Risk analysis, cybersecurity governance, supply chain security, Zero Trust, incident reporting to ANSSI: We’re building your cybersecurity resilience today so that NIS 2 will be a mere formality when the time comes—not a race against the clock.

+ Over 200 companies have already placed their trust in us
The NIS 2 Directive (Network and Information Security 2 — EU 2022/2555) is the European legislation that expands and strengthens the cybersecurity framework for businesses and government agencies. Adopted on December 14, 2022, it replaces the 2016 NIS 1 Directive by significantly expanding its scope—from 7 to 18 sectors—and imposing stricter requirements for risk management and governance.
In France,ANSSI (the National Agency for the Security of Information Systems) will oversee the implementation. The transposition is being driven by the “Resilience” bill, which jointly transposes NIS 2, the REC, and DORA. Once the law is passed, entities will have a compliance deadline, but the foundational projects (risk analysis, mapping, securing third parties) generally take 12 to 18 months.
Far from being a mere administrative requirement, NIS 2 should be viewed as a genuine driver of cyber resilience: it influences B2B procurement processes, secures your operational workflows, and protects the personal liability of executives, which is now explicitly addressed by the directive.
NIS 2 distinguishes between two categories of entities, with differently calibrated obligations and penalties. These two regimes cover a total of 18 sectors, compared with 7 under the NIS 1 Directive.
"Stricter regulations · ex ante inspections · penalties of up to 10 million euros or 2% of global revenue"
Supervisory regime · ex post audits · penalties of up to €7 million or 1.4% of global revenue
How can you tell if your company is affected? The general rule combines a sector-based criterion with a size criterion (≥ 50 employees or revenue > 10 M€). However, there are exceptions, including for SMEs that play a key role in a critical chain, digital service providers, and certain government agencies. The ANSSI’s MesServicesCyber portal allows you to take an online test and pre-register. We have also developed a free NIS 2 self-assessment tool that lets you evaluate your maturity level in just a few minutes.
Article 21 sets forth the minimum categories of measures that entities must implement in a manner proportionate to their risks.
Here is how these measures translate into concrete actions.
Identify, assess, and address cyber risks using a structured approach, supported by an up-to-date map of critical assets, services, dependencies, and processes.
Qualification, handling, and reporting procedures. Early warning within 24 hours, notification within 72 hours, and final report within 1 month to the notification channel designated by the applicable French framework (CSIRT or competent authority).
Business Continuity Plans (BCPs), Disaster Recovery Plans (DRPs), backup management, and resilience against ransomware and major cyberattacks. Regular failover tests and crisis drills.
Supply chain risk analysis. Assessment of critical suppliers (cloud providers, MSPs, software vendors), contractual cybersecurity provisions, regular audits, and a transition plan in the event of a supplier incident.
Technical measures to secure IT services: specifically, vulnerability management, patching, and security throughout the development and operations cycles.
Indicators, internal audits, regular reviews of cybersecurity policies, and maturity metrics to verify and demonstrate the effectiveness of the system during an audit.
Ongoing awareness-raising for all employees, specialized training for IT teams and executives, phishing simulations, and management of risky behavior within hybrid teams.
Policy on data encryption at rest and in transit, key management, with cryptographic choices tailored to the risk and, in France, aligned with ANSSI recommendations where applicable.
Access lifecycle management (onboarding, mobility, offboarding), multi-factor authentication (MFA), the principle of least privilege, privileged accounts, and audit trails for sensitive operations.
Implement multi-factor or continuous authentication for high-risk access points, secure internal communications, and establish a secure crisis communication channel when necessary. A Zero Trust architecture can be an effective approach for verifying every access attempt, limiting privileges, and minimizing the impact of a security breach.
Approval and oversight of the cybersecurity framework at the highest level. Mandatory training for senior management. Senior executives must approve and oversee the framework. The applicable sanctions and individual measures depend on the national implementation framework.
ANSSI has launched the MesServicesCyber portal to help organizations assess their eligibility, pre-register, and prepare for NIS2 compliance. The final regulatory requirements will depend on the French transposition legislation, which is still being finalized.
Good to know. The CNIL provides templates and industry-specific guides, but it’s up to you to implement them. Failing to fully understand your obligations exposes your company to audits, formal notices, and, ultimately, financial and reputational penalties. A 30-minute gap analysis with one of our consultants is all it takes to identify priority risk areas. Want to discuss this?
Most companies don't lack goodwill when it comes to NIS 2. What they lack is a clear understanding of their blind spots: governance, third parties, and incidents. Here's why.
NIS 2 requires explicit involvement by management. The Executive Committee and the Board of Directors must approve policies, monitor indicators, and be personally accountable in the event of a serious breach.
The massive shift to remote work has dramatically expanded the attack surface: overloaded VPNs, unmanaged BYOD devices, direct cloud access, and mobile workstations. Protecting hybrid teams has become a key focus of cyber resilience.
SaaS, managed services, MSPs, software vendors, cloud hosting providers: half of all incidents stem from a third party. NIS 2 requires a formal analysis of third-party risks and the inclusion of cybersecurity clauses in contracts.
Very few companies know how to classify an incident, escalate it internally, and report it in a timely manner (early warning within 24 hours, notification within 72 hours). Yet the lack of a formalized procedure is one of the main reasons for penalties.
Many organizations have heard of Zero Trust without actually implementing it: partial MFA, lack of segmentation, poorly applied principle of least privilege, and privileged accounts with little oversight. NIS 2 will set a concrete standard.
In the absence of a full-time CISO, many small and medium-sized businesses and mid-market companies typically assign cybersecurity responsibilities to the IT department or senior management. An outsourced CISO provides a practical solution to this gap, particularly when it comes to meeting compliance deadlines without having to hire someone immediately.
Our agile approach turns these obstacles into manageable steps. A dedicated expert guides you through each milestone, simply and effectively.
Talk to an expert →Make ISO 27001 Your NIS 2 Accelerator
The ISO/IEC 27001 standard establishes an Information Security Management System (ISMS) that inherently covers most NIS 2 requirements: risk analysis, technical measures (Annex A), incident management, business continuity, and awareness. ISO 27001 is currently the shortest and most effective path to robust and auditable NIS 2 compliance.
+More than 200 customers have already called on FeelAgile
"Thanks to Feel Agile, we managed to achieve ISO 27001 certification without any non-conformities, which is a rare feat."

Julien Cassagnabère -RSSI
"We received excellent support. The project manager thoroughly reviewed our quality system, which made the entire project run smoothly."

Stefano FIORENTINI - CTO
"Feel Agile has a deep understanding of the process, a project plan with an efficient timeline, and existing documentation to save time."
.webp)
Mickaël KLAUS
All you need to know about NIS 2
Do you have any questions? Would you like a quote for certification or support?