NIS2 compliance required by end 2027 — Fines up to €10M

Prove your NIS2 compliance before you're asked

NIS2 self-assessment platform with intelligent remediation plan, real-time scoring and exportable report. For SMEs, mid-market companies and MSPs across Europe.

What matters is no longer declaring… but demonstrating. Compliance must be traceable, justifiable — and ultimately audited continuously.

Core NIS2 principle — Solutions Numériques

NIS2 is not a certification

No label, no stamp

NIS2 is not a certification in the ISO sense. There is no label, no stamp, no mandatory annual audit leading to a certificate. The logic is one of declarative and demonstrable compliance: the company must be able to prove, in the event of an ANSSI audit or an incident, that it meets the requirements.

Demonstrable compliance

What changes with NIS2 is the end of pure declaration. Compliance must be traceable, justifiable — with documented evidence. This is exactly where CyberSCV makes sense: every answer, every piece of evidence, every remediation action is tracked and exportable.

New — 17 March 2026

ReCyF — France Cyber Framework

Since 17 March 2026, ANSSI has published the Référentiel Cyber France (ReCyF), listing recommended measures to achieve the security objectives set by NIS2. This non-mandatory framework allows entities that choose to apply it to rely on it during an ANSSI audit.

ReCyF structures compliance around mandatory security objectives ('what') and acceptable means of compliance ('how'). Entities can rely during an audit on the use of ANSSI-qualified services or certification to relevant international standards.

20 security objectives: IS inventory, governance, ecosystem management, HR security, IS management, and other operational domains.

NIS2 fines

10M€ / 2%

For Essential Entities — €10 million or 2% of global turnover

7M€ / 1.4%

For Important Entities — €7 million or 1.4% of global turnover

Directors may also face criminal prosecution and bans from holding similar positions.

7 countries covered, each with its national framework

CyberSCV integrates the specific requirements of each Member State — a universal EU score + a national score

🇫🇷Pending

France

ReCyF v2.5

Authority: ANSSI

Law: PJL Résilience

EE fines: 10M€ / 2%

Le ReCyF v2.5 est un document de travail quasi-définitif. Statut à confirmer auprès de votre Assemblée Nationale.
🇩🇪In force

Deutschland

BSIG §30 / KRITIS 2025

Authority: BSI

Law: BSIG révisé + KRITIS-DachG

EE fines: 10M€ / 2%

Obligations en vigueur depuis le 6 décembre 2025 — pas de période de transition.
🇧🇪In force

Belgique / België

CyFun® 2025

Authority: CCB

Law: Loi NIS2 du 26 avril 2024

EE fines: 10M€ / 2%

Auto-évaluation CyFun à transmettre au CCB avant le 18 avril 2026.
🇮🇹In force

Italia

FNCS (NIST CSF 2.0) 2025

Authority: ACN

Law: D.Lgs. 138/2024

EE fines: 10M€ / 2%

Enregistrement ACN annuel obligatoire (janvier-février).
🇪🇸Pending

España

ENS (proxy) RD 311/2022

Authority: INCIBE

Law: Proyecto Ley Coordinación y Gobernanza Ciberseguridad

EE fines: 2M€

Transposition non finalisée — overlay provisoire basé sur NIS2 EU + ENS.
🇵🇹In force

Portugal

DL 125/2025 2025

Authority: CNCS

Law: DL n° 125/2025

EE fines: 10M€ / 2%

En vigueur le 3 avril 2026 — Responsável de Cibersegurança à nommer sous 20 jours.
🇬🇧Partial

United Kingdom

NCSC CAF 2024

Authority: NCSC

Law: NIS Regulations 2018 + Cyber Resilience

EE fines: 17M£

UK is not subject to NIS2 (post-Brexit). Score based on NCSC CAF framework.

What CyberSCV delivers

A complete platform to assess, remediate and prove your NIS2 compliance

Country-adapted questionnaire

NIS2 EU baseline (Art. 21) enriched with your country's national requirements: ReCyF (FR), CyFun (BE), BSIG (DE)... Question count adapts to your entity profile and jurisdiction.

Maturity radar

Global score, domain scores, maturity level (1-5) and comparison with previous assessments.

Remediation plan

Auto-generated actions, kanban tracking, dynamic scoring and remediation history.

AI Strategy (Claude)

AI analyses your assessment and proposes remediation scenarios with phases, effort, budget and priorities.

Exportable PDF report

Report admissible to NCSC/ANSSI: cover, scores, domain detail, action plan, evidence.

MSP Console

Manage your clients, consolidate scores, customise your brand — built for managed service providers.

Are you an IT provider, MSP or MSSP?

Run your clients' NIS2 compliance from a single console

Manage your whole portfolio, cluster subsidiaries by holding, generate consolidated reports — all white-labelled, under your own brand.

Ready to demonstrate your NIS2 compliance?

Create your free account and launch your first assessment in 10 minutes.