From the European deadline to actual readiness

This article revisits 2024 from a 2026 perspective; it is not presented as a publication issued in 2024. The NIS2 Directive set 17 October 2024 as the Member States' transposition deadline. That date does not automatically impose identical obligations on every French business. As of 4 October 2026, the ANSSI pages consulted still describe a national transposition process. An entity's applicable position needs assessment using current official texts and guidance.

Operational preparation can nevertheless progress without inventing legal status. A programme needs to understand exposed services, owners, existing measures and missing evidence. Another policy does not fix a backup that has never been restored or an alert chain nobody can activate. This article organises that work rather than providing a compliance certificate.

Illustrative scenario: a green report cannot restart the service

The people and numbers are fictional teaching examples, not claimed CYTIZEN client results. Marianne leads a manufacturer's operations. The cyber programme shows thirty documented measures out of thirty-two. The plant uses a scheduling application, industrial workstations and a remote-maintenance supplier. During a review, IT states that backups run daily.

Marianne asks how long recovery of the schedule would take after a data error. Nobody knows. The supplier holds a copy, but the procedure does not specify which version to restore, required permissions or production's acceptance checks. A successful backup is therefore different evidence from successful service recovery.

The team chooses one pilot service: preparing the following day's schedule. It identifies the business owner, data source, interfaces, permissions and recovery sequence. The sponsor retains the documentary report but adds a demonstration status. A measure can be written, implemented and tested to different degrees; those states should no longer be confused.

Assess scope without making the programme a legal practice

The first record distinguishes legal entities, activities, locations and services provided. Competent functions examine legal scope, criteria and any designations. Programme leadership collects those facts and maintains decisions. It does not alone decide that a business falls inside or outside a regulatory category.

A group may contain entities and countries with different obligations. Supplying a covered organisation does not automatically put the supplier in the same scope. The customer may, however, require contractual commitments or security evidence. Distinguish the organisation's own obligation, a commitment to a customer and an internal risk-reduction choice.

In the scenario, the scope record includes classification to confirm, a legal owner and a documentary reference. That uncertainty does not prevent correcting excessive maintenance access. Uncertainty about status is not a reason to leave a known operational risk without an owner.

Connect measures with observable evidence

TopicInsufficient stateEvidence example
Remote supplier accessSigned policyNamed account, limited permissions, controlled activation and tested removal
RestorationSuccessful backup reportSchedule restored in an authorised environment and data reconciled
AlertOld telephone listContact exercise including deputies and timeline
VulnerabilitiesList without a decisionExposure-based priority, owner, verified fix or compensating measure
SuppliersQuestionnaire receivedIdentified gap, contractual or technical action and closure evidence

Evidence should not cost more to maintain than the measure it describes. Retain an identifier, date, owner and retrieval location. Flag expired evidence and evidence invalidated by change. Copying the same screenshot into five folders does not multiply control.

Write success conditions before the exercise. For the illustrative schedule, they include restoration of an identified version, checks on ten test production orders, matching quantities and business authorisation to restart. Ten is a scenario parameter; the actual set depends on risks and production variants. Preserve failed checks as well as successful ones so the record explains the decision.

The recovery test exposes forgotten dependencies

The first rehearsal finds that restoration needs an account owned by an absent employee and an interface file excluded from backup. The team has not demonstrated its local recovery objective. Starting the server is not enough. Marianne needs a usable schedule and assurance that completed operations will not be repeated.

The timeline separates detection, decision, technical restoration, checks and service resumption. In the exercise, fifty minutes are spent finding access, forty restoring and thirty reconciling data: two hours overall. The breakdown shows where to act. Replacing it with incident resolved in two hours would lose the information needed for the next event.

The report creates two specific actions: make emergency access available to an authorised deputy and include the interface file in recovery procedures. Each has a closure test. General cyber-awareness training would solve neither missing access nor the absent file.

The team also checks whether restoration assumptions hold during a supplier outage. A procedure that depends on a remote specialist may work when the supplier is available and fail when that dependency is the incident itself. Record this uncovered scenario and decide whether another test, a local capability or an accepted temporary restriction is needed.

Prepare alert decisions and communication

The arrangement specifies who receives the signal, coordinates the incident, evaluates consequences and checks notification obligations. Applicable legal deadlines require competent review of the relevant texts and circumstances. The programme should not replace that analysis with an invented internal deadline labelled as a regulatory rule.

A tabletop exercise can test whether the team quickly assembles facts: affected service, time of awareness, users involved, potentially affected data, measures taken and uncertainties. The record preserves changes and avoids turning an initial estimate into a definitive fact. Communication uses validated information and identifies when the next update will be issued.

Provide a deputy and a channel independent of the failed service. A procedure stored only in the unavailable environment is not a reliable coordination mechanism. Test contactability without issuing false external alerts: simulation participants and channels are identified in advance. The exercise should establish who can approve a message when the ordinary approver is unavailable.

Prioritise a portfolio with visible criticality

The programme register should not rank actions solely by age. Describe the affected service, exposure, current protection, owner and decision needed. A recent issue involving exposed privileged access may be more urgent than an old document. Security proposes technical priority, the business describes consequences and the sponsor allocates capacity and commitments.

A completed example could state: remote maintenance still uses a shared account with three users; industrial operations is accountable; the intended solution is named accounts and time-limited activation; suspend access immediately if an unassignable connection is observed; closure requires a demonstrated opening and revocation. That record enables a practical discussion without claiming to cover every NIS2 requirement.

Measure scope coverage, action completion and evidence validity separately. Describing eight services out of ten does not mean eight are controlled. If the two missing ones support the main production activity, their criticality belongs in the decision. An average score should not erase those gaps.

Capacity planning also matters. A list of high-priority corrections without engineers, supplier involvement or production windows is not an executable plan. Show the next available opportunity and interim protection for each material action. The sponsor can then decide whether to change resources or accept a clearly described delay within their authority.

Transfer maintenance into ordinary operations

After initial preparation, service owners update dependencies, security follows measures, procurement relays supplier changes and operations retests affected procedures. Programme coordination preserves decisions and handles reviews beyond local authority. Valid evidence should not depend on retaining a project team forever.

Changes to suppliers, access, applications and business processes trigger impact assessment. A new interface can make an earlier exercise incomplete. The service must know which evidence is invalidated and who authorises the changed operation. Periodic reviews complement this trigger rather than replacing it.

The sponsor receives a concise view of principal risks, missing evidence, decisions required and dates. Page count does not measure readiness. A failed or refused demonstration can represent progress when it reveals a previously invisible dependency and produces an actionable decision. The report should explain that learning rather than disguise the failure as a documentation issue.

Different operations need different evidence

In industry, remote access must respect process safety and intervention windows. A technical fix cannot be improvised during production without coordination with industrial owners. Recovery validates both data and the relevant physical state of the schedule. The service owner must understand how a digital discrepancy could affect the next production sequence.

For healthcare organisations, unavailability may affect access to information required for care. Priorities and degraded modes are defined with accountable functions. An IT availability indicator alone does not describe the consequence for people. The exercise should make communication and authorised manual procedures visible.

In digital services, examine shared dependencies and customer commitments. A fallback using the same identity and network providers does not cover every scenario. The record states what is truly independent and what remains common, allowing the sponsor to understand the limits of the proposed alternative.

Sources, method and limitations

Primary sources consulted on 4 October 2026: European Commission on the NIS2 Directive; ANSSI presentation of NIS2; ANSSI MesServicesCyber NIS2. These sources distinguish the European timetable from the national framework requiring verification.

The method connects services, owners, measures and demonstrations. Every time, volume and threshold in the case is illustrative. Legal obligations, notifications and scope criteria must be assessed for the entity and country involved. The article provides a preparation and coordination method; it certifies neither an organisation's regulatory scope nor its compliance.