NIS 2: Is My Company In Scope, and What Exactly Is Required?0%
    Back to blog
    Security·31 Juil 2026

    NIS 2: Is My Company In Scope, and What Exactly Is Required?

    By Helion Cloud Team

    The NIS 2 directive sharply widens the number of regulated companies. How to tell whether you are in scope and where to start.

    Share

    NIS 2 usually reaches the boardroom sideways: a client asking where your cybersecurity stands, a more demanding insurer, a tender with new clauses. The first question to settle is not technical but legal: are you in scope?

    01

    What the directive changes compared with NIS 1

    NIS 2 considerably widens the number of regulated entities and introduces a proportionality mechanism. It distinguishes two categories by criticality: essential entities and important entities. Obligations and supervision differ between the two, but both are regulated.
    02

    How to tell whether you are in scope

    Two criteria combine. First the sector: the directive lists highly critical and critical sectors in its annexes. Then size: the entity must at least reach the medium-sized enterprise threshold under the European definition, or exceed the stated ceilings. Essential entities generally operate in highly critical sectors with more than 250 full-time-equivalent employees.
    03

    Registering with ANSSI

    Once an entity has assessed that it falls within scope, it must register with ANSSI, the French national cybersecurity agency. Registration happens online on the MonEspaceNIS2 platform. It is a declarative process: the company performs the analysis, the administration does not come looking for it.
    04

    The reference framework

    Since 17 March 2026, ANSSI has published the French Cyber Framework (ReCyF), listing the measures it recommends to meet the security objectives set by NIS 2. That is the document to compare against your current situation, rather than starting from a generic checklist found online.
    05

    What it means in practice for an SME or mid-cap

    In practice the work items are usually the same: knowing who has access to what and being able to evidence it, having strong authentication, being able to detect and log an incident, holding backups that are tested and not merely configured, and being able to report an incident within the deadline. On a Microsoft environment, much of this already exists in the licences in place and is simply not switched on.
    06

    Where to start

    Start with the scope analysis, written and dated, even if the conclusion is that you are not concerned: that document is what protects you when the question comes back. If you are in scope, then measure the gap between the framework and what exists. The gap gives you the work plan, not a catalogue of tools.

    Summary

    NIS 2 is first a matter of scope and evidence, not tooling. Helion Cloud can run the eligibility analysis, measure the gap against your current Microsoft tools and switch on what is already dormant in your licences.

    Need support

    Our team of experts based in Lille supports companies across France, Belgium and Europe. Available Monday to Friday.