{"id":15388,"date":"2025-05-07T12:54:46","date_gmt":"2025-05-07T10:54:46","guid":{"rendered":"https:\/\/www.poggi-avocats.com\/?p=15388"},"modified":"2025-05-07T12:54:47","modified_gmt":"2025-05-07T10:54:47","slug":"transposition-of-nis-2","status":"publish","type":"post","link":"https:\/\/www.poggi-avocats.com\/en\/transposition-de-nis-2","title":{"rendered":"Transposition of NIS 2"},"content":{"rendered":"<p class=\"wp-block-paragraph\">The ANSSI recently published its panorama of the cyberthreat 2024, a richly informative document that I invite you to consult. This overview looks at the means used by attackers and the vulnerabilities exploited. The year was particularly marked by vulnerabilities affecting security equipment located at the edge of information systems and by attacks targeting the supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In June 2024, a survey conducted by ANSSI among the members of CLUSIF, an association of cyber professionals, revealed that an attack costs an average of between 5 and 10 % of an organisation's turnover. These costs can be broken down into operating losses, the cost of external support and restoration services, and damage to reputation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bill on \"the resilience of critical infrastructures and the strengthening of cybersecurity\", adopted by the Senate on 12 March, is now being examined in committee by the French National Assembly. The bill aims to transpose the ECN, NIS2 and DORA directives. The REC directive updates the security arrangements for critical activities, while the DORA directive concerns the financial, banking and insurance sectors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a reminder, the aim of the NIS2 directive is to strengthen the cybersecurity of around 15,000 essential entities and 1,500 local and regional authorities. The application criteria include sectoral and size criteria. The sectors targeted include providers of digital infrastructure and information and communication services. In terms of size, players with fewer than 50 employees and a turnover of less than \u20ac10 million are not affected. Finally, organisations already subject to equivalent sector-specific regulations will not be affected either.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is up to each organisation, whether public or private, to check whether it is affected by NIS2 and, if so, to declare itself to ANSSI. To facilitate this process, ANSSI has opened a dedicated page, \"monespacenis2.cyber.gouv.fr\", which includes an online test to determine whether your entity is regulated by NIS 2. This test has no legal value and should be confirmed by a more detailed analysis if necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your organisation is regulated by NIS2, incidents will have to be reported to ANSSI. The bill defines an incident as \"an event compromising the availability, authenticity, integrity or confidentiality of data\".<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Vincent Strubel, Director of the ANSSI, has announced a three-year compliance period, during which investment in cyber security will have to be demonstrated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After this period, administrative fines may reach \u20ac10 million or 2 % of annual worldwide turnover.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The next steps are the final adoption of the law, the implementing decrees, and then the publication of technical guidelines by ANSSI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>The ANSSI recently published its panorama of the cyberthreat 2024, a richly informative document that I invite you to consult. This overview looks at the means used by attackers and the vulnerabilities exploited. The year was particularly marked by vulnerabilities affecting security equipment located at the edge of IS ... <a title=\"Transposition of NIS 2\" class=\"read-more\" href=\"https:\/\/www.poggi-avocats.com\/en\/transposition-de-nis-2\" aria-label=\"Read more about Transposition of NIS 2\">Read more<\/a><\/p>","protected":false},"author":4,"featured_media":10246,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"Transposition de NIS 2","_seopress_titles_desc":"Le projet de loi relatif \u00e0 \u00ab la r\u00e9silience des infrastructures critiques et au renforcement de la cybers\u00e9curit\u00e9 \u00bb, adopt\u00e9 au S\u00e9nat le 12 mars, est d\u00e9sormais examin\u00e9 en commission \u00e0 l\u2019Assembl\u00e9e. Ce projet de loi vise \u00e0 transposer les directives REC, NIS2 et DORA. La directive REC actualise les dispositifs de s\u00e9curit\u00e9 des activit\u00e9s vitales, tandis que la directive DORA concerne les secteurs financier, bancaire et assurantiel.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"none","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","footnotes":""},"categories":[1,31],"tags":[56,54,57,55],"class_list":["post-15388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualites","category-cybersecurite","tag-anssi","tag-cyber","tag-loi-relatif-a-la-resilience-des-infrastructures-critiques-et-au-renforcement-de-la-cybersecurite","tag-nis-2"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/posts\/15388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/comments?post=15388"}],"version-history":[{"count":1,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/posts\/15388\/revisions"}],"predecessor-version":[{"id":15391,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/posts\/15388\/revisions\/15391"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/media\/10246"}],"wp:attachment":[{"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/media?parent=15388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/categories?post=15388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.poggi-avocats.com\/en\/wp-json\/wp\/v2\/tags?post=15388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}