🚨 Transposition of NIS2 into French law : Requirements applicable to major and critical industrial entities starting in 2026 Does this apply to you?

NIS2 Directive · EU 2022/2555 · Industry & OT

NIS2 & Industry: Your OT Remote Access must be secured prior to compliance

The NIS2 Directive imposes specific requirements on industrial control systems (ICS/SCADA), remote access, and cybersecurity risk management for thousands of French industrial companies.

5 000+
French companies affected by NIS2
10M€ or 2% of revenue
Maximum fine for an Essential Entity
24h
To report an incident to ANSSI (early warning)
2026
Deadline for France's transposition of NIS2
Scope of NIS2

Is your industrial company subject to NIS2?

EU Directive 2022/2555 distinguishes between two categories of entities, each with different obligations and penalties. Determine which category applies to you.

ESSENTIAL ENTITY (EE)
Sectors Affected
Energy (electricity, natural gas, oil, hydrogen)
Transportation (air, rail, maritime, road)
Drinking Water and Wastewater
Healthcare (hospitals, laboratories)
Digital Infrastructure and ICT Services
Size Criteria
More than 250 employees OU Annual revenue > 50 M€
Maximum fine
10 M€ or 2% of global revenue
SIGNIFICANT ENTITY (SE)
Sectors Affected
Manufacturing industry (machinery, electronics, automotive)
Chemistry and Chemicals
Agri-Food and Food
Postal and Courier Services
Waste Management
Size Criteria
More than 50 employees OU Annual revenue > 10 M€
Maximum fine
7 million euros, or 1.4% of global revenue
SPECIAL CASES
Affected entities, regardless of their size
Critical EE/EI Suppliers (Supply Chain)
Contractors with access to industrial systems
Essential Service Operators (formerly OIV/OSE NIS1)
Manufacturers of critical products for EE/EI
Managed Security Service Providers (MSSPs)
Point of Attention
Even very small businesses and small and medium-sized enterprises (SMEs) that are energy suppliers or energy infrastructure operators may be subject to NIS2 under the supply chain provision of Article 21, paragraph 2(d).
Not sure about your NIS2 scope?
ANSSI will publish the official list of entities subject to NIS2 in France. In the meantime, our team can help you assess your situation and identify your specific obligations.
Describe my situation
Article 21 — EU Directive 2022/2555

What NIS2 Specifically Requires for Your Industrial Remote Access

Article 21 of the NIS2 Directive lists minimum technical and organizational measures. Here’s what they mean in practice for your OT and ICS/SCADA systems.

Art. 21, §2(a)

Multifactor Authentication (MFA)

NIS2 requires multi-factor authentication or continuous authentication for all remote access to OT industrial systems. A simple username/password combination is no longer sufficient to access your PLCs, SCADA systems, or ICS networks.

MFA RequiredOT/ICS AccessZero Trust
Art. 21, §2(j)

Session Logging and Traceability

Every remote access to your industrial network must be logged: who logged in, when, from which IP address, and what actions were taken. This traceability is required for ANSSI audits and serves as proof of your compliance.

Audit trailSecure logsSIEM-ready
Art. 21, §2(h)

IT/OT Network Segmentation

The directive requires effective separation of IT networks and OT networks. This segmentation prevents a cyberattack from spreading laterally from the office IT system to your critical production equipment.

Industrial DMZOT IsolationApplication firewall
Art. 21, §2(e)

Vulnerability Management and Patch Management

NIS2 requires a documented process for identifying, assessing, and addressing vulnerabilities. For industrial systems, this involves monitoring CVEs on your OT equipment and implementing an update strategy that takes into account production continuity constraints.

CVE TrackingOT PatchCVSS scoring
Art. 23

Incident Response Plan — 24-Hour Deadline (ANSSI)

In the event of a significant cyber incident, NIS2 requires notification to ANSSI within 24 hours (early warning) followed by a full report within 72 hours (Article 23). Your incident response plan must incorporate these deadlines and designate the responsible parties.

ANSSI 24hCSIRTContingency Plan
Art. 21, §2(d)

Supplier Risk Assessment (Supply Chain)

Supply chain security is at the heart of NIS2. You are responsible for the cyber risks introduced by your service providers, system integrators, and industrial equipment suppliers who have access to your OT network.

Due DiligenceContractual ProvisionsTPVM
Personal Liability of Directors (Art. 20 NIS2)
Unlike NIS1, the NIS2 Directive explicitly holds management (CISO, CIO, CEO, Managing Director) personally liable. In the event of a serious breach, a temporary ban on holding management positions may be imposed, in addition to administrative fines against the company.
NIS2 Compliance by Design

How the Eziwan Platform Meets NIS2 Requirements

Each Eziwan feature has been designed to directly address the provisions of the NIS2 Directive. Here is the complete mapping.

NIS2 RequirementArticleEziwan FeatureStatut
Multifactor AuthenticationArt. 21, §2(a)MFA (TOTP/FIDO2) for all OT remote access, enterprise LDAP/SSO integrationIncluded
Session LoggingArt. 21, §2(j)Comprehensive audit trail: logins, duration, actions, SIEM export (Syslog, REST API)Included
IT/OT SegmentationArt. 21, §2(h)OpenVPN outbound tunnel architecture, industrial router in the DMZ, VLAN isolationIncluded
Traceability and AuditabilityArt. 21, §2(j)Compliance dashboard, audit reports exportable as PDFs, configurable retentionIncluded
Communication EncryptionArt. 21, §2(h)End-to-end TLS 1.3 encryption, X.509 certificates, Perfect Forward SecrecyIncluded
Secure VPN TunnelArt. 21, §2(h)Outbound OpenVPN VPN tunnel (no incoming ports open), Zero Trust architectureIncluded
Alerts and Incident NotificationsArt. 23Real-time alerts, webhooks, SIEM/SOC integration, ANSSI-formatted incident reportsIncluded
Data SovereigntyArt. 21, §2(h)Hosting 100% in France (OVHcloud SecNumCloud); data does not leave the EUIncluded
Proven methodology

Your 4-Step NIS2 Compliance Plan for Remote Access

A structured 3- to 6-month process, from taking inventory of your OT equipment to preparing your ANSSI compliance report.

01
2 to 4 weeks

Cartographie

Comprehensive inventory of all your OT equipment (PLCs, SCADA systems, IIoT sensors, HMIs) and existing remote access points. Identification of IT/OT network traffic and third parties with access to your industrial network.

Inventory of OT and ICS Equipment
Mapping Existing Remote Access Points
Identification of Third Parties and Service Providers
Analysis of IT/OT Network Traffic
02
2 to 3 weeks

Risk Analysis (Gap Analysis)

Assessment of the gaps between your current situation and the NIS2 requirements for your OT remote access. Prioritization of actions based on risk level and business impact. Deliverable: a documented NIS2 gap analysis report.

Assessment vs. Requirements, Art. 21 NIS2
Risk Scoring by Critical Asset
Prioritizing Corrective Actions
Budget Estimate for Compliance
03
4 to 8 weeks

Technical Deployment

Deployment of Eziwan routers at industrial sites, configuration of IT/OT segmentation, activation of MFA for all remote access, and implementation of centralized logging and audit trails.

Installation of Industrial VPN Routers
IT/OT Segmentation and Industrial DMZ
Enabling MFA for all OT access points
Logging and Alerts Configuration
04
2 to 4 weeks

Documentation and Testing

Drafting security procedures, incident response plans, and access policies that comply with NIS2. Conducting business continuity tests, simulating incident responses, and preparing the compliance dossier for the ANSSI audit.

Drafting of OT Security Policies
Incident Response Plan (Art. 23)
Continuity and Recovery Tests
Complete NIS2 Compliance Dossier
Ready to start your NIS2 journey?
Our experts will guide you from the initial assessment through the preparation of your compliance documentation. Your first compliance audit is free.
Start My NIS2 Audit
Frequently Asked Questions

NIS2 & Industry FAQ

Everything you need to know about the NIS2 Directive and its implications for your OT systems.

Deadline: 2026 — Don't wait

Don't let NIS2 become a risk to your business

The NIS2 Directive is not just an administrative burden. It reflects the reality of cyber threats to industrial systems: in 2024, more than 40% of cyberattacks targeted industrial infrastructure and attacks on OT networks have increased by 87% over the past two years.

Your window of opportunity to achieve compliance before the 2026 deadline is narrowing. Every month of delay increases your risk of a fine and, more importantly, the risk of a cyber incident affecting your production equipment.

Fine of up to 10M€ or 2% of revenue
for Essential Entities (Art. 34)
Personal Liability of Executives
disbarment (Art. 32, §5)
Incident Reporting to ANSSI Within 24 Hours
or face additional penalties
ANSSI Audit Upon Request
Review of Your OT Security Measures
Hosting in France (OVHcloud)
OT/ICS Expertise Since 2018
ANSSI-Compliant Support
Deployment in 48 hours

This page is provided for informational purposes only and does not constitute legal advice. For a detailed analysis of your situation with regard to the NIS2 Directive (EU 2022/2555) and its transposition into French law, consult an attorney specializing in digital law or an ANSSI-certified consultant.