Policy generator
NIS2 compliance for SMEs
The NIS2 directive mandates documented cybersecurity governance for more than 15,000 French entities. Generate the expected policies — ISSP, continuity, incidents, suppliers — in minutes, in English and French.
What is the NIS2 directive?
NIS2 (Directive (EU) 2022/2555) extends cybersecurity obligations to more than 15,000 entities in France: medium-sized companies, subcontractors and digital service providers in strategic sectors. It requires documented governance — an information security policy (ISSP), risk management, business continuity and disaster recovery, incident notification and supply-chain security. Penalties reach €10M or 2% of global turnover, with personal liability for executives. PolicyForge produces this documentary layer for NIS2 as well as ISO 27001, SOC 2, GDPR and DORA.
Essential entity or important entity: what is the difference?
NIS2 classifies in-scope organisations in two tiers. Essential entities (EE) are, broadly, large organisations — 250+ employees, or over €50M turnover — in highly critical sectors: energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration and space. Important entities (IE) cover mid-sized organisations in those sectors — from 50 employees or €10M turnover — plus organisations in the other critical sectors: postal services, waste, chemicals, food, manufacturing, digital providers and research.
The substantive obligations are largely the same for both tiers; what changes is the supervision regime and the sanction ceiling. ANSSI’s MonEspaceNIS2 eligibility test on cyber.gouv.fr determines your category in a few questions.
Where does the French law stand?
The EU transposition deadline was 17 October 2024 and France missed it: as of mid-2026, the “resilience” bill — adopted by the Sénat in March 2025, then in committee at the Assemblée nationale in September 2025 — is still awaiting its plenary examination. ANSSI has not waited: in March 2026 it published the Référentiel Cyber France (ReCyF), which sets out 20 security objectives with acceptable means of compliance, and advises in-scope entities to prepare now rather than wait for the final text.
NIS2 thresholds and sanctions at a glance
Classification thresholds and sanction ceilings under Directive (EU) 2022/2555:
| Essential entity (EE) | Important entity (IE) | |
|---|---|---|
| Typical size | 250+ employees, or turnover > €50M (highly critical sectors) | 50+ employees, or turnover > €10M |
| Sectors | Highly critical (Annex I): energy, transport, health, banking, digital infrastructure… | Highly critical (mid-sized) + other critical sectors (Annex II): postal, waste, chemicals, food, manufacturing… |
| Maximum fine | €10M or 2% of worldwide turnover | €7M or 1.4% of worldwide turnover |
| Management liability | Personal | Personal |
How to generate your NIS2 policies
- 1
Check your scope
Essential entity, important entity, or subcontractor of a covered entity: the expected documentation shares the same baseline.
- 2
Answer the wizard
A few questions about your organisation automatically tailor the content.
- 3
Generate the policies
PolicyForge drafts complete, structured documents with an approval block and versioning.
- 4
Export and get sign-off
Export to PDF or DOCX, get management sign-off, keep the version. The audit log tracks changes.
About 5 minutes per policy.
Which policies for NIS2 compliance?
The documents expected by the Article 21 risk-management measures. Click to see a sample PDF:
- Risk management policy (risk analysis)
- Information security policy (ISSP)
- Incident response & notification policy
- Business continuity policy (BCP)
- Backup & recovery policy (DRP)
- Supply chain security policy
- Access control policy
- Vulnerability management policy
- Logging & monitoring policy
- Security awareness training policy
Frequently asked questions
Is my company in scope for NIS2?
Generally, companies with more than 50 employees or €10M turnover in a strategic sector are in scope. But a smaller SME can be indirectly affected: essential and important entities must secure their supply chain, so a subcontractor providing a critical digital service will be assessed against NIS2 criteria.
What is the compliance deadline?
The EU transposition deadline was 17 October 2024. The French transposition law (the “resilience” bill) is still before Parliament as of mid-2026; obligations will phase in once it passes. ANSSI advises preparing now — its ReCyF framework (March 2026) already describes the expected measures, and planned penalties reach €10M or 2% of global turnover.
Which documents does NIS2 require?
Article 21 expects documented measures: an information security policy (ISSP), risk analysis and management, incident handling and notification, business continuity (BCP) and disaster recovery (DRP), supply-chain security, access control, vulnerability management and awareness training.
Are NIS2 and ISO 27001 compatible?
Yes. An ISO 27001 programme covers most NIS2 measures. PolicyForge templates stay aligned with both frameworks so you do not document twice.
Are the documents bilingual?
Yes, every policy is available in English and French.
Start your NIS2 compliance
Free account, no credit card. Your first policies in minutes.
Start free