NIS2 and ReCyF self-assessment: 20 questions
One question per objective of ANSSI's ReCyF, with the evidence that answers it: enough to place a company in an hour, before a real assessment.
To place a company quickly against ReCyF, you need one question per objective and one rule: answer "yes" only if you can show evidence. The 20 questions below follow the 20 objectives of ANSSI's framework. In an hour they give a first reliable picture of the gaps — not an assessment, but enough to know where to start.
ReCyF is a French document. An entity supervised outside France answers to its own country's transposition of NIS2; the grid is still useful as a structured checklist, and it becomes binding when a French client or group writes it into a contract.
How do you answer the 20 questions?#
Three possible answers to each question:
- Yes, and I can show it: a document, a screenshot, an export, a dated record.
- Partly: the measure exists, but not everywhere, not up to date, or without a trace.
- No, or I cannot prove it: to an auditor, the two amount to the same thing.
ReCyF publishes no scoring scale: it judges an objective met or not met. That is why evidence counts for more than intent. Objectives 16 to 20 concern essential entities only; for an important entity, stop at the first fifteen. The three-question test tells you which category the company falls into.
Governance#
- Objective 1 · Inventory of information systems. Is there an up-to-date inventory of applications, equipment, interconnections and their owners? Evidence: the inventory and the date it was last updated.
- Objective 2 · Governance framework. Are security roles written down, does a steering body meet, and has management made a formal commitment? Evidence: a signed policy and the minutes of the last meeting.
- Objective 3 · Control of the ecosystem. Are the suppliers with access to the systems listed, with security clauses in their contracts? Evidence: the list of critical suppliers and a standard contract.
- Objective 4 · Human resources. Do arrivals, role changes and departures trigger security actions, and are staff made aware? Evidence: the leaver procedure and a record of the last awareness session.
- Objective 16 · Risk-based approach (essential entities). Is there a formal risk analysis, and do treatment decisions follow from it? Evidence: the analysis and the treatment plan.
- Objective 17 · Audit (essential entities). Are security audits carried out regularly, with the gaps followed up? Evidence: the latest report and the status of its recommendations.
Protection#
- Objective 5 · Control of the information systems. Are updates and vulnerabilities managed, including equipment out of support? Evidence: a patch report and the list of obsolete systems.
- Objective 6 · Physical access. Is access to sensitive premises controlled and logged, visitors included? Evidence: the list of authorisations or an access log.
- Objective 7 · Architecture. Is the network segmented, so that one compromised machine does not open everything? Evidence: a network diagram and the filtering rules.
- Objective 8 · Remote access. Do remote working and supplier access go through strong authentication and encrypted connections? Evidence: the VPN or access-gateway configuration.
- Objective 9 · Malicious code. Is protection deployed on every workstation and server, and is its state actually monitored? Evidence: the antivirus or EDR console, with its coverage.
- Objective 10 · Identities and access. Are accounts named, rights reviewed, leavers revoked and multi-factor authentication in place? Evidence: the last access review and the share of accounts with MFA.
- Objective 11 · Administration. Are administrator accounts separate from everyday accounts, few in number and logged? Evidence: the list of administrators and an extract of the log.
- Objective 18 · Configuration (essential entities). Are hardened baseline configurations defined, applied and checked? Evidence: the hardening baseline and a compliance check.
- Objective 19 · Dedicated administration (essential entities). Is administration done from dedicated workstations and networks, isolated from office IT and the internet? Evidence: a description of those workstations and their network.
Defence#
- Objective 12 · Incidents. Can you detect, qualify and handle an incident, and report it within the NIS2 deadlines — early warning within 24 hours, notification within 72 hours, final report within a month? Evidence: the procedure and the reporting contacts.
- Objective 20 · Monitoring (essential entities). Are security logs collected and analysed to detect abnormal activity? Evidence: the collection tool and an alert that was handled.
Resilience#
- Objective 13 · Continuity and recovery. Are backups protected, and has a restore actually been tested? Is there a continuity and recovery plan? Evidence: the date and result of the last restore test.
- Objective 14 · Crisis management. Is a crisis cell planned, with roles and fallback means of communication? Evidence: the crisis organisation sheet and the offline directory.
- Objective 15 · Exercises. Are the arrangements tested through exercises, and do they lead to improvements? Evidence: the report of the last exercise.
How do you read the result?#
Count the "no" and "partly" answers: each one is a gap. Do not average — a good result on protection does not make up for a missing incident procedure. Start with the gaps that block everything else: the inventory, identities and access, tested backups, the incident procedure.
When Vigicap ran the same exercise on itself, technical protection held up well; the gaps clustered in governance, defence and resilience. What was mostly missing were documents and habits: a signed policy, a written incident procedure, a continuity plan, an exercise.
What does this self-assessment not replace?#
It replaces neither a full assessment, nor an audit, nor the authority's judgement. ReCyF itself is a working document, with no final version before the transposition is complete. And a "yes" without evidence is still a "no" the day someone asks to see it.
That is what a tooled assessment adds: in Vigicap, connectors read part of the answers directly from the client's tools — MFA, EDR, backups — and every level is validated by the consultant, evidence attached. To go further, the mapping table shows how the same 20 objectives line up with Article 21 of NIS2 and with ISO 27001.
Read next
ReCyF: the ANSSI cyber framework for MSPs
What ANSSI's ReCyF framework is, how it differs from the French cyber hygiene guide and from ISO 27001, and how an MSP runs an assessment.
ReCyF, NIS2, ISO 27001: the mapping table
ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.
ANSSI's 42 hygiene measures as a diagnostic base
Why ANSSI's cyber hygiene guide is still the best starting point for a small-business security diagnostic, and how to turn it into a costed plan.