • Annex I: energy (electricity, district heating and cooling, oil, gas, hydrogen); transport (air, rail, water, road); banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure (internet exchange points, DNS, top-level domain registries, cloud, data centres, content delivery networks, trust services, public electronic communications); ICT service management between businesses (managed service and managed security service providers); public administration; space.
  • Annex II: postal and courier services; waste management; the manufacture, production and distribution of chemicals; the production, processing and distribution of food; manufacturing (medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles, other transport equipment); digital providers (online marketplaces, online search engines, social networking platforms); research organizations.

Question 2: is the organization medium-sized or larger?

Take the last approved accounts and the average headcount of the year. Fewer than 50 staff and a turnover or a balance sheet at or under 10 million euros: the enterprise is small, and out of scope unless question 3 catches it. Anything above: in scope. Then place it on the second line: 250 staff or more, or a turnover above 50 million euros and a balance sheet above 43 million euros, makes it a large enterprise, which is what separates essential from important entities in the Annex I sectors.

Two practical traps. Public bodies do not have a turnover, so their scope rests on the annex entry for public administration and on the national law, which in France also reaches local authorities above thresholds the law will fix. And a group’s figures follow the enterprise in the accounts, not the site: a 30-person data centre owned by a 3,000-person group is sized with the group.

Question 3: is the entity in regardless of size?

Article 2(2) keeps a set of entities in scope whatever their size, because their failure would matter out of proportion to their headcount. Providers of public electronic communications networks or services, trust service providers, top-level domain name registries and DNS service providers are in regardless of size. So are entities that are the sole provider in a member state of a service essential to critical societal or economic activities, entities whose disruption could significantly affect public safety, security or health, entities that could induce a systemic risk with cross-border effects, entities that are critical because of their importance for a sector or for interdependent sectors, central government public administration entities, and entities identified as critical under the Critical Entities Resilience directive, which in France covers the operators of vital importance.

Question 3 is the one an organization cannot answer alone: several of these categories are identified by the member state. Under the French regime the identification belongs to the authority, and the safe reading for a small operator in a critical niche is to prepare as if identified.

Question 4: essential or important?

Article 3 splits the entities in scope into two labels. Essential entities are, in short, the large enterprises of the Annex I sectors, plus the trust service providers, TLD registries and DNS providers, the medium-sized providers of public electronic communications, central government bodies, the entities identified as critical, and the operators that were already essential service operators under the first NIS directive. Every other entity in scope is an important entity: the medium-sized enterprises of Annex I and all the enterprises, medium and large, of Annex II.

The label changes the regime, not the obligations. Both categories owe the Article 21 risk-management measures and the Article 23 incident reporting. Essential entities are supervised ex ante and ex post (audits, inspections, information requests at any time) and face administrative fines up to 10 million euros or 2 % of worldwide annual turnover, whichever is higher; important entities are supervised ex post, on evidence of a breach, with fines up to 7 million euros or 1.4 %. In both cases the management body approves the measures, oversees their implementation and can be held liable, and must follow training.

Sector-specific regimes: banks, insurers and DORA

Article 4 makes NIS2 the baseline that sector-specific Union acts can displace when they impose at least equivalent requirements. For the financial sector that act is DORA: banks, insurers, investment firms and the other financial entities it covers apply DORA’s ICT risk management and incident reporting instead of NIS2’s Articles 21 and 23. They are still in the banking and financial market infrastructure sectors of Annex I for the rest, notably the cooperation between authorities. A bank’s CISO therefore reads DORA for the measures and NIS2 for the map.

The other overlap is the Critical Entities Resilience directive, transposed in France within the same bill as NIS2 through the recast of the operators of vital importance. An entity identified as critical under that regime is an essential entity under NIS2 by construction.

Where France stands

NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. As the bill stands, régions, départements, métropoles, the larger communes and their groupings come into scope; the thresholds are fixed by the law and its decrees. Two consequences follow. The directive’s obligations do not bind a private French entity until the national law and its decrees are in force, so there is no sanction to fear today; and the content of those obligations is already known, since the law transposes the directive and the sectors, the thresholds and the two labels come from the European text. Preparation is the rational reading of the delay, not postponement.

ANSSI, the national cybersecurity authority, has been designated to run the regime and has published a self-assessment tool, MonEspaceNIS2, on which an organization answers the sector and size questions above and gets an indicative scope. The result is indicative: the law and the identification decisions will settle the edge cases, and the tool says so. It remains the fastest way to get a first answer and to register the organization once registration opens.

If the answer is yes: the first four moves

The scope question ends where the program starts. The organizations that are ready on the day a supervisor asks have done four things before that day.

  • Fixed the perimeter in writing: the legal entities in scope, their sector and label, the group entities that share their systems, and the person accountable for the registration and the reporting.
  • Put the management body to work: a decision approving the risk-management measures, a training session on the record, and a reporting cadence that reaches them with the risk register and the state of the measures.
  • Mapped the Article 21 measures to existing controls and evidence, with the gaps as dated actions: risk analysis, incident handling, continuity, supply-chain security, secure development, effectiveness assessment, cyber hygiene, cryptography, access control and multi-factor authentication.
  • Rehearsed the reporting clocks: who decides that an incident is significant, who files the early warning within 24 hours, the notification within 72 hours and the final report within a month, with which template and to which address.

What Mindlapse does with the answer

On the platform the perimeter, the measures and the evidence live in one place: the Article 21 measures are mapped to controls whose status is computed from live evidence, the incident-reporting clocks are workflows with owners, third parties carry a grade that moves with their signals, and the management body reads a cockpit built from the same facts. The NIS2 use case page walks through it obligation by obligation.

QUESTIONS

The questions people actually ask.

Does NIS2 apply to a company of 30 people?

Not by size: an enterprise with fewer than 50 staff and a turnover or balance sheet at or under 10 million euros is small, and small enterprises are out of scope. It is in scope if it belongs to one of the size-independent categories of Article 2(2), for instance a DNS provider, a trust service provider or the sole provider of an essential service, or if its group makes it a medium-sized enterprise under the SME rules on linked enterprises.

Our company is the French subsidiary of a large group. Are we in scope?

Assume yes and check. The SME definition sizes an enterprise with its partner and linked enterprises, so a subsidiary of a large group is generally large. The directive lets member states weigh the independence of the subsidiary’s network and information systems, which the French regime may use; until the law and its decrees say how, the prudent reading is to prepare as an entity in scope.

We are a bank. NIS2 or DORA?

DORA, for the ICT risk management and incident reporting measures: it is the sector-specific act that Article 4 of NIS2 lets prevail. The bank stays in the banking sector of Annex I for the parts DORA does not cover, and its authority remains the financial supervisor for DORA’s obligations.

Are French organizations already bound while the law is before Parliament?

No sanction applies to a private entity before the transposition law and its decrees are in force. NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. The obligations themselves are already written in the directive, so the delay changes the date of enforcement, not the content of what to prepare.

Are local authorities concerned?

As the bill stands, régions, départements, métropoles, the larger communes and their groupings come into scope; the thresholds are fixed by the law and its decrees. Central government administrations are essential entities under the directive itself; the reach into regional and local bodies is a national choice, and the French bill makes it.

What are the fines?

For essential entities, administrative fines up to 10 million euros or 2 % of total worldwide annual turnover, whichever is higher; for important entities, up to 7 million euros or 1.4 %. The directive also lets authorities suspend certifications and, for essential entities, temporarily bar a natural person with management responsibilities from exercising them, and it makes the management body liable for the breaches.

GLOSSARY

Terms this guide builds on.

ON MINDLAPSE

Where this guide meets the platform.

The pages that turn the obligations into verified controls.

SEE IT VERIFIED

Knowing the obligation is the start. Proving it is the product.

Thirty minutes on your scope: which entities, which measures, which evidence, and how the platform keeps them verified between two audits.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.