Référentiel Cyber France
NIS2 says what you must achieve, never how you demonstrate it. France answers with ReCyF. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
ReCyF is a recommendation framework, not a certification scheme: there is no ReCyF label to hold. It also sits on a law that is not yet promulgated — the loi résilience was still before Parliament in July 2026 — so the binding obligations remain to be fixed by implementing decree. Treat ReCyF as the best available statement of what ANSSI will expect, not as settled law.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the recognised international route, and ANSSI sector reference documents apply to specific activities.
2 routes, chosen by scope and depth
The lighter grade of the same measures.
Important entities
The full grade, with ex ante supervision.
Essential entities
What it is built on
ReCyF does not invent its own taxonomy. It sits on The security objectives of NIS2, restated as graduated measures.
Organised by security objective rather than by control catalogue, with measures graduated according to whether the entity is important or essential. ANSSI has indicated entities would have roughly three years from publication of the technical requirements to reach full compliance.
Why there is no unit-level mapping
ReCyF is organised by security objective rather than by numbered control catalogue, with measures graduated according to whether the entity is important or essential.
No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.
No stable public identifiers to map against
This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.
What you already have, for the same measure
Nobody in scope starts from nothing. ReCyF is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
France Transposition Pack
NIS2 as transposed in France: ANSSI as competent authority, entity classification, and the national registration procedure.
- National reference document (Markdown): what binds you in France, not the directive
- The national law, its adoption and entry-into-force dates, and its current status
- How France numbers the article 21(2) measures, and any measure it adds
- Registration channel and portal, with the deadline rule
- Supervision: who inspects, and from when
- Référentiel Cyber France (ReCyF): the two entity grades, and the plain warning that it sits on a law which is not yet promulgated
- Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
Instant download · 30-day money-back guarantee
We are not affiliated with Agence nationale de la sécurité des systèmes d'information (ANSSI). ReCyF and related marks belong to their owners.