Regulation, entities concerned, obligations: the essentials of the directive and why the continuity of your document assets is becoming strategic
NIS 2 is no longer a distant topic: with around 15,000 French entities soon to be concerned, penalties of up to €10M or 2% of worldwide turnover, and direct liability for executives, the directive is redefining cybersecurity requirements.
Protecting your data and guaranteeing the continuity of your document-based activities is becoming a compliance issue in its own right: this is precisely the purpose of the GoFAST Protect offer.
What exactly is NIS 2?
The European NIS 2 directive (Directive (EU) 2022/2555), published at the end of 2022, succeeds NIS 1 with a clear ambition: to massively raise the cybersecurity level of European organizations in the face of multiplying cyberattacks, ransomware and data breaches.
The change of scale is spectacular: where NIS 1 concerned a few hundred entities in France, NIS 2 targets around 15,000. The French transposition is carried by the "Résilience" law (resilience of critical infrastructure and strengthening of cybersecurity), adopted by the Senate in March 2025 and currently under review by the National Assembly. Pending its enactment, ANSSI published the Référentiel Cyber France (ReCyF) in March 2026, which already translates NIS 2 obligations into concrete security objectives: the substance of compliance is known, only the enforcement date remains open.
Who is concerned by NIS 2?
NIS 2 distinguishes between Essential Entities and Important Entities, spread across 18 sectors of activity:
- Public sector: administrations, and in France local authorities fall within the scope (regions, departments, municipalities of more than 30,000 inhabitants and their groupings)
- Critical sectors: energy, transport, healthcare, water, digital infrastructure, banking and finance
- Mid-caps and large companies: industry, agri-food, chemicals, digital services, research, from 50 employees and €10M in turnover depending on the sector
- By cascade effect: subcontractors and suppliers of regulated entities, through the cyber clauses and security questionnaires already circulating in calls for tenders
What is at stake: governance, incidents, executive liability
NIS 2 imposes structuring obligations:
- Risk management: risk analysis, information system security policies, supply chain security
- Incident notification: early warning within 24 hours in the event of a significant incident
- Business continuity: Article 21 requires backups, business continuity and disaster recovery plans (BCP/DRP) and crisis management
- Executive liability: cybersecurity is no longer the CIO's concern alone — management bodies are now personally responsible for approving and supervising the measures
- Penalties: up to €10M or 2% of worldwide turnover for essential entities
Protecting your data: the heart of the matter
Behind the requirements of NIS 2 lies a simple reality: documents are the organization's information assets. Contracts, procedures, HR data, sensitive files, crisis plans: this is precisely what attackers target, and what the regulation requires you to protect, trace and restore.
Yet many organizations entrust these entire assets to a single ecosystem, often Microsoft 365, exposed to extraterritorial laws such as the Cloud Act: data remains accessible upon request regardless of the datacenter's location. A dependency that raises both a sovereignty and a business continuity question: what happens when Microsoft 365 goes down (global outage, cyberattack, access blocked)? Every hour of interruption comes at a cost: paralyzed activity, blocked teams, interrupted services, and for major incidents, heavy financial losses and reputational damage.
GoFAST, the collaborative, sovereign and open-source platform
GoFAST, the sovereign and open-source collaboration and document management platform, provides native answers to the directive's requirements:
- Sovereignty: On-Premise deployment or hosting on SecNumCloud-qualified infrastructure with European providers, out of reach of extraterritorial laws
- Access control and classification: fine-grained permissions management, compartmentalized spaces, C0 to C3 / EUCS / TLP classification levels with the impossibility of extracting sensitive documents
- Traceability and document governance: versioning, audit trail, validation workflows — the very evidence expected in the event of an audit
- Open-source and auditable: a platform built on proven components (Alfresco ECM, Bonita BPM, OnlyOffice), with no black box
GoFAST Protect: your backup environment for BCP/DRP
Which leaves the question NIS 2 now forces you to ask: if your Microsoft 365 environment is unavailable tomorrow morning, how do your teams keep working?
GoFAST Protect is the answer: a dedicated backup environment, totally independent and decorrelated from Microsoft, ready to be activated. GoFAST does not rely on any Microsoft component: your backup platform keeps running even when the main ecosystem is down.
- Functional continuity: guaranteed access to critical documents, procedures and spaces, with DMS, collaborative spaces, co-editing, videoconferencing, chat, workflows and forms: the activity continues, not just the data
- Ransomware resistance: more than a simple backup, a compartmentalized environment capable of restarting your activities within a controlled perimeter, and of restarting from healthy data in the event of a compromise, without depending on the attacked ecosystem
- Controlled recovery: the backup environment is set up, tested and ready to take over before the incident, not improvised in an emergency
- Simple and predictable business model: a single annual On-Premise subscription, with optional synchronization from your production platform (SharePoint, file server, etc.)
Anticipating means turning a regulatory constraint into an advantage: an organization that controls its data, its access and its business continuity is quite simply more resilient.
Assess your resilience level with GoFAST Protect : let's start from your critical activities and the BCP/DRP arrangement suited to your challenges.
Sources:
https://cyber.gouv.fr/reglementation/cybersecurite-systemes-dinformation/directives-nis-nis2-et-dispositif-saiv/directive-nis-2/
https://www.nis-2-directive.com/Transposition/France.html
https://forge-agency.fr/blog/nis2-loi-resilience-2026-pme-dirigeant-guide-pratique
https://www.leto.legal/news/nis2-transposition-septembre-2026
https://www.legiscope.com/blog/transposition-nis2-france.html