The European NIS2 directive (EU 2022/2555) requires cyber risk management for essential and important entities across 18 sectors, and by ricochet for their suppliers. SYAGA NIS2-Express delivers the complete and operational reference document (ISMS policy + compliance mapping), without tying up your teams for months.
What the European directive concretely changes for the entities concerned
The NIS2 directive (EU 2022/2555) very significantly widens the scope of the former NIS1, with a trigger threshold generally set at around 50 employees and EUR 10M in revenue, across 18 essential and important sectors.
The texts provide for administrative fines (on the order of several million euros or a percentage of worldwide turnover depending on the type of entity) and personal liability for management, which can go as far as a temporary ban from duties.
France has not yet transposed NIS2 into national law (a transposition bill is in preparation). Companies that get ahead now avoid the expected bottleneck once the French text comes into force.
A typical NIS2/ISO 27001 compliance engagement led by a large consulting firm is counted in months. A budget often out of reach for an SME/mid-cap of 50 to 500 employees that nonetheless has to address it.
NIS2 requires essential/important entities to verify the security of their supply chain. In practice, your principals are already sending you - or will send you - a supplier security questionnaire. Examples of real questions from this type of questionnaire:
« For which services do you enforce MFA? Email, VPN, RDP, network-cloud administration, privileged accounts. »
« What controls do you use against email spoofing (SPF, DKIM, DMARC)? Have you disabled legacy protocols (unsecured IMAP, POP3, SMTP)? »
« What is your incident response plan, and within what timeframe would you notify us of a cybersecurity incident? »
« Do you use fourth-tier subcontractors? Will you accept contractual clauses requiring NIS2 compliance (controls, breach notification, audit rights)? »
« Are backups performed? Are integrity and restoration procedures tested at least once a year? »
« Is your information security policy based on a recognized framework (NIST, ISO 27001)? »
The ISMS policy produced by NIS2-Express answers this type of questionnaire point by point, with the associated evidence.
5 days, 20 chapters, 1 operational document your teams can apply from the following Monday
2-hour interview with the CIO or the executive. Collection of context, scope, business stakes and current maturity via our structured questionnaire (10 domains, 60 questions).
Asset inventory (servers, workstations, applications), network architecture analysis, identification of critical flows. Light vulnerability scan subject to prior agreement.
Drafting of the 20 chapters with your real data: security organization chart, risk matrix, operational procedures, IT charter. Everything is specific to your context.
Detailed NIS2 mapping (governance, risk management measures, incident notification), ISO 27001, ANSSI and GDPR. Generation of annexes: asset inventory, Statement of Applicability matrix, incident, access and change management procedures.
Presentation of the deliverable to the management committee. Q&A session. Handover of editable files (HTML, PDF, DOCX) for adoption by your teams.
A complete, ready-to-deploy pack with all the documents you need
Complete security policy covering all ISO 27001 domains, the documentary core expected under NIS2.
Summary of the security posture with visual indicators.
Operational documents directly applicable by your teams.
Correspondence between your ISMS policy and the main obligation chapters of the NIS2 directive.
Statement of Applicability and mapping of the 93 Annex A controls (ISO 27001:2022).
All documents in formats you can modify.
A single document to answer all your frameworks
Coverage of the main chapters governance, risk management measures and incident notification. Compliance mapping included.
Statement of Applicability of the 93 Annex A controls. Structure aligned with clauses 4 to 10 and the 4 themes (organizational, human, physical, technological).
The ANSSI IT hygiene measures are covered across the 20 chapters. Explicit correspondence in the compliance mapping.
Appropriate technical and organizational measures to ensure the security of personal data. Data classification and processing register addressed.
Choose the plan that fits your context - customized quote within 24h
SME < 50 employees, single site
SME/mid-cap 50-250 employees, multi-site
Mid-cap 250+ employees, regulated sector
Annual maintenance: EUR 500 excl. VAT/year (indicative)
Annual update of the ISMS policy (regulatory developments, IT changes). Review of procedures, update of the compliance mapping, new PDF.
Indicative pricing for a standard perimeter. The final amount is established on quote, after an initial discussion of your actual perimeter.
Contact us to receive a customized quote within 24 hours.