Back to blog
Compliance & Regulation14 min read

Eyako × ReCyF ANSSI
Mapping, checklist and continuous monitoring

By Eyako — The CISO Command Platform · Updated: August 2026

ReCyFANSSINIS2ConformitéPME ETI

The ReCyF (Référentiel Cyber France) by ANSSI is now the reference framework for NIS2 audits in France. This guide gives you the complete mapping, a practical checklist and an implementation plan.

What this guide gives you

  • The complete mapping of the 10 ReCyF domains and what Eyako covers natively.
  • The interactive self-assessment — 33 points across the 10 domains, with the expected evidence.
  • The implementation plan — where to start if you are beginning from scratch.

Part 1 — The ReCyF in 5 minutes

What is the ReCyF?

The Référentiel Cyber France (ReCyF) is the operational framework published by ANSSI to translate the NIS2 directive into concrete, verifiable requirements. It organizes the obligations into 10 control domains, each with expected measures and evidence to produce during an audit.

The ReCyF applies to essential entities (EE) and important entities (EI) under NIS2 — thousands of French organizations across health, energy, transport, finance, digital infrastructure and more.

What the ReCyF concretely changes

Before the ReCyF, NIS2 compliance stayed abstract — a hard-to-audit obligation of means. The ReCyF makes compliance auditable, domain by domain, evidence by evidence. The question auditors will now ask is no longer "are you NIS2 compliant?" It is:

"Show me how you manage each of these 10 domains, with the corresponding evidence."

Why most CISOs are not ready

The vast majority of SME and mid-market CISOs we meet already have the right controls in place. What they lack is the continuous demonstration of those controls — the layer that centralizes evidence, keeps it current, and makes it exportable on demand. That is exactly the problem Eyako solves.

Part 2 — Mapping Eyako × the 10 ReCyF domains

How to read the table

Direct coverageEyako handles this domain natively, with exportable evidence.
Coverage via monitoringEyako aggregates and monitors data from your existing tools for this domain.
Coverage via integrationEyako integrates your specialized tools and centralizes the key indicators.

1Governance

Direct coverage

What the ReCyF requires:

  • A formalized security policy, signed by management, dated less than 12 months ago
  • A documented, up-to-date cyber program covering the current period
  • A traceable cyber budget linked to risk-reduction objectives
  • Planned and documented management reviews

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Cyber program dashboardConsolidated program view, continuously updated
Security policy managementVersion history, approval dates, signatories
Management review trackingReview minutes, agenda, attendees, decisions
Board reportingDated PDF exports of board presentations

What the auditor will accept: Eyako program export → current policy with management approval date → latest review minutes.

2Risk management

Direct coverage

What the ReCyF requires:

  • A formalized risk analysis with documented methodology
  • A treatment plan with named owners and deadlines
  • Residual risks arbitrated by management (not just the CISO)
  • A risk map review at least annually

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Risk mappingRisk register with methodology and update date
Treatment plan managementRemediation actions with owner, deadline and real-time status
Management arbitrationHistory of residual risks approved by management
Escalation alertsTraceability of escalated risks and decisions taken

What the auditor will accept: Risk map export → treatment plan with status → evidence of management arbitration.

3Human resources

Coverage via monitoring

What the ReCyF requires:

  • A formalized cybersecurity awareness program
  • Training tracking with completion rates
  • An offboarding procedure (access revocation)

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Awareness KPI monitoringDashboard with simulated phishing rate and training rate
Integration with your training toolsData from KnowBe4, Proofpoint, etc. centralized
Offboarding action trackingAccess closure checklist with traceability

What the auditor will accept: Awareness KPI dashboard → training rate per period → access revocation log.

4Assets & configuration

Coverage via integration

What the ReCyF requires:

  • An up-to-date critical asset inventory
  • Vulnerability management with prioritization
  • Patch management tracking

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Unified vulnerability viewConsolidated data from your scanners (Tenable, Qualys, Wiz…)
Patch management trackingPatch coverage indicators, remediation timelines
Critical asset mappingView of at-risk assets with exposure level

What the auditor will accept: Open vulnerabilities by severity → remediation timelines → patch coverage of critical assets.

5Access control

Coverage via monitoring

What the ReCyF requires:

  • Identity and privilege management (IAM)
  • Documented periodic access reviews
  • Privileged account management

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
IAM risk monitoringAccess drift indicators, inactive accounts, excessive privileges
Access review monitoringScheduling, completion tracking, centralized results
Access remediation actionsRemediation plans with owner and deadline

What the auditor will accept: Latest access review results → open actions with deadlines → current IAM indicators.

6Security operations

Coverage via integration

What the ReCyF requires:

  • Anomaly detection (SIEM, logs)
  • Operational patch management
  • Logging of critical systems

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Operational posture dashboardConsolidated view of SIEM alerts and indicators
Open vulnerability trackingProcessing times, remediation SLAs
Logging coverageLog coverage indicators per critical system

What the auditor will accept: SIEM coverage level view → remediation timelines → logging indicators.

7Incident management

Direct coverage

What the ReCyF requires:

  • A formalized and tested incident management procedure
  • Notification within 24h (initial alert) and 72h (detailed report)
  • A documented post-mortem after every significant incident

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Incident registerComplete history with timeline, severity, status
Notification trackingDetection, alert and ANSSI notification timestamps
NIS2 report templatesIncident reports in the expected format, exportable
Formalized post-mortemStructured and archived lessons learned

What the auditor will accept: Export of the last significant incident → timeline → proof of on-time notification → associated post-mortem.

8Business continuity

Direct coverage

What the ReCyF requires:

  • A documented business continuity plan (BCP)
  • Defined and justified RTO/RPO
  • BCP tests performed and documented within the last 12 months

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
BCP managementVersioned BCP document with update status
Test trackingTest scheduling, results, identified gaps
BCP alertsAutomatic notification if the annual test is not scheduled
RTO/RPO per systemDocumentation of objectives per critical asset

What the auditor will accept: Current BCP → latest test results → gaps and associated remediation.

9Supply chain (TPRM)

Direct coverage

What the ReCyF requires:

  • Identification of critical suppliers
  • Security assessment of each critical supplier at least annually
  • Appropriate cyber contractual clauses
  • A procedure in case of supplier compromise

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
Critical supplier registerPrioritized list with criticality and assessment dates
Supplier scoringAssessment results with history
Questionnaire trackingResponse rate, reminders, pending assessments
Renewal alertsNotification before assessments expire

What the auditor will accept: Supplier register → assessments from the last 12 months for critical suppliers → current risk scoring.

10Compliance & audit

Direct coverage

What the ReCyF requires:

  • A measurable and up-to-date compliance status
  • A formalized regulatory watch
  • Accessible and organized evidence for the auditor

What Eyako covers:

Eyako capabilityEvidence produced for the auditor
ReCyF/NIS2 compliance dashboardReal-time view of coverage per domain
Auditor exportComplete evidence package exportable on demand
Built-in regulatory watchAlerts on NIS2, DORA and ReCyF changes
Compliance status historyCoverage evolution over time

What the auditor will accept: Compliance dashboard export → evidence per domain → evolution history.

Summary: Eyako × ReCyF coverage

ReCyF domainEyako coverageType
1. GovernanceCompleteNative
2. Risk managementCompleteNative
3. Human resourcesMonitoringVia KPIs
4. Assets & configurationMonitoringVia integrations
5. Access controlMonitoringVia integrations
6. Security operationsMonitoringVia integrations
7. Incident managementCompleteNative
8. Business continuityCompleteNative
9. Supply chainCompleteNative
10. Compliance & auditCompleteNative

Eyako directly covers 6 of the 10 ReCyF domains. For the other 4 (human resources, assets, access, operations), Eyako provides the monitoring layer via your existing tools.

Part 3 — The 33-point ReCyF self-assessment

Rather than a static checklist, we built an interactive self-assessment covering the 10 domains in 33 points. For each control, the question is binary: can you produce the evidence right now, without preparation? You get your score and its interpretation in 15 minutes.

Self-assessment NIS2 / ReCyF in 33 points

An interactive scorecard aligned with the Référentiel Cyber France (ReCyF): tick what you can prove, watch your score update live, and read where your compliance file will hold — or give way. Printable in A4.

10 domains · 33 controls · ~15 minutes

Start the self-assessment

Part 4 — ReCyF implementation plan with Eyako

Step 1 — Map your current coverage

Start with the 6 domains covered directly by Eyako: governance, risk, incidents, continuity, suppliers, compliance. Configure the matching modules and import your existing data.

Expected outcome: A ReCyF compliance dashboard with your starting baseline.

Step 2 — Connect your existing tools

Enable Eyako integrations for your operational security tools (vulnerability scanner, SIEM, IAM platform, training tool). Each integration automatically feeds domains 3 to 6.

Expected outcome: A unified view of your entire cyber program, with no manual rebuilding.

Step 3 — Centralize existing evidence

For each domain, import existing evidence: policies, review minutes, incident reports, supplier assessments. The goal: your compliance file exists permanently — not just before an audit.

Expected outcome: Centralized evidence, exportable on demand, for each of the 10 domains.

Step 4 — Monitor continuously

Set up alerts and periodic reviews in Eyako: overdue-risk alerts, BCP test reminders, supplier assessment renewals. ReCyF compliance becomes a permanent state — not a project.

Expected outcome: ReCyF compliance maintained continuously, with proactive alerts if a domain degrades.

Frequently asked questions

Is Eyako ReCyF ANSSI certified?+
The ReCyF is not a product certification framework — it is an audit framework for entities. Certification applies to your organization, not to the tool. Eyako is aligned with the 10 ReCyF domains and designed to produce the evidence ANSSI auditors ask for.
What is the difference between Eyako and other tools that mention the ReCyF?+
Other tools (MakeItSafe, Tenacy) offer ReCyF documentary modules — forms and storage spaces. Eyako is a living monitoring platform: indicators update continuously from your tools, evidence is built automatically, and you get an active dashboard — not a binder to fill in.
Does the ReCyF apply to my SME?+
The ReCyF applies to essential entities (EE) and important entities (EI) under the French transposition of NIS2. The scope is broader than in 2021 and now includes SMEs in certain sectors (health, water, energy, transport, digital infrastructure, digital services). Check your status on the ANSSI website or request a quick assessment.
Which domain should I start with?+
Start with the domains where your evidence is most lacking — often risk management (out-of-date treatment plan) and supply chain (informal supplier assessments). These are also the domains most frequently checked in the first NIS2 audits.

Turn ReCyF compliance into a permanent state

Eyako centralizes your 10 ReCyF domains in a live dashboard, with associated evidence exportable on demand — no rebuilding before each audit.

Request a ReCyF assessment
Eyako × ReCyF ANSSI: Mapping, Checklist & Continuous Monitoring Guide | Eyako