Skip to content
CyberNIS2

Glossary

Critical Provider to the State

A private contractor or subcontractor whose services are essential to the continuity of the State's sovereign functions, brought into NIS 2's scope to secure the supply chain.

A critical provider to the State is a private contractor, software vendor or subcontractor whose services or technologies are essential to the continuity of the State's sovereign functions, public safety or national sovereignty. NIS 2 brings these players into scope to secure the supply chain as a whole and prevent a cyberattack on a weak link from paralysing a major public institution.

Who is in scope?

Typically considered critical providers to the State:

  • Software vendors used by ministries or public hospitals.
  • Hosting or cloud providers for sensitive State information systems.
  • Companies maintaining industrial control systems (SCADA) for national infrastructure.
  • IT integrators and subcontractors with privileged access to government networks.

Practical consequences

  • Subject to NIS 2 obligations regardless of size.
  • Required to register with ANSSI under a formal mandate from the legal representative.
  • Hardened access controls (MFA, isolated environments dedicated to the State).
  • Ultra-fast incident notification within 24 hours.
  • Exposure to ANSSI's a priori inspections (audits without a prior incident).