- FR
- EN
Network and Information Systems 2
NIS2 Directive
1/ NIS 2 (EUROPEAN DIRECTIVE)
The digital transformation of European societies and the interconnection of Member States have exposed the European market to new cyber threats. It became urgent to collectively guarantee adequate security conditions for the entire European Union. That is why the European Parliament and the Council of the European Union adopted the "Network and Information Security" (NIS) Directive in July 2016. Transposed into national law in 2018, this directive aimed to raise the level of cybersecurity of major players in ten sectors.
2/ WHAT WILL CHANGE WITH THE ADOPTION OF THE NIS 2 DIRECTIVE?
The NIS 2 Directive is extremely ambitious. It builds on the achievements of the NIS 1 Directive to mark a real paradigm shift, at both national and European levels. Faced with malicious actors who are ever more capable and better equipped, and who target more and more entities that are too often poorly protected, the NIS 2 Directive broadens its objectives and its scope to provide greater protection. This extension of scope under NIS 2 is unprecedented in cyber regulation.
3/ WHY IS THIS DIRECTIVE OF SUCH STRATEGIC IMPORTANCE FOR EUROPEAN UNION MEMBER STATES?
While the complex, professional and constantly evolving threat shows no sign of weakening and information systems remain partly vulnerable, the NIS 2 Directive represents a unique opportunity: its implementation will enable thousands of entities to better protect themselves. It will be an opportunity to broadly mobilize the national economy and the public sector. It also leads Member States to strengthen their cooperation on cyber crisis management.
4/ WHEN WILL THE NIS 2 DIRECTIVE COME INTO FORCE?
The directive has been in force since October 2024.
Key features
Risk management
ISO 27001 Annex A controls management
CyFun requirements management
Technical and organizational measures management
Incident / nonconformity management
CyFun self-assessment 2023 / 2025
Internal and external audit management
Action management
Objectives and indicators management
Process management
Processor and supplier management
Alert management
Risk management
The software lets you create assessment criteria for each standard (ISO or GDPR)
A validation cycle is defined.
A status history helps you follow the various exchanges between the people involved.
ISO 27001 Annex A controls management
CyFun requirements management
CCB framework.
Technical and organizational measures management
Technical and organizational measures are managed by area (ISO/GDPR). The person responsible for each measure and its completion date, actual or planned, are identified and managed.
A measures management screen gives an overall view for tracking measures, deadlines and owners by area.
Incident / nonconformity management
Incident and nonconformity management tool
Email notifications are sent to the assigned owner.
CyFun self-assessment 2023 / 2025
Internal and external audit management
Plan your internal and external audits. Write your audit reports directly in the software.
Action management
Tool to manage all actions.
Email notifications are sent to the assigned owner.
Objectives and indicators management
Process management
Identification of processes and sub-processes by entity
Identification of process owners
Processor and supplier management
This feature lets you manage contract compliance and assess your critical suppliers based on assessment criteria.
Alert management
Alerts on deadlines (actions, data subject requests, breaches, ...) and gaps (contracts, justifications, ...) are automatically identified by the software. A register of all alerts is generated so that the person in charge can manage them.