NIS 2, CER, DORA: the end of the grace period for organizations
After two years of delays, the transposition of the NIS 2 and CER directives into French law and the implementation of the DORA regulation are finally here. Both public and private organizations can no longer afford to wait. These regulations make cybersecurity a direct responsibility of executive leadership. They also shift the focus from a "best efforts" approach to a requirement for proven results: organizations must be able to identify risks, detect and report incidents, and rapidly restore operations. Given the volume of requirements—such as mapping, action plans, evidence, and compliance under Decree 2022-513—managing this via spreadsheets is no longer sufficient. Unified, purpose-built governance tools have become essential.

For nearly two years, the transposition of the NIS 2 and CER directives into French law, along with the implementation of the DORA regulation, was relegated to a technical matter. It was a text announced, then postponed. A European deadline that slipped month after month, to the point of becoming an insider's issue. However, recent events have served as a reminder of what these acronyms actually represent: the ability of the state, local authorities, hospitals, essential operators, and businesses to continue functioning in the aftermath of a cyberattack.
Testifying before the National Assembly's special committee, Anne Le Hénanff, Minister for Digital Affairs, made an observation that many would have preferred not to hear: the threat did not wait for the legislator to advance.
In recent months, several strategic government agencies have been hit. Incidents targeting the ANTS, the DGFIP, and other public bodies have shown that no organization is beyond reach. The risk no longer concerns only operators of vital importance; it extends to any organization whose activity relies on digital technology, from rural municipalities to international corporations.
The paradox is glaring. While attacks were multiplying, France was falling behind on the European texts specifically designed to strengthen organizational resilience.
That period is coming to an end. And that is precisely why public and private sector players can no longer afford to stall.
The obstacle was not legal
For a long time, many organizations justified their wait-and-see approach by the lack of a definitive legislative framework. The argument was understandable: it is difficult to secure budgets, launch a compliance program, or overhaul cyber governance without a passed law.
That argument no longer holds water. The guidelines for NIS 2, CER, and DORA have been known for years. The European texts are published, and the main obligations have been identified. The competent authorities have set out their expectations, and ANSSI has made a large portion of the necessary reference frameworks available to help organizations prepare for compliance.
Regulatory visibility was therefore already in place. What was often missing was the willingness to make tough decisions.
Preparing for NIS 2 or REC is about more than just filling out a few forms. It often requires rethinking your governance, risk analysis methods, detection capabilities, business continuity plans, crisis management, and third-party oversight. It is a cultural transformation. And like any transformation of this kind, it is disruptive.
Cybersecurity is moving out of the server room
For years, digital security was seen as a technical matter. Whenever the topic came up, it was handed off to the IT department or the CISO. Once the expert was appointed, the issue was considered settled.
That model is fading. NIS 2, REC, and DORA are driving a much deeper shift: cybersecurity is becoming a governance issue. This is arguably the core message from the minister's hearing.
Digital security now joins financial management, compliance, and human resources as a direct responsibility of executive leadership. This shift is far from trivial.
When an attack paralyzes a local authority, cripples a hospital, or leads to a massive exposure of personal data, the matter is no longer just technical. It becomes political, economic, legal, and sometimes societal. Its consequences extend far beyond the information system. It is this change in perspective that European regulations aim to enforce.
From resources to results
For a long time, compliance meant proving that you had put resources in place: antivirus software, a password policy, an IT charter, and a few occasional audits.
This mindset is giving way to much stricter requirements. What matters now is not what is written on paper, but what actually works in real-world conditions.
Organizations must now prove that they can identify their risks, manage them, detect incidents, report them, and quickly restore operations in the event of a crisis. Resilience has become the core concept.
This is where the accumulated backlog is concerning. Resilience cannot be mandated. It requires time, methodology, tools, solid documentation, regular exercises, and the long-term commitment of the entire organization. It is not the publication of a law in the Official Journal that makes an organization resilient, but a profound transformation of how it operates.
Local authorities and public bodies on the front line
Parliamentary debates have widely echoed the concerns of local authorities. These concerns are well-founded: many have limited resources, scarce expertise, and IT teams that are already stretched thin.
However, it would be risky to conclude that this transformation can wait. Local authorities have become prime targets. They hold sensitive data, provide essential services, and operate critical infrastructure at the local level. Above all, they sometimes represent the weak link in a much larger ecosystem.
An attacker does not necessarily target the most prestigious entity, but often the easiest one. This is what led the European Union to significantly expand the scope of entities covered: collective resilience is an illusion if entire sections of the system remain poorly protected.
No more spreadsheet management
This is one of the key takeaways from these texts: when faced with a mountain of requirements, manual management quickly reaches its limits.
Risk mapping, security measures, action plans, audits, certifications, controls, documentary evidence, gap analyses, and incident reporting: the volume is becoming overwhelming.
Many organizations have already experienced this scenario with GDPR. At first, a few Excel files and scattered procedures seemed sufficient. A few years later, the most mature ones had equipped themselves with genuine governance platforms to manage their compliance in a scalable, industrial way.
Cybersecurity is now following the same trajectory. The most advanced organizations are no longer just looking to be compliant; they are looking to manage that compliance sustainably. The distinction matters. One-off compliance reassures the auditor; continuous governance protects the organization.
Certifications: the overlooked challenge
Public debate naturally focuses on NIS 2, REC, and DORA. However, many government agencies must also contend with another structural obligation: security certification.
Decree 2022-513 has strengthened the requirements imposed on government agencies regarding the management of digital risks. Here again, the challenge goes beyond the technical: it is documentary, organizational, and methodological.
Conducting a security accreditation requires a clear vision of your information system, its risks, the measures deployed, and the decisions made by the competent authorities. This captures the very spirit of NIS 2: document, manage, and take ownership of your choices. Organizations that move forward with their accreditations are, in effect, preparing a significant portion of their future compliance.
Adequacy Cyber: A timely response
In this context, the launch of Adequacy Cyber on October 8th comes at the perfect time.
The goal is not to add yet another tool to the cyber toolkit, but to provide public and private organizations with a platform capable of supporting this new digital risk governance.
NIS 2 compliance, documentation of requirements, tracking action plans, gathering evidence, accreditations, and obligations stemming from Decree 2022-513: all these initiatives fundamentally address the same challenge—structuring risk management for the long term.
For too long, these obligations have been handled in silos. Legal teams managed compliance, CISOs handled risks, DPOs oversaw personal data, auditors managed controls, and business units handled their own processes. This fragmentation is no longer sustainable. On the contrary, new regulations call for unified governance.
The time for excuses is over
For two years, the delay in transposition gave many organizations an excuse to put off certain decisions. That time is over. The obligations are arriving, and audits will follow. As for incidents, they never took a break.
The question is no longer when to prepare, but whether you started early enough. Experience consistently shows that organizations that wait for regulatory pressure to act realize the complexity of the subject only when it is already too late.
NIS 2, CER, and DORA are not just a new set of rules. They mark the definitive entry of cybersecurity into strategic governance. Organizations that understand this will turn a constraint into an operational asset.
The others will learn the hard way the difference between compliance and resilience: the former is verified during an audit, the latter on the day the attack strikes.
FAQ - NIS 2, DORA, CER
What is the NIS 2 directive?
NIS 2 is a European directive adopted in 2022 that strengthens the cybersecurity of organizations deemed essential or important to the economy and society. It significantly expands the number of entities covered compared to the first NIS directive: in France, this is expected to grow from approximately 300 operators to over 15,000 entities. It specifically targets local authorities and players in the health, energy, transport, and digital sectors. It mandates risk management measures, incident notification obligations, and direct liability for management.
What is the difference between NIS 2, CER, and DORA?
NIS 2 focuses on the cybersecurity of essential and important entities. The CER (Critical Entities Resilience) directive focuses on the resilience of critical operators against primarily non-cyber threats: natural disasters, physical attacks, sabotage, and health crises. The cybersecurity of these operators falls under NIS 2. DORA is a regulation that applies specifically to the financial sector: banks, insurance companies, and their critical ICT service providers. It governs the digital operational resilience of this sector. These three texts share a common goal: ensuring business continuity in the face of crises.
Is my organization affected by NIS 2?
Your organization may be affected if it operates in one of the 18 sectors listed by the directive and exceeds certain size thresholds (headcount, turnover). Some entities are covered regardless of their size due to their critical role. Government administrations and a portion of local authorities also fall within the scope. In France, this represents nearly 1,000 inter-municipal authorities and approximately 300 municipalities with more than 30,000 inhabitants. An eligibility assessment is the first step to determine whether you are an "essential entity" or an "important entity."
Should you wait for the French transposition law to achieve compliance?
No. DORA is a European regulation and does not require transposition; it has been directly applicable since January 17, 2025. For NIS 2 and the CER directive, the main obligations have been known since the publication of the European directives. Furthermore, in March 2026, ANSSI published the Référentiel Cyber France (ReCyF) to help organizations prepare. Achieving compliance takes time: you must evolve your governance, risk analysis, detection, crisis management, and third-party oversight. Waiting for the final text risks creating a delay that will be difficult to overcome.
Who is responsible for NIS 2 compliance within the organization?
NIS 2 makes cybersecurity a responsibility of the management bodies. Executives must approve risk management measures, oversee their implementation, and undergo training. The CISO, CIO, DPO, and legal teams remain key players, but responsibility can no longer simply be delegated to the technical team.
What is the security accreditation required by Decree 2022-513?
Security accreditation is a formal decision by which an administrative authority accepts the residual risks of an information system before it goes live. It is based on a risk analysis and the security measures deployed. Decree 2022-513 strengthened these requirements for the information systems of the State and its public institutions. Conducting an accreditation process involves documenting your system, its risks, and your choices, which provides a significant foundation for NIS 2 compliance.
Why is a spreadsheet no longer sufficient for managing cyber compliance?
NIS 2, CER, and DORA increase the number of items that must be produced and kept up to date: risk maps, security measures, action plans, audits, documentary evidence, and incident notifications. A spreadsheet quickly becomes unmanageable, difficult to share between teams, and unreliable during an audit. A dedicated platform allows you to centralize these elements and ensure continuous compliance management.
How does Adequacy Cyber help with NIS 2 compliance?
Adequacy Cyber is a platform that enables public and private organizations to structure their digital risk governance. It covers the documentation of NIS 2 requirements, the tracking of action plans, the compilation of evidence, and the management of accreditations, including those stemming from Decree 2022-513. It brings together the work of CISOs, DPOs, legal counsel, and auditors—previously handled in silos—into a single tool.

