Directive (EU) 2022/2555

Tooling for NIS2 without promising compliance.

The NIS2 directive requires essential and important entities to manage their risks, involve their management and report their incidents. TechWatchAlert provides tooling for the part of these obligations that concerns vulnerabilities, inventory, suppliers and incidents, and produces the evidence an auditor asks for.

In short

  • In France, the transposition law has not yet been finally adopted as of September 23, 2026; ANSSI has already published its ReCyF framework.
  • TechWatchAlert provides tooling for monitoring, the register of accepted risks, remediation deadlines, inventory reviews, the supplier register, incident reporting and the report for management.
  • It certifies nothing, reports nothing to ANSSI on your behalf and does not replace legal advice.
  • The compliance space is included in the Plus, Pro and Enterprise plans.

What NIS2 requires

Directive (EU) 2022/2555, known as NIS2, applies to essential and important entities in eighteen sectors. ANSSI estimates that about 15,000 entities are concerned in France. Three articles carry most of the obligations.

  • Article 20, governance. Management bodies approve the risk-management measures, oversee their implementation and can be held liable for infringements. Their members are required to follow training.
  • Article 21, risk management. Ten areas of measures, including incident handling, supply chain security, vulnerability handling and disclosure, assessing the effectiveness of measures, and asset management.
  • Article 23, reporting of significant incidents. An early warning within 24 hours of becoming aware, an incident notification within 72 hours, then a final report no later than one month after the notification.

For digital service providers (cloud computing, managed services and managed security services, data centers, DNS, online marketplaces, search engines, social networks, trust services…), Implementing Regulation (EU) 2024/2690 details these measures point by point. Among other things, it requires them to obtain information on vulnerabilities through appropriate channels, including CSIRT announcements (point 6.10 of its annex).

Where France stands

Transposition goes through the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, known as the “Résilience” bill. The Senate adopted it in March 2025; as of September 23, 2026, it has not yet been finally adopted. In July 2026, the European Commission brought proceedings against several Member States that were late in transposing the directive.

Without waiting for the law, ANSSI published its ReCyF framework (Référentiel Cyber France) on March 17, 2026: 20 security objectives, 15 for all regulated entities and 5 more for essential entities. It is not mandatory by default, but an entity that applies it will be able to rely on it during an inspection.

At EU level, ENISA has been running the European Vulnerability Database (EUVD), provided for by Article 12 of the directive, since May 2025.

What TechWatchAlert provides tooling for

Each module addresses a specific obligation and leaves a dated trace. Registers are never rewritten: a decision is closed and another one replaces it, which keeps the history readable for an auditor.

Mapping between the modules and the texts. References to Regulation 2024/2690 only apply to the digital service providers it covers.
ModuleWhat it doesTexts
Monitoring, including national CSIRTsNine vulnerability feeds, including CERT-FR advisories and alerts and ENISA’s EUVD database. Exploitation reported by KEV, CERT-FR or the EUVD counts as confirmed exploitation, and the default prioritization puts it first.Art. 21.2.e; Regulation 2024/2690, point 6.10
Register of accepted risksDeferring a patch becomes a justified request: rationale, compensating measures, review date. Management approves or rejects it, never the requester themselves when another approver exists. When the date comes, the risk goes back into review.Art. 20; Regulation 2024/2690, point 6.6
Remediation deadlines and escalationA remediation policy by severity, tightened when exploitation is confirmed and adjusted to asset criticality. Each open CVE gets a deadline: a reminder before it, an alert when it is missed, then escalation to the CISO.Regulation 2024/2690, points 6.6 and 6.10
Asset criticality and inventory reviewsEach project and each component carries a criticality (vital, important, standard, low). The periodic inventory review is attested and dated, and every SBOM import is recorded as evidence.Art. 21.2.i; Regulation 2024/2690, point 12
Supplier registerFed from the vendors in your stack, then qualified: criticality, security contact, contract clauses, data location, periodic assessments. For each supplier: open CVEs, exploited CVEs, end-of-life dates.Art. 21.2.d and 21.3; Regulation 2024/2690, point 5
IncidentsIncident register, qualification, computed deadlines (24 hours and 72 hours after becoming aware, one month after the notification), reminders, pre-filled report templates to copy, and a timestamped log.Art. 23
Report for managementIndicators per obligation and a PDF report for management: summary, mapping to the texts, register appendices.Art. 20 and 21.2.f

Roles are assigned within the organization: management, CISO, incident contact. By default, management falls to the organization’s owners, the CISO role to management and the incident contact to the CISO.

What TechWatchAlert does not do

  • No certification. No tool is enough to bring an organization into line with NIS2. TechWatchAlert produces evidence; your organization, and where relevant ANSSI, draw the conclusions.
  • No automatic reporting. The tool prepares the incident report and keeps a record of it; you are the one who submits it to ANSSI, through its channels.
  • No legal advice. Whether your organization is an essential or important entity, and what French law will require of it, is a matter for ANSSI and your advisers.
  • Not all of Article 21. Business continuity and backups, cryptography, human resources security, access control to your own systems, training: these areas are handled elsewhere.

Plans concerned

The compliance space is included in the Plus, Pro and Enterprise plans; it is not available on the free plan. CERT-FR advisories and alerts and EUVD entries, on the other hand, are visible on every plan: they are vulnerability data like any other. Compare the plans.

And TechWatchAlert as a supplier?

If you are subject to NIS2, we are part of your supply chain (Article 21.2.d). Our Security page brings together what a supplier assessment usually asks for: hosting, subprocessors and transfer safeguards, measures in place, disclosure contact.

FAQ

Does TechWatchAlert make my organization NIS2-compliant?

No, and no tool can. TechWatchAlert provides tooling for part of the obligations (monitoring, patching, inventory, suppliers, incidents) and produces dated evidence. Compliance is assessed on all of your measures, by your organization and, where relevant, by ANSSI.

Should we wait for the French law before starting?

That choice is yours. The directive already sets the framework, and ANSSI’s ReCyF framework has been available since March 2026. Keeping your registers from now on gives you a history to show on the day the obligations apply.

Does TechWatchAlert send the incident report to ANSSI?

No. The tool computes the deadlines (24 hours and 72 hours after becoming aware, one month after the notification), reminds you of them, prepares pre-filled templates and logs every step. Submission remains your responsibility, through ANSSI’s channels.

Does NIS2 ban American providers such as Cloudflare?

No. NIS2 asks you to assess the risks tied to your suppliers, not to exclude a nationality. In France, it is the SREN law (Article 31) that requires SecNumCloud-type offerings for certain public administrations handling sensitive data. TechWatchAlert is not SecNumCloud-qualified and publishes the list of its subprocessors on its Security page.

Which plans include the compliance space?

Plus, Pro and Enterprise. The free plan does not give access to it, but like the others it shows the CERT-FR advisories and EUVD entries linked to your CVEs.

Plus, Pro and Enterprise plans

Your NIS2 evidence, where your monitoring already lives.

Register of accepted risks, remediation deadlines, inventory reviews, suppliers, incidents and a report for management, in the tool that already tracks your vulnerabilities. Start with the free plan; the compliance space opens from the Plus plan up.

  • Subprocessors published
  • Built & hosted in France
  • Export your data at any time
Create a free account