NIS2: a guide for IT service providers
Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.
Practical guides and analysis on NIS2, ISO 27001 and the ANSSI referential, written for MSPs and French IT service providers.
Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.
ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.
One question per objective of ANSSI's ReCyF, with the evidence that answers it: enough to place a company in an hour, before a real assessment.
Sector, size, exceptions: three questions decide whether NIS2 applies to your company. And what to do when the honest answer is no.
Why cyber insurance questionnaires have got tougher, what they always check, and how an MSP turns answering them into billable work.
Your firm is below the NIS2 size thresholds, but your regulated clients still ask you for evidence. Here is why, and what they expect.
A screenshot proves nothing to an auditor, who wants evidence that a control held all year. What auditors mean by evidence, and how to build it.
What ANSSI's ReCyF framework is, how it differs from the French cyber hygiene guide and from ISO 27001, and how an MSP runs an assessment.
How to move from one-off audits to a cyber governance subscription: scope, deliverables, pricing, and industrialising the service so the margin holds.
Why ANSSI's cyber hygiene guide is still the best starting point for a small-business security diagnostic, and how to turn it into a costed plan.
The 93 Annex A controls of ISO 27001:2022, their four themes, the role of the Statement of Applicability and the real road to certification.