Skip to content
NIS2 compliance: gap assessment, roadmap and training

NIS2 compliance: gap assessment, roadmap and training

NIS2 takes France from roughly 500 regulated organisations to close to 15,000, and the picture is comparable across the EU. The requirements are already known, so there is no reason to wait for the implementing texts. Castelis runs your NIS2 compliance from the eligibility check through to hardening your systems and training your teams.

# They chose our expertise

/ Our Clients

Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
/

Is your organisation in scope of NIS2?

Directive (EU) 2022/2555 widens the scope of European cyber regulation considerably. Two criteria determine where you stand: your sector and your size.

Essential entities

Essential entities

Highly critical sectors, from 250 employees or 50 million euros in turnover. The strictest supervision regime and the most advanced security objectives.

Important entities

Important entities

From 50 employees or 10 million euros in turnover in the covered sectors. Comparable substantive obligations, with supervision applied after the fact.

18 sectors covered

18 sectors covered

Energy, transport, health, water, banking, digital infrastructure and public administration, plus postal services, waste, food, and manufacturing.

# Your obligations

/ What NIS2 requires from regulated entities

Four obligations structure the directive. They apply as soon as your entity falls in scope, with fines of up to 10 million euros or 2 % of worldwide turnover.

Registration with the authority

Registration with the authority

Declaring yourself as a regulated entity. In France, ANSSI already runs an eligibility simulator and a pre-registration service.

Cyber risk management

Cyber risk management

Risk analysis, access control, encryption, business continuity and supply chain security.

Incident notification

Incident notification

Early warning within 24 hours, detailed notification within 72 hours, final report within one month.

Management body training

Management body training

Management bodies approve the measures, oversee their implementation and must follow dedicated training.

/

How we support your NIS2 compliance

NIS2 compliance is not won on paper alone. We cover the full chain, from the eligibility check through to genuinely hardening the information system, alongside the teams who will operate those measures day to day.

Eligibility assessment

Eligibility assessment

Your status under NIS2 (essential, important or out of scope), which group entities are concerned, and the technical perimeter involved.

Gap assessment

Gap assessment

Your security level measured against the 20 objectives of ANSSI's Referentiel Cyber France, read differently depending on whether you are an important or an essential entity.

Risk analysis

Risk analysis

Mapping of your assets, dependencies and supply chain, then the documented and maintainable risk analysis the directive requires.

Prioritised roadmap

Prioritised roadmap

An action plan sequenced by severity of gap, your maturity and your resources, costed so you can arbitrate and defend the budget internally.

Policies and procedures

Policies and procedures

Your information security policy, incident handling and access management procedures, and the security requirements applied to your suppliers.

Technical hardening

Technical hardening

The measures actually implemented: configuration hardening, segmentation, multi-factor authentication, vulnerability management, backups and encryption.

Detection and notification

Detection and notification

Security monitoring and the notification chain that lets you meet the deadlines NIS2 imposes when a significant incident occurs.

Continuity and crisis management

Continuity and crisis management

Business continuity and disaster recovery plans designed and tested, plus cyber crisis exercises that genuinely put your procedures under strain.

Keeping compliance alive

Keeping compliance alive

Indicator tracking, periodic review of measures, documentation upkeep and audit readiness, with an outsourced CISO if you lack the resource in house.

/
NIS2 training starts at board level

NIS2 is not limited to technical measures. The directive requires management bodies to follow cybersecurity training, and encourages entities to offer equivalent training to their staff on a regular basis.

We build a path per audience rather than a single module: obligations and personal liability for executives, ReCyF objectives and notification procedures for IT teams, everyday reflexes for the wider workforce. Phishing campaigns then measure the progress that has actually been made.

NIS2 training starts at board level

/ Our NIS2 compliance method

A step-by-step approach that gets you compliant without bringing the business to a halt, aligned with the ReCyF objectives and the principle of proportionality.

1

Qualification

Establishing your status under NIS2 and drawing a precise boundary around the perimeter concerned.

Eligibility Perimeter
2

Gap assessment

The distance between your current practices and the expected security objectives, backed by a documented risk analysis.

ReCyF Risk
3

Roadmap

Actions prioritised and a workable timeline, agreed with the leadership team.

Priorities Trade-offs
4

Implementation

Organisational and technical measures rolled out, documentation formalised and teams trained.

Engineering Training
5

Upkeep and audits

Registration, notification procedures, exercises, continuous monitoring and readiness for supervisory checks.

Monitoring Audits

/
NIS2 compliance operated, not just recommended

Castelis is ISO 27001:2022 certified and holds the CyberVadis Platinum 2025 medal (983/1000). We apply to our own organisation the requirements we deploy at our clients.

That is the difference with a consulting firm: after the audit, we implement the measures, we train the teams and we operate the monitoring over time. With 25+ years of experience and 500+ projects delivered, we sequence compliance without breaking your business.

Badge score Cybervadis Castelis 983/100 - Médaille de platine

/
Frequently asked questions about NIS2 compliance

Two criteria combine: your sector and your size. NIS2 covers 18 sectors, split between highly critical and other critical sectors. Organisations with at least 50 employees or more than 10 million euros in turnover are generally in scope, with the threshold raised to 250 employees or 50 million euros for essential entities. Some entities are covered whatever their size because of their critical role. In France, ANSSI provides an eligibility simulator, and we run this assessment with you, including for multi-entity groups.

They fall into three families. First, registration with the national authority. Second, risk management measures covering risk analysis, incident handling, business continuity, supply chain security, access control, encryption and training. Third, notification of significant incidents through a multi-stage process. On top of that sits a governance requirement: management bodies approve the measures, oversee their implementation and follow dedicated training.

The directive provides for fines of up to 10 million euros or 2 % of total worldwide annual turnover for essential entities, and 7 million euros or 1.4 % for important entities, whichever is higher. Beyond fines, authorities can impose corrective measures and, for essential entities, temporarily suspend certain authorisations or management responsibilities. Liability of management bodies is explicitly engaged on approving and following up the measures.

NIS2 is a European directive: it takes effect once transposed into national law. In France, transposition is carried by the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, whose passage through parliament is not yet complete. Implementing decrees and orders will follow. That wait is no reason to do nothing: the criteria, the obligations and the expected security level are already known, and ANSSI has published its technical framework along with a pre-registration service.

The Referentiel Cyber France, published by ANSSI since 17 March 2026, translates the NIS2 requirements into 20 concrete security objectives. The first 15 apply by default to important and essential entities alike, while objectives 16 to 20, more advanced, target only essential entities in the working version released. The framework builds in a principle of proportionality: the expected effort is adapted to the maturity and resources of the organisation. It is currently the best working basis available to prepare.

It depends on your starting maturity, the size of the perimeter and the state of your documentation. An organisation already structured around security will mostly be closing documentation and process gaps. One starting further back will need technical workstreams spread over several months. We always begin with a short scoping exercise that gives a clear view of the effort involved and allows a realistic quote and timeline.

CONTACT

Let's assess your NIS2 compliance