Skip to content

SSPM for NIS2 & ReCyF: Mapping SaaS Posture to French Cyber Resilience

By Black Cat Security Team · Updated August 14, 2026

NIS2 (EU Directive 2022/2555) requires "essential" and "important" entities to implement cybersecurity risk-management measures, report incidents on strict deadlines, and put management-body oversight — including personal accountability — behind it. France’s transposition (the loi de résilience, expected in 2026) is set to operationalize NIS2 through ReCyF, an ANSSI security-measures referential reportedly built around roughly 20 objectives for entités essentielles and 15 for entités importantes.

Black Cat SSPM maps 40 controls to the NIS2 Directive today — governance, MFA and access control, asset inventory, supplier risk, and incident-reporting readiness — continuously scanned across your connected SaaS estate.

How NIS2 and ReCyF map to your SaaS estate

Based on the EU NIS2 Directive (2022/2555) and Black Cat's NIS2 framework mapping
NIS2 / ReCyF objective areaWhat it requiresHow Black Cat SSPM covers it
Governance & management oversight (NIS2 Art. 20)The management body must approve, oversee, and be trained on cybersecurity risk-management measures — with accountability for non-compliance.Continuous compliance posture mapped to the NIS2-20 governance controls, tracked and evidenced on every scan.
Access control & MFA (NIS2 Art. 21.j)Use of multi-factor authentication, secure authentication, and privileged-access hygiene.MFA-posture and admin/privileged-role checks run across every connected SaaS app, continuously.
Asset, identity & data inventoryKnow your systems, accounts, data flows, and third-party access.Cross-SaaS identity inventory, dormant/orphaned-account detection, and shadow-AI / OAuth-app discovery.
Supply-chain & third-party risk (NIS2 Art. 21.d)Assess and manage security risk in supplier and service-provider relationships.Third-party SaaS and OAuth-app discovery with risk classification surfaces your vendor exposure automatically.
Incident handling & reporting readiness (NIS2 Art. 23)Detect significant incidents and report within the directive’s strict deadlines.Drift and finding alerts (custom CEL rules) plus audit-log export feed your incident-response and reporting workflow.

Why SaaS posture matters for NIS2

Most NIS2 risk-management obligations — access control, asset inventory, supplier risk, incident detection — live in the same place your organization actually operates day to day: Microsoft 365, Google Workspace, Okta, Slack, GitHub, and the dozens of SaaS apps your teams connect via OAuth. A posture tool that only looks at network infrastructure misses most of what a modern NIS2 audit will ask about.

What Black Cat SSPM covers today

The NIS2 framework page lists the full set of 40 controls Black Cat maps policy evaluations to, spanning governance, risk-management measures, and incident-reporting readiness. Every scan re-evaluates your posture against these controls and produces audit-ready evidence.

What we don’t claim

ReCyF’s final objective list has not been published as of this writing — the loi de résilience is expected in 2026. We map the EU NIS2 Directive’s requirements today and will extend coverage to ReCyF’s specific objectives once ANSSI finalizes the referential; we don’t claim ReCyF conformity ahead of that text existing.

Frequently asked questions

What is NIS2 and who does it apply to?

NIS2 (EU Directive 2022/2555) sets cybersecurity risk-management and incident-reporting obligations for "essential" and "important" entities across roughly 18 sectors. France’s transposition — the loi de résilience, expected to pass in 2026 — is expected to bring on the order of 15,000 entities into scope, with the "entité importante" band generally covering organizations of 50+ employees or €10M+ turnover.

What is ReCyF?

ReCyF is the security-measures referential expected under France’s NIS2 transposition (via ANSSI), reportedly structured around roughly 20 objectives for entités essentielles and 15 for entités importantes. The final text is tied to the loi de résilience, expected in 2026. Black Cat maps the underlying EU NIS2 Directive today (40 controls) and will extend the mapping to ReCyF’s objectives once the referential is published.

Does NIS2 create personal liability for management?

Yes — Article 20 of the NIS2 Directive requires the management body to approve and oversee cybersecurity risk-management measures and undergo training, and member states can hold management bodies accountable for infringements of the directive.

How does Black Cat SSPM help with NIS2 compliance?

Continuous scanning mapped to 40 NIS2 controls — covering governance, access control, asset inventory, supplier risk, and incident-reporting readiness — plus audit-ready evidence exports you can hand to an auditor or regulator.

Can I see my NIS2 gap before I buy?

Yes — run a free posture scan. It connects with read-only-by-default access to one SaaS tenant (e.g. Microsoft 365 or Google Workspace) and gives you an immediate view of where your SaaS estate stands against NIS2-relevant controls.

Competitor information on this page is drawn from publicly available sources (vendor websites, product pages, and independent press coverage) as of the date noted next to each claim, and is believed accurate at time of writing. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Vendor offerings change over time — verify current details directly with the vendor before making a purchasing decision.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default OAuth access you can revoke any time.

Run a free posture scan