NIS2 preparation, ReCyF framework
GRC
Prepare for NIS2 with the ReCyF framework, one information system at a time.
GRC is the preparation tool for NIS2 built on ReCyF, the framework the French cybersecurity agency (ANSSI) published as a working document on 17 March 2026: 20 security objectives broken down into 152 acceptable means of compliance. You describe your in-scope entities and their information systems, you answer means by means, and the tool produces what an inspector asks to read: a per-system analysis, a dated action plan with a named owner, and a register of time-stamped evidence. This is neither a certification, nor an attestation, nor a guarantee: the French transposition of NIS2 is not enacted and ReCyF itself is still a working document. It is the file you will have to present, kept up to date, rather than a spreadsheet rebuilt under pressure.
- The ReCyF security objectives, in their official wording
- 20 objectives
- Acceptable means of compliance, each tied to its objective
- 152 means
- One analysis and one action plan per information system
- Per system
What this tool is, and what it is not
ReCyF is an ANSSI working document dated 17 March 2026, and the French transposition of the NIS2 directive is not enacted. GRC helps you prepare your file against that framework: it issues no certification, no attestation and no compliance guarantee, and it shows no score. Compliance is established at inspection time, by the competent authority.
What the platform does
The framework, the action plan and the evidence, in one place.
The ReCyF framework, as published
The 20 security objectives and 152 acceptable means of compliance of the ANSSI working document dated 17 March 2026, in their original wording, linked to one another. You work on the framework text, not on an in-house paraphrase nobody could map back to a version. The framework version in use is shown on every analysis.
Per information system analysis
The same means is not implemented the same way on a mail system and on a production line. Analysis therefore happens per information system, each with its own scope, owners and progress. One in-scope entity can carry several, and each keeps its own file.
A dated action plan, the one an inspector reads
Every means that is not covered produces an action: what is to be done, who owns it, by when, and where the work stands. That is the ReCyF 2.C artefact, the first thing an inspector opens. PDF and CSV export, with no reformatting on your side.
Register of time-stamped evidence
A signed policy, a configuration screenshot, an exercise report: each item is filed under the means it documents, time-stamped on upload, and stays attached to the current version of the action plan. No more hunting last year's evidence through chat threads.
Verifiable archive, readable without us
From the Pro plan on, you export the whole file and its evidence as an offline archive, along with the digests that let anyone check nothing moved since the export. It reads back with no account and no connection: your file does not depend on our service being up, nor on your subscription continuing.
Drafting suggestions you approve
Describing how a means is implemented is the most tedious part of the file. From the Pro plan on, the tool proposes wording based on what you already filled in; it arrives as a draft and only enters the file once you have reviewed and approved it. Nothing is written in your name without your say-so.
How it works
From scope to action plan.
- 01
You describe your entities and systems
In-scope entity, sector, size, then the information systems inside the perimeter. That breakdown drives how many files you keep, hence which plan you need.
- 02
You answer means by means
For each acceptable means of compliance: implemented, partially, not yet, or not applicable with its justification. Means you rule out stay visible with their rationale: that is the first thing an inspector challenges.
- 03
You file the evidence
Each supporting item is attached to the means it documents and time-stamped on upload. The register tracks successive versions of the file.
- 04
You export the action plan
Whatever is not covered becomes a dated action with an owner. PDF and CSV export, plus the verifiable offline archive from the Pro plan on.
Benefits
What changes when the inspection comes.
A file kept up to date, not rebuilt
The cost of an inspection does not come from the measures themselves, it comes from rebuilding the file six months later. By keeping the analysis and the evidence current, you answer with what already exists.
The topic becomes assignable
An action plan carries an owner and a due date per action. "Where are we on NIS2" stops being an opinion and becomes a list you can review in a meeting.
You keep your file
PDF and CSV export ships with the first plan, the verifiable offline archive from the Pro plan on. Nothing keeps you here other than the tool being useful.
Consistent with the technical side
A ReCyF means such as control of exposed assets is demonstrated with technical material. What our EASM or a pentest produces can be filed straight into the evidence register, under the means it documents.
Pricing
Three plans, by number of entities and information systems.
Starter
€149 / mo
- In plain terms: one in-scope entity and three information systems, to prepare your file without a spreadsheet.
- The 20 objectives and 152 acceptable means of the French ReCyF framework
- Per-system analysis, with a dated action plan and a named owner
- Register of time-stamped evidence, attached to the means it documents
- Action plan export as PDF and CSV
For businesses only, a company identifier is asked at the next step.
Pro
€399 / mo
- In plain terms: three entities and fifteen information systems, with the archive you hand to an inspector.
- Verifiable offline archive: the file and its evidence, readable without us
- API keys to feed the evidence register from your own tools
- AI drafting suggestions for your means, which you review before approving
- Action plan version history
For businesses only, a company identifier is asked at the next step.
Business
€899 / mo
- In plain terms: as many entities and information systems as a group or a local authority actually has.
- Unlimited entities and information systems
- Consolidated view and comparison across entities
- Per-entity roles and scopes
- Priority support
For businesses only, a company identifier is asked at the next step.
VAT not applicable (art. 293 B of the French tax code)
Questions fréquentes
Your questions about NIS2 preparation.
Does GRC make me compliant with NIS2?
Why do you not show a compliance percentage?
What is ReCyF, and why start there?
How is this different from your NIS2 audit?
What exactly is the verifiable archive?
Do the AI suggestions write my file for me?
Is there a minimum term, and how do I cancel?
Do I need a credit card, is there a free plan?
How long between payment and actual access?
Can I change plan mid-subscription?
Going further on NIS2 and ReCyF.
ReCyF: the ANSSI cybersecurity framework
The 20 objectives, the 152 means, and what the working document actually says.
Read →NIS2 for a small business
Who is in scope, above which thresholds, and what it means in practice.
Read →GRC in cybersecurity
Governance, risk and compliance: what the discipline is for, without the jargon.
Read →A scope to size up?
Tell us how many entities and information systems you need to cover: we get back to you within 24 business hours.