Skip to main content
ANSSI

ReCyF, NIS2, ISO 27001: the mapping table

ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.

L'équipe Vigicap7 min read

The 20 objectives of ANSSI's ReCyF cover the ten measures of Article 21 of the NIS2 Directive, and most of them have a counterpart in Annex A of ISO/IEC 27001:2022. One well-run assessment can therefore feed all three readings. The table below gives those correspondences objective by objective; the rest of the article explains where they stop, because a mapping is never an equivalence.

Why a mapping table, and what does it not say?#

An MSP looking after several clients hears all three names in the same week: one client falls within NIS2, another is preparing for ISO 27001 certification, a third has received a questionnaire that cites ReCyF. Running three assessments for three texts that largely talk about the same measures makes no sense.

But be precise about what a correspondence allows. A ReCyF objective "maps" to an ISO control when both deal with the same subject and the same evidence can serve both. It does not mean that meeting one amounts to meeting the other: the level of requirement, the scope and the way of checking differ. The ISO 27001 correspondences below come from ANSSI's comparator; the reading of Article 21 and the advice are ours.

ReCyF is also a French document. An entity supervised outside France answers to its own country's transposition of NIS2; ReCyF is relevant to it when a French client or group writes it into a contract, or simply as a well-structured grid to assess against.

What do the three texts say, in one sentence each?#

  • The NIS2 Directive sets the obligation. Its Article 21 lists ten families of measures, points (a) to (j); Article 20 makes management bodies accountable, and Article 23 organises incident reporting.
  • ANSSI's ReCyF v2.5 translates those obligations into 20 security objectives: 15 apply to important entities, all 20 to essential entities. It is a working document, with no final version before the French transposition is complete.
  • ISO/IEC 27001:2022 is a voluntary certification standard: an information security management system (clauses 4 to 10) and 93 controls in Annex A.

The table, objective by objective#

The NIS2 column is our reading of Article 21(2): the letters refer to its points. The next two columns come from the comparator published by ANSSI on MesServicesCyber, which matches each of ReCyF's 152 requirements to the ISO 2700x standards; we grouped its correspondences by objective. The level sums up what ANSSI records for the objective's requirements: "strong" when at least 60% of them are rated a high correspondence, "weak" when at least half are rated weak, "partial" otherwise. Data retrieved on 29 September 2026.

ReCyF objectiveNIS2 (Art. 21(2))ISO/IEC 27001:2022, Annex ACorrespondence according to ANSSI
1 · Inventory of information systems(i) asset management5.9, 5.30weak
2 · Digital security governance framework(a) policies; Art. 205.1, 5.2, 5.4, 5.5, 5.31, 5.36strong
3 · Control of the ecosystem(d) supply chain5.19–5.22partial
4 · Security in human resources management(i) human resources; (g) training5.10, 5.11, 5.16–5.18, 6.2, 6.3, 6.5, 6.6strong
5 · Control of the information systems(e) maintenance, vulnerabilities5.7, 5.9, 5.37, 8.7–8.9, 8.19strong
6 · Control of physical access to premisesArt. 21(2), all-hazards approach5.15, 7.1–7.4, 7.6–7.8strong
7 · Securing the architecture(e) network and system security8.2, 8.12, 8.18, 8.20–8.22, 8.27strong
8 · Securing remote access(j) strong authentication, secured communications5.17, 6.7, 7.9, 8.1, 8.5, 8.24partial
9 · Protection against malicious code(g) cyber hygiene5.10, 6.2, 6.3, 7.9, 7.10, 8.1, 8.3, 8.7, 8.20, 8.21, 8.27strong
10 · User identities and access(i) access control; (j) MFA5.15–5.18, 8.3, 8.5, 8.18strong
11 · Control of administration(i) access control5.3, 5.15, 5.18, 8.2, 8.18weak
12 · Identification of and response to incidents(b) incident handling; Art. 235.20, 5.24–5.28, 6.8strong
13 · Business continuity and recovery(c) continuity, backups5.29, 5.30, 8.6, 8.7, 8.13strong
14 · Response to crises of cyber origin(c) crisis management; (j) emergency communications5.20, 5.24, 5.26, 5.30weak
15 · Exercises, tests and drills(c); (f) assessing effectiveness5.2, 5.30, 6.3partial
16 · Risk-based approach (EE)(a) risk analysis5.2, 5.31strong
17 · Security audit (EE)(f) assessing effectiveness5.35, 5.36, 8.8, 8.9strong
18 · Securing the configuration (EE)(e); (g)8.9strong
19 · Administration from dedicated resources (EE)(i) access control5.17, 8.1, 8.20–8.22, 8.24, 8.27partial
20 · Security monitoring (EE)(b) incident detection5.19, 5.28, 8.15, 8.16strong

(EE): objective reserved for essential entities. For an important entity the assessment covers the other fifteen — the three-question test tells you which category a client falls into.

ANSSI also links nine objectives to the clauses of the standard on risk assessment and treatment (6.1.2, 6.1.3, 8.2 and 8.3), objective 2 to clause 5 on leadership, and objective 17 to clauses 9.2 (internal audit) and 10.2 (nonconformity).

Where does the mapping stop?#

According to ANSSI, the correspondence is weak for three objectives: the inventory of information systems (1), control of administration (11) and response to crises of cyber origin (14). The standard covers these subjects, but not at ReCyF's level of requirement. Four more correspond only in part: the ecosystem (3), remote access (8), exercises (15) and administration from dedicated resources (19). These seven objectives are where a client certified to ISO 27001 will most often show gaps.

Conversely, part of ISO 27001 is linked to no ReCyF requirement. Secure development is the clearest case: of controls 8.25 to 8.31, only 8.27 (secure system architecture) appears in the comparator. A ReCyF assessment therefore does not cover the software development lifecycle.

Cryptography, point (h) of Article 21, has no ReCyF objective bearing its name: ANSSI links control 8.24 (use of cryptography) to remote access (8) and to administration from dedicated resources (19).

For some providers, Article 21 is detailed elsewhere. Managed service providers and managed security service providers — a large share of MSPs, when they fall within scope themselves — are also subject to Implementing Regulation (EU) 2024/2690, which sets out the technical requirements of Article 21 for their sector. ANSSI's comparator also compares ReCyF with the annex to that regulation.

Does ISO 27001 certification mean NIS2 compliance?#

No. It covers a large part of it and provides reusable evidence — policy, risk analysis, management review, Annex A controls — but NIS2 is a legal obligation whose fulfilment is assessed by the national authority, on the scope and against the requirements of the national transposition. The certificate replaces neither registration, nor incident reporting, nor the management-body accountability of Article 20. It remains an excellent starting point.

How does an MSP use it in practice?#

Assess once, report three times. For a first snapshot before the assessment, the 20-question self-assessment follows the same objectives. The assessment runs on the 20 ReCyF objectives (or 15 for an important entity), each level backed by evidence. That same evidence then fills the ISO 27001 statement of applicability for a client aiming at certification, and answers a customer's NIS2 questionnaire.

Two rules avoid bad surprises: never carry a level from one framework to another without re-reading the evidence, and treat the no-mapping areas listed above separately. That is also how Vigicap works: its ISO 27001 statement of applicability is derived from the ReCyF assessment, and controls with no counterpart stay explicitly "to be assessed" rather than inheriting a level that has nothing to do with them.

TopicsReCyFNIS2ISO 27001Article 21mappingMSP