NIS 2 Compliance

Risk analysis, cybersecurity governance, supply chain security, Zero Trust, incident reporting to ANSSI: We’re building your cybersecurity resilience today so that NIS 2 will be a mere formality when the time comes—not a race against the clock.

100% Satisfaction
13 Reference systems
+200 Customers
Square with text bubble Complies with requirements

+ Over 200 companies have already placed their trust in us

Logo aniah
jamespot logo
Logo airon telematica
Logo seqino
SBS Interactive logo
auqfood logo

Understanding NIS 2 and
: What It Means for Your Business

The NIS 2 Directive (Network and Information Security 2 — EU 2022/2555) is the European legislation that expands and strengthens the cybersecurity framework for businesses and government agencies. Adopted on December 14, 2022, it replaces the 2016 NIS 1 Directive by significantly expanding its scope—from 7 to 18 sectors—and imposing stricter requirements for risk management and governance.

In France,ANSSI (the National Agency for the Security of Information Systems) will oversee the implementation. The transposition is being driven by the “Resilience” bill, which jointly transposes NIS 2, the REC, and DORA. Once the law is passed, entities will have a compliance deadline, but the foundational projects (risk analysis, mapping, securing third parties) generally take 12 to 18 months.

Far from being a mere administrative requirement, NIS 2 should be viewed as a genuine driver of cyber resilience: it influences B2B procurement processes, secures your operational workflows, and protects the personal liability of executives, which is now explicitly addressed by the directive.

Governance & Executive Accountability
Management bodies approve and oversee cybersecurity measures
Identify, address, monitor, and report risks on an ongoing basis
Risk Management & Cyber Resilience
Incident Reporting to ANSSI
Early warning within 24 hours, notification within 72 hours, final report within 1 month
NIS 2
EU Directive 2022/2555 · Transposed through the Resilience Bill
10M€ Or 2% of global revenue—maximum penalty for essential entities
~15,000 Affected entities in France (all sizes, 18 sectors)
24/72 hours Early warning/incident notification timeframe to ANSSI
27 countries Uniform application throughout the EU
Personal Liability of Executives: NIS 2 explicitly holds management bodies accountable; they may be held liable and subject to temporary suspension in the event of a serious breach.

Are you an essential entity
or a significant entity ?

NIS 2 distinguishes between two categories of entities, with differently calibrated obligations and penalties. These two regimes cover a total of 18 sectors, compared with 7 under the NIS 1 Directive.

Annex I to the Directive

Essential Entities (EE)

"Stricter regulations · ex ante inspections · penalties of up to 10 million euros or 2% of global revenue"

Highly Critical Sectors

  • Energy (electricity, natural gas, hydrogen)
  • Transportation (air, rail, road, maritime)
  • Banks & Financial Infrastructure
  • Health & Pharmaceuticals
  • Digital Infrastructure (DNS, IXP, cloud, data centers)
  • Drinking Water & Wastewater
  • Central Government Agencies
  • Space & Satellites
Annex II of the Directive

Significant Entities (SE)

Supervisory regime · ex post audits · penalties of up to €7 million or 1.4% of global revenue

OTHER CRITICAL SECTORS

  • Postal & Shipping Services
  • Waste management
  • Chemical Manufacturing, Production, and Distribution
  • Agri-Food Industry
  • Manufacturing (medical devices, electronics, machinery, vehicles)
  • Digital providers (marketplaces, search engines, social media platforms)
  • Scientific Research
  • Local governments (based on thresholds)

How can you tell if your company is affected? The general rule combines a sector-based criterion with a size criterion (≥ 50 employees or revenue > 10 M€). However, there are exceptions, including for SMEs that play a key role in a critical chain, digital service providers, and certain government agencies. The ANSSI’s MesServicesCyber portal allows you to take an online test and pre-register. We have also developed a free NIS 2 self-assessment tool that lets you evaluate your maturity level in just a few minutes.

The 10 categories of cybersecurity measures cybersecurity measures provided for under NIS2

Article 21 sets forth the minimum categories of measures that entities must implement in a manner proportionate to their risks.
Here is how these measures translate into concrete actions.

Information Systems Risk Analysis & Security Policy

Identify, assess, and address cyber risks using a structured approach, supported by an up-to-date map of critical assets, services, dependencies, and processes.

Incident Management & Notification

Qualification, handling, and reporting procedures. Early warning within 24 hours, notification within 72 hours, and final report within 1 month to the notification channel designated by the applicable French framework (CSIRT or competent authority).

Business Continuity & Cyber Resilience

Business Continuity Plans (BCPs), Disaster Recovery Plans (DRPs), backup management, and resilience against ransomware and major cyberattacks. Regular failover tests and crisis drills.

Safety & Risks Related to Third Parties

Supply chain risk analysis. Assessment of critical suppliers (cloud providers, MSPs, software vendors), contractual cybersecurity provisions, regular audits, and a transition plan in the event of a supplier incident.

Safety in Development and Operations

Technical measures to secure IT services: specifically, vulnerability management, patching, and security throughout the development and operations cycles.

Effectiveness Evaluation Policies

Indicators, internal audits, regular reviews of cybersecurity policies, and maturity metrics to verify and demonstrate the effectiveness of the system during an audit.

Cyber Hygiene Practices & Training

Ongoing awareness-raising for all employees, specialized training for IT teams and executives, phishing simulations, and management of risky behavior within hybrid teams.

Cryptography & Encryption

Policy on data encryption at rest and in transit, key management, with cryptographic choices tailored to the risk and, in France, aligned with ANSSI recommendations where applicable.

Human Resources Security & Access Control

Access lifecycle management (onboarding, mobility, offboarding), multi-factor authentication (MFA), the principle of least privilege, privileged accounts, and audit trails for sensitive operations.

Strong Authentication and Secure Communications

Implement multi-factor or continuous authentication for high-risk access points, secure internal communications, and establish a secure crisis communication channel when necessary. A Zero Trust architecture can be an effective approach for verifying every access attempt, limiting privileges, and minimizing the impact of a security breach.

Governance & Executive Accountability

Approval and oversight of the cybersecurity framework at the highest level. Mandatory training for senior management. Senior executives must approve and oversee the framework. The applicable sanctions and individual measures depend on the national implementation framework.

Pre-registration & NIS2 procedures with ANSSI

ANSSI has launched the MesServicesCyber portal to help organizations assess their eligibility, pre-register, and prepare for NIS2 compliance. The final regulatory requirements will depend on the French transposition legislation, which is still being finalized.

Good to know. The CNIL provides templates and industry-specific guides, but it’s up to you to implement them. Failing to fully understand your obligations exposes your company to audits, formal notices, and, ultimately, financial and reputational penalties. A 30-minute gap analysis with one of our consultants is all it takes to identify priority risk areas. Want to discuss this?

NIS 2: A High-Stakes Issue
, Which Companies Are Still Not Adequately Prepared For

Most companies don't lack goodwill when it comes to NIS 2. What they lack is a clear understanding of their blind spots: governance, third parties, and incidents. Here's why.

Cybersecurity governance managed solely by the IT department

NIS 2 requires explicit involvement by management. The Executive Committee and the Board of Directors must approve policies, monitor indicators, and be personally accountable in the event of a serious breach.

Hybrid Teams & Remote Workers Lacking Adequate Protection

The massive shift to remote work has dramatically expanded the attack surface: overloaded VPNs, unmanaged BYOD devices, direct cloud access, and mobile workstations. Protecting hybrid teams has become a key focus of cyber resilience.

A supply chain that has never been audited

SaaS, managed services, MSPs, software vendors, cloud hosting providers: half of all incidents stem from a third party. NIS 2 requires a formal analysis of third-party risks and the inclusion of cybersecurity clauses in contracts.

No notification procedure to the competent authority

Very few companies know how to classify an incident, escalate it internally, and report it in a timely manner (early warning within 24 hours, notification within 72 hours). Yet the lack of a formalized procedure is one of the main reasons for penalties.

Zero Trust Remains a Theoretical Concept

Many organizations have heard of Zero Trust without actually implementing it: partial MFA, lack of segmentation, poorly applied principle of least privilege, and privileged accounts with little oversight. NIS 2 will set a concrete standard.

Cybersecurity Without a CISO

In the absence of a full-time CISO, many small and medium-sized businesses and mid-market companies typically assign cybersecurity responsibilities to the IT department or senior management. An outsourced CISO provides a practical solution to this gap, particularly when it comes to meeting compliance deadlines without having to hire someone immediately.

FeelAgile turns these obstacles into manageable steps.

Our agile approach turns these obstacles into manageable steps. A dedicated expert guides you through each milestone, simply and effectively.

Talk to an expert →

Our solutions

On your own

  • GDPR E-Learning
  • Customized training
  • Access to the Knowledge Base (Registry Templates, AIPD, DPA, Privacy Policy, etc.)
  • Oversecur GRC Tool
  • CSM assistance Oversecur
  • Tool training and onboarding
  • Consulting
  • Diagnosis & White Audit

Accompaniment

Premium
  • Documentary database
  • Control & audit your compliance
  • Regular follow-up with an expert
  • Management of the compliance or maintenance project
  • Team training & change management
  • Assistance with document drafting
  • Guaranteed results
  • DPO designation
  • Audit
  • Managing the compliance project
  • Documentation support
  • Awareness

Expert on these regulations

DORA logo
GDPR logo
NIS2 logo
But also IA Act, Cyber Resilience Act and Data Act
Read more

Why Choose Us for Your Compliance
NIS 2 ?

FeelAgile brings together cybersecurity consultants, ISO 27001 Lead Implementers, and a proven outsourced CISO service with a track record of over 200 projects. Our pragmatic approach focuses on operational effectiveness: every NIS 2 measure is supported by tools, documented, and auditable.
Expert guidance

ISO 27001 as a Catalyst for NIS 2

An ISO 27001 information security management system (ISMS) inherently covers 70 to 80 percent of the NIS 2 requirements. Our approach builds on this foundation: what you build today will serve you tomorrow in compliance with the directive and in your B2B tenders.

Optimized lead times

We help you achieve your certifications and compliance in less than 6 months without compromising on quality or the rigor of the requirements.

Adaptability and comprehensive service

Consulting, training, project management or outsourcing, we tailor our support to your needs.

In-depth knowledge of regulations

We work on a wide range of reference systems, offering you comprehensive expertise to meet your challenges.

A Joint Interpretation of NIS 2, DORA, and the GDPR

Many companies are subject to several EU regulations at the same time. We consolidate policies, documentation, and controls to avoid duplicate paperwork and maintain a consistent system.

A Comprehensive Approach to Compliance

GDPR, ISO 27001, ISO 27701, HDS, SecNumCloud: We build coherent data governance systems and anticipate your future contractual and regulatory requirements.

Make ISO 27001 Your NIS 2 Accelerator
The ISO/IEC 27001 standard establishes an Information Security Management System (ISMS) that inherently covers most NIS 2 requirements: risk analysis, technical measures (Annex A), incident management, business continuity, and awareness. ISO 27001 is currently the shortest and most effective path to robust and auditable NIS 2 compliance.

Our ISO 27001 offering →

They trust us

+More than 200 customers have already called on FeelAgile

★★★★★

"Thanks to Feel Agile, we managed to achieve ISO 27001 certification without any non-conformities, which is a rare feat."

Profile photo Julien Caasagnabere
Val Solutions

Julien Cassagnabère -RSSI

★★★★★

"We received excellent support. The project manager thoroughly reviewed our quality system, which made the entire project run smoothly."

Male image
Airon Telematica

Stefano FIORENTINI - CTO

★★★★★

"Feel Agile has a deep understanding of the process, a project plan with an efficient timeline, and existing documentation to save time."

Male image
Aniah

Mickaël KLAUS

FAQ

Frequently Asked Questions from Businesses About Compliance NIS 2

All you need to know about NIS 2

Who is affected by the GDPR?

The GDPR applies to any organization—public or private, regardless of its size —as long as it processes personal data, provided that:

  • it is established within the European Union;
  • or its business is directly aimed at European residents.

Small businesses, SMEs, nonprofit organizations, and local governments: no one is exempt. This applies to you if you manage your employees’ HR data, process customer or prospect data, or outsource these operations on behalf of another organization.

What is personal data?

Personal data is any information that allows a natural person to be identified, either directly or indirectly:

  • Immediately: last name, first name, photo;
  • Indirectly: phone number, customer ID, IP address, voice.

Identification may be based on a single piece of data (for example, a Social Security number) or on a combination of several pieces of information (for example: gender, city, year of birth, subscription, membership in an organization). As soon as a link to a natural person is possible, the data is personal—and the GDPR applies.

Does my company need to appoint a DPO?

The appointment of a Data Protection Officer (DPO) is mandatory in three cases defined by Article 37 of the GDPR:

  1. The organization is a government agency or public body (local governments, ministries, etc.).
  2. The core business involves regular, systematic, and large-scale monitoring of individuals (banks, insurance companies, internet service providers, etc.).
  3. The core business involves the large-scale processing of sensitive data (health, criminal records, etc.), similar to what is done in hospitals.

Please note: Regardless of the situation, every organization remains obligated to comply with the GDPR, whether or not a data protection officer has been appointed. The CNIL strongly recommends appointing a data protection officer in other cases—it is the best way to structure and document your compliance.

FeelAgile offers an outsourced DPO service for organizations that do not wish to hire an in-house DPO.

Is it mandatory to maintain a record of processing activities?

Yes. The record of processing activities is mandatory for all organizations (Article 30 of the GDPR), whether public or private, regardless of their size. For each processing operation involving personal data, it lists: the purpose, the legal basis, the categories of data and data subjects, the recipients, the retention periods, and the security measures.

Provisions for Organizations with Fewer Than 250 Employees

Companies with fewer than 250 employees are exempt from the requirement to maintain a record: they are only required to record the following processing activities:

  • non-recurring tasks (payroll management, customer/prospect management, supplier management, etc.);
  • that may pose a risk to rights and freedoms (geolocation, video surveillance, etc.);
  • involving sensitive data (health information, criminal records, etc.).

However, we recommend that you document all of your processing activities. This will give you a comprehensive overview of the personal data you process and allow you to identify corrective actions in the event of an audit. The record of processing activities is one of the first deliverables we establish during a GDPR engagement.

What should you do in the event of a personal data breach?

Any personal data breach (leak, loss, unauthorized access, ransomware, etc.) must be reported to the CNIL within 72 hours, unless it poses no risk to individuals. When the risk is high, the affected individuals must also be notified.

An effective response requires a pre-established procedure:

  1. Incident classification and documentation.
  2. Notification to the CNIL (and to individuals, if necessary).
  3. Corrective Action Plan.

Our outsourced DPO service includes comprehensive management of these situations.

What are the penalties for non-compliance with the GDPR?

The CNIL may issue warnings, formal notices, and financial penalties of up to 20 million euros or 4% of annual global revenue —whichever is higher.

In addition to the fine, penalties may include an order to comply, public disclosure of the decision, and a temporary or permanent restriction on data processing. The reputational and commercial risk is often more severe than the penalty itself.

How long does it take to become GDPR-compliant?

It all depends on your current level of readiness and the scope of your data processing activities. As a general rule, achieving full compliance takes between 3 and 9 months.

With FeelAgile’s agile method, our clients achieve operational compliance in less than 4 months on average, thanks to a sprint-based approach and a priority focus on high-risk areas (cookies, records, third-party service providers).

How much does GDPR compliance cost?

The budget depends on the size of the company, the number of data processing operations, and whether or not there is an in-house DPO.

As a general guide, the initial cost of achieving compliance for an SME typically ranges from €8,000 to €25,000, to which may be added a flat fee for an outsourced DPO (starting at a few hundred euros per month).

FeelAgile will provide you with a personalized quote following a free 30-minute scoping audit.

GDPR, ISO 27001, ISO 27701, and HDS: How Do These Standards Relate to One Another?

These standards are complementary:

  • GDPR: European legal framework for the protection of personal data;
  • ISO 27001: international standard for information security;
  • ISO 27701: an extension of ISO 27001 focused on privacy, providing an excellent technical foundation for demonstrating GDPR compliance;
  • HDS: Mandatory certification for health data hosting providers, with stricter requirements.

FeelAgile can help you implement an integrated data governance system that covers these various data repositories while avoiding redundancies.

Who should I contact for assistance with the GDPR?

Implementing the GDPR requires expertise in information technology, law, and risk management, as well as a solid understanding of the laws applicable to your industry.

You can:

  • Hire or train an in-house DPO with the necessary skills;
  • Hire an external DPO who can audit, advise, and oversee compliance efforts.

The process of achieving GDPR compliance is a significant undertaking that should not be overlooked. Please feel free to contact FeelAgile for an initial consultation and expert guidance.

Our experts will get back to you within 24 hours.

Do you have any questions? Would you like a quote for certification or support?

Over 200 companies trust us
jamespot logo
auqfood logo
SBS Interactive logo
Logo seqino
Logo aniah
Logo airon telematica