Skip to main content
own2pwn

NIS2 preparation, ReCyF framework

GRC

Prepare for NIS2 with the ReCyF framework, one information system at a time.

GRC is the preparation tool for NIS2 built on ReCyF, the framework the French cybersecurity agency (ANSSI) published as a working document on 17 March 2026: 20 security objectives broken down into 152 acceptable means of compliance. You describe your in-scope entities and their information systems, you answer means by means, and the tool produces what an inspector asks to read: a per-system analysis, a dated action plan with a named owner, and a register of time-stamped evidence. This is neither a certification, nor an attestation, nor a guarantee: the French transposition of NIS2 is not enacted and ReCyF itself is still a working document. It is the file you will have to present, kept up to date, rather than a spreadsheet rebuilt under pressure.

Subscription with no minimum term, cancel at any time. No free plan: the entry plan is 149 € per month.
The ReCyF security objectives, in their official wording
20 objectives
Acceptable means of compliance, each tied to its objective
152 means
One analysis and one action plan per information system
Per system

What this tool is, and what it is not

ReCyF is an ANSSI working document dated 17 March 2026, and the French transposition of the NIS2 directive is not enacted. GRC helps you prepare your file against that framework: it issues no certification, no attestation and no compliance guarantee, and it shows no score. Compliance is established at inspection time, by the competent authority.

What the platform does

The framework, the action plan and the evidence, in one place.

The ReCyF framework, as published

The 20 security objectives and 152 acceptable means of compliance of the ANSSI working document dated 17 March 2026, in their original wording, linked to one another. You work on the framework text, not on an in-house paraphrase nobody could map back to a version. The framework version in use is shown on every analysis.

Per information system analysis

The same means is not implemented the same way on a mail system and on a production line. Analysis therefore happens per information system, each with its own scope, owners and progress. One in-scope entity can carry several, and each keeps its own file.

A dated action plan, the one an inspector reads

Every means that is not covered produces an action: what is to be done, who owns it, by when, and where the work stands. That is the ReCyF 2.C artefact, the first thing an inspector opens. PDF and CSV export, with no reformatting on your side.

Register of time-stamped evidence

A signed policy, a configuration screenshot, an exercise report: each item is filed under the means it documents, time-stamped on upload, and stays attached to the current version of the action plan. No more hunting last year's evidence through chat threads.

Verifiable archive, readable without us

From the Pro plan on, you export the whole file and its evidence as an offline archive, along with the digests that let anyone check nothing moved since the export. It reads back with no account and no connection: your file does not depend on our service being up, nor on your subscription continuing.

Drafting suggestions you approve

Describing how a means is implemented is the most tedious part of the file. From the Pro plan on, the tool proposes wording based on what you already filled in; it arrives as a draft and only enters the file once you have reviewed and approved it. Nothing is written in your name without your say-so.

How it works

From scope to action plan.

  1. 01

    You describe your entities and systems

    In-scope entity, sector, size, then the information systems inside the perimeter. That breakdown drives how many files you keep, hence which plan you need.

  2. 02

    You answer means by means

    For each acceptable means of compliance: implemented, partially, not yet, or not applicable with its justification. Means you rule out stay visible with their rationale: that is the first thing an inspector challenges.

  3. 03

    You file the evidence

    Each supporting item is attached to the means it documents and time-stamped on upload. The register tracks successive versions of the file.

  4. 04

    You export the action plan

    Whatever is not covered becomes a dated action with an owner. PDF and CSV export, plus the verifiable offline archive from the Pro plan on.

Benefits

What changes when the inspection comes.

01

A file kept up to date, not rebuilt

The cost of an inspection does not come from the measures themselves, it comes from rebuilding the file six months later. By keeping the analysis and the evidence current, you answer with what already exists.

02

The topic becomes assignable

An action plan carries an owner and a due date per action. "Where are we on NIS2" stops being an opinion and becomes a list you can review in a meeting.

03

You keep your file

PDF and CSV export ships with the first plan, the verifiable offline archive from the Pro plan on. Nothing keeps you here other than the tool being useful.

04

Consistent with the technical side

A ReCyF means such as control of exposed assets is demonstrated with technical material. What our EASM or a pentest produces can be filed straight into the evidence register, under the means it documents.

Pricing

Three plans, by number of entities and information systems.

Starter

€149 / mo

  • In plain terms: one in-scope entity and three information systems, to prepare your file without a spreadsheet.
  • The 20 objectives and 152 acceptable means of the French ReCyF framework
  • Per-system analysis, with a dated action plan and a named owner
  • Register of time-stamped evidence, attached to the means it documents
  • Action plan export as PDF and CSV
Subscribe

For businesses only, a company identifier is asked at the next step.

Recommended

Pro

€399 / mo

  • In plain terms: three entities and fifteen information systems, with the archive you hand to an inspector.
  • Verifiable offline archive: the file and its evidence, readable without us
  • API keys to feed the evidence register from your own tools
  • AI drafting suggestions for your means, which you review before approving
  • Action plan version history
Subscribe

For businesses only, a company identifier is asked at the next step.

Business

€899 / mo

  • In plain terms: as many entities and information systems as a group or a local authority actually has.
  • Unlimited entities and information systems
  • Consolidated view and comparison across entities
  • Per-entity roles and scopes
  • Priority support
Subscribe

For businesses only, a company identifier is asked at the next step.

VAT not applicable (art. 293 B of the French tax code)

Questions fréquentes

Your questions about NIS2 preparation.

Does GRC make me compliant with NIS2?

No, and nobody can promise that today. The French transposition of the NIS2 directive is not enacted, ReCyF is published by ANSSI as a working document dated 17 March 2026, and there is no NIS2 certification or attestation a vendor could issue. What the tool does is different and checkable: it walks you through the framework objective by objective and means by means, and produces a per-system analysis, a dated action plan and an evidence register. That is the file you will present and defend yourself. Compliance is established at inspection time, by the competent authority.

Why do you not show a compliance percentage?

Because a percentage would suggest an official measurement that does not exist, and because it misleads on substance: the 152 means carry neither the same weight nor the same applicability depending on your activity, and a means ruled out for good reason should not count like a missing one. So you see, per information system, the means covered, partially covered, not covered, and ruled out with their justification. Less flattering than a single figure, and closer to what an inspector will open.

What is ReCyF, and why start there?

ReCyF is the cybersecurity framework published by ANSSI to help entities that will fall under NIS2 know what to implement: 20 security objectives broken down into 152 acceptable means of compliance. Starting there rather than from an in-house framework has one simple upside: your file speaks the vocabulary of the administration that will inspect you. The version in use is a working document and it will move; the tool shows which version each analysis uses, and your answers are carried across versions.

How is this different from your NIS2 audit?

The NIS2 audit we sell as an engagement is the technical side: we test what is exposed and produce evidence that the measures work. GRC is the documentary tool that keeps the file over time, across the whole framework, including the organisational part we do not practise as an engagement. The two complement each other: pentest or EASM deliverables can be filed into the GRC evidence register, under the means they document.

What exactly is the verifiable archive?

An export of the full file, its action plan and its evidence, together with a cryptographic digest of every item and a signed index. It reads offline, with no account and without our service, and recomputing the digests lets a third party confirm the content has not changed since the export. It is not a qualified timestamp under eIDAS: it proves the integrity of your file, not an enforceable date.

Do the AI suggestions write my file for me?

No. They propose wording based on what you already filled in for that means, and the proposal stays a draft until you have reviewed and approved it. Nothing enters the file without your explicit approval, and what you sign remains your own declaration. The feature ships from the Pro plan on and can be left aside without losing anything else.

Is there a minimum term, and how do I cancel?

No minimum term. The subscription is monthly or annual (annual works out at ten months paid), renewed tacitly at each due date, and you cancel it at any time, with no justification to give: either you do it yourself from your billing area, or you write to contact@own2pwn.fr and the answer comes within 24 hours. No notice period to serve: cancellation takes effect at the end of the current billing period, and you keep access until then. In return, that period is not refunded pro rata. That is not a sales promise, it is article 7 of the terms of sale. Do export your file before the due date: PDF and CSV export is available on every plan.

Do I need a credit card, is there a free plan?

There is no free plan on GRC: the entry plan is Starter, at 149 € per month. A card is therefore only asked for when you subscribe, on own2pwn.fr, by card only, and there is no trial that turns into a charge after fourteen days. If you first want to know whether NIS2 applies to you, the public diagnostic is free and asks for no payment method.

How long between payment and actual access?

Access opens immediately after the payment is validated. As soon as the payment is confirmed, the subscription is attached to your account and the plan quotas apply, with no manual step in between. If you subscribe without an own2pwn account yet, the payment creates one and you get an email to set your password: access is live as soon as that is done. If anything gets stuck, write to contact@own2pwn.fr, the answer comes within 24 hours.

Can I change plan mid-subscription?

Yes, and without starting over: your entities, information systems, answers and evidence stay in place, only the quotas change. You request the change by email to contact@own2pwn.fr, stating the plan you want and the date it should take effect; the answer comes within 24 hours. What is settled on the billing side is that the period already paid for is not refunded pro rata (article 7 of the terms of sale); the exact amount and the effective date of the new plan are confirmed to you in writing before anything is validated.

A scope to size up?

Tell us how many entities and information systems you need to cover: we get back to you within 24 business hours.