Back to blog
Compliance & Regulation9 min read

ReCyF ANSSI
What the New Framework Really Changes for SME CISOs

ReCyFANSSINIS2ConformitéPME ETI

The ReCyF is the operational translation of NIS2 by ANSSI — the playbook auditors will use when they show up. Here's what it actually requires, domain by domain.

Key takeaways

  • ReCyF is ANSSI's operational translation of NIS2: the concrete framework auditors will rely on.
  • It structures requirements domain by domain (governance, risk, protection, defence, resilience) — beyond a simple checklist.
  • For an SME CISO, the goal is continuous compliance: tracked posture and centralised evidence rather than a one-off audit.

The framework nobody is talking about yet — but every auditor will use

NIS2 has been transposed into French law since January 1, 2025. But between the European directive and the concrete audit, there is an intermediary that many CISOs have not yet integrated into their program: the ReCyF.

The Référentiel Cyber France is the operational framework published by ANSSI to translate NIS2 into concrete requirements. It's not another legal text. It's the playbook auditors will follow when they arrive at your door.

What the ReCyF is — and what it is not

The ReCyF organizes NIS2 requirements into 10 control domains. For each domain, it defines expected measures — and most importantly, the evidence to produce if an auditor asks for it.

1
Governance
2
Risk management
3
Human resources
4
Assets & configuration
5
Access control
6
Security operations
7
Incident management
8
Business continuity
9
Supply chain
10
Compliance & audit

Key distinction: The ReCyF is not a product certification. Your SIEM vendor cannot be "ReCyF certified." Neither can your GRC platform. What is evaluated is your organization — its ability to demonstrate that it continuously manages each of these 10 domains in a structured way.

What auditors will actually look at

1. Governance

What the ReCyF requires: A formalized security policy, signed by management. A documented and up-to-date cyber program. A traceable budget linked to security objectives.

What the auditor will ask: "Show me the current version, with management's signature, dated less than 12 months ago." And: "How do you track progress on your program?"

2. Risk management

What the ReCyF requires: A formalized risk analysis, a treatment plan with owners and deadlines, residual risks arbitrated by management (not just the CISO).

What the auditor will ask: "Where does your treatment plan stand today? Who owns each open risk? When did you last review residual risks with your management?"

3. Incident management

What the ReCyF requires: A formalized, tested incident response procedure with assigned roles. The ability to produce an alert within 24h and a detailed report within 72h of detection.

What the auditor will ask: "Show me the last time you simulated an incident. Who was on call? How did you notify? How long did it take?"

4. Supply chain

What the ReCyF requires: An up-to-date list of critical suppliers. A security assessment of each within the past 12 months. Appropriate contractual clauses.

The real problem: you probably cover these domains — but you can't prove it

Here is what I observe with the majority of SME and mid-market CISOs I meet: the controls exist. The policies have been written. Suppliers have been assessed. Risks have been analyzed. There have been management reviews. But everything is scattered — in SharePoint folders, emails, archived PowerPoint presentations, in the memory of someone who left 8 months ago.

The ReCyF problem is not control coverage. It's continuous demonstration of that coverage. NIS2 — and the ReCyF in particular — requires you to be able to respond at any moment, not just during a scheduled audit.

The question auditors ask first

Based on the first NIS2 audits conducted across Europe, the most common opening question is not "are you compliant?" It is:

"How do you manage your cybersecurity program on a day-to-day basis?"

This is not a question about your technical tools. It's a question about your organization, governance, and ability to maintain a structured security posture over time. CISOs who answer this best are not those with the best tools — they're those who can show, in 10 minutes, how their program works, who is responsible, and where things stand today.

Where to start if you haven't yet mapped your ReCyF coverage

  • Step 1 — Identify your NIS2 status. Are you an essential entity (EE) or important entity (EI) under French transposition? The scope has expanded and now includes SMEs in certain sectors (health, water, energy, transport, digital infrastructure).
  • Step 2 — Review the 10 domains. For each domain, ask two questions: "Do we do this?" and "Can we prove it today, without 48 hours of preparation?"
  • Step 3 — Prioritize evidence gaps. It's often not controls that are missing — it's traceability. Start there: centralize existing evidence before creating new controls.
  • Step 4 — Establish continuous monitoring. ReCyF compliance is not a project with an end date. It's a state to maintain. What tool, meeting, or process guarantees that your ReCyF coverage stays up to date next week, next month, next year?

Frequently asked questions

What is the ReCyF ANSSI?+
The ReCyF (Référentiel Cyber France) is the operational framework published by ANSSI to translate NIS2 into concrete requirements. It organizes requirements into 10 control domains and defines expected measures — and the evidence to produce for each domain. It's not a product certification — it's your organization that is evaluated.
What are the 10 domains of the ReCyF?+
The ReCyF organizes NIS2 requirements into 10 domains: (1) Governance, (2) Risk management, (3) Human resources, (4) Assets & configuration, (5) Access control, (6) Security operations, (7) Incident management, (8) Business continuity, (9) Supply chain, (10) Compliance & audit.
What is the difference between NIS2 and the ReCyF?+
NIS2 is the European directive transposed into French law. The ReCyF is the operational framework published by ANSSI to implement it concretely. The ReCyF is what auditors will use to evaluate NIS2 compliance for French companies.
How to prepare your organization for the ReCyF?+
In 4 steps: (1) Identify your NIS2 status. (2) Review the 10 domains asking "do we do this?" and "can we prove it today?". (3) Prioritize evidence gaps rather than missing controls. (4) Establish continuous monitoring to maintain compliance over time.

Assess your ReCyF coverage in 30 minutes

Eyako centralizes your 10 ReCyF domains in a live dashboard, with associated evidence exportable on demand. The question "how do you manage your program?" gets an immediate answer.

Request a ReCyF assessment
ReCyF ANSSI: What the New Framework Really Changes for SME CISOs | Eyako