Skip to content

Practice · Cyber & compliance

The law has not been passed. Your obligations are already written

France's national cyber framework, the Référentiel Cyber France, has been published since March 2026. It translates NIS2 into twenty security objectives for essential entities and fifteen for important entities. The content of your future compliance is therefore known. Only its enforcement date remains open.

Book a meeting With Jean-Philippe Coste, lead partner

The calculation

Waiting for the vote is the most expensive calculation

France was required to transpose NIS2 before October 2024. The text has still not been adopted, held up by a debate unrelated to your obligations. In the meantime, three things have happened.

The scope has been settled

Several thousand French entities now fall within scope, against a few hundred under NIS1.

The content has been published

ANSSI has released the Référentiel Cyber France together with a mapping tool to ISO 27001, ISO 27002 and sector frameworks. An organisation that structures its security on that basis will discover nothing on the day enforcement begins.

The supply chain moved first

Companies outside the scope are already receiving security questionnaires from their in-scope clients. For many, the real constraint comes from the customer, not the legislator.

A compliance programme takes between twelve and twenty-four months. Starting on the day of the vote means arriving late.

Our method

We work on your frameworks, not on ours

Référentiel Cyber FranceNIS2ISO 27001ISO 27005NISTGDPRDORAFrench Military Programming ActSector frameworks

We sell no solution, represent no vendor and hold no reseller agreement. Our recommendations serve no interest other than yours.

Independence

This practice rests on the method and the track record of its lead partner. Our analysis tools intervene only on the sifting work, investigation and evidence-based audit, never on judgement. We prefer to say so rather than let you assume otherwise.

Levels of engagement

Three entry points, depending on your starting maturity

Indicative durations. Pricing is established case by case, in a meeting.

01

Compliance review 5 days

You know you are in scope; you do not know where to start. Interviews, documentary review, positioning against the applicable frameworks, high-level costing of the remediation.

You leave with

  • A map of your gaps by criticality
  • A budget and schedule estimate
  • A paper for your executive committee

02

Programme framing 15 to 20 days

Risk analysis, cyber governance, prioritised remediation plan, evidence file, preparation of registration with ANSSI. Includes training the executive committee on its own obligations: under NIS2, directors are personally accountable.

You leave with

  • Your security policy
  • Your risk analysis
  • A costed, dated plan
  • A responsibility matrix
  • An assembled evidence file

03

Programme delivery 6 to 24 months

Running the remediation programme and the technical projects: SOC, EDR and XDR, IAM, PAM, continuity and recovery planning. CISO support, or holding the role while you recruit.

You leave with

  • An arrangement that runs
  • A trained internal lead
  • A deliverable describing what your teams can do on their own

AI in this practice

AI is both an investigative tool and an object of compliance

Assisted investigation

Internal investigations and forensic analysis on corpora nobody has time to read. The model reasons where the material sits: nothing leaves your infrastructure.

Assisted audit

Your policies, procedures and evidence set against the applicable frameworks. Gaps are established on evidence, not on assertions.

Governance of AI usage

Inventory of AI use cases, risk qualification, compliance with the European AI Act, articulation with the GDPR and your security policy.

AI runs through all three of our practices. Our approach to AI →

Lead partner

Jean-Philippe Coste

Partner, programme director

More than twenty years directing cybersecurity programmes in sectors where compliance is not negotiable: banking, insurance, healthcare.

In a European financial institution, he led the cybersecurity programme and defined the security policies applicable to artificial intelligence and Big Data.

At a European healthcare operator, he secured the cloud, deployed a security operations centre and rebuilt the business continuity and disaster recovery plan.

ISO 27001ISO 27005NISTDORANISLPMGDPRAI Act

Book a meeting with Jean-Philippe Coste His full track record →

Frequently asked

What clients ask us first

Am I in scope if the law has not been passed?

Scope is set by the European directive, not by the French timetable. ANSSI's platform already lets you test your eligibility. And many companies outside the scope are constrained by their in-scope clients.

Should we wait for the implementing decrees?

The Référentiel Cyber France already describes the expected objectives. The decrees will specify the procedures, not the substance.

How long does a compliance programme take?

Twelve to twenty-four months depending on size, starting maturity and the number of entities involved.

We already hold ISO 27001 certification. Is that enough?

No, but it is a solid base. ANSSI has published a mapping tool to the main standards. Some of your controls will be recognised; our work is to identify what remains to be covered.

We have no CISO.

That is true of most entities entering the scope. We can hold the role for the duration of the compliance programme, then train the internal lead.

Let us position you against your obligations

The partner you meet leads the engagement.

Book a meeting with Jean-Philippe Coste