Eyako × ReCyF ANSSI
Mapping, checklist and continuous monitoring
By Eyako — The CISO Command Platform · Updated: August 2026
The ReCyF (Référentiel Cyber France) by ANSSI is now the reference framework for NIS2 audits in France. This guide gives you the complete mapping, a practical checklist and an implementation plan.
What this guide gives you
- The complete mapping of the 10 ReCyF domains and what Eyako covers natively.
- The interactive self-assessment — 33 points across the 10 domains, with the expected evidence.
- The implementation plan — where to start if you are beginning from scratch.
Part 1 — The ReCyF in 5 minutes
What is the ReCyF?
The Référentiel Cyber France (ReCyF) is the operational framework published by ANSSI to translate the NIS2 directive into concrete, verifiable requirements. It organizes the obligations into 10 control domains, each with expected measures and evidence to produce during an audit.
The ReCyF applies to essential entities (EE) and important entities (EI) under NIS2 — thousands of French organizations across health, energy, transport, finance, digital infrastructure and more.
What the ReCyF concretely changes
Before the ReCyF, NIS2 compliance stayed abstract — a hard-to-audit obligation of means. The ReCyF makes compliance auditable, domain by domain, evidence by evidence. The question auditors will now ask is no longer "are you NIS2 compliant?" It is:
"Show me how you manage each of these 10 domains, with the corresponding evidence."
Why most CISOs are not ready
The vast majority of SME and mid-market CISOs we meet already have the right controls in place. What they lack is the continuous demonstration of those controls — the layer that centralizes evidence, keeps it current, and makes it exportable on demand. That is exactly the problem Eyako solves.
Part 2 — Mapping Eyako × the 10 ReCyF domains
How to read the table
1Governance
Direct coverageWhat the ReCyF requires:
- •A formalized security policy, signed by management, dated less than 12 months ago
- •A documented, up-to-date cyber program covering the current period
- •A traceable cyber budget linked to risk-reduction objectives
- •Planned and documented management reviews
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Cyber program dashboard | Consolidated program view, continuously updated |
| Security policy management | Version history, approval dates, signatories |
| Management review tracking | Review minutes, agenda, attendees, decisions |
| Board reporting | Dated PDF exports of board presentations |
What the auditor will accept: Eyako program export → current policy with management approval date → latest review minutes.
2Risk management
Direct coverageWhat the ReCyF requires:
- •A formalized risk analysis with documented methodology
- •A treatment plan with named owners and deadlines
- •Residual risks arbitrated by management (not just the CISO)
- •A risk map review at least annually
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Risk mapping | Risk register with methodology and update date |
| Treatment plan management | Remediation actions with owner, deadline and real-time status |
| Management arbitration | History of residual risks approved by management |
| Escalation alerts | Traceability of escalated risks and decisions taken |
What the auditor will accept: Risk map export → treatment plan with status → evidence of management arbitration.
3Human resources
Coverage via monitoringWhat the ReCyF requires:
- •A formalized cybersecurity awareness program
- •Training tracking with completion rates
- •An offboarding procedure (access revocation)
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Awareness KPI monitoring | Dashboard with simulated phishing rate and training rate |
| Integration with your training tools | Data from KnowBe4, Proofpoint, etc. centralized |
| Offboarding action tracking | Access closure checklist with traceability |
What the auditor will accept: Awareness KPI dashboard → training rate per period → access revocation log.
4Assets & configuration
Coverage via integrationWhat the ReCyF requires:
- •An up-to-date critical asset inventory
- •Vulnerability management with prioritization
- •Patch management tracking
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Unified vulnerability view | Consolidated data from your scanners (Tenable, Qualys, Wiz…) |
| Patch management tracking | Patch coverage indicators, remediation timelines |
| Critical asset mapping | View of at-risk assets with exposure level |
What the auditor will accept: Open vulnerabilities by severity → remediation timelines → patch coverage of critical assets.
5Access control
Coverage via monitoringWhat the ReCyF requires:
- •Identity and privilege management (IAM)
- •Documented periodic access reviews
- •Privileged account management
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| IAM risk monitoring | Access drift indicators, inactive accounts, excessive privileges |
| Access review monitoring | Scheduling, completion tracking, centralized results |
| Access remediation actions | Remediation plans with owner and deadline |
What the auditor will accept: Latest access review results → open actions with deadlines → current IAM indicators.
6Security operations
Coverage via integrationWhat the ReCyF requires:
- •Anomaly detection (SIEM, logs)
- •Operational patch management
- •Logging of critical systems
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Operational posture dashboard | Consolidated view of SIEM alerts and indicators |
| Open vulnerability tracking | Processing times, remediation SLAs |
| Logging coverage | Log coverage indicators per critical system |
What the auditor will accept: SIEM coverage level view → remediation timelines → logging indicators.
7Incident management
Direct coverageWhat the ReCyF requires:
- •A formalized and tested incident management procedure
- •Notification within 24h (initial alert) and 72h (detailed report)
- •A documented post-mortem after every significant incident
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Incident register | Complete history with timeline, severity, status |
| Notification tracking | Detection, alert and ANSSI notification timestamps |
| NIS2 report templates | Incident reports in the expected format, exportable |
| Formalized post-mortem | Structured and archived lessons learned |
What the auditor will accept: Export of the last significant incident → timeline → proof of on-time notification → associated post-mortem.
8Business continuity
Direct coverageWhat the ReCyF requires:
- •A documented business continuity plan (BCP)
- •Defined and justified RTO/RPO
- •BCP tests performed and documented within the last 12 months
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| BCP management | Versioned BCP document with update status |
| Test tracking | Test scheduling, results, identified gaps |
| BCP alerts | Automatic notification if the annual test is not scheduled |
| RTO/RPO per system | Documentation of objectives per critical asset |
What the auditor will accept: Current BCP → latest test results → gaps and associated remediation.
9Supply chain (TPRM)
Direct coverageWhat the ReCyF requires:
- •Identification of critical suppliers
- •Security assessment of each critical supplier at least annually
- •Appropriate cyber contractual clauses
- •A procedure in case of supplier compromise
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| Critical supplier register | Prioritized list with criticality and assessment dates |
| Supplier scoring | Assessment results with history |
| Questionnaire tracking | Response rate, reminders, pending assessments |
| Renewal alerts | Notification before assessments expire |
What the auditor will accept: Supplier register → assessments from the last 12 months for critical suppliers → current risk scoring.
10Compliance & audit
Direct coverageWhat the ReCyF requires:
- •A measurable and up-to-date compliance status
- •A formalized regulatory watch
- •Accessible and organized evidence for the auditor
What Eyako covers:
| Eyako capability | Evidence produced for the auditor |
|---|---|
| ReCyF/NIS2 compliance dashboard | Real-time view of coverage per domain |
| Auditor export | Complete evidence package exportable on demand |
| Built-in regulatory watch | Alerts on NIS2, DORA and ReCyF changes |
| Compliance status history | Coverage evolution over time |
What the auditor will accept: Compliance dashboard export → evidence per domain → evolution history.
Summary: Eyako × ReCyF coverage
| ReCyF domain | Eyako coverage | Type |
|---|---|---|
| 1. Governance | Complete | Native |
| 2. Risk management | Complete | Native |
| 3. Human resources | Monitoring | Via KPIs |
| 4. Assets & configuration | Monitoring | Via integrations |
| 5. Access control | Monitoring | Via integrations |
| 6. Security operations | Monitoring | Via integrations |
| 7. Incident management | Complete | Native |
| 8. Business continuity | Complete | Native |
| 9. Supply chain | Complete | Native |
| 10. Compliance & audit | Complete | Native |
Eyako directly covers 6 of the 10 ReCyF domains. For the other 4 (human resources, assets, access, operations), Eyako provides the monitoring layer via your existing tools.
Part 3 — The 33-point ReCyF self-assessment
Rather than a static checklist, we built an interactive self-assessment covering the 10 domains in 33 points. For each control, the question is binary: can you produce the evidence right now, without preparation? You get your score and its interpretation in 15 minutes.
Self-assessment NIS2 / ReCyF in 33 points
An interactive scorecard aligned with the Référentiel Cyber France (ReCyF): tick what you can prove, watch your score update live, and read where your compliance file will hold — or give way. Printable in A4.
10 domains · 33 controls · ~15 minutes
Part 4 — ReCyF implementation plan with Eyako
Step 1 — Map your current coverage
Start with the 6 domains covered directly by Eyako: governance, risk, incidents, continuity, suppliers, compliance. Configure the matching modules and import your existing data.
Expected outcome: A ReCyF compliance dashboard with your starting baseline.
Step 2 — Connect your existing tools
Enable Eyako integrations for your operational security tools (vulnerability scanner, SIEM, IAM platform, training tool). Each integration automatically feeds domains 3 to 6.
Expected outcome: A unified view of your entire cyber program, with no manual rebuilding.
Step 3 — Centralize existing evidence
For each domain, import existing evidence: policies, review minutes, incident reports, supplier assessments. The goal: your compliance file exists permanently — not just before an audit.
Expected outcome: Centralized evidence, exportable on demand, for each of the 10 domains.
Step 4 — Monitor continuously
Set up alerts and periodic reviews in Eyako: overdue-risk alerts, BCP test reminders, supplier assessment renewals. ReCyF compliance becomes a permanent state — not a project.
Expected outcome: ReCyF compliance maintained continuously, with proactive alerts if a domain degrades.
Frequently asked questions
Is Eyako ReCyF ANSSI certified?+
What is the difference between Eyako and other tools that mention the ReCyF?+
Does the ReCyF apply to my SME?+
Which domain should I start with?+
Going further
NIS2 checklist for SME CISOs
15 priority controls, aligned with the ReCyF domains.
Download the checklistAssess your ReCyF coverage
An Eyako team member reviews your coverage across the 10 domains (30 min).
Request the assessmentEyako platform demo
See how Eyako monitors your ReCyF compliance in real time.
See the demoTurn ReCyF compliance into a permanent state
Eyako centralizes your 10 ReCyF domains in a live dashboard, with associated evidence exportable on demand — no rebuilding before each audit.
Request a ReCyF assessment