Back to Blog
Business

NIS2: how Astry helps you achieve compliance

September 22, 20265 min read

NIS2: how Astry helps you achieve compliance

1. Which companies are subject to NIS 2?

The original NIS directive only covered a handful of players, the so-called operators of essential services. NIS 2 considerably widens that scope: it now covers mid-sized to large entities (50 employees or more, or €10 million in revenue or more), as well as certain strategic players regardless of their size.

The directive sorts these players into two broad categories.

A. Essential Entities β€” the strictest requirements, the harshest penalties

  • Energy: producers, distributors and transporters (electricity, gas, oil, district heating, hydrogen).
  • Healthcare: healthcare providers (hospitals, clinics), reference laboratories, manufacturers of pharmaceuticals and critical medical devices.
  • Transport: air, rail, maritime and inland waterway, intelligent road transport.
  • Digital infrastructure: telecom operators, cloud hosting providers, data centre operators, DNS, TLD and CDN providers.
  • Managed IT services (MSP / MSSP): IT service companies managing critical systems on behalf of clients.
  • Drinking water and wastewater.
  • Public sector: central government bodies and large local authorities.

B. Important Entities β€” similar obligations, under an after-the-fact oversight regime

  • Postal and courier services.
  • Waste management.
  • Manufacturing and chemical industry: electronic components, fine chemicals, machinery and equipment, automotive, aerospace.
  • Food industry: large-scale production, processing and distribution of food.
  • Digital providers: online marketplaces, search engines, social networks.

The effect also ripples down the supply chain: a small subcontractor β€” a software vendor, a maintenance provider, a systems integrator β€” can end up contractually bound to NIS 2 standards simply because one of its large enterprise clients requires it.

2. How does Astry help these companies comply with NIS 2?

Article 21 of the directive (risk management measures) and Article 23 (notification obligations) set out precise operational requirements. Here's how Astry addresses each one.

A. Incident handling and response (Art. 21.2.b)

The directive requires detecting, handling and resolving IT security incidents without delay. Astry connects to detection tools (SIEM, EDR, monitoring) and automates the escalation chain: as soon as a critical signal is raised, the on-call engineer or cyber on-call team is notified immediately, with automatic escalation if nobody acknowledges it.

B. Meeting the legal notification deadlines (Art. 23)

An entity affected by a significant incident must notify the national authority β€” ANSSI, in France β€” on a tight schedule:

  • 24 hours for the early warning, indicating whether the incident is suspected to be malicious;
  • 72 hours for the detailed notification, with an initial impact assessment;
  • 1 month for the final closing report.

Meeting a 24-hour deadline requires an internal transmission chain that's close to instant. Astry mobilises the crisis unit β€” CISO, CIO, legal counsel, communications β€” within seconds through its multi-channel alerts (SMS, phone calls, push notifications), so a critical incident never sits unnoticed in an inbox overnight or over a weekend.

C. Business continuity and crisis management (Art. 21.2.c)

The company must guarantee the resilience of its operations, with formalized business continuity (BCP) and disaster recovery (DRP) plans that actually work in practice. Astry continuously plans on-call rotations (business hours and after-hours) so a qualified resource is always available, and lets you attach a runbook or crisis procedure directly to an alert, for a standardized response from the first minute.

D. Traceability and auditability

In the event of an ANSSI audit or inspection, the company must be able to demonstrate the rigor of its operational governance and document its interventions. Astry's dashboards and reports β€” alert logs, send time, acknowledgment time, MTTA, MTTR β€” provide exactly the kind of evidence auditors look for to verify how well response times are controlled.

E. Supply-chain security and sovereignty (Art. 21.2.d)

The entity must assess the security and compliance level of the third-party tools and providers it entrusts with its critical operations. Against US players like PagerDuty or OpsGenie, subject to the Cloud Act, Astry is developed in France and hosted in the European Union. For a CISO in a critical sector β€” healthcare, defense, energy β€” hosting the technical details of its vulnerabilities and incidents on an entirely European platform limits the risk of unauthorized access and makes compliance easier to demonstrate.

Ignoring the NIS 2 directive now exposes a company to a risk that goes well beyond IT: it's a risk to its financial survival, and to the executives themselves. Lawmakers deliberately raised the stakes to force leadership teams to take the issue seriously.

Breaking down the risks

1. Strict oversight and heavy financial penalties

ANSSI now holds inspection and sanctioning powers similar to those the CNIL holds for GDPR. It can demand security audits, request access to data and security policies, and impose compliance orders backed by daily penalties. For Important Entities, these inspections most often happen after the fact, following an incident.

The amounts involved are meant to sting: up to €10 million or 2% of worldwide revenue for Essential Entities, and up to €7 million or 1.4% for Important Entities.

2. Cyber insurers walking away

This is the most immediate financial risk in the event of a ransomware attack or a full business shutdown. Cyber insurance policies require compliance with legal standards: if a post-incident audit reveals the company wasn't NIS 2 compliant β€” no crisis management plan, a critically slow response β€” the insurer can invoke negligence to refuse payment, or even terminate the policy. Without proof of solid cyber governance and reliable response tools, a company becomes hard to insure, or faces prohibitive premiums.

3. Executives' personal liability

This is NIS 2's main legal novelty: Article 20 puts an end to blindly delegating cybersecurity to the CIO. Governing bodies are now legally required to approve risk management measures and oversee their implementation. In the event of a failure, their personal liability β€” including their personal assets β€” can be engaged; in cases of gross negligence, for Essential Entities, authorities can even seek the temporary suspension of an executive.

In conclusion

Whether or not your company is subject to NIS 2, you need to prepare for security incidents, and more broadly for anything that could bring your business to a halt. Astry helps you comply with NIS 2, but more importantly, it helps you prepare for a crisis, whatever its origin.

Cybersecurity is no longer a technical cost center: it's a governance issue, and a form of legal protection for the company and its executives. Failing to invest today in reliable crisis management tools like Astry means risking having to explain to your shareholders tomorrow why your business ground to a halt, why your insurer refused to pay out, and why ANSSI is holding you personally liable.

Astry lets you produce the tangible, legally required proof that you're able to mobilize your teams and respond to a cyberattack without delay. In today's environment, inaction usually costs far more than preparation.

Want to talk it through? Contact us to discuss your NIS 2 compliance approach, or get started for free.

Keywords: NIS2, compliance, ANSSI, crisis management, cybersecurity, CISO, on-call.