SMB CybersecuritySeptember 29, 202617 minBy Kevin Lefebvre

NIS2 and ReCyF: is your SME in France affected?

The short answer. NIS2 generally covers medium-sized and larger entities in specified sectors; some smaller organisations are also covered by exceptions. For an SME in France, check its activities, staff and financial thresholds, and group relationships using ANSSI's scope simulator. ReCyF helps structure cybersecurity preparation. It does not certify compliance.

How to use this guide. Scope and threshold checks prepare your assessment. Worked cases explain the reasoning. Responsibility, evidence and incident worksheets help organise work with management and service providers. This guide addresses the French context: ANSSI is France's national cybersecurity agency and ReCyF is a French framework. Their procedures are not a universal implementation of NIS2 across EU countries. Some linked official resources are in French.

Contents

A business connected to an access key and a backup vault: organise responsibilities, access and recovery.
Named owners, controlled access and tested recovery.

Does your SME fall within scope?

Do not stop at headcount. Assess the actual activity, financial figures, relationships with other businesses and special cases as well.

Your situationFirst check
Activity in a covered sectorExamine size thresholds and linked enterprises
Small organisation providing DNS or trust servicesExamine exceptions that apply irrespective of size
Questionnaire received from a customerSeparate the customer's contractual requirements from your entity's own regulatory status
  1. Describe the activity. Identify the services actually supplied and the relevant sector.
  2. Examine size. Check staff numbers, financial data and relationships with other enterprises.
  3. Confirm the position. Use ANSSI's guidance, then resolve exceptions and ambiguities.

The official NIS2 simulator provides initial guidance for France. Prepare the activity description, staff numbers, turnover, balance sheet total and group structure. Record the date and assumptions used.

ANSSI explains the scope criteria and the thresholds and exceptions. Its guidance includes managed IT service providers within ICT service management. A small subsidiary cannot necessarily be assessed using its own accounts alone.

If the position is unclear, obtain a scope assessment. A simulator result does not replace a legal assessment of your circumstances and applicable legislation.

A customer sends you a NIS2 questionnaire

This may reflect the customer's security requirements for suppliers. The request alone does not establish that your business is directly regulated.

Check the contract, service concerned, data processed and commitments requested. Respond with verifiable information. Avoid asserting overall "NIS2 compliance" simply because you have antivirus software or have completed a questionnaire.

Understand thresholds beyond 50 employees

The European recommendation defines a small enterprise using this logic: staff < 50 AND (annual turnover ≤ EUR 10 million OR annual balance sheet total ≤ EUR 10 million). The financial "or" matters: exceeding the turnover threshold alone does not exclude the small-enterprise category. Calculations must account for partner or linked enterprises and reference-period rules; staff numbers use annual work units. Recommendation 2003/361/EC, Annex, Articles 2 to 6.

Fictional exercises, assuming autonomous enterprises and stable figures:

FiguresConclusion limited to size
35 staff, EUR 12m turnover, EUR 8m balance sheetSmall-enterprise status remains possible: the balance sheet criterion is within the ceiling
35 staff, EUR 12m turnover, EUR 11m balance sheetBoth financial ceilings are exceeded: small-enterprise status is excluded under these assumptions
50 staff, EUR 6m turnover, EUR 4m balance sheetThe "fewer than 50" criterion is no longer met

None of these rows determines NIS2 applicability on its own. Activity, exceptions, jurisdiction and applicable legislation still need review. Have the entity's financial adviser calculate the relevant figures; do not mechanically add every employee in a group without assessing the relationships involved.

Describe the real service, not just an activity code

Write a verifiable sentence: "The entity supplies [service] to [customer type], from [country], with [operational role]." For an IT provider, distinguish hardware sales, occasional consulting, ongoing systems operation and managed security. Two businesses marketed as "IT companies" may supply different services.

Attach standard contracts, the service description and responsibilities actually assumed. Compare those documents with the official categories. An activity code may guide research; classification must address the activities really performed. ANSSI's scope FAQ.

What is ReCyF for?

ReferencePurpose
NIS2EU directive: scope, responsibilities and risk management
Applicable national legislationDuties and procedures to check for your situation
ReCyFFrench reference framework for preparing cybersecurity measures
Customer contractCommitments agreed with that customer

ANSSI page checked on 29 September 2026: its NIS2 page still presents ReCyF as a working document, non-mandatory by default. The version consulted is version 2.5, dated 17 March 2026.

Use it to organise the work. It is neither a certification nor a blanket declaration of compliance. Check official publications when making a regulatory decision. The European framework is set out in Directive 2022/2555.

Choose the right framework and check its status

ReCyF distinguishes the security objective to achieve from the proposed acceptable means of achieving it. Working version 2.5 lists twenty objectives, with objectives 16 to 20 specifically addressing essential entities. This does not mean every SME should tick twenty identical boxes. ReCyF introduction and contents.

ENISA also provides technical guidance, organised around recommendations, evidence examples and mappings. It supports Implementing Regulation 2024/2690 for certain digital categories, including cloud, data centres and managed services. It is not automatically the regulatory checklist for every French SME. Its educational value includes showing how to document implementation of a requirement.

For a decision, record the legislation, version, entity category, applicable provisions and verification date. On 29 September 2026, the ANSSI page consulted still describes ReCyF as a working document. The Senate legislative file consulted carries an update date of 17 March 2026: that gap means published legislation must be checked before drawing conclusions about the current national timetable. Official legislative tracking. This article does not establish a general commencement date for all businesses. Organisations operating outside France must check the relevant national authorities and rules.

What should you prepare?

The following table is an operational starting point. It does not cover every possible requirement.

ActionUseful evidence to keep
Assign ownersWho decides, who acts and who provides cover
Inventory critical servicesApplications, dependencies and owners
Protect sensitive accessMFA enabled, permissions reviewed, leavers processed
Test backupsRestore report and measured duration
Prepare for an incidentContacts available outside the affected IT system, procedure and exercise
Manage service providersWritten access rights, responsibilities and commitments
Apply a security control, test it, then record the scope, date, result and limits.
Useful evidence describes a real, dated control.
Read the diagram as text

Apply a control within a defined scope. Test its real behaviour, for example by restoring a backup and checking the service. Record the date, result, limits, next action and owner.

Start with a service whose loss would disrupt the business. Identify who can access it, where its data resides, who can restore it and how long that restore actually takes.

Prioritise multi-factor authentication, or MFA, for sensitive access. Our SME MFA guide helps identify where to start. For recovery, use the business backup guide.

For each gap, specify an action, an owner and a date. Have management decide priorities. Cybersecurity also requires decisions about business activities and available resources.

Three cases to practise the reasoning

These situations are fictional. The exercise is to choose the next verification, without issuing a legal verdict from a few lines.

SituationExpected reasoningNext document to obtain
An 18-person workshop receives a major customer's security questionnaireThe request does not establish direct regulatory scope. Examine activity, size, relationships and contract separatelyDescription of services supplied and the relevant contractual clause
A 12-person company provides DNS services to customersSmall staff numbers do not rule out exceptions for certain servicesPrecise description of the DNS service, followed by assessment against official sources
A 30-person subsidiary belongs to a groupIts own staff numbers are insufficient to concludeOwnership structure, accounts and data needed to assess linked or partner enterprises

Your turn. A director says: "We have fewer than 50 employees and our provider installed a firewall, so we are outside scope." What is wrong with that reasoning?

Worked answer. The activity, financial criteria, relationships with other enterprises and possible exceptions are missing. A firewall is a technical control; it does not determine legal scope. The correct conclusion is "status requires assessment", accompanied by the missing information. ANSSI guidance on thresholds and exceptions.

Turn a claim into useful evidence

"We have backups" says neither what is covered nor whether the business can recover. Useful evidence specifies scope, date, test, result and limits.

Fictional completed control record:

FieldCompleted example
ServiceQuotation management: application and database
Internal objectiveRecover in less than 4 hours; lose no more than 24 hours of data
TestOn 25 September, restore the 24 September, 22:00 backup in an isolated environment
ResultTechnical restore in 1 h 20; opening and editing a test quotation validated after another 20 minutes
LimitEmail sending not tested; a whole-site outage not simulated
Gap and next actionTest the mail relay; assigned operator; due by 2 October
Evidence retainedRestore report, backup reference and business owner's acceptance

The test gives 1 h 40 for the scope tested. It does not yet demonstrate complete service recovery within 4 hours. To verify the maximum 24-hour data loss, compare the recoverable point with the simulated incident time and check data consistency. The age of the latest backup file alone is insufficient.

Exercise. A table says "MFA enabled: yes". It covers nine out of ten administrator accounts; the tenth uses a legacy application. Can the action be marked complete?

Worked answer. Not for an objective covering all ten accounts. Write "9/10 covered; one account under exception" and record the risk, compensating restrictions, owner and review date. A compensating measure must be assessed; it does not automatically make the exception equivalent to MFA. Keep detailed exports in a space restricted to authorised people.

Who decides, implements and verifies?

Article 20 of NIS2 provides for management bodies to approve and oversee measures and receive training. Outsourcing operations does not replace that role. Directive 2022/2555.

Example allocation to adapt:

Decision or taskSuggested ownerExpected record
Define indispensable servicesManagement with business teamsApproved list and consequences of interruption
Decide risk, budget and deadlinesManagementWritten decision, including temporarily accepted risks
Configure and maintain controlsIT team or appointed providerWork record, configuration and current procedure
Accept a restored serviceBusiness ownerWorkflows tested and results accepted
Review exceptionsSecurity contact with the decision-makerException, owner, deadline and reassessment

A small team may combine roles. It must still know who decides how to address a gap and who checks the result. "The provider handles it" identifies neither the scope nor the decision-maker.

Turn priorities into a working file

The following Initial Infra proposal helps prepare the discussion. It complements the first six actions and does not claim to cover all of ReCyF.

Practical questionUseful documentWeakness to identify
Which systems deliver the service?Simple map: application, data, identity, network and hostingA dependency known to only one person
Who can administer it?Dated privileged-account inventory and exceptionsShared account without a named owner
How are vulnerabilities addressed?Update register, internal deadlines and exceptionsPatch claimed as installed without a version check
Which data needs protection?Data categories, authorised access and planned protectionEncryption claimed without key management
What can be detected?Alerts, recipients and latest testLogs collected but never reviewed
What happens without the usual tools?Contacts and instructions accessible outside the affected systemPlan stored only on the unavailable server
How are providers monitored?Service record, contacts and verifiable commitmentsUnrecorded subcontractor or remote access
How do exercises lead to learning?Exercise report, observed mistakes and assigned correctionsExercise completed with no follow-up

For each row, distinguish planned, implemented, tested and open gap. A signed policy may prove a decision; it does not prove that a control works. Conversely, a technical screenshot without scope or date is difficult to use as evidence.

Five useful questions for a critical provider

Identify the supplied service and authorised access; specify how to reach the provider during an incident, what it reports to you, what evidence it can supply and how data and access will be recovered at contract end. ENISA discusses supplier selection, contracting and monitoring in Chapter 5 on supply-chain security. Adapt commitments to your service and applicable regime.

Prepare to report a significant incident

Article 23 of the directive provides for an early warning without undue delay and within 24 hours, followed by an incident notification within 72 hours of becoming aware of a significant incident. The final report is normally due within one month after that notification. Special rules address trust services and incidents still ongoing. Article 23.

These ceilings are not waiting periods. Before an incident, confirm the criteria, recipient, reporting channel and rules applicable to your entity. Do not confuse this process with possible GDPR or contractual notifications.

To practise without submitting a notification, simulate an outage accompanied by suspicious administrator access. Record discovery time, established facts, uncertainties, affected services, classification decision, owner and next update. Check that the decision-maker and contact details remain accessible when the main email system is unavailable.

Organise a first month of work

This schedule is an internal planning proposal, not a legal deadline or a promise of compliance. It helps obtain decisions and some verifiable evidence.

PeriodWorkDecision support
Week 1Describe the entity, activities and relationships; assess uncertaintiesDated scope worksheet, sources and open questions
Week 2Select a critical service; identify owners, access and providersService map and priority gaps
Week 3Test a restore and check sensitive accessTest reports with scope, exceptions and follow-up
Week 4Exercise an incident scenario and decide correctionsDecisions, owners, deadlines and next review

Adapt the order to known risks. An urgent exposure cannot wait for the week listed in a table. For a real incident, check applicable reporting duties; this schedule does not replace them.

Answer a customer questionnaire precisely

Adapt this template only using verified facts:

For [service], we checked [control] on [date]. The check covers [scope] and shows [result]. The following limitation remains open: [gap]. [Owner] is tracking [corrective action] for [date]. Supporting evidence can be shared through an agreed channel after a confidentiality check. This response addresses the controls described; it is not an overall declaration of NIS2 compliance.

Ask the customer which service, clause and evidence it wants to assess. Do not send passwords, a detailed infrastructure map or logs containing personal data to answer a simple commercial question.

Your starting worksheet

Entity / exact activity / country / assessment date:
Staff / turnover excluding VAT / balance sheet / reference year:
Linked or partner enterprises / supporting documents:
Sector examined / exception examined / official source:
Initial guidance / assumptions / points requiring assessment:
Person confirming the assessment / deadline:
Critical service / owner / dependencies:
Control / objective / scope / test date:
Observed result / evidence / limitation or exception:
Next action / owner / deadline / acceptance:

The practical workbook: worked cases and worksheets lets a team repeat the exercises and record a first control. The worksheets organise preparation; they do not cover every applicable requirement.

Download the editable text worksheet.

Frequently asked questions

Does fewer than 50 employees mean outside scope?

Not necessarily. Size rules, relationships with other enterprises and exceptions must be examined together.

Can a provider handle everything?

A provider can support the work. Agree in writing who decides, operates, retains evidence and responds to an incident. Management responsibilities still need to be assessed under the applicable framework.

What first deliverable should you request?

A dated assessment: unresolved scope questions, critical services, existing controls and priority actions. The Initial Infra infrastructure diagnostic can help document the technical part.

English educational edition prepared on 29 September 2026 from the expanded French guide of 27 September. ANSSI, ReCyF and ENISA sources checked again on 29 September. Cases and test results are fictional. The controls illustrate a working method, not an exhaustive compliance checklist. Check applicable legislation at the time of your decision; the workbook supports a first scope and evidence workshop in the French regulatory context.

View sources (9)

Support available on this topic

Initial Infra handles these topics for SMBs and mid-size companies. A short call is enough to identify priorities and the right scope of intervention.