DEEP-DIVE TOPIC

NIS2

NIS2 is neither a checklist nor merely a scoping questionnaire. For an entity in scope, the directive places governance, proportionate risk management and the ability to evidence implemented measures at the centre of the framework.

Sources verified on August 25, 2026

KEY POINT

Cybercoria separates three questions: whether an entity is in scope, what the legal text requires, and how the actual information system supports implementation. A self-assessment does not replace any of these analyses.

01

Governance is a requirement in its own right

Article 20 provides that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken to comply with Article 21 and oversee their implementation. It also addresses training for management-body members. For CIO and CISO teams, a credible NIS2 programme therefore needs to translate into decisions, responsibilities, trade-offs and evidence that management can understand.

02

Measures must be proportionate to actual risk

Article 21 requires appropriate and proportionate technical, operational and organisational measures to manage risks to network and information systems and minimise incident impact. That makes context essential: delivered services, supporting systems, important assets, dependencies, third parties, disruption scenarios and existing safeguards. Useful mapping helps connect these elements; it is not, by itself, evidence of compliance.

03

In France, ReCyF helps structure readiness work

In March 2026, ANSSI published version 2.5 of the Référentiel Cyber France as part of its NIS2 support programme. ANSSI explicitly presents it as a working document. Cybercoria therefore uses it as a readiness and objective-mapping reference, not as final binding legislation. Keeping that distinction prevents a support framework from being misrepresented as a legal requirement.

RECOMMENDED PATH

Understand → assess → go deeper

FRAMING REFERENCES

3 official sources

  1. 2022-12-14
    EUR-Lex — Directive (EU) 2022/2555, NIS2 ↗

    Consolidated directive, notably Article 20 on governance and Article 21 on cybersecurity risk-management measures.

  2. 2026-03-18
    ANSSI — NIS2 support programme and ReCyF ↗

    ANSSI presents the Référentiel Cyber France as a working document intended to support organisations in the NIS2 security programme.

  3. 2026-03-17
    ANSSI — Référentiel Cyber France (ReCyF) v2.5 ↗

    Version 2.5 dated 17 March 2026. The document is explicitly labelled as a working document.

These references support verification of the topic framing. Editorial conclusions remain Cybercoria’s and do not constitute legal advice or compliance certification.