Homologation you can decide on, sovereignty you can show.
Dozens of téléservices without a current homologation decision, an RSSI shared across a métropole and its communes, elected officials who answer for cyber risk as the management body under NIS2. Mindlapse gives every service a decision file and every obligation one evidence base, hosted only in Europe.
Security-by-Design record · téléservice Illustrative data
SBD-00187
Online benefits application service
High Téléservice Citizens
personal datahomologationnew
Contextualization
Routing
GRC analysis
Action plan
Monitoring
Completed
Current step · GRC analysis 3 / 4
Risk analysis (EBIOS RM)
Data classification
Baseline controls
Privacy scoping
Analyst review
Validate step →
Blocker: identity provider assessment pending.
The homologation file is the by-product of a project done right, not a separate exercise.
THE SITUATION
The RGS obligation nobody owns.
01
Homologation debt
Téléservices opened years ago, no risk analysis on file, and an autorité d’homologation that never asked.
02
One RSSI, many mayors
A DSI mutualisée, one RSSI shared across the communes, and elected officials who will owe cyber training under NIS2 that nobody has told them about.
03
Security ends at award
The tender carried a security clause; the editor signed it, delivered, and was never assessed again.
04
The cloud arbitration that blocks projects
Sensitive-data classification unclear in practice, few qualified offers, and every project waiting on a doctrine question.
WHO IS IN SCOPE
Who is in scope in the public sector?
Central government entities are a NIS2 Annex I sector, regional entities join them as each member state defines them, and local entities where the member state so decides. As the bill stands, régions, départements, métropoles, the larger communes and their groupings come into scope; the thresholds are fixed by the law and its decrees. Independently of NIS2, every administrative authority that opens a téléservice owes it an RGS homologation, decided by an autorité d’homologation on a risk analysis, and public bodies designate a data protection officer under the GDPR. The NIS2 page lists the sectors and the entity test.
Written for
Ministries and opérateurs de l’ÉtatNIS2 essential, PSSIE, the HFDS chain
Régions, départements, métropoles and communesNIS2 by national designation, RGS, a shared RSSI
Établissements publicsNIS2 as designated, the procurement code
Public-sector editors and outsourcersSupply-chain flow-down, SecNumCloud as a market gate
WHAT MINDLAPSE CHANGES
One record per service, one evidence base per obligation.
What NIS2, the RGS and the cloud doctrine ask, and what Mindlapse verifies.
EU rows first, the two French specifics tagged; every "verifies" cell is a product claim at ledger level and none carries a date; the one dated sentence on this page sits under the table.
What NIS2, the RGS and the cloud doctrine ask, and what Mindlapse verifies.
A posture the executive can read, exposure by public service against the appetite it approved; the cyber-risk policy it adopts published, versioned and attested by the agents it binds; the training itself stays the body’s own duty
Art. 21 · measures for public administration entities
One control set, NIS2 pre-mapped, each control carrying dated, reviewed evidence that also answers the RGS and your PSSI
Control Atlas
GDPR
Art. 37 · a mandatory DPO; Art. 35 · a DPIA on high-risk processing
Privacy scoping at initiative intake, GDPR-related control sets in the atlas, the DPO reading with a scoped role; the DPIA remains yours to write and to keep
Annex III 5(a) · AI deciding access to public benefits, high-risk
The AI system declared on the value chain of the service it serves, its obligations carried as controls with evidence; the AI Act page carries the dates
Risk Register
RGS FR
Homologation of a téléservice before it opens
The téléservice as an initiative: contextualisation, EBIOS RM analysis, recommendations as actions, the decision recorded on its evidence; the homologation act and the attestation remain the authority’s
Security by Design
Cloud doctrine FR
SecNumCloud-level hosting for the sensitive data of State administrations and their operators; a procurement criterion elsewhere
Sensitive-data classification at intake; your hosts assessed as suppliers in the context of the service they carry; Mindlapse itself hosted only in the EU and holding no SecNumCloud qualification
Supplier Hub
NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.
A QUARTER, THEN THE DAY THE AUTHORITY ASKS
A normal quarter contextualises, answers and republishes; the request finds the analysis already behind the decision.
Four moments of an ordinary quarter in a mutualised DSI, and what the platform had already done; then the day the autorité d’homologation asks, in three steps.
A quarter in the public sector, then the request Illustrative data
A normal quarter
WEEK 2
Five new téléservices arrived from the services.
Each was described in business terms by its owner and routed by criticality; two took the fast track, three went to analyst review.
Surface: Security by Design
alert: WEEK 5
The payroll editor answered its questionnaire.
Through the portal, in the context of the payroll service; two answers contradicted its own documents and were flagged with the evidence.
Surface: Supplier Hub
WEEK 8
The PSSI came back from the executive with its changes.
Republished as a new version and attested by the agents it binds, each attestation dated.
Surface: Policies
verified: WEEK 12
The autorité d’homologation signed for the benefits téléservice.
The decision was recorded on the record itself, against its analysis and its closed actions; the act stayed the authority’s.
Surface: Security by Design
The day the authority asks
THE REQUEST
The autorité d’homologation asks for the risk analysis behind a téléservice opened three years ago.
The service had been re-entered as an initiative; its analysis, its recommendations and their closure sat on one record.
Surface: Security by Design
WHAT OPENS
The initiative record: analysis, recommendations, their closure, the derogations.
Each recommendation as an action with an owner and a closure date; each derogation with its compensating measures and its expiry.
Surface: Action queue
WHAT IS EXPORTED
The evidence the decision rests on.
From Audit mode, scoped to the téléservice: the controls, their dated evidence, the closed actions; the decision and the attestation remained the authority’s to sign.
Surface: Control Atlas
Illustrative quarter: the moments are fictional, the surfaces are the product’s; the téléservice and the editor are invented.
FROM THE FIELD
Built with the people who answer to the citizen.
CYBER COLLECTIVE LAB · Edition 5
Compliance: NIS2, DORA and CRA - round table and field feedback
NIS2 as the first cyber regulation many public bodies will meet: what the round table on NIS2, DORA and CRA said about starting from the obligation rather than from the tool.
−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization
2–3×
risk visibility across the organization
Measured with our design-partner CISOs, figures under continuous validation.
Does Mindlapse hold the SecNumCloud qualification?
Not today. Customer data is hosted and processed only in the European Union, on European regions of certified providers, with nothing transferred outside it; ISO 27001 is in progress and SOC 2 is planned, with the dates on the trust center. A dedicated instance, a private cloud or an on-premise deployment are available where your doctrine requires them.
Can we buy through a purchasing body or a framework agreement?
Case by case. Purchasing-body routes and framework agreements are handled consultation by consultation: send the consultation documents to the bid desk, which answers in writing on the vehicle, the deployment option and the hosting commitments, and tells you up front if it will not bid.
Does it replace MonServiceSécurisé for the homologation?
No. Mindlapse carries the analysis, the recommendations as actions and the decision as living records on the téléservice, so the file is the by-product of the project; the homologation act, and the attestation that goes with it, remain yours to sign, whatever tool you file them in.
Does NIS2 apply to our commune?
NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. As the bill stands, régions, départements, métropoles, the larger communes and their groupings come into scope; the thresholds are fixed by the law and its decrees.
Can the DPO and the RSSI share one platform?
Yes. Each works from a scoped role on the same records: the RSSI on the risks, controls and suppliers, the DPO on the privacy scoping done at intake and the GDPR-related control sets, all mapped to the same control set as NIS2. Personal data itself stays in your systems; the platform holds governance records.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy