← All resources

NIS2 France: are accounting firms and fiduciaries in scope?

Published October 2, 2026 · 7 min read · CyberNovaLabs.io

An accounting practice is not an entity listed by NIS2, and France has not even finished transposing it. This guide sets out what does affect you, with the official texts and figures.

The short answer

No: an accounting firm or fiduciary is not, as such, an entity covered by the NIS2 directive. The annexes to Directive (EU) 2022/2555 list 18 sectors - energy, transport, health, digital infrastructure, managed ICT services, public administration, chemicals, waste, food - and the accounting profession is not among them[2][3]. And in France, as of 2 October 2026, there is still no NIS2 obligation to comply with: transposition is not complete, and the Resilience bill whose Title II carries NIS2 has not been enacted[1].

Three things do affect you, and two of them are already in force. This NIS2 guide for accounting firms in France sets out which ones, with the texts and the numbers.

Are you in scope? The tests, in order

Ask these in order. The first no takes you out of direct scope.

  1. Is my activity in one of the 18 annex sectors? For a practice doing bookkeeping, audit review, payroll and advisory: no.
  2. Does my firm provide managed IT services to clients? Hosting their ERP, administering their workstations, billed IT management. If so, you enter through the managed ICT services door, which is in the annexes[3].
  3. The size thresholds. Essential entity: at least 250 staff, or turnover above 50 million euros and a balance sheet above 43 million euros. Important entity: at least 50 staff, or turnover and balance sheet above 10 million euros[2]. The vast majority of French practices stay below the second threshold.
  4. Am I a supplier to a regulated entity? This is the question that actually matters, and we return to it below.

ANSSI publishes an official simulator to settle an individual case[2]. Run it once, archive the answer, date it.

Where France stands: nothing binding, but a framework already published

ANSSI leads the transposition and says it plainly: it is ongoing, and pending publication of the texts, future essential and important entities are invited to start now on a security approach consistent with NIS 2[1]. For a practice, that has three concrete consequences:

The three doors through which NIS2 still reaches an accounting firm

DoorWhat happensWhat you must hold
Supplying a regulated clientA clinic, a carrier, a manufacturer or a public body becomes an essential or important entity. The directive requires it to secure its supply chain. It turns to its suppliers, including you.A security questionnaire completed, dated, signed and reusable. Plus a security clause in your engagement letter.
Managed IT servicesIf you host or administer your clients' IT, even as a side activity, you fall within an annex sector.A written perimeter: what you manage, what you do not. Ambiguity is expensive here.
Professional secrecy and GDPRArticle 21 of Ordinance no. 45-2138 of 19 September 1945 binds the French chartered accountant to professional secrecy under the conditions and penalties of article 226-13 of the Criminal Code[10]. Payroll adds health data.Named per-client access rights, a processing register, a data breach procedure.

The first door is the one that arrives in the post without warning. We covered it in our guide to NIS2 for healthcare, hospitals and labs in Belgium: in-scope hospitals send their questionnaires to every supplier, accountants included.

1 September 2026 has already changed your exposure

Since 1 September 2026, every French business must be able to receive electronic invoices, and large and mid-sized companies must issue theirs through an approved platform[4]. Small businesses and micro-enterprises must issue from 1 September 2027[5]. An approved platform is a dematerialisation operator registered by the tax administration for a renewable three-year period[6].

For a practice, that means one thing: you become the digital transit point for your clients' invoicing. A compromised platform account does not hit one file, it hits the whole client book. That is precisely the target profile an attacker looks for.

Three questions to put to your software vendor this week

In writing, in three sentences: what is your approved platform's registration number? Is two-factor authentication enforced or merely optional on my firm's accounts? Who, on your side, can view my clients' invoices, and where are they stored?

The real risk for a French practice, in numbers

Cybermalveillance.gouv.fr, the national victim assistance scheme, assisted 33,012 professionals in 2025 - 27,934 businesses or associations and 5,078 public bodies - a 63 % rise in assistance requests compared with 2024[7]. The 2025 ranking of threats against businesses and associations leaves little doubt about what targets a practice[8]:

ThreatShare of requestsYear-on-year change
Account takeover21 %+52 %
Phishing16 %+29 %
Payment transfer fraud13.5 %+93 %
Ransomware8.1 %+9 %

Transfer fraud is up 93 % in a year[8]. It is the threat aimed most directly at an accounting firm: you hold the bank details, you prepare the payment files, and an email that looks like it came from the managing director is enough. Ransomware remains the fourth threat, with 1,691 assistance requests across all professional audiences in 2025[7].

The first five actions

  1. Run ANSSI's NIS2 simulator and archive the dated answer[2]. Ten minutes. It gives you a written answer to hand the first client who asks.
  2. Write your bank detail verification procedure. Every IBAN change is confirmed by phone, on a number you already hold, never the one given in the email. Two people for any transfer above a threshold you set. That is the counter-measure to the +93 %.
  3. Enforce two-factor authentication on email, the approved invoicing platform and the client portal. Account takeover is the top threat, at 21 % of requests[8].
  4. Book a MonAideCyber diagnostic. ANSSI offers a free first diagnostic with a cyber helper, in about an hour and a half, ending in six tailored recommendations[9].
  5. Prepare your answer to security questionnaires once and for all. One master document: perimeter, hosting, backups and restore testing, access management, subcontractors, notification deadline. You will fill it in twenty times.

If your firm also prospects, contact rules are a separate matter: we covered them in B2B prospecting and GDPR in France, Belgium and the Netherlands.

At CyberNovaLabs.io

CyberNovaLabs.io works in the Netherlands, Belgium, France and Luxembourg. For an accounting practice, two free tools with no sign-up: the NIS2 check, which tells you in a few questions whether you are in scope or only a supplier to a regulated entity, and the email security check, which verifies SPF, DKIM and DMARC on your domain - the way in for phishing and transfer fraud.

We also run B2B appointment setting for accounting and fiduciary firms, in Paris and across France. Priced on quotation, with no minimum term.

Let us talk about your firm in 20 minutes

Sources

  1. ANSSI - La directive NIS 2
  2. MesServicesCyber (ANSSI) - NIS 2 et simulateur
  3. Directive (UE) 2022/2555 (NIS2) - EUR-Lex
  4. impots.gouv.fr - Facturation electronique
  5. impots.gouv.fr - A partir de quand suis-je concerne par la reforme de la facturation electronique
  6. impots.gouv.fr - Facturation electronique et plateformes agreees
  7. Cybermalveillance.gouv.fr - Rapport d'activite 2025
  8. Cybermalveillance.gouv.fr - Les principales cybermalveillances visant les professionnels en 2025
  9. ANSSI - MonAideCyber
  10. Ordonnance n. 45-2138 du 19 septembre 1945 portant institution de l'ordre des experts-comptables
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked