Glossary
Critical Provider to the State
A private contractor or subcontractor whose services are essential to the continuity of the State's sovereign functions, brought into NIS 2's scope to secure the supply chain.
A critical provider to the State is a private contractor, software vendor or subcontractor whose services or technologies are essential to the continuity of the State's sovereign functions, public safety or national sovereignty. NIS 2 brings these players into scope to secure the supply chain as a whole and prevent a cyberattack on a weak link from paralysing a major public institution.
Who is in scope?
Typically considered critical providers to the State:
- Software vendors used by ministries or public hospitals.
- Hosting or cloud providers for sensitive State information systems.
- Companies maintaining industrial control systems (SCADA) for national infrastructure.
- IT integrators and subcontractors with privileged access to government networks.
Practical consequences
- Subject to NIS 2 obligations regardless of size.
- Required to register with ANSSI under a formal mandate from the legal representative.
- Hardened access controls (MFA, isolated environments dedicated to the State).
- Ultra-fast incident notification within 24 hours.
- Exposure to ANSSI's a priori inspections (audits without a prior incident).