Glossary
NIS2
European directive (effective 2024) that extends cybersecurity obligations to tens of thousands of companies, including SMBs.
NIS2 (Network and Information Systems 2) is the update of the 2016 NIS directive. It substantially extends the scope: while NIS1 covered about 300 organisations in France, NIS2 covers between 10,000 and 15,000 — including SMBs in digital services, postal, manufacturing, administrative services, research, food, and more.
Main obligations: risk analysis, proportionate technical and organisational measures (security, incident management, continuity, supply chain), incident notification within 24 hours then 72 hours, and designation of a cybersecurity lead.
Fines are substantial: up to €10M or 2% of global revenue for essential entities, and €7M or 1.4% for important entities. French transposition is ongoing — the exact timeline depends on the sector. If your company is in scope, a Cyber Foundation or Advisory engagement structures the compliance work.