Your SME falls under NIS2 if it operates in one of the 18 sectors covered by the directive and exceeds 50 employees or €10 million in annual turnover. It falls under DORA if it is a regulated financial entity, or if it provides IT services to one. In both cases, the measures these texts require are precisely the ones cyber insurers check before agreeing to cover you, and how far you have implemented them weighs directly on your premium.
What exactly are NIS2 and DORA?
NIS2 is the European Directive 2022/2555 on the security of network and information systems. According to ANSSI, the French cybersecurity agency, it takes France from roughly 500 regulated entities to close to 15,000, across 18 sectors, with mandatory cybersecurity measures, registration and incident notification.
DORA (Digital Operational Resilience Act) is the European Regulation 2022/2554 on digital operational resilience in the financial sector, directly applicable without transposition since 17 January 2025. It targets financial entities (banks, insurers, asset managers, payment institutions) and, by extension, their ICT service providers.
An essential entity, under NIS2, is a large organisation in a "highly critical" sector (Annex I): proactive supervision by ANSSI, audits, the highest penalties. An important entity is a medium-sized organisation in a highly critical sector, or a medium or large one in a "critical" sector (Annex II): the same obligations, but ex-post supervision and lower penalty caps.
How do you know whether your SME is in scope of NIS2?
Two questions: your sector and your size. Annex I covers energy, transport, banking and finance, health, water, digital infrastructure, business-to-business ICT service management (managed services, managed security), public administration and space. Annex II adds postal services, waste, chemicals, food, manufacturing (medical devices, electronics, machinery, vehicles), digital providers (online marketplaces, social networks) and research.
On size, you are in scope from 50 employees or €10 million in turnover or balance sheet, except for activities covered regardless of size (DNS, telecoms, trust services). Above 250 employees, or €50 million in turnover and €43 million in balance sheet, you become a large enterprise, hence an essential entity in an Annex I sector.
| Company situation | Annex I sector (highly critical) | Annex II sector (critical) |
|---|---|---|
| Under 50 employees and ≤ €10M | Out of scope (with exceptions) | Out of scope |
| 50 to 249 employees, or €10M to €50M | Important entity | Important entity |
| ≥ 250 employees, or > €50M turnover and > €43M balance sheet | Essential entity | Important entity |
| Maximum fine | €10M or 2% of worldwide turnover | €7M or 1.4% of worldwide turnover |
The eligibility simulator on ANSSI's MonEspaceNIS2 portal settles borderline cases.
Where does NIS2 transposition stand in France in September 2026?
France is transposing NIS2 through the bill "on the resilience of critical infrastructure and the strengthening of cybersecurity", adopted by the Senate on 12 March 2025 and examined by a special committee of the National Assembly (report of 10 September 2025). At the time of writing, according to the parliamentary records, the text has been neither definitively adopted nor promulgated, and decrees will then have to set the technical measures.
ANSSI did not wait. On 17 March 2026 it published the Référentiel Cyber France (ReCyF), which breaks NIS2 down into 20 security objectives: the first 15 for important entities, all 20 for essential entities. Its director general has stated that no penalties would be applied during the first three years after the framework enters into force.
What concrete obligations does NIS2 impose?
Three blocks. Risk management measures: incident handling, business continuity and backups, supply chain security, access control and multi-factor authentication, encryption, training. Notification of significant incidents to ANSSI in three steps: an early warning within 24 hours, a detailed notification within 72 hours, a final report within one month. Finally, governance: management bodies must approve the measures, undergo training, and can be held liable, up to a temporary ban from management functions for essential entities. Even out of scope, you will face these requirements by contract, because a NIS2 entity must secure its supply chain, and therefore its SaaS vendors.
What does DORA change if you are a fintech or an ICT provider?
For a regulated fintech, DORA requires a documented ICT risk framework, a register of information listing every ICT contract (submitted to the ACPR by 31 March 2026), resilience testing, and faster notification than NIS2: an initial notification within 4 hours of classifying the incident as major (and no later than 24 hours after becoming aware of it), an intermediate report within 72 hours, a final report within one month.
An ICT third-party provider, under DORA, is any company supplying digital services to a financial entity: hosting, SaaS, managed services, payments. Whatever its size, it is not directly regulated unless designated as "critical" by the European supervisory authorities (a first list of 19 providers was published on 18 November 2025), but it is bound by DORA through contract: security, incident notification, audits, exit strategy.
NIS2 or DORA compliance and cyber insurability are two sides of the same coin: in both cases, you are asked to prove you have reduced your risk before anyone agrees to carry it with you.
What do cyber insurers actually check in 2026?
Without multi-factor authentication on remote access, email and administrator accounts, most insurers refuse to quote the risk or exclude losses arising from account compromise. ReCyF asks for the same thing.
Multi-factor authentication (MFA) requires, in addition to a password, a second proof of identity (one-time code, hardware key, phone notification). It blocks most intrusions based on stolen credentials, account hijacking being the number one threat to businesses according to Cybermalveillance.gouv.fr. EDR (Endpoint Detection and Response) is software installed on every workstation and server that analyses suspicious behaviour and isolates a compromised machine, where antivirus only recognises known malware.
| NIS2 / ReCyF requirement | What the cyber insurer checks | Effect on the policy |
|---|---|---|
| Access control and MFA | MFA on VPN, email, admin accounts, cloud | Prerequisite; refusal or exclusion without MFA |
| Detection and response | EDR or MDR across the whole estate | Access to the best pricing |
| Continuity and backups | Offline or immutable backups, tested | Deductible and limit adjusted |
| Incident handling | Written and rehearsed response plan | Access to crisis management cover |
Offline (or immutable) backups are copies of your data disconnected from the network, or locked in a format no account can alter for a set period: the only guarantee you can restore without paying when an attacker encrypts your servers. An incident response plan is the short, tested document that says who calls whom, what to unplug, and how to notify the insurer, the data protection authority and, soon, ANSSI within the deadlines.
Why does compliance lower an SME's cyber premium?
Because the cyber premium is a direct function of your demonstrated maturity. For a French SME, the orders of magnitude observed in 2026 run from €1,000 to €3,000 a year for 10 to 50 employees, and €3,000 to €10,000 above that. At equal size, the gap between a company that ticks every prerequisite and one that ticks half of them runs to tens of percent. AMRAE's LUCY 2026 study reports an average 32% drop in premiums for large companies over 2025, but claims rising from €54.5 million to €83.2 million: insurers remain selective, on evidence. ANSSI's 2025 cyber threat overview highlights the stakes: SMEs, micro-enterprises and mid-caps accounted for 37% of the ransomware victims it handled in 2025. A well-kept NIS2 or DORA file is therefore also a ready-made underwriting file.
Frequently asked questions
Is a 30-employee SME covered by NIS2?
In principle no, unless it exceeds €10 million in turnover or balance sheet, or operates an activity covered regardless of size (DNS, telecoms, trust services). It may however face the contractual requirements of its NIS2 or DORA customers.
Is NIS2 already mandatory in France in September 2026?
Not yet formally: the transposition law had not been promulgated at the time of writing and decrees must follow. ANSSI nevertheless recommends registering on MonEspaceNIS2 and starting compliance work on the basis of ReCyF, with an announced three-year grace period.
Does cyber insurance replace NIS2 or DORA compliance?
No. Insurance transfers the residual financial risk (crisis management, business interruption, third-party liability) but covers neither the notification obligation nor directors' liability. Conversely, a successful attack on a compliant company still costs money.
What should I prioritise if my cyber renewal comes before my compliance work is done?
Start with the three measures every insurer checks: MFA everywhere, EDR on every endpoint, tested offline backups. Document them with dated evidence and write a one-page incident response plan. That is often enough to obtain a quote.
At Lesto, we support SMEs and scale-ups, especially SaaS and fintech companies, starting from their real risk: we read your NIS2 or DORA requirements as an underwriting file, consult nine insurers on average, and tell you which measure unlocks which saving. Want to know what your premium should be worth? Discover our cyber insurance offer and request an analysis within 72 hours.
Recommended coverage
Our offers
The coverages we recommend most often to businesses.
Professional Liability
When a client blames you for a mistake or a delay, legal fees pile up fast. Professional Liability picks up the bill for you.
DiscoverProperty Damage (BOP)
A fire or water damage can shut your premises overnight. This insurance pays for the repairs and keeps you afloat until you reopen.
DiscoverCyber
One morning your files are locked and a hacker demands a ransom. Cyber insurance pays for the recovery and the crisis response.
DiscoverTags
- #NIS2
- #DORA
- #cyber insurance
- #SME
- #cybersecurity

Loïc Carbonne
CTO
Loïc is passionate about tech, code and artificial intelligence. He is building the platform that allows Lesto's clients to be properly insured.
LinkedIn →