The calculation
Waiting for the vote is the most expensive calculation
France was required to transpose NIS2 before October 2024. The text has still not been adopted, held up by a debate unrelated to your obligations. In the meantime, three things have happened.
The scope has been settled
Several thousand French entities now fall within scope, against a few hundred under NIS1.
The content has been published
ANSSI has released the Référentiel Cyber France together with a mapping tool to ISO 27001, ISO 27002 and sector frameworks. An organisation that structures its security on that basis will discover nothing on the day enforcement begins.
The supply chain moved first
Companies outside the scope are already receiving security questionnaires from their in-scope clients. For many, the real constraint comes from the customer, not the legislator.
A compliance programme takes between twelve and twenty-four months. Starting on the day of the vote means arriving late.
Our method
We work on your frameworks, not on ours
We sell no solution, represent no vendor and hold no reseller agreement. Our recommendations serve no interest other than yours.
Independence
This practice rests on the method and the track record of its lead partner. Our analysis tools intervene only on the sifting work, investigation and evidence-based audit, never on judgement. We prefer to say so rather than let you assume otherwise.
Levels of engagement
Three entry points, depending on your starting maturity
Indicative durations. Pricing is established case by case, in a meeting.
01
Compliance review 5 days
You know you are in scope; you do not know where to start. Interviews, documentary review, positioning against the applicable frameworks, high-level costing of the remediation.
You leave with
- A map of your gaps by criticality
- A budget and schedule estimate
- A paper for your executive committee
02
Programme framing 15 to 20 days
Risk analysis, cyber governance, prioritised remediation plan, evidence file, preparation of registration with ANSSI. Includes training the executive committee on its own obligations: under NIS2, directors are personally accountable.
You leave with
- Your security policy
- Your risk analysis
- A costed, dated plan
- A responsibility matrix
- An assembled evidence file
03
Programme delivery 6 to 24 months
Running the remediation programme and the technical projects: SOC, EDR and XDR, IAM, PAM, continuity and recovery planning. CISO support, or holding the role while you recruit.
You leave with
- An arrangement that runs
- A trained internal lead
- A deliverable describing what your teams can do on their own
AI in this practice
AI is both an investigative tool and an object of compliance
Assisted investigation
Internal investigations and forensic analysis on corpora nobody has time to read. The model reasons where the material sits: nothing leaves your infrastructure.
Assisted audit
Your policies, procedures and evidence set against the applicable frameworks. Gaps are established on evidence, not on assertions.
Governance of AI usage
Inventory of AI use cases, risk qualification, compliance with the European AI Act, articulation with the GDPR and your security policy.
AI runs through all three of our practices. Our approach to AI →
Lead partner
Jean-Philippe Coste
Partner, programme director
More than twenty years directing cybersecurity programmes in sectors where compliance is not negotiable: banking, insurance, healthcare.
In a European financial institution, he led the cybersecurity programme and defined the security policies applicable to artificial intelligence and Big Data.
At a European healthcare operator, he secured the cloud, deployed a security operations centre and rebuilt the business continuity and disaster recovery plan.
Book a meeting with Jean-Philippe Coste His full track record →
Frequently asked
What clients ask us first
Am I in scope if the law has not been passed?
Scope is set by the European directive, not by the French timetable. ANSSI's platform already lets you test your eligibility. And many companies outside the scope are constrained by their in-scope clients.
Should we wait for the implementing decrees?
The Référentiel Cyber France already describes the expected objectives. The decrees will specify the procedures, not the substance.
How long does a compliance programme take?
Twelve to twenty-four months depending on size, starting maturity and the number of entities involved.
We already hold ISO 27001 certification. Is that enough?
No, but it is a solid base. ANSSI has published a mapping tool to the main standards. Some of your controls will be recognised; our work is to identify what remains to be covered.
We have no CISO.
That is true of most entities entering the scope. We can hold the role for the duration of the compliance programme, then train the internal lead.
Let us position you against your obligations
The partner you meet leads the engagement.