Skip to main content
ANSSI

ReCyF: the ANSSI cyber framework for MSPs

What ANSSI's ReCyF framework is, how it differs from the French cyber hygiene guide and from ISO 27001, and how an MSP runs an assessment.

L'équipe Vigicap6 min read

A client asks whether you are "ReCyF compliant". You go looking for the answer and find almost nothing: no explainer page, no article that sets out plainly what it is. That is to be expected — the document has only existed for a few months, and it has no definitive status yet. Here is what you need to know before answering that client.

What is ReCyF, and who publishes it?#

ReCyF (Référentiel Cyber France) is the digital security framework published by ANSSI, France's national cybersecurity agency, to structure the compliance work of entities falling within the scope of the NIS2 directive. The version in force, v2.5, published on 17 March 2026, defines 20 security objectives whose level of requirement varies depending on whether the entity is classified as an "important entity" or an "essential entity" within the meaning of the NIS2 directive.

It is not a general-purpose text aimed at every SME: it is the tool ANSSI is building to assess the entities that will fall under NIS2 supervision in France, once the French transposition is complete.

How does ReCyF differ from the 42-measure cyber hygiene guide?#

ANSSI's guide d'hygiène informatique — its cyber hygiene guide — is a generic baseline of good practice, applicable to any organisation, with no formal link to a particular regulatory regime. ReCyF, by contrast, was built specifically to support NIS2 supervision: it covers neighbouring families of measures — governance, technical protection, detection, resilience — but organises them into assessable objectives, with an explicit distinction between what is required of every covered entity and what is required only of essential entities.

In practice, the hygiene guide answers "which good practices should we apply?". ReCyF answers "what will the regulator check, and at what level, given my NIS2 category?". A client can follow the first without ever being concerned by the second — but if it falls within the NIS2 scope, it is the second that counts for its compliance.

What is the relationship between ReCyF and ISO 27001?#

The two cover close ground — security governance, access management, business continuity — without sharing either purpose or structure. ISO/IEC 27001:2022 is an international certification standard, organised around an information security management system (ISMS) and 93 Annex A controls grouped into four themes: organisational, people, physical and technological. An organisation conforms to it voluntarily and can have that conformity certified by an accredited body.

ReCyF is not a certification standard: it is a regulatory supervision framework, specific to France, with no certification mechanism provided for at this stage. An entity already structured around ISO 27001 does in fact cover a good share of ReCyF's objectives — but the two frameworks do not map term for term, and presenting one as a simple subset of the other oversimplifies. The ReCyF, NIS2 and ISO 27001 mapping table sets the 20 objectives against the Annex A controls, and shows where that mapping stops.

What are the 20 ReCyF objectives, and how are they distributed?#

ReCyF organises its 20 objectives into four pillars: Governance, Protection, Defence and Resilience. The split is not sequential — objectives 16 to 20, reserved for essential entities, are interleaved across the four pillars rather than grouped separately:

  • Governance (6 objectives): inventory of information systems (1); implementation of a digital security governance framework (2); control of the ecosystem (3); integration of digital security into human resources management (4); implementation of a risk-based approach (16, essential entities only); information system security audit (17, essential entities only).
  • Protection (9 objectives): control of information systems (5); control of physical access to premises (6); securing information system architecture (7); securing remote access to information systems (8); protection of information systems against malicious code (9); user identity and access management (10); control of information system administration (11); securing the configuration of resources (18, essential entities only); administration from dedicated resources (19, essential entities only).
  • Defence (2 objectives): identification of and response to security incidents (12); information system security monitoring (20, essential entities only).
  • Resilience (3 objectives): business continuity and recovery (13); response to cyber crises (14); exercises, tests and drills (15).

The first 15 objectives (excluding 16 to 20) form the common baseline, applicable to any entity covered by NIS2, important or essential. Objectives 16 to 20 are added only for essential entities.

One point diagnostic tools often pass over in silence: ReCyF defines no maturity scale. For each objective, ANSSI publishes "moyens acceptables de conformité" — acceptable means of compliance — and the measure is judged met or not met, with no official intermediate scoring. Any "level 0 to 4" scale you see in a diagnostic tool is a management construct added by the vendor, not an ANSSI requirement. Useful for prioritising an action plan, but never to be presented to a client as a grade issued by ANSSI.

How does an MSP actually run a ReCyF assessment?#

First, qualify the client under NIS2: sector of activity (Annexes I and II of the directive) and headcount, to establish whether it is out of scope, an important entity or an essential entity — and therefore which objectives apply. Then start systematically with objective 1, the inventory of information systems: without that inventory, every objective that follows rests on assumptions rather than verified facts.

Then work through the applicable objectives one by one, collecting the evidence that shows — or fails to show — that the means of compliance have been met: a documented policy, a verifiable technical configuration, an incident log, the result of a restore test. This is an evidence-gathering exercise, not a declarative questionnaire: a client who answers "yes" with no evidence attached has not moved its NIS2 file forward by a single step.

Is ReCyF already a final standard?#

No. Beneath the version number, the cover page of the document published on 17 March 2026 carries the mention « VERSION DE TRAVAIL » — working draft. The framework places itself explicitly within the French national transposition of NIS2 — that is the document's own title — and its content can therefore still change.

That has a direct commercial consequence: the target is known, the date of the exam is not. An MSP can already help its clients organise around the 20 objectives — inventory, governance, identity management, continuity plan — without being able to promise a compliance date or a certified status. Faced with a client asking where it stands, the most honest wording remains "ReCyF preparation", not "ReCyF compliance": the framework it is preparing for can still change before its final version.


Vigicap builds its assessment directly on the official ReCyF — the 20 objectives, the important/essential entity distinction, the mapping to ISO 27001 — and displays that "working draft" caveat rather than selling a compliance that does not yet exist.

TopicsReCyFANSSINIS2MSP