The EU NIS 2 directive greatly expands the number of organisations in scope. In France, national transposition is still underway in 2026. This article explains the EU framework and the measures worth preparing now.
What is NIS 2?
The European NIS 2 directive (Network and Information Security) succeeds the first NIS directive of 2016. Its objective: to significantly raise the common level of cybersecurity within the European Union, as cyberattacks become more frequent and sophisticated targeting critical infrastructures.
NIS 2 extends the EU framework to many organisations across 18 sectors. In France, ANSSI is supporting the transposition process and has published the Référentiel Cyber France to help future regulated entities prepare their security measures.
Who is affected by NIS 2?
NIS 2 distinguishes two categories of entities:
- Essential entities: the category includes certain organisations in the highly critical sectors listed in Annex I. Classification depends on size and on the specific cases set out in Article 3.
- Important entities: this category covers other in-scope organisations in Annexes I and II that are not classified as essential. Size thresholds apply, with specific exceptions.
Important: even if your company does not meet these thresholds, you may be subject to NIS 2 if you are a critical supplier to an organisation in scope. Supply-chain security is a central requirement of the directive.
Unsure whether your organisation is in scope? ANSSI provides a self-assessment questionnaire on monespaceanssi.ssi.gouv.fr. It is strongly recommended to do this without delay.
The 4 major obligations of NIS 2
- Cyber risk management. Entities must adopt appropriate technical and organizational measures to manage risks to their information systems: risk analysis, formalized security policy, access management, physical security.
- Supply chain security. Organizations must assess and supervise the level of cybersecurity of their suppliers and IT service providers. Choosing compliant technology partners becomes a legal obligation, not just a best practice.
- Notification of incidents. Any significant incident must be reported to ANSSI within strict deadlines: early warning within 24 hours, notification within 72 hours, final report within 30 days. The significance criteria are defined by decree.
- Management accountability. Management bodies must approve and oversee cybersecurity risk-management measures and can be held liable for infringements under national law. The directive sets maximum administrative fines of at least €10 million or 2% of worldwide annual turnover for essential entities, whichever is higher.
How backup supports NIS 2 readiness
Among the technical measures required by NIS 2, secure data backup is explicitly mentioned as an essential component of business continuity management. Entities must be able to restore their systems after an incident within defined time frames, which means having recent, tested backups protected against tampering.
Oxibox can support an NIS2 readiness programme through automatic backup disconnection, source-side encryption and traceability of backup and recovery operations. Hosting and jurisdiction remain explicit deployment choices.
Compliance schedule
In 2026, French transposition of NIS 2 is still underway. Entry into force depends on the legislation and implementing texts being enacted. Organisations can already prepare asset mapping, governance, incident management and recovery capabilities, then follow ANSSI publications for the legally binding timetable.
Best practices now: carry out an inventory of your cyber posture, formalize your backup policy, map your critical IT subcontractors and document your incident response procedures. This work will be useful regardless of your NIS 2 category.