NIS2 France: are accounting firms and fiduciaries in scope?
An accounting practice is not an entity listed by NIS2, and France has not even finished transposing it. This guide sets out what does affect you, with the official texts and figures.
The short answer
No: an accounting firm or fiduciary is not, as such, an entity covered by the NIS2 directive. The annexes to Directive (EU) 2022/2555 list 18 sectors - energy, transport, health, digital infrastructure, managed ICT services, public administration, chemicals, waste, food - and the accounting profession is not among them[2][3]. And in France, as of 2 October 2026, there is still no NIS2 obligation to comply with: transposition is not complete, and the Resilience bill whose Title II carries NIS2 has not been enacted[1].
Three things do affect you, and two of them are already in force. This NIS2 guide for accounting firms in France sets out which ones, with the texts and the numbers.
Are you in scope? The tests, in order
Ask these in order. The first no takes you out of direct scope.
- Is my activity in one of the 18 annex sectors? For a practice doing bookkeeping, audit review, payroll and advisory: no.
- Does my firm provide managed IT services to clients? Hosting their ERP, administering their workstations, billed IT management. If so, you enter through the managed ICT services door, which is in the annexes[3].
- The size thresholds. Essential entity: at least 250 staff, or turnover above 50 million euros and a balance sheet above 43 million euros. Important entity: at least 50 staff, or turnover and balance sheet above 10 million euros[2]. The vast majority of French practices stay below the second threshold.
- Am I a supplier to a regulated entity? This is the question that actually matters, and we return to it below.
ANSSI publishes an official simulator to settle an individual case[2]. Run it once, archive the answer, date it.
Where France stands: nothing binding, but a framework already published
ANSSI leads the transposition and says it plainly: it is ongoing, and pending publication of the texts, future essential and important entities are invited to start now on a security approach consistent with NIS 2[1]. For a practice, that has three concrete consequences:
- ReCyF, the French cyber framework published by ANSSI on 17 March 2026, is a set of recommended measures, non-mandatory by default[1]. It is currently the best available reading grid in French.
- Registration with ANSSI exists only as voluntary pre-registration. No statutory deadline applies yet[1][2].
- Penalties expressed as a percentage of turnover circulate widely in sales pitches. They come from the directive and the bill, not from a French text in force. Be wary of any provider selling you a dated French fine.
The three doors through which NIS2 still reaches an accounting firm
| Door | What happens | What you must hold |
|---|---|---|
| Supplying a regulated client | A clinic, a carrier, a manufacturer or a public body becomes an essential or important entity. The directive requires it to secure its supply chain. It turns to its suppliers, including you. | A security questionnaire completed, dated, signed and reusable. Plus a security clause in your engagement letter. |
| Managed IT services | If you host or administer your clients' IT, even as a side activity, you fall within an annex sector. | A written perimeter: what you manage, what you do not. Ambiguity is expensive here. |
| Professional secrecy and GDPR | Article 21 of Ordinance no. 45-2138 of 19 September 1945 binds the French chartered accountant to professional secrecy under the conditions and penalties of article 226-13 of the Criminal Code[10]. Payroll adds health data. | Named per-client access rights, a processing register, a data breach procedure. |
The first door is the one that arrives in the post without warning. We covered it in our guide to NIS2 for healthcare, hospitals and labs in Belgium: in-scope hospitals send their questionnaires to every supplier, accountants included.
1 September 2026 has already changed your exposure
Since 1 September 2026, every French business must be able to receive electronic invoices, and large and mid-sized companies must issue theirs through an approved platform[4]. Small businesses and micro-enterprises must issue from 1 September 2027[5]. An approved platform is a dematerialisation operator registered by the tax administration for a renewable three-year period[6].
For a practice, that means one thing: you become the digital transit point for your clients' invoicing. A compromised platform account does not hit one file, it hits the whole client book. That is precisely the target profile an attacker looks for.
Three questions to put to your software vendor this week
In writing, in three sentences: what is your approved platform's registration number? Is two-factor authentication enforced or merely optional on my firm's accounts? Who, on your side, can view my clients' invoices, and where are they stored?
The real risk for a French practice, in numbers
Cybermalveillance.gouv.fr, the national victim assistance scheme, assisted 33,012 professionals in 2025 - 27,934 businesses or associations and 5,078 public bodies - a 63 % rise in assistance requests compared with 2024[7]. The 2025 ranking of threats against businesses and associations leaves little doubt about what targets a practice[8]:
| Threat | Share of requests | Year-on-year change |
|---|---|---|
| Account takeover | 21 % | +52 % |
| Phishing | 16 % | +29 % |
| Payment transfer fraud | 13.5 % | +93 % |
| Ransomware | 8.1 % | +9 % |
Transfer fraud is up 93 % in a year[8]. It is the threat aimed most directly at an accounting firm: you hold the bank details, you prepare the payment files, and an email that looks like it came from the managing director is enough. Ransomware remains the fourth threat, with 1,691 assistance requests across all professional audiences in 2025[7].
The first five actions
- Run ANSSI's NIS2 simulator and archive the dated answer[2]. Ten minutes. It gives you a written answer to hand the first client who asks.
- Write your bank detail verification procedure. Every IBAN change is confirmed by phone, on a number you already hold, never the one given in the email. Two people for any transfer above a threshold you set. That is the counter-measure to the +93 %.
- Enforce two-factor authentication on email, the approved invoicing platform and the client portal. Account takeover is the top threat, at 21 % of requests[8].
- Book a MonAideCyber diagnostic. ANSSI offers a free first diagnostic with a cyber helper, in about an hour and a half, ending in six tailored recommendations[9].
- Prepare your answer to security questionnaires once and for all. One master document: perimeter, hosting, backups and restore testing, access management, subcontractors, notification deadline. You will fill it in twenty times.
If your firm also prospects, contact rules are a separate matter: we covered them in B2B prospecting and GDPR in France, Belgium and the Netherlands.
At CyberNovaLabs.io
CyberNovaLabs.io works in the Netherlands, Belgium, France and Luxembourg. For an accounting practice, two free tools with no sign-up: the NIS2 check, which tells you in a few questions whether you are in scope or only a supplier to a regulated entity, and the email security check, which verifies SPF, DKIM and DMARC on your domain - the way in for phishing and transfer fraud.
We also run B2B appointment setting for accounting and fiduciary firms, in Paris and across France. Priced on quotation, with no minimum term.
Let us talk about your firm in 20 minutes
Sources
- ANSSI - La directive NIS 2
- MesServicesCyber (ANSSI) - NIS 2 et simulateur
- Directive (UE) 2022/2555 (NIS2) - EUR-Lex
- impots.gouv.fr - Facturation electronique
- impots.gouv.fr - A partir de quand suis-je concerne par la reforme de la facturation electronique
- impots.gouv.fr - Facturation electronique et plateformes agreees
- Cybermalveillance.gouv.fr - Rapport d'activite 2025
- Cybermalveillance.gouv.fr - Les principales cybermalveillances visant les professionnels en 2025
- ANSSI - MonAideCyber
- Ordonnance n. 45-2138 du 19 septembre 1945 portant institution de l'ordre des experts-comptables
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →