Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
EU NIS2 DIRECTIVE - TRANSPOSITION IN PROGRESS IN FRANCE

Your NIS2 compliance file
in 5 days

The European NIS2 directive (EU 2022/2555) requires cyber risk management for essential and important entities across 18 sectors, and by ricochet for their suppliers. SYAGA NIS2-Express delivers the complete and operational reference document (ISMS policy + compliance mapping), without tying up your teams for months.

5
Business days
20
Chapters covered
93
ISO 27001 controls
120+
Pages delivered

The NIS2 directive, in figures

What the European directive concretely changes for the entities concerned

Around 160,000 entities concerned across the EU

The NIS2 directive (EU 2022/2555) very significantly widens the scope of the former NIS1, with a trigger threshold generally set at around 50 employees and EUR 10M in revenue, across 18 essential and important sectors.

Sanctions that reach up to management

The texts provide for administrative fines (on the order of several million euros or a percentage of worldwide turnover depending on the type of entity) and personal liability for management, which can go as far as a temporary ban from duties.

French transposition is under way

France has not yet transposed NIS2 into national law (a transposition bill is in preparation). Companies that get ahead now avoid the expected bottleneck once the French text comes into force.

💰

Consulting firms charge for lengthy engagements

A typical NIS2/ISO 27001 compliance engagement led by a large consulting firm is counted in months. A budget often out of reach for an SME/mid-cap of 50 to 500 employees that nonetheless has to address it.

The ricochet effect: even if you are not directly subject to NIS2

NIS2 requires essential/important entities to verify the security of their supply chain. In practice, your principals are already sending you - or will send you - a supplier security questionnaire. Examples of real questions from this type of questionnaire:

Multi-factor authentication (MFA)

« For which services do you enforce MFA? Email, VPN, RDP, network-cloud administration, privileged accounts. »

Référence type CSA CAIQ v4 IAM-14.1 / SIG Lite

Email security

« What controls do you use against email spoofing (SPF, DKIM, DMARC)? Have you disabled legacy protocols (unsecured IMAP, POP3, SMTP)? »

Référence type Google VSAQ / Beazley Ransomware Supplemental

Incident response plan

« What is your incident response plan, and within what timeframe would you notify us of a cybersecurity incident? »

Référence type 3rdRisk - 7 Questions NIS2

Subcontracting and supply chain

« Do you use fourth-tier subcontractors? Will you accept contractual clauses requiring NIS2 compliance (controls, breach notification, audit rights)? »

Référence type 3rdRisk - 7 Questions NIS2

Backups and continuity

« Are backups performed? Are integrity and restoration procedures tested at least once a year? »

Référence type CSA CAIQ v4 BCR-08

Security governance

« Is your information security policy based on a recognized framework (NIST, ISO 27001)? »

Référence type 2022 SIG Lite (Shared Assessments)

The ISMS policy produced by NIS2-Express answers this type of questionnaire point by point, with the associated evidence.

The solution: NIS2-Express

5 days, 20 chapters, 1 operational document your teams can apply from the following Monday

D1
Day 1 - Scoping

Questionnaire and management interview

2-hour interview with the CIO or the executive. Collection of context, scope, business stakes and current maturity via our structured questionnaire (10 domains, 60 questions).

D2
Day 2 - Technical analysis

Collection and mapping of the information system

Asset inventory (servers, workstations, applications), network architecture analysis, identification of critical flows. Light vulnerability scan subject to prior agreement.

D3
Day 3 - Drafting

Generation of the customized ISMS policy

Drafting of the 20 chapters with your real data: security organization chart, risk matrix, operational procedures, IT charter. Everything is specific to your context.

D4
Day 4 - Consolidation

Compliance mapping and annexes

Detailed NIS2 mapping (governance, risk management measures, incident notification), ISO 27001, ANSSI and GDPR. Generation of annexes: asset inventory, Statement of Applicability matrix, incident, access and change management procedures.

D5
Day 5 - Delivery

Presentation and knowledge transfer

Presentation of the deliverable to the management committee. Q&A session. Handover of editable files (HTML, PDF, DOCX) for adoption by your teams.

What you receive

A complete, ready-to-deploy pack with all the documents you need

📝

ISMS policy - 20 chapters

Complete security policy covering all ISO 27001 domains, the documentary core expected under NIS2.

  • Security governance and organization
  • Classification of assets and data
  • Access and identity management
  • Network, system and application security
  • Business continuity and incident management
📈

Express audit report

Summary of the security posture with visual indicators.

  • Maturity radar (10 domains)
  • Risk matrix (impact/probability)
  • Top 10 critical vulnerabilities
  • Prioritized action plan (PDCA)
  • Recommended security budget
📄

Procedures and charter

Operational documents directly applicable by your teams.

  • PROC-01: Incident management
  • PROC-02: Access management
  • PROC-03: Change management
  • PROC-04: Backup and restoration
  • IT charter (ready to sign)
🎯

NIS2 mapping

Correspondence between your ISMS policy and the main obligation chapters of the NIS2 directive.

  • Art. 20 - Governance
  • Art. 21 - Risk management measures (10 domains)
  • Art. 23 - Incident notification
  • Standard answers to the NIS2 supplier questionnaire
  • Compliance matrix with status
🔐

ISO 27001 annexes

Statement of Applicability and mapping of the 93 Annex A controls (ISO 27001:2022).

  • SoA with justification per control
  • Detailed server inventory
  • Vulnerability register
  • Identified attack chains
  • Budgeted action plan
💻

Editable files

All documents in formats you can modify.

  • Standalone HTML (openable in any browser)
  • High-quality PDF (A4 print)
  • Editable DOCX (Microsoft Word)
  • Bilingual FR/EN (optional)
  • High-resolution PNG charts

Compliance covered

A single document to answer all your frameworks

N2

NIS2 (EU Directive 2022/2555)

Coverage of the main chapters governance, risk management measures and incident notification. Compliance mapping included.

ISO

ISO 27001:2022

Statement of Applicability of the 93 Annex A controls. Structure aligned with clauses 4 to 10 and the 4 themes (organizational, human, physical, technological).

AN

ANSSI guide - IT hygiene

The ANSSI IT hygiene measures are covered across the 20 chapters. Explicit correspondence in the compliance mapping.

RG

GDPR (Art. 32)

Appropriate technical and organizational measures to ensure the security of personal data. Data classification and processing register addressed.

Indicative pricing

Choose the plan that fits your context - customized quote within 24h

Essential

SME < 50 employees, single site

3,000
EUR excl. VAT (one-shot, indicative)
  • Customized 20-chapter ISMS policy
  • 4 operational procedures
  • IT charter
  • NIS2 and GDPR mapping
  • Presentation to the management committee
  • HTML + PDF + DOCX formats
Request a quote

Premium

Mid-cap 250+ employees, regulated sector

8,000
EUR excl. VAT (one-shot, indicative)
  • Everything in Standard +
  • DORA mapping (financial sector)
  • Sector templates (healthcare, industry, finance)
  • Budgeted remediation plan over 12 months
  • ISO 27001 certification support
  • Priority support for 12 months
Request a quote

Annual maintenance: EUR 500 excl. VAT/year (indicative)

Annual update of the ISMS policy (regulatory developments, IT changes). Review of procedures, update of the compliance mapping, new PDF.

Indicative pricing for a standard perimeter. The final amount is established on quote, after an initial discussion of your actual perimeter.

Frequently asked questions

Is my company subject to NIS2?
The threshold generally applied is that of a company with more than 50 employees or more than EUR 10M in revenue, active in one of the 18 covered sectors (energy, transport, health, digital, industry, water, food, space, postal, chemicals, waste, manufacturing, research, digital services, public administration, financial markets, digital infrastructure, digital providers). Even outside these criteria, you may be concerned by ricochet if you are a supplier to an entity subject to NIS2 (see the "Ricochet effect" section above). A precise qualification of your situation is a matter for legal counsel.
Has France already transposed NIS2?
No, not yet as of today: the French transposition law is in preparation. This does not mean you should wait: companies that prepare now avoid the expected bottleneck once the French text comes into force, and already meet today the requirements their clients/principals are already passing on to them by contract (ricochet effect).
What is the difference with an ISMS policy produced by a large consulting firm?
The content targets the same level of rigor: same 20 chapters, same ISO 27001 coverage, same depth of analysis. The difference: we rely on a generator that produces a customized document from your real data, whereas a traditional engagement is counted in months of manual drafting.
Is the document valid for an ISO 27001 certification?
The NIS2-Express ISMS policy provides a solid foundation to start an ISO 27001 certification. It covers the Statement of Applicability (SoA) for the 93 controls and the structure of clauses 4 to 10. Additional support will be needed for operational implementation and the certification audit.
How much of my teams' time do I need to commit?
2 hours on the first day (management interview) and 2 hours on the last day (handover). The rest of the work is carried out by our auditors without requiring your teams' involvement. If a technical scan is planned, temporary network access will be requested on day 2.
Is annual maintenance mandatory?
No, it is optional but recommended. Cyber risk management assumes a periodic review of security measures. Annual maintenance includes updating the document according to regulatory developments and changes to your information system.
What makes SYAGA qualified to produce this document?
SYAGA CONSULTING has been conducting IT security audits since 2009 (EURL founded on 08/12/2009), for clients across various sectors (industry, tourism, health, services). We have built a generator that capitalizes on this audit experience to produce customized compliance documents rapidly.

Ready to secure your NIS2 compliance?

Contact us to receive a customized quote within 24 hours.

NIS2-Express is a tool to support compliance efforts. It does not constitute legal advice. The qualification of your entity with regard to the NIS2 directive and its French transposition must be confirmed by legal counsel.