Assessment · NIS2 compliance
Am I in scope for NIS2?
The European NIS2 directive significantly broadens the range of companies subject to cybersecurity obligations, and many executives discover only late that it applies to them. It no longer targets only large critical operators: many small and mid-sized businesses are now in scope, either directly because they operate in a regulated sector, or indirectly as a link in a critical supply chain.
This self-assessment helps you place your organisation. In five questions about your type of establishment, your sector, your headcount and your financials, it indicates whether you likely fall into the "essential entity" or "important entity" category, or appear to be out of scope. The reasoning follows the French transposition currently under way, and it is returned to you point by point.
One methodological note, because it matters: this result is provided strictly for guidance. It is neither legal advice nor a decision by the competent authority, and it does not replace the analysis of a qualified adviser. It gives you a reliable starting point to open the right internal conversation, not a binding verdict.
Your assessment in five questions
Select the answer that best matches your situation. Nothing is stored until you request the detailed report.
Cet outil d'auto-diagnostic est fourni à titre purement indicatif et ne constitue ni un avis juridique, ni une décision de l'autorité compétente. La qualification définitive d'une entité au titre de NIS2 relève de la réglementation applicable et, le cas échéant, de l'ANSSI. La transposition française de la directive (UE) 2022/2555 est en cours et continue d'évoluer : ce contenu, arrêté à la date de référence indiquée, doit être confirmé auprès d'une source officielle ou d'un conseil juridique avant toute conclusion.