ReCyF ANSSI
What the New Framework Really Changes for SME CISOs
The ReCyF is the operational translation of NIS2 by ANSSI — the playbook auditors will use when they show up. Here's what it actually requires, domain by domain.
Key takeaways
- ReCyF is ANSSI's operational translation of NIS2: the concrete framework auditors will rely on.
- It structures requirements domain by domain (governance, risk, protection, defence, resilience) — beyond a simple checklist.
- For an SME CISO, the goal is continuous compliance: tracked posture and centralised evidence rather than a one-off audit.
The framework nobody is talking about yet — but every auditor will use
NIS2 has been transposed into French law since January 1, 2025. But between the European directive and the concrete audit, there is an intermediary that many CISOs have not yet integrated into their program: the ReCyF.
The Référentiel Cyber France is the operational framework published by ANSSI to translate NIS2 into concrete requirements. It's not another legal text. It's the playbook auditors will follow when they arrive at your door.
What the ReCyF is — and what it is not
The ReCyF organizes NIS2 requirements into 10 control domains. For each domain, it defines expected measures — and most importantly, the evidence to produce if an auditor asks for it.
Key distinction: The ReCyF is not a product certification. Your SIEM vendor cannot be "ReCyF certified." Neither can your GRC platform. What is evaluated is your organization — its ability to demonstrate that it continuously manages each of these 10 domains in a structured way.
What auditors will actually look at
1. Governance
What the ReCyF requires: A formalized security policy, signed by management. A documented and up-to-date cyber program. A traceable budget linked to security objectives.
What the auditor will ask: "Show me the current version, with management's signature, dated less than 12 months ago." And: "How do you track progress on your program?"
2. Risk management
What the ReCyF requires: A formalized risk analysis, a treatment plan with owners and deadlines, residual risks arbitrated by management (not just the CISO).
What the auditor will ask: "Where does your treatment plan stand today? Who owns each open risk? When did you last review residual risks with your management?"
3. Incident management
What the ReCyF requires: A formalized, tested incident response procedure with assigned roles. The ability to produce an alert within 24h and a detailed report within 72h of detection.
What the auditor will ask: "Show me the last time you simulated an incident. Who was on call? How did you notify? How long did it take?"
4. Supply chain
What the ReCyF requires: An up-to-date list of critical suppliers. A security assessment of each within the past 12 months. Appropriate contractual clauses.
The real problem: you probably cover these domains — but you can't prove it
Here is what I observe with the majority of SME and mid-market CISOs I meet: the controls exist. The policies have been written. Suppliers have been assessed. Risks have been analyzed. There have been management reviews. But everything is scattered — in SharePoint folders, emails, archived PowerPoint presentations, in the memory of someone who left 8 months ago.
The ReCyF problem is not control coverage. It's continuous demonstration of that coverage. NIS2 — and the ReCyF in particular — requires you to be able to respond at any moment, not just during a scheduled audit.
The question auditors ask first
Based on the first NIS2 audits conducted across Europe, the most common opening question is not "are you compliant?" It is:
"How do you manage your cybersecurity program on a day-to-day basis?"
This is not a question about your technical tools. It's a question about your organization, governance, and ability to maintain a structured security posture over time. CISOs who answer this best are not those with the best tools — they're those who can show, in 10 minutes, how their program works, who is responsible, and where things stand today.
Where to start if you haven't yet mapped your ReCyF coverage
- Step 1 — Identify your NIS2 status. Are you an essential entity (EE) or important entity (EI) under French transposition? The scope has expanded and now includes SMEs in certain sectors (health, water, energy, transport, digital infrastructure).
- Step 2 — Review the 10 domains. For each domain, ask two questions: "Do we do this?" and "Can we prove it today, without 48 hours of preparation?"
- Step 3 — Prioritize evidence gaps. It's often not controls that are missing — it's traceability. Start there: centralize existing evidence before creating new controls.
- Step 4 — Establish continuous monitoring. ReCyF compliance is not a project with an end date. It's a state to maintain. What tool, meeting, or process guarantees that your ReCyF coverage stays up to date next week, next month, next year?
Frequently asked questions
What is the ReCyF ANSSI?+
What are the 10 domains of the ReCyF?+
What is the difference between NIS2 and the ReCyF?+
How to prepare your organization for the ReCyF?+
Assess your ReCyF coverage in 30 minutes
Eyako centralizes your 10 ReCyF domains in a live dashboard, with associated evidence exportable on demand. The question "how do you manage your program?" gets an immediate answer.
Request a ReCyF assessment