/ Our Clients
Is your organisation in scope of NIS2?
Directive (EU) 2022/2555 widens the scope of European cyber regulation considerably. Two criteria determine where you stand: your sector and your size.
Essential entities
Highly critical sectors, from 250 employees or 50 million euros in turnover. The strictest supervision regime and the most advanced security objectives.
Important entities
From 50 employees or 10 million euros in turnover in the covered sectors. Comparable substantive obligations, with supervision applied after the fact.
18 sectors covered
Energy, transport, health, water, banking, digital infrastructure and public administration, plus postal services, waste, food, and manufacturing.
/ What NIS2 requires from regulated entities
Four obligations structure the directive. They apply as soon as your entity falls in scope, with fines of up to 10 million euros or 2 % of worldwide turnover.
Registration with the authority
Declaring yourself as a regulated entity. In France, ANSSI already runs an eligibility simulator and a pre-registration service.
Cyber risk management
Risk analysis, access control, encryption, business continuity and supply chain security.
Incident notification
Early warning within 24 hours, detailed notification within 72 hours, final report within one month.
Management body training
Management bodies approve the measures, oversee their implementation and must follow dedicated training.
How we support your NIS2 compliance
NIS2 compliance is not won on paper alone. We cover the full chain, from the eligibility check through to genuinely hardening the information system, alongside the teams who will operate those measures day to day.
Eligibility assessment
Your status under NIS2 (essential, important or out of scope), which group entities are concerned, and the technical perimeter involved.
Gap assessment
Your security level measured against the 20 objectives of ANSSI's Referentiel Cyber France, read differently depending on whether you are an important or an essential entity.
Risk analysis
Mapping of your assets, dependencies and supply chain, then the documented and maintainable risk analysis the directive requires.
Prioritised roadmap
An action plan sequenced by severity of gap, your maturity and your resources, costed so you can arbitrate and defend the budget internally.
Policies and procedures
Your information security policy, incident handling and access management procedures, and the security requirements applied to your suppliers.
Technical hardening
The measures actually implemented: configuration hardening, segmentation, multi-factor authentication, vulnerability management, backups and encryption.
Detection and notification
Security monitoring and the notification chain that lets you meet the deadlines NIS2 imposes when a significant incident occurs.
Continuity and crisis management
Business continuity and disaster recovery plans designed and tested, plus cyber crisis exercises that genuinely put your procedures under strain.
Keeping compliance alive
Indicator tracking, periodic review of measures, documentation upkeep and audit readiness, with an outsourced CISO if you lack the resource in house.
/
NIS2 training starts at board level
NIS2 is not limited to technical measures. The directive requires management bodies to follow cybersecurity training, and encourages entities to offer equivalent training to their staff on a regular basis.
We build a path per audience rather than a single module: obligations and personal liability for executives, ReCyF objectives and notification procedures for IT teams, everyday reflexes for the wider workforce. Phishing campaigns then measure the progress that has actually been made.
/ Our NIS2 compliance method
A step-by-step approach that gets you compliant without bringing the business to a halt, aligned with the ReCyF objectives and the principle of proportionality.
Qualification
Establishing your status under NIS2 and drawing a precise boundary around the perimeter concerned.
Gap assessment
The distance between your current practices and the expected security objectives, backed by a documented risk analysis.
Roadmap
Actions prioritised and a workable timeline, agreed with the leadership team.
Implementation
Organisational and technical measures rolled out, documentation formalised and teams trained.
Upkeep and audits
Registration, notification procedures, exercises, continuous monitoring and readiness for supervisory checks.
/
NIS2 compliance operated, not just recommended
Castelis is ISO 27001:2022 certified and holds the CyberVadis Platinum 2025 medal (983/1000). We apply to our own organisation the requirements we deploy at our clients.
That is the difference with a consulting firm: after the audit, we implement the measures, we train the teams and we operate the monitoring over time. With 25+ years of experience and 500+ projects delivered, we sequence compliance without breaking your business.
/
Frequently asked questions about NIS2 compliance
Two criteria combine: your sector and your size. NIS2 covers 18 sectors, split between highly critical and other critical sectors. Organisations with at least 50 employees or more than 10 million euros in turnover are generally in scope, with the threshold raised to 250 employees or 50 million euros for essential entities. Some entities are covered whatever their size because of their critical role. In France, ANSSI provides an eligibility simulator, and we run this assessment with you, including for multi-entity groups.
They fall into three families. First, registration with the national authority. Second, risk management measures covering risk analysis, incident handling, business continuity, supply chain security, access control, encryption and training. Third, notification of significant incidents through a multi-stage process. On top of that sits a governance requirement: management bodies approve the measures, oversee their implementation and follow dedicated training.
The directive provides for fines of up to 10 million euros or 2 % of total worldwide annual turnover for essential entities, and 7 million euros or 1.4 % for important entities, whichever is higher. Beyond fines, authorities can impose corrective measures and, for essential entities, temporarily suspend certain authorisations or management responsibilities. Liability of management bodies is explicitly engaged on approving and following up the measures.
NIS2 is a European directive: it takes effect once transposed into national law. In France, transposition is carried by the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, whose passage through parliament is not yet complete. Implementing decrees and orders will follow. That wait is no reason to do nothing: the criteria, the obligations and the expected security level are already known, and ANSSI has published its technical framework along with a pre-registration service.
The Referentiel Cyber France, published by ANSSI since 17 March 2026, translates the NIS2 requirements into 20 concrete security objectives. The first 15 apply by default to important and essential entities alike, while objectives 16 to 20, more advanced, target only essential entities in the working version released. The framework builds in a principle of proportionality: the expected effort is adapted to the maturity and resources of the organisation. It is currently the best working basis available to prepare.
It depends on your starting maturity, the size of the perimeter and the state of your documentation. An organisation already structured around security will mostly be closing documentation and process gaps. One starting further back will need technical workstreams spread over several months. We always begin with a short scoping exercise that gives a clear view of the effort involved and allows a realistic quote and timeline.
Let's assess your NIS2 compliance