Compliance

ReCyF at a Glance

Published by ANSSI on March 17, 2026, the ReCyF (Cyber France Framework) translates the requirements of the European NIS 2 Directive into concrete, enforceable obligations for French organizations. This infographic summarizes the key points of the ReCyF to give you a clear and actionable overview of your obligations.

Download

This infographic will help you:

Identify which entities are covered by ReCyF, under which category (Significant Entity or Essential Entity), along with the security objectives associated with each level.
View the 20 security objectives, organized into four pillars (Governance, Protection, Defense, Resilience), to understand what ReCyF compliance actually entails.
Identify the four recognized methods for demonstrating compliance: internal documentation, ISO/IEC 27001:2022, ANSSI services, and alternative measures.

Key points from the ReCyF infographic

A framework based on NIS 2:

The ReCyF establishes mandatory security objectives by decree (the "what to do"), while allowing flexibility regarding the compliance measures proposed by ANSSI (the "how to do it").

Two levels of requirements depending on your status:

EI entities are subject to 15 security objectives (SO1 through SO15), while EE entities are subject to 20 objectives (SO1 through SO20), with additional requirements regarding the risk-based approach, hardening, and supervision.

4 pillars to guide your compliance efforts:

Governance (5 objectives), Protection (9 objectives), Defense (3 objectives), and Resilience (3 objectives) cover the full scope of security requirements set by ANSSI.

About Tenacy

Tenacy is a cyber GRC platform designed for security teams looking to streamline their compliance processes, automate their management, and demonstrate measurable results to senior management.

More than 200 organizations in 32 countries rely on Tenacy to streamline their risk management and multi-compliance efforts (NIS 2, DORA, ISO 27001, etc.).

Find out how Tenacy can transform your organization’s cybersecurity management with a personalized demo: book your demo today.