France NIS2 Manufacturing: How Airbus, Safran, and Thales Pull Suppliers Into Compliance They Don’t Legally Owe
Quick answer: if your factory sits in France and employs 50 or more people — or turns over and holds a balance sheet both above €10 million — NIS2 almost certainly applies to you as an important entity under Annex II, Section 5. But a second, quieter mechanism reaches further than that test: if you supply Airbus, Safran, Thales, or another French essential entity, you can face NIS2-grade security demands with zero staff and zero direct legal obligation. This guide covers both.
Manufacturing is one of six sectors added to NIS2’s Annex II, and France layers its own national authority, its own security framework, and a decades-old critical-infrastructure regime on top of the EU baseline. Most compliance guides stop at the directive’s text. This one covers what’s specific to operating a factory in France — including the supply-chain mechanism that pulls subcontractors into compliance the size-cap rule was never meant to catch.
Does NIS2 Apply to Your French Manufacturing Business?
In plain terms: if you manufacture physical products in France and clear a modest headcount or revenue bar, you’re almost certainly in scope — the test is public and mechanical, not a judgment call by a regulator.
NIS2 Annex II, Section 5 covers six manufacturing categories: medical devices and in vitro diagnostics under Regulations (EU) 2017/745 and 2017/746 (excluding the subset already captured under Annex I’s health provisions), and four NACE Rev. 2 divisions — computer, electronic and optical products (Division 26), electrical equipment (27), machinery and equipment not elsewhere classified (28), motor vehicles and trailers (29), and other transport equipment (30), which is where most aerospace and rail-rolling-stock manufacturers sit [2].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The size test that actually puts you in scope has two parts, and the exact wording matters: an entity is regulated once it has 50 or more staff, OR — if headcount stays below 50 — once both annual turnover and balance sheet total exceed €10 million. Clearing turnover alone, with a smaller balance sheet, doesn’t put a sub-50-staff company in scope on its own. Large enterprises (250+ staff, or turnover above €50 million with a balance sheet above €43 million) don’t get pushed into the stricter "essential entity" tier just for being big: under Article 3(2), an Annex II entity that doesn’t separately qualify under one of Article 3(1)’s specific essential-entity criteria stays classified as an important entity regardless of scale [1]. A 3,000-employee automotive-parts plant and a 60-employee electronics workshop can carry the same classification.
| Test | Threshold | Result |
|---|---|---|
| Headcount | ≥50 staff | In scope (at least important) |
| Financials (only checked if staff <50) | Turnover AND balance sheet both >€10M | In scope (at least important) |
| Large-enterprise ceiling | ≥250 staff OR (turnover>€50M AND balance>€43M) | Still "important" for Annex II — size alone doesn’t escalate you to essential [1] |
If you’re below both thresholds, NIS2 doesn’t reach you directly — skip to the section on Airbus, Safran, and Thales below, because a second mechanism might reach you anyway.
The Article 21 Measures Your Factory Floor Must Document
In plain terms: NIS2 doesn’t hand manufacturers an OT-specific rulebook — it applies the same ten measures written for any sector, and translating "network security" into segmented PLC networks and legacy SCADA is your documentation problem, not the legislator’s.
Article 21(2) sets ten mandatory risk-management measures. For a factory environment, the ones that create the most original documentation work are risk analysis covering both IT and OT assets, incident handling built around the 24-hour/72-hour/one-month reporting sequence, business continuity planning that accounts for OT recovery timelines rather than IT-standard RTOs, and supply chain security — which requires assessing "the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers," per Article 21(3) [3]. That last measure, 21(2)(d), is the legal hook behind the Airbus/Safran/Thales mechanism covered further down.
What France Adds on Top of the Directive: ANSSI, ReCyF, and MonEspaceNIS2
In plain terms: France centralises NIS2 supervision in a single agency instead of splitting it across regulators, and that agency has already published its own interpretation of what the ten measures should look like in practice.
ANSSI (Agence nationale de la sécurité des systèmes d’information) holds three roles other member states typically split across separate bodies: national competent authority, single point of contact for cross-border coordination, and national CSIRT through CERT-FR [4]. On 17 March 2026, ANSSI published the Référentiel Cyber France (ReCyF) — a working framework that translates NIS2’s ten Article 21 measures into 20 security objectives across four groups (governance, IT protection, detection/response, and enhanced requirements for essential entities), built around a proportionality principle so the expected effort scales to an entity’s actual maturity [5]. ReCyF isn’t mandatory by default, but ANSSI has said entities that apply it can point to it as evidence during an inspection [5].
The MonEspaceNIS2 portal (messervices.cyber.gouv.fr/nis2) has been open for voluntary pre-registration since late 2025 and includes a scope simulator for a preliminary essential/important read before the national transposition law — the Loi Résilience — formally opens registration [4]. France missed the original 17 October 2024 EU transposition deadline and received a European Commission reasoned opinion over it in May 2025; final adoption is expected during 2026 [9]. Until it passes, ANSSI is running enforcement under its existing NIS1-era powers while encouraging early voluntary action — see this site’s France penalties and enforcement guide for the audit and sanctions timeline in detail.
Your OIV Status Is Not Your NIS2 Status
In plain terms: France already had a critical-infrastructure regime running for a decade before NIS2 existed — and unlike NIS2’s scope test, it doesn’t use a number you can look up.
Since the 2013 Loi de Programmation Militaire, France has designated certain operators as Opérateurs d’Importance Vitale (OIV) — entities whose damage or destruction could severely harm national defence or economic capacity, or seriously endanger public health or life, under Article R1332-1 of the Code de la défense [6]. Manufacturing shows up here too: the OIV framework spans sectors including industry and armament activities. The critical difference from NIS2’s Annex II test is how you find out you’re covered. NIS2 gives you a headcount and turnover figure you can check yourself. OIV designation, under Article R1332-3, works by ministerial order on a case-by-case basis, after review by an interministerial advisory commission — there is no published staff or revenue threshold, and the designation orders themselves aren’t published [6]. Roughly 250–300 organisations reportedly hold OIV status in France, but the list is classified, and designated operators are asked not to discuss their inclusion.
The practical consequence: passing the NIS2 Annex II size test tells you nothing about your OIV status, and vice versa. A 40-employee precision-components maker could clear NIS2’s size-cap easily (staff below 50 keeps it out unless both financial thresholds are also cleared) and still be sitting on a classified OIV designation because of what it supplies into. Don’t treat "we checked, we’re not OIV-designated" as proof you’re also outside NIS2 — or the reverse. Confirm each test separately, and route the OIV question to your legal or compliance team rather than assuming IT would know. See this site’s France NIS2 overview for how the two regimes interact on enforcement.
The Airbus, Safran, and Thales Effect: Compliance Reaches Suppliers NIS2 Never Named
In plain terms: Some of France’s largest manufacturers are already NIS2 essential entities, and the directive requires them to police their own suppliers’ security — which is how a subcontractor with twelve employees ends up meeting NIS2-grade requirements it was never legally handed.
According to compliance analysis from Ayi Nedjimi Consultants, Airbus, Dassault Aviation, Safran, and Thales are already operating as NIS2 essential entities and are expected to demonstrate they secure their entire digital supply chain [7]. NIS2 itself doesn’t regulate their subcontractors directly — Article 21(2)(d) and 21(3) place the obligation on the prime contractor to assess "the vulnerabilities specific to each direct supplier," not on the supplier to independently comply [3]. But that obligation has to land somewhere, and in practice it lands in the contract. The same analysis reports that contractual security clauses are already built into new Airbus, Dassault, and Safran tenders, with consequences for subcontractors who fail them ranging from contract non-renewal to exclusion from future bids [7].
The industry’s own response predates NIS2: AirCyber Bronze, a labelling framework run through the BoostAeroSpace consortium the four primes established with ANSSI’s encouragement, sets out 44 ANSSI-aligned security measures that reportedly cover around 80% of what a subcontractor would face under direct NIS2 obligations [7]. For context on scale, one industry estimate puts Airbus’s own supplier base at roughly 18,000 subcontractors, with around 1,000 flagged as critical [8] — a population where the overwhelming majority sit well under NIS2’s 50-employee threshold and have no statutory relationship with the directive at all.
The upshot for any French Annex II manufacturer reading this because you sell into aerospace or defense: you may have zero direct NIS2 obligation and still face a harder security bar than the directive itself sets — because your customer’s Article 21(2)(d) obligation becomes your contract clause. Check your next tender renewal for security-attestation language before you assume the size-cap rule protects you from the conversation entirely, and see this site’s supply chain security guide for how to document supplier-side compliance evidence even when you’re the smaller party.
Your Compliance Checklist and Timeline
In plain terms: most of the useful preparation work doesn’t require the national law to pass first — the scope test, the gap assessment, and the contract review can all start now.
| Step | Effort | When |
|---|---|---|
| Run the Annex II Section 5 scope test above against your actual headcount/turnover/balance sheet | Low | Now |
| Pre-register on MonEspaceNIS2 and run the scope simulator | Low | Available now |
| Ask legal/compliance — not just IT — whether any site carries an undisclosed OIV designation | Low | Now |
| Gap-assess against ReCyF’s 20 objectives or Article 21(2)(a)–(j) directly | Medium | Before Q4 2026 audits begin |
| Review Airbus/Safran/Thales/Dassault tender language for security-attestation clauses if you supply them | Medium | At next tender renewal, not after |
| Build a documented supplier-criticality register under Article 21(2)(d), whichever side of the contract you’re on | High | Before your next audit or tender cycle |
ANSSI has signalled a phased posture: information and awareness through 2026, targeted audits from 2026 into 2027, and sanctions from 2027 onward for entities that fail an audit and don’t remediate. Fine exposure once the Loi Résilience is promulgated mirrors the directive’s own ceilings — up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher in each case. The full enforcement ladder and appeals process are covered in this site’s France penalties and enforcement guide.
Frequently Asked Questions
Does NIS2 apply to a French subcontractor with only 15 employees?
Not directly — you’re below the 50-staff threshold, and unless your turnover and balance sheet both clear €10 million, the size-cap rule doesn’t reach you. But if you supply an essential entity like Airbus or Safran, you can still face NIS2-grade security requirements contractually, as covered above.
Is ISO 27001 certification enough to satisfy NIS2 in France?
Not on its own. ANSSI’s own ReCyF comparison guidance credits ISO 27001 with directly satisfying only a handful of its 20 security objectives — broader coverage typically requires layering ISO 27002 controls on top, and Essential Entities are expected to address all 20 objectives rather than a partial set.
Does having (or not having) an OIV designation change our NIS2 obligations?
No — the two regimes run in parallel, not as substitutes for each other. OIV/LPM obligations under the Code de la défense are typically stricter and can require ANSSI certification before certain systems may even operate; NIS2 uses administrative fines instead. Confirm each status separately rather than assuming one implies the other.
What happens if we get our scope determination wrong?
ANSSI’s enforcement ladder starts with warnings and binding instructions before any fine is considered, and essential entities face proactive audits while important entities are typically reviewed reactively, after an incident or complaint. Getting the classification wrong early is far cheaper to fix than getting caught unprepared at audit — see the France penalties guide linked above for the full sequence.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive (EU) 2022/2555, Article 3 — Essential and Important Entities, nis-2-directive.com
- NIS2 Directive Annex II, Section 5 (Manufacturing) — streamlex.eu mirror of the directive text
- NIS2 Directive Article 21 — Cybersecurity Risk-Management Measures, nis-2-directive.com
- "NIS 2 : l’ANSSI poursuit et renforce sa dynamique d’accompagnement," ANSSI, 18 March 2026
- Code de la défense, Articles R1332-1 to R1332-42 (Protection des installations d’importance vitale), Légifrance
- "AirCyber et NIS 2 : Conformité Supply Chain Aérospatiale," Ayi Nedjimi Consultants
- "Industrie : Airbus et Safran face au défi des chaînes d’approvisionnement," Information en Direct
- "NIS 2 Directive | Transposition in France," nis-2-directive.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
