NIS2 and Network Security: What the Directive Requires
The European NIS2 (Network and Information Systems 2) Directive entered into force on October 17, 2024, and was transposed into French law in April 2025. It imposes strict cybersecurity obligations on 10,000+ French entities, with fines of up to €10M or 2% of revenue. Its impact on networks is significant. NIS2 2026 guide.
Entities in scope
Essential entities (EE)
- Energy (electricity, gas, oil, hydrogen)
- Transport (air, rail, road, maritime)
- Banks and financial markets
- Healthcare (hospitals, laboratories, pharmaceuticals)
- Drinking water and wastewater
- Digital infrastructure (DNS, TLD, cloud, CDN, data centers)
- Public administration
- Size: >250 employees or >€50M in revenue
Important entities (IE)
- Postal services, waste management, chemicals, food production
- Medical/automotive manufacturing
- Digital service providers
- Research
- Size: >50 employees or >€10M in revenue
Obligations
- Formal risk assessment (annual)
- Appropriate technical + organizational measures
- Business continuity + disaster recovery
- Supply chain security (suppliers)
- Appropriate cryptography + MFA
- Vulnerability management + patch management
- Employee cybersecurity training
- Incident notification: early warning within 24 hours, report within 72 hours, and final report within 1 month
Technical network measures
- Segmentation + micro-segmentation
- Zero-Trust Network Access (ZTNA)
- NGFW with SSL inspection
- SIEM + 24×7 SOC
- EDR on endpoints
- Offline backup + monthly recovery tests
- Encryption of data at rest + in transit
- Log retention for at least 1 year
Penalties
- EE: up to €10M or 2% of global revenue (whichever is higher)
- IE: up to €7M or 1.4% of global revenue
- Personal liability of senior executives
- Possible suspension of business operations
- France: ANSSI provides oversight and conducts audits
Impact on IT budgets
- IE SMEs (50-250 employees): additional €80-200k excl. VAT for compliance
- EE mid-market companies (250-2000): additional €500k to €2M
- Large enterprises: additional €5-20M depending on existing maturity
- ROI: fewer incidents + avoided fines
Compliance steps
- 1. Gap assessment
- 2. Prioritized action plan (quick wins + strategic initiatives)
- 3. Tool deployment: SIEM, EDR, ZTNA, SOC
- 4. Training + awareness
- 5. Testing (pentests, red team)
- 6. Documentation + annual audit
Relationship with DORA and other regulations
- DORA (Digital Operational Resilience Act): financial sector, 2025
- CRA (Cyber Resilience Act): digital products, 2027
- GDPR: personal data protection (since 2018)
- Interaction: NIS2 complements these regulations; it does not replace them
Order from OPTINOC
NIS2 support: gap audit, NGFW+SIEM+SOC deployment, and training. Expertise in ANSSI, Stormshield, and FortiGate. Quotes for EE/IE entities within 1 week.
