NIS2 Directive compliance
Is your organization within the expanded scope of NIS2? Whether you are an essential or important entity, we support you from qualification of your applicability through to compliance.
Why become NIS2 compliant?
The European Directive NIS2 (UE 2022/2555), transposed into French law, massively expands the scope compared with NIS1: the ANSSI estimates that around 15,000 entities are concerned in France, compared with around 500 operators of essential services under NIS1. It now covers around 18 sectors (energy, healthcare, transport, water, digital infrastructure, public administration, agri-food, etc.) and distinguishes essential entities from important entities.
The obligations are concrete: measures for cyber risk management, securing the supply chain, incident notification (early warning within 24h, notification within 72h), executive accountability and training. Penalties can reach €10M or 2% of global turnover. Compliance is no longer optional.
A regulatory obligation
NIS2 is a European directive transposed into French law. Applicability brings binding obligations that can be audited.
Heavy penalties
Up to €10M or 2% of global turnover, not including the personal liability of executives.
The supply chain
NIS2 requires you to secure your suppliers and subcontractors. Even if you are not directly subject to it, you may be required to comply by your clients.
Incident management
Early warning within 24h, notification within 72h: you need a genuinely operational detection and incident response capability.
Sustainable governance
Structure sustainable cyber governance over time, rather than superficial compliance.
Competitive advantage
Stand out to clients that are increasingly demanding about the security of their service providers.
Who is concerned?
Companies and public bodies within the scope of one of the covered sectors, classified as essential entities (the largest and most critical) or important entities, as well as their subcontractors and suppliers involved in securing the supply chain. The first challenge is often to determine whether you are subject to the requirements and at what level: this is precisely the starting point of our support.
Our methodology
We begin by precisely qualifying your applicability before starting any workstream, so that we only address what actually applies to you. Our approach is resolutely pragmatic and tailored: governance, risk management, incident management and business continuity, calibrated to your requirement level (essential or important entity). No unnecessary theory: a framework ready for an ANSSI audit.
The steps toward NIS2 compliance
Applicability qualification
Determination of your status (essential or important entity) and the scope concerned according to your sector and size.
NIS2 gap analysis
Gap analysis between your current framework and the applicable obligations: governance, risks, incidents, supply chain.
Action plan
Development of a prioritized and realistic action plan, aligned with your operational constraints and timeline.
Compliance implementation
Implementation: governance and executive involvement, cyber risk management, incident management, business continuity.
Preparation for ANSSI audits
Evidence collection, documentation formalization, and team preparation for audits by the competent authority.
Long-term maintenance
Compliance monitoring and updates to the framework as incidents occur and regulations evolve.
Verified expertise, not just claimed
BCIT is a partner PECB & EXIN, whose certifications (including ISO 27001 Lead Auditor/Implementer) require an exam and long-term maintenance of skills. Our consultants are not discovering your framework alongside you.
Why choose BCIT for support?
Regulatory & technical expertise
We master both the NIS2 framework and its operational implementation in the field. An expert, not a generalist.
Proportionate approach
We calibrate the requirements to your actual status (essential or important) to avoid both over-commitment and non-compliance.
From diagnosis to audit
End-to-end support, from applicability qualification to ANSSI audit preparation and ongoing maintenance.
Estimate the price of your certification
Interactive calculator: company size, sector, additional compliance requirements... get a price range in just a few clicks.
Price estimate
If certification is not obtained because of our actions, we will refund the full amount paid.
Ready to bring your organization into NIS2 compliance?
Let's take 15 minutes for an initial discussion. We will qualify your applicability, your challenges and your context, and propose tailored, realistic support.
NIS2 Directive compliance
Is your organization within the expanded scope of NIS2? Whether you are an essential or important entity, we support you from qualification of your applicability through to compliance.
Why become NIS2 compliant?
The European Directive NIS2 (UE 2022/2555), transposed into French law, massively expands the scope compared with NIS1: the ANSSI estimates that around 15,000 entities are concerned in France, compared with around 500 operators of essential services under NIS1. It now covers around 18 sectors (energy, healthcare, transport, water, digital infrastructure, public administration, agri-food, etc.) and distinguishes essential entities from important entities.
The obligations are concrete: measures for cyber risk management, securing the supply chain, incident notification (early warning within 24h, notification within 72h), executive accountability and training. Penalties can reach €10M or 2% of global turnover. Compliance is no longer optional.
A regulatory obligation
NIS2 is a European directive transposed into French law. Applicability brings binding obligations that can be audited.
Heavy penalties
Up to €10M or 2% of global turnover, not including the personal liability of executives.
The supply chain
NIS2 requires you to secure your suppliers and subcontractors. Even if you are not directly subject to it, you may be required to comply by your clients.
Incident management
Early warning within 24h, notification within 72h: you need a genuinely operational detection and incident response capability.
Sustainable governance
Structure sustainable cyber governance over time, rather than superficial compliance.
Competitive advantage
Stand out to clients that are increasingly demanding about the security of their service providers.
Who is concerned?
Companies and public bodies within the scope of one of the covered sectors, classified as essential entities (the largest and most critical) or important entities, as well as their subcontractors and suppliers involved in securing the supply chain. The first challenge is often to determine whether you are subject to the requirements and at what level: this is precisely the starting point of our support.
Our methodology
We begin by precisely qualifying your applicability before starting any workstream, so that we only address what actually applies to you. Our approach is resolutely pragmatic and tailored: governance, risk management, incident management and business continuity, calibrated to your requirement level (essential or important entity). No unnecessary theory: a framework ready for an ANSSI audit.
The steps toward NIS2 compliance
Applicability qualification
Determination of your status (essential or important entity) and the scope concerned according to your sector and size.
NIS2 gap analysis
Gap analysis between your current framework and the applicable obligations: governance, risks, incidents, supply chain.
Action plan
Development of a prioritized and realistic action plan, aligned with your operational constraints and timeline.
Compliance implementation
Implementation: governance and executive involvement, cyber risk management, incident management, business continuity.
Preparation for ANSSI audits
Evidence collection, documentation formalization, and team preparation for audits by the competent authority.
Long-term maintenance
Compliance monitoring and updates to the framework as incidents occur and regulations evolve.
Verified expertise, not just claimed
BCIT is a partner PECB & EXIN, whose certifications (including ISO 27001 Lead Auditor/Implementer) require an exam and long-term maintenance of skills. Our consultants are not discovering your framework alongside you.
Why choose BCIT for support?
Regulatory & technical expertise
We master both the NIS2 framework and its operational implementation in the field. An expert, not a generalist.
Proportionate approach
We calibrate the requirements to your actual status (essential or important) to avoid both over-commitment and non-compliance.
From diagnosis to audit
End-to-end support, from applicability qualification to ANSSI audit preparation and ongoing maintenance.
Estimate the price of your certification
Interactive calculator: company size, sector, additional compliance requirements... get a price range in just a few clicks.
Price estimate
If certification is not obtained because of our actions, we will refund the full amount paid.
Ready to bring your organization into NIS2 compliance?
Let's take 15 minutes for an initial discussion. We will qualify your applicability, your challenges and your context, and propose tailored, realistic support.