Directive NIS2 European Union
ReCyF · first publication

Référentiel Cyber France

NIS2 says what you must achieve, never how you demonstrate it. France answers with ReCyF. If you operate there, this is what your regulator reads.

Published
Implementation routes
2
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

ReCyF is a recommendation framework, not a certification scheme: there is no ReCyF label to hold. It also sits on a law that is not yet promulgated — the loi résilience was still before Parliament in July 2026 — so the binding obligations remain to be fixed by implementing decree. Treat ReCyF as the best available statement of what ANSSI will expect, not as settled law.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the recognised international route, and ANSSI sector reference documents apply to specific activities.

Implementation routes

2 routes, chosen by scope and depth


Entité importante

The lighter grade of the same measures.

Important entities

Entité essentielle

The full grade, with ex ante supervision.

Essential entities

What it is built on

ReCyF does not invent its own taxonomy. It sits on The security objectives of NIS2, restated as graduated measures.

Organised by security objective rather than by control catalogue, with measures graduated according to whether the entity is important or essential. ANSSI has indicated entities would have roughly three years from publication of the technical requirements to reach full compliance.

Mapping

Why there is no unit-level mapping


Basis

ReCyF is organised by security objective rather than by numbered control catalogue, with measures graduated according to whether the entity is important or essential.

Limit of this mapping

No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.

No stable public identifiers to map against

This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.

The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. ReCyF is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to ReCyF and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training 5.37 6.3 8.7 AT SI CM
(h) Cryptography 8.24 SC
(i) HR, access, assets 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

France

France Transposition Pack

NIS2 as transposed in France: ANSSI as competent authority, entity classification, and the national registration procedure.

  • National reference document (Markdown): what binds you in France, not the directive
  • The national law, its adoption and entry-into-force dates, and its current status
  • How France numbers the article 21(2) measures, and any measure it adds
  • Registration channel and portal, with the deadline rule
  • Supervision: who inspects, and from when
  • Référentiel Cyber France (ReCyF): the two entity grades, and the plain warning that it sits on a law which is not yet promulgated
  • Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
129 € excl. VAT

Instant download · 30-day money-back guarantee

Sources

We are not affiliated with Agence nationale de la sécurité des systèmes d'information (ANSSI). ReCyF and related marks belong to their owners.

Cart 0