S.01NIS2 guide

NIS2: who is in scope, and what to prove.

The NIS2 Directive (Directive (EU) 2022/2555) requires essential and important entities to manage cyber risk, report incidents and keep evidence. This guide says who is in scope, what Articles 21 and 23 ask, where the French transposition stands as of 4 October 2026, and where a penetration test fits in those duties. It is not legal advice, and Darkmoon does not certify compliance.

15,000
entities expected in France, up from 500 under NIS 1 (Sénat)
24 h · 72 h · 1 month
early warning, notification, final report (Article 23)
10
risk-management measures (Article 21(2))
17 Oct 2024
transposition deadline for Member States

Sources :Sénat report no. 393Directive (EU) 2022/2555European Commission FAQ

S.03The Directive
One directive, two categories of entities, evidence to produce.

NIS2 is Directive (EU) 2022/2555 of 14 December 2022 "on measures for a high common level of cybersecurity across the Union". It replaces NIS 1, widens the list of sectors, sets size thresholds and leaves transposition into national law to each Member State, due by 17 October 2024.

What NIS2 is

Directive (EU) 2022/2555 of 14 December 2022

Objective

A high common level of cybersecurity

The Directive asks Member States to regulate the entities whose services matter to society and the economy: risk management (Article 21), incident reporting (Article 23), registration and supervision by a national authority. Member States had to establish the list of essential and important entities by 17 April 2025 and review it at least every two years (Article 3(3)).

Article 3

Essential or important: two statuses, two supervision regimes

Essential entities are Annex I types that exceed the medium-sized ceilings, plus cases identified regardless of size: qualified trust service providers, TLD name registries, DNS service providers, central-government bodies, CER critical entities. Important entities are all the other Annex I and Annex II entities. Essential entities are subject to ex-ante and ex-post supervision, important entities to ex-post supervision.

Supervision

National authorities, penalties set by national law

Each Member State designates its competent authorities; in France, ANSSI runs implementation and registration. The Directive sets maximum fines of at least €10 M or 2 % of worldwide turnover for essential entities, €7 M or 1.4 % for important ones, to be written into national law. In France that law is not promulgated as of 4 October 2026: no NIS2 penalty is in force.

S.04Scope
Who is in scope: a listed entity type, then a size.

Article 2(1), verbatim: the Directive "applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union". Two cumulative conditions: being of a listed type, and reaching the size, except for the special cases below.

Art. 2(1)

The size rule (Recommendation 2003/361/EC)

An entity of a listed type is in scope when it is at least "medium-sized", i.e. when it is NOT small: 50 staff or more, OR (turnover above €10 M AND balance-sheet total above €10 M).An entity of an Annex I type that exceeds the medium ceilings (250 staff or more, or turnover above €50 M and balance sheet above €43 M) is an essential entity (Article 3(1)(a)); an Annex I entity that is only medium-sized, and all Annex II entities, are important entities (Article 3(2)).Article 2(1), second sentence: "Article 3(4) of the Annex to that Recommendation shall not apply" (the partner / linked-enterprise exception is switched off); group data may have to be consolidated.

Art. 2(2)-(7)

Where size does not matter (Article 2(2) to 2(7))

(a) providers of public electronic communications networks or publicly available electronic communications services, trust service providers, top-level domain name registries and DNS service providers;(b) "the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities";(c) disruption "could have a significant impact on public safety, public security or public health";(d) disruption "could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact";(e) the entity "is critical because of its specific importance at national or regional level";(f) public administration entities of central government, or at regional level where a risk-based assessment shows that disruption could have a significant impact on critical societal or economic activities;Article 2(3): critical entities under Directive (EU) 2022/2557 (CER). Article 2(4): domain name registration services. Article 2(5): Member States may extend the Directive to local public administration and education institutions. Article 2(7): national security, public security, defence and law enforcement are excluded. Article 2(10) and Article 4: DORA prevails for financial entities.

Annex I

Annex I: sectors of high criticality.

Eleven sectors, named as in the Directive, with the type of entity in one line. An Annex I entity is essential above the medium-sized ceilings and important below them, unless identified otherwise. Tiles linked to an industry page open that page.

Annex I · industry page
1 · Electricity, district heating and cooling, oil, gas, hydrogen
Energy

Electricity undertakings carrying out supply, distribution and transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or storage, operators of recharging points; operators of district heating or cooling; oil pipelines, production, refining, storage and central stockholding entities; gas supply, networks, storage and LNG operators; operators of hydrogen production, storage and transmission.

Annex I · industry page
2 · Air, rail, water, road
Transport

Commercial air carriers, airport managing bodies, air traffic control providers; railway infrastructure managers and railway undertakings; inland, sea and coastal water transport companies (not individual vessels), port managing bodies and facilities, vessel traffic services; road authorities responsible for traffic management, intelligent transport systems operators.

Annex I · industry page
3
Banking

"Credit institutions as defined in Article 4, point (1), of Regulation (EU) No 575/2013". For these entities DORA prevails (NIS2 Article 4).

Annex I · industry page
4
Financial market infrastructures

Operators of trading venues (Directive 2014/65/EU), central counterparties (Regulation (EU) No 648/2012). DORA prevails (NIS2 Article 4).

Annex I · industry page
5
Health

"Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU"; EU reference laboratories; entities carrying out research and development of medicinal products; manufacturers of basic pharmaceutical products and preparations (NACE Rev. 2 C 21); manufacturers of medical devices considered critical during a public-health emergency.

Annex I · industry page
6
Drinking water

Suppliers and distributors of water intended for human consumption (Directive (EU) 2020/2184), excluding distributors for which it is a non-essential part of distributing other goods.

Annex I · industry page
7
Waste water

Undertakings collecting, disposing of or treating urban, domestic or industrial waste water (Directive 91/271/EEC), excluding those for which it is a non-essential part of their activity.

Annex I · industry page
8
Digital infrastructure

Internet Exchange Point providers; DNS service providers (excluding root servers); TLD name registries; cloud computing service providers; data centre service providers; content delivery network providers; trust service providers; providers of public electronic communications networks and publicly available electronic communications services. No size cap for DNS, TLD, trust-service and telecom providers.

Annex I · industry page
9
ICT service management (business-to-business)

"Managed service providers" and "managed security service providers". Commission Implementing Regulation (EU) 2024/2690 details their technical requirements.

Annex I
10
Public administration

"Public administration entities of central governments as defined by a Member State" and "public administration entities at regional level as defined by a Member State". Local-level bodies are covered only where national law says so (Article 2(5)). The French bill (Senate text) targets communes above 30,000 inhabitants: not final.

Annex I
11
Space

"Operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services", excluding providers of public electronic communications networks.

Annex II

Annex II: other critical sectors.

Seven sectors whose entities, when they reach the size, are important entities. The last tile recalls who is listed nowhere.

Annex II
1
Postal and courier services

Postal service providers under Directive 97/67/EC, "including providers of courier services".

Annex II
2
Waste management

Undertakings carrying out waste management (Directive 2008/98/EC), "excluding undertakings for whom waste management is not their principal economic activity".

Annex II
3
Manufacture, production and distribution of chemicals

Undertakings manufacturing substances, distributing substances or mixtures, or producing articles from substances or mixtures (REACH Regulation, Article 3).

Annex II
4
Production, processing and distribution of food

Food businesses (Regulation (EC) No 178/2002) "which are engaged in wholesale distribution and industrial production and processing". Retail and restaurants are not named.

Annex II · industry page
5 · Medical devices and in vitro diagnostics; computer, electronic and optical products; electrical equipment; machinery; motor vehicles; other transport equipment
Manufacturing

Manufacturers under Regulations (EU) 2017/745 and 2017/746, except those already in Annex I point 5; NACE Rev. 2 section C divisions 26, 27, 28, 29 and 30.

Annex II · industry page
6
Digital providers

"Providers of online marketplaces", "providers of online search engines", "providers of social networking services platforms". Implementing Regulation (EU) 2024/2690 applies.

Annex II
7
Research

"Research organisations" (Article 6 definition). Education institutions are covered only where the Member State opts in (Article 2(5)(b)).

Annex II · industry page
Not listed
Professions and activities outside both Annexes

Law firms, accounting firms, notaries, HR and payroll firms, generic SaaS vendors, consultancies, insurance brokers, hotels, retail, construction: no Annex names them. They are caught only when their actual activity fits a listed type (a software vendor that is a cloud computing service provider, a consultancy that operates managed services). Otherwise NIS2 reaches them through their regulated customers (Article 21(2)(d)).

Sources :EUR-Lex, Directive (EU) 2022/2555, Annexes I and II

As of 4 October 2026. This page is a documentary summary, not legal advice: your exact scope depends on the final French text and, where applicable, on your identification by the authority. Use ANSSI's self-test and consult your counsel. Darkmoon does not certify compliance.

S.05Article 21
The ten Article 21 risk-management measures.

Article 21(1) requires measures that are "appropriate and proportionate", taking into account the state of the art and the cost of implementation; Article 21(2) sets the minimum list below, in the order of the text. Article 21(4) adds corrective measures "without undue delay" when non-compliance is found. The Directive never names a "penetration test": it is one means of implementing point (f), not a mandated deliverable.

(a) policies on risk analysis and information system securityArticle 21(2) (a)

The foundation: a documented risk analysis and the information-security policy that follows from it. The other points are its declinations.

(b) incident handlingArticle 21(2) (b)

Detect, qualify, contain, learn. This point feeds the Article 23 reporting deadlines directly.

(c) business continuity, such as backup management and disaster recovery, and crisis managementArticle 21(2) (c)

Backups, recovery, crisis management: the ability to keep delivering the service during and after an incident.

(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providersArticle 21(2) (d) · Indirect lever for suppliers

NIS2's indirect lever: a regulated entity must address the security of its direct suppliers. A firm, a software vendor or an MSP that is listed nowhere thus receives contractual requirements and requests for evidence, without being a NIS2 entity itself.

(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosureArticle 21(2) (e)

Vulnerability handling: find, qualify, fix, disclose. A report of exploited findings and a remediation trail document this process.

(f) policies and procedures to assess the effectiveness of cybersecurity risk-management measuresArticle 21(2) (f) · Where testing sits

This is where testing sits. Assessing effectiveness means confronting the measures with a real attempt: a validated penetration test, with exploitation evidence, is a recognised way to produce that assessment. The Directive mandates neither a test type nor a frequency.

(g) basic cyber hygiene practices and cybersecurity trainingArticle 21(2) (g)

Updates, passwords, awareness: basic practices and the training of people.

(h) policies and procedures regarding the use of cryptography and, where appropriate, encryptionArticle 21(2) (h)

When and how to encrypt, with which algorithms and which key management.

(i) human resources security, access control policies and asset managementArticle 21(2) (i)

Who has access to what, on which known and inventoried assets, from onboarding to departure.

(j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriateArticle 21(2) (j)

Multi-factor or continuous authentication, secured communications, an emergency channel: the measures named explicitly, "where appropriate".

For eleven categories (DNS, TLD registries, cloud computing, data centres, CDN, managed service and managed security service providers, online marketplaces, search engines, social networks, trust services), Commission Implementing Regulation (EU) 2024/2690 details the technical and methodological requirements of these measures.

Sources :Directive, Article 21Implementing Regulation (EU) 2024/2690

S.06Article 23
Reporting significant incidents: 24 hours, 72 hours, one month.

Article 23(4) sets the deadlines below for every significant incident, counted from the moment the entity becomes aware of it. Testing before an incident does not replace these duties, and Darkmoon provides no incident-reporting service.

(a) · 24 h

Early warning

"Without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning".

(b) · 72 h

Incident notification

"Without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification" including its severity and impact, as well as, where available, the indicators of compromise.

(c) · on request

Intermediate report

Upon the request of the CSIRT or the competent authority, an intermediate report on relevant status updates.

(d) and (e) · 1 month

Final report

"A final report not later than one month after the submission of the incident notification under point (b)". If the incident is still ongoing: a progress report, then a final report within one month of its handling. Derogation: trust service providers file the incident notification within 24 hours.

Sources :EUR-Lex, Directive (EU) 2022/2555, Article 23

S.07Transposition
Where France stands as of 4 October 2026: the law is not promulgated.

The "projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité" transposes CER, NIS2 and the DORA directive at once. Filed at the Sénat on 15 October 2024, adopted by the Sénat in first reading on 12 March 2025, filed at the Assemblée nationale on 13 March 2025, special-committee report on 10 September 2025. No joint committee, final reading, promulgation or Journal officiel publication has occurred: France has not completed transposition, whose deadline was 17 October 2024.

Assemblée nationale
Legislative file
Public session on Wednesday 7 October 2026

The text is scheduled for public session at the Assemblée nationale on Wednesday 7 October 2026. Until the law is promulgated, no NIS2 duty is in force in France; thresholds, penalties and registration deadlines may still change.

ANSSI
messervices.cyber.gouv.fr/nis2
Pre-registration and eligibility self-test

ANSSI's portal states that "la transposition de la directive NIS 2 en France est en cours" and that once an entity has assessed it falls within the NIS2 scope, it must register with ANSSI. Today only a pre-registration and a self-test are offered; three obligations are named: registration, cyber risk management, incident declaration.

ANSSI
Since 17 March 2026
The Référentiel Cyber France (ReCyF)

ANSSI's NIS 2 page states that the Référentiel Cyber France, which lists the measures ANSSI recommends, has been available since 17 March 2026, and invites future regulated entities to start now.

Press quoting ANSSI
Announced approach, not a legal text
Three years without penalties, except registration and incidents

According to the specialised press quoting ANSSI's director general, no penalty for non-compliance would be applied within three years after transposition, with exceptions for registration and incident notification. This is not a legal text: an announced approach, not to be confused with a statutory grace period.

Sénat
Report no. 393
From 500 to 15,000 regulated entities

The Sénat report describes the "passage d'environ 500 entités régulées au titre de NIS 1 à 15 000 entités régulées au titre de NIS 2". Thirty times more organisations, most of which have never had a cyber supervisory authority.

Senate text, not final
Local authorities
A 30,000-inhabitant threshold for communes

In the text adopted by the Sénat on 12 March 2025, State administrations, régions, départements and communes of more than 30,000 inhabitants (and agglomeration communities including such a commune) would be treated as essential entities; communautés de communes whose activities fall in a listed sector as important entities. The final text may change at the Assemblée.

As of 4 October 2026. This page is a documentary summary, not legal advice: your exact scope depends on the final French text and, where applicable, on your identification by the authority. Use ANSSI's self-test and consult your counsel. Darkmoon does not certify compliance.

S.08Map
NIS2, ISO 27001, DORA: what overlaps, what does not.

Three texts of a different nature. NIS2 is a directive to be transposed, ISO/IEC 27001 a voluntary, certifiable standard, DORA a regulation directly applicable to financial entities. Confusing them produces false feelings of compliance.

Directive

NIS2: a legal duty, not a certification

Directive (EU) 2022/2555: applies to the Annex I and II entity types that reach the size, through national law. Article 21 measures, Article 23 deadlines, registration and supervision. There is no "NIS2 certification" in the Directive: compliance is the entity's responsibility, assessed by the competent authority.

Standard

ISO/IEC 27001: a management system, voluntary and certifiable

ISO/IEC 27001 describes an information security management system, certified by a third-party body. NIS2 does not require it, and an ISO 27001 certificate does not by itself establish NIS2 compliance. In practice the Article 21 measures overlap heavily with the controls of an ISMS, so evidence can be reused; Darkmoon Pro reports map their findings to ISO 27001.

Regulation

DORA: the special text for financial entities

Regulation (EU) 2022/2554, applicable since 17 January 2025. For financial entities DORA prevails over NIS2 (NIS2 Article 4, lex specialis; Article 2(10)). Its Article 24 requires a resilience testing programme, Article 25 explicitly lists penetration testing, Article 26 reserves TLPT, at least every three years, to entities designated by their authority.

S.09Testing

Where a penetration test fits, and what it does not do.

Article 21(2)(f) asks entities to assess the effectiveness of their measures. A validated penetration test is an accepted way to produce that assessment: it confronts the measures with a real attempt and leaves evidence. It does not cover the whole of Article 21, and it replaces nothing else.

01
What point (f) asks

"Policies and procedures to assess the effectiveness of cybersecurity risk-management measures." The entity must prove its measures hold, not only that they exist. Article 21(4) adds corrective measures "without undue delay" when non-compliance is found.

Learn more

S.10Darkmoon
What Darkmoon adds to the evidence file, concretely.

Darkmoon is an autonomous penetration-testing platform: an orchestrator and 50 specialist agents, 142 security tools behind a build-enforced allow-list, tool execution gatekept by an MCP gateway (the model never gets a shell). Here is what that produces for an entity that must document Article 21.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Findings qualified by exploitation

Every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED by an adversarial rubric; the evidence (requests, payloads, screenshots) is kept. The criterion is machine-verified exploitation, not a probability score.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Coverage that follows your perimeter

Web applications and APIs, cloud (AWS, Azure, GCP), Active Directory and Entra ID, Kubernetes, CI/CD, databases, message brokers, IoT and firmware, AI/LLM endpoints and MCP servers (OWASP LLM Top 10). An infrastructure graph links hosts, paths and relationships.

Attack surfaceexposure

Mapped, recurring reports

Markdown and JSON in the Community edition; PDF and web reports, CVSS 3.1, MITRE ATT&CK and ISO 27001 mapping, scheduled campaigns and a live dashboard in Pro. The remediation agent proposes sandbox-validated fixes as pull requests for human review, never auto-merged.

New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

A managed engagement at a flat rate

Pentest on Demand: describe the target in a guided form, sign the legal framework online (test authorization, scope, liability), €799 per engagement shown upfront (indicative, adjusted to the final scope), a scoping call, the report and a debrief video call in a secure client space. Run end to end by ASC-IT's security experts.

S.11Limits
What Darkmoon does not do.

The evidence stays on your side: the Privacy Gateway tokenizes sensitive values (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, a local LLM via Ollama or llama.cpp is supported, and self-hosting is the default (GPLv3 Community edition on GitHub). But a platform does not do compliance for you.

Explicitly out of scope
  • No certification: there is no NIS2 certification, and Darkmoon does not certify compliance.
  • No attestation and no compliance guarantee: the reports are pieces of your evidence file, not a decision of the authority.
  • No incident-reporting service: the Article 23 deadlines are your organisation's duty.
  • No legal advice: the scope and qualification of your entity depend on national law and on your counsel.
  • No OT/ICS protocol testing or PLC fuzzing: we test the IT side and what is reachable over the network.

S.12Frequently asked
What a CISO or an executive asks first.

What is NIS2?

NIS2 is Directive (EU) 2022/2555 of 14 December 2022 on a high common level of cybersecurity across the Union. It replaces NIS 1, widens the list of sectors, imposes ten risk-management measures (Article 21) and the reporting of significant incidents within 24 hours, 72 hours and one month (Article 23). Each Member State had to transpose it by 17 October 2024; France has not yet promulgated its law as of 4 October 2026.

Who is in scope of NIS2?

Public or private entities of a type listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) that are at least medium-sized enterprises: 50 staff or more, or a turnover and a balance-sheet total above €10 M. Some entities are in scope regardless of size (DNS service providers, TLD name registries, trust service providers, telecom providers, central-government bodies, entities identified by the State). A profession is never in scope on its own: a listed entity type is required.

Essential entity or important entity: what is the difference?

An essential entity is an Annex I type that exceeds the medium-sized ceilings (250 staff or more, or turnover above €50 M and balance sheet above €43 M), plus certain types identified regardless of size. An important entity is any other Annex I or Annex II entity. Essential entities face ex-ante and ex-post supervision, important entities ex-post supervision; the maximum fines differ (at least €10 M or 2 % of worldwide turnover, versus €7 M or 1.4 %), to be set by national law.

What does Article 21 of NIS2 require?

Technical, operational and organisational measures that are "appropriate and proportionate", covering at least ten areas: risk analysis, incident handling, business continuity, supply chain, secure development and vulnerability handling, assessing the effectiveness of measures, cyber hygiene and training, cryptography, human resources and access control, multi-factor authentication and secured communications. A penetration test is not named: it serves point (f), assessing effectiveness.

What are the Article 23 deadlines?

For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours (severity, impact, available indicators of compromise), an intermediate report on request, and a final report not later than one month after the notification. Trust service providers notify within 24 hours.

NIS2 in France: when does it apply?

There is no entry-into-force date yet. The bill on the resilience of critical infrastructure and the strengthening of cybersecurity was adopted by the Sénat on 12 March 2025 and its public session at the Assemblée nationale is scheduled for 7 October 2026; the law is not promulgated as of 4 October 2026. ANSSI offers a pre-registration and a self-test on messervices.cyber.gouv.fr/nis2 and published the Référentiel Cyber France (ReCyF) on 17 March 2026.

Does NIS2 apply to local authorities?

The Directive covers central and regional public administration (Annex I); local-level bodies are covered only where the Member State decides so (Article 2(5)). The text adopted by the French Sénat treats régions, départements and communes of more than 30,000 inhabitants, with their agglomeration communities, as essential entities, and communautés de communes active in a listed sector as important entities. That threshold is not final until the law is promulgated.

NIS2 vs ISO 27001: what is the difference?

NIS2 is a legal duty for listed entities, transposed into national law; ISO/IEC 27001 is a voluntary management-system standard, certified by a third-party body. The Directive does not require ISO 27001 and an ISO 27001 certificate is not NIS2 compliance; in practice the controls of an ISMS cover a large part of the Article 21 measures and the evidence can be reused.

NIS2 and DORA: which one applies to a financial entity?

DORA, Regulation (EU) 2022/2554, applicable since 17 January 2025. NIS2 Article 4 sets its provisions aside where a sector-specific act imposes at least equivalent duties, and Article 2(10) excludes entities exempted from DORA. DORA requires a resilience testing programme (Article 24) that lists penetration testing (Article 25) and reserves TLPT to entities designated by their authority (Article 26).

Is there a NIS2 audit or a NIS2 certification?

The Directive creates no "NIS2 certification". Audits and evidence are the entity's duty, checked by the competent authority: Article 21 requires assessing the effectiveness of measures and Article 21(4) corrective measures without undue delay. A documented penetration test is one piece of that file. Darkmoon does not certify compliance and issues no attestation.

Is a penetration test mandatory under NIS2?

Not by name: Article 21 names no test type and no frequency. It does require, at point (f), policies and procedures to assess the effectiveness of risk-management measures. A validated penetration test, with exploitation evidence, is a recognised way to produce that assessment, not the only one.

S.14Next
A perimeter to document? Describe the target, we scope it.

A managed engagement at a €799 flat rate (indicative, adjusted to the final scope), a legal framework signed online, the report and a debrief in a secure client space. Or self-host the open-source engine and keep everything on your side.