
The European NIS2 directive, gradually transposed into French law, redefines what it means for a company to be “protected.” In Poitiers, where the economic fabric combines industrial SMEs, digital services, and public actors, the convergence between fiber connectivity and cybersecurity obligations creates a concrete situation: having high-speed access is no longer enough; it must be proven that the infrastructure utilizing it complies with a rapidly evolving regulatory framework.
NIS2 Compliance in Poitiers: What the Directive Changes for Local SMEs
NIS2 significantly broadens the scope of entities subject to IT security obligations. Where the first version primarily targeted operators of vital services, NIS2 now encompasses sectors such as waste management, logistics, and digital service providers. For a Poitiers-based SME that develops SaaS software or manages health data, the question is no longer theoretical.
ANSSI has planned a gradual ramp-up: awareness phase until 2026, targeted audits starting in 2026, and then effective sanctions from 2027. This timeline leaves little room for organizations that have not yet mapped their critical systems or formalized incident response procedures.
Companies treating cybersecurity and connectivity in Poitiers as a purely technical subject, delegated to the IT service provider, risk discovering too late that NIS2 requires documented governance, not just an up-to-date antivirus.
Fiber Eligibility Address by Address: The Forgotten Link in Network Security

When discussing connectivity at the municipal level, overall figures obscure very variable realities. Fiber eligibility is now verified by address, not by municipality. In Poitiers and its metropolitan area, availability discrepancies exist from one street to another.
For a company subject to NIS2, the quality of the connection is not a comfort: it is an operational prerequisite. An unstable fiber link or a residual copper connection complicates the deployment of secure cloud solutions, real-time monitoring, and incident notification within the timelines mandated by the directive.
Open data fiber mapping tools allow for precise verification of a professional location’s eligibility. Before subscribing to a managed security offer or migrating data to a cloud platform, checking the actual connection of one’s address avoids costly surprises regarding latency or link redundancy.
Incident Notification and Software Publisher Obligations: The Often Ignored Aspect
The cyber component of the 2024-2030 military programming law has introduced obligations that directly affect local digital service providers. Software publishers must now notify certain vulnerabilities, and ANSSI has enhanced powers over hosts, access providers, registrars, and data center operators.
For a Poitiers-based company using SaaS solutions or hosting services for its clients, this entails several concrete checks:
- Ensuring that each software publisher used has a vulnerability disclosure policy compliant with the new notification requirements
- Verifying that the host or cloud provider complies with the obligations imposed by the military programming law, particularly regarding cooperation with ANSSI
- Documenting the digital subcontracting chain, as NIS2 makes the contracting entity co-responsible for the security of its providers
This last point is the one that surprises leaders the most. Compliance does not stop at the internal perimeter: it extends throughout the entire digital trust chain.
Data Theft and Incident Response: Adapting One’s Posture to the ANSSI 2025 Landscape

The threat landscape published by ANSSI for 2025 indicates a stability in the number of incidents handled compared to 2024. The threat is not progressing so much in volume as it is shifting: data exfiltration is seeing a marked increase, indicating that attackers prefer stealing information over simply disrupting services.
For companies in the Poitiers region, this evolution changes the nature of the risk. A classic ransomware attack blocks activity, but a silent exfiltration of customer data can go unnoticed for weeks. Detecting this type of attack relies on network monitoring capabilities that many SMEs have not deployed.
Two areas deserve particular attention:
- Implementing centralized logging of access to sensitive data, with alerts on unusual download volumes
- Regularly testing the incident response plan by simulating an exfiltration scenario rather than just the ransomware encryption scenario
- Integrating notification to the relevant authorities within a constrained timeframe, as NIS2 requires, which implies having identified interlocutors and procedures in advance
An untested incident response plan is a document, not a protection. The difference between the two is measured on the day the attack occurs.
Shifting from a general discourse on digital security to a verifiable operational posture represents the real challenge for Poitiers companies in the coming months. The regulatory deadlines of 2027 are approaching quickly, and preparation is happening now, address by address, system by system.