{"id":30524,"date":"2026-07-22T16:50:43","date_gmt":"2026-07-22T15:50:43","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=30524"},"modified":"2026-07-22T17:05:22","modified_gmt":"2026-07-22T16:05:22","slug":"nis-2-what-impact-on-the-soc","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/","title":{"rendered":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0"},"content":{"rendered":"\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h1 style=\"text-align: justify;\" aria-level=\"1\"><span data-contrast=\"none\">The NIS 2\u00a0directive<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:360,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h1>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">A European\u00a0directive\u2026<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Directive\u00a0<\/span><b><span data-contrast=\"auto\">(EU) 2022\/2555<\/span><\/b><span data-contrast=\"auto\">\u00a0also known as the NIS 2 Directive (Network and Information Security 2), is a European directive adopted at the end of 2022. It aims to strengthen the cybersecurity and resilience of essential entities (EE) and important entities (IE)\u00a0operating\u00a0in critical sectors within the European Union.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">It was officially published on 27 December 2022 and requires Member States to transpose its provisions into national law by 17 October 2024 at the latest.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The directive is supplemented by several texts and documents that clarify its implementation, in particular:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\">The\u00a0<\/span><i><span data-contrast=\"auto\">NIS 2 Directive &#8211; Commission implementing Regulation C\u00a0(2024) 7151<\/span><\/i><span data-contrast=\"auto\">, which\u00a0accompanies\u00a0the NIS 2 Directive and details the requirements applicable to certain types of digital service providers: DNS providers, TLD domain name registries, security providers, etc.\u00a0<\/span><span data-contrast=\"auto\">(<\/span><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/nis2-commission-implementing-regulation-critical-entities-and-networks\"><span data-contrast=\"none\">link<\/span><\/a><span data-contrast=\"auto\">).<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">ENISA recommendations, which provide guidance for implementing the NIS 2 Directive:\u00a0<\/span><a href=\"https:\/\/www.enisa.europa.eu\/publications\/nis2-technical-implementation-guidance\"><span data-contrast=\"none\">NIS 2 Technical Implementation Guidance | ENISA<\/span><\/a><span data-contrast=\"auto\">. These recommendations are not, however, regulatory requirements and are intended solely to support compliance efforts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Transposition at national level<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><b><span data-contrast=\"auto\">The transposition of the NIS 2 Directive into French law is ongoing,<\/span><\/b><span data-contrast=\"auto\">\u00a0through a national legislative process and work by\u00a0the\u00a0French Cybersecurity Agency (ANSSI)\u00a0to\u00a0define\u00a0the requirements. A first working version, not yet legally enforceable, of the\u00a0<\/span><b><span data-contrast=\"auto\">French Cybersecurity Framework (ReCyF)<\/span><\/b><span data-contrast=\"auto\">\u00a0was published by ANSSI on 17 March 2026. It sets out a series of security\u00a0objectives\u00a0(20 in total) intended to clarify the requirements applicable to important\u00a0and\u00a0essential entities.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">At the same time, ANSSI has also made guidance available to help\u00a0organizations\u00a0identify\u00a0their status under NIS 2,\u00a0in particular to\u00a0determine\u00a0whether they fall within the scope of the entities subject to this regulation.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h1 style=\"text-align: justify;\" aria-level=\"1\"><span data-contrast=\"none\">Focus on the impact of NIS 2 on SOCs<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:360,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h1>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Operational security in NIS 2<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">A SOC (Security Operations Center) brings together the human,\u00a0organizational\u00a0and technical capabilities dedicated to\u00a0monitoring\u00a0the security of the information system. Its missions include collecting and\u00a0analyzing\u00a0security events, detecting suspicious activity,\u00a0qualifying\u00a0and escalating alerts, and supporting incident response.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Although the NIS 2 Directive does not directly target the SOC as a function, it imposes several requirements\u00a0directly related\u00a0to cyber risk management and\u00a0security\u00a0incident management.\u00a0As a result, NIS 2\u00a0directly affects\u00a0the\u00a0organization,\u00a0processes\u00a0and expected capabilities of SOCs within the entities in scope, notably through two key articles:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\">Article 21, which defines cybersecurity\u00a0risk-management\u00a0measures.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Article 23, which defines notification and information obligations\u00a0in the event of\u00a0a significant incident.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Focus on outsourced SOCs<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Today, many organizations rely on an\u00a0<\/span><b><span data-contrast=\"auto\">external or hybrid model<\/span><\/b><span data-contrast=\"auto\">, entrusting all or part of their SOC activities to MSSPs. This outsourcing makes regulatory compliance more complex, particularly with NIS 2.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">In this case, it is important to distinguish between the obligations\u00a0that apply to\u00a0the\u00a0in-scope\u00a0entity and those that may apply directly to the MSSP.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:120,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><b><span data-contrast=\"none\">The NIS 2 Directive defines the cybersecurity requirements applicable to essential and important entities<\/span><\/b><span data-contrast=\"none\">. These requirements\u00a0remain\u00a0<\/span><b><span data-contrast=\"none\">the responsibility of the entity<\/span><\/b><span data-contrast=\"none\">, although the entity may\u00a0<\/span><b><span data-contrast=\"none\">rely on service providers<\/span><\/b><span data-contrast=\"none\">\u00a0(such as MSSPs) to implement all or part of them.\u00a0In general, entities are not responsible for ensuring their providers&#8217; compliance with NIS 2 requirements that apply directly to those providers. However, they must ensure that critical providers\u00a0maintain\u00a0an appropriate level\u00a0of security.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:120,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">ENISA is currently working on a European certification scheme (EUMSS) for managed security service providers. This scheme aims to\u00a0harmonize\u00a0requirements across the EU and strengthen trust in these providers by making it easier to assess their security level and compliance with European regulatory requirements (NIS 2, DORA, etc.).<\/span><span data-ccp-props=\"{&quot;335559738&quot;:120,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">For MSSPs, the European Commission published\u00a0<\/span><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/nis2-commission-implementing-regulation-critical-entities-and-networks\"><span data-contrast=\"none\">Commission Implementing Regulation C(2024) 7151<\/span><\/a><span data-contrast=\"none\">, which sets out\u00a0<\/span><b><span data-contrast=\"none\">risk-management and incident-management requirements directly applicable to MSSPs<\/span><\/b><span data-contrast=\"none\">\u00a0(and certain other digital providers). This implementing\u00a0regulation requires MSSPs to be capable of\u00a0<\/span><b><span data-contrast=\"none\">managing cybersecurity risks and incidents<\/span><\/b><span data-contrast=\"none\">\u00a0end to end, not only for their clients but also\u00a0<\/span><b><span data-contrast=\"none\">within their own scope<\/span><\/b><span data-contrast=\"none\">.\u00a0In particular, it\u00a0requires MSSPs to:<\/span><span data-ccp-props=\"{&quot;335559738&quot;:120,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"none\">Implement cyber risk management within their own scope (identify\u00a0risks and apply\u00a0appropriate security\u00a0measures)<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\">Be able to\u00a0demonstrate\u00a0compliance with NIS 2 requirements<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\">Have operational capabilities for detecting,\u00a0qualifying\u00a0and responding to incidents, including notifying authorities, clients and stakeholders where\u00a0required<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\">Assess risks related to their own suppliers<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 style=\"text-align: justify;\" aria-level=\"2\">\u00a0<\/h2>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">SOC objectives in\u00a0ReCyF<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30538\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image1-1.png\" alt=\"\" width=\"624\" height=\"338\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image1-1.png 624w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image1-1-353x191.png 353w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image1-1-71x39.png 71w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">ReCyF\u00a0covers security incident management\u00a0in particular through\u00a0the following\u00a0objectives:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\"><strong>Objective 12 :<\/strong> Identification of and response to security incidents<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\"><strong>Objective 20 :<\/strong> Monitoring of information system security<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">These two\u00a0objectives\u00a0reflect a simple expectation: the entity must be able to\u00a0<\/span><b><span data-contrast=\"auto\">detect an incident<\/span><\/b><span data-contrast=\"auto\">,\u00a0<\/span><b><span data-contrast=\"auto\">qualify\u00a0it<\/span><\/b><span data-contrast=\"auto\">\u00a0and\u00a0<\/span><b><span data-contrast=\"auto\">respond to it<\/span><\/b><span data-contrast=\"auto\">\u00a0in a structured manner. This requires clear procedures, effective use of security events, and the ability to\u00a0identify\u00a0and handle alerts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">These\u00a0objectives\u00a0mainly apply\u00a0to essential entities (EE). Point 12.3, which requires a process to be defined for\u00a0analyzing\u00a0and qualifying\u00a0anomalous\u00a0events, is an exception, as it applies to both important entities (IE) and essential entities (EE).<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Action Plan for Compliance<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Checklist for compliance<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The NIS 2 Directive, as well as national frameworks such as those issued by ANSSI, primarily define\u00a0<\/span><b><span data-contrast=\"auto\">security\u00a0objectives<\/span><\/b><span data-contrast=\"auto\">\u00a0to be achieved. However, they deliberately\u00a0remain\u00a0relatively non-prescriptive\u00a0regarding\u00a0the means to be implemented.\u00a0But what does compliance mean in practice?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The first step is to\u00a0<\/span><b><span data-contrast=\"auto\">carry out a gap analysis<\/span><\/b><span data-contrast=\"auto\">\u00a0to assess the entity\u2019s current level of compliance with regulatory requirements across its entire scope. This includes precisely\u00a0identifying\u00a0activities performed internally and those outsourced to service providers (notably MSSPs or outsourced SOCs). It is essential to remember that, even\u00a0in the event of\u00a0outsourcing,\u00a0<\/span><b><span data-contrast=\"auto\">responsibility for compliance\u00a0remains\u00a0fully with the entity<\/span><\/b><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">We have\u00a0identified\u00a0eight key points to address the main NIS 2 requirements, based on our synthesis of the requirements most\u00a0impactful\u00a0for the SOC and ENISA\u2019s recommendations. This list is intended to support compliance efforts but does not replace a gap analysis based directly on the regulatory texts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\"> <img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30540\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image2-1.png\" alt=\"\" width=\"624\" height=\"365\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image2-1.png 624w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image2-1-327x191.png 327w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image2-1-67x39.png 67w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Image2-1-120x70.png 120w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">To improve readability, the key points have been grouped so that they can be addressed through the definition and implementation of two policies: an incident management policy and a\u00a0detection policy. For each key point, we propose key steps to implement,\u00a0mainly based\u00a0on ENISA recommendations.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h1 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Incident management policy<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h1>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Define a process for reporting\u00a0anomalous\u00a0events<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Before implementing complex monitoring through the collection and analysis of IT logs, it\u00a0is important to ensure that a mechanism for reporting and analyzing\u00a0anomalous\u00a0events is in place.\u00a0The first line of detection already relies on employee involvement, who may detect and report weak signals and suspicious events, such as phishing emails or\u00a0anomalous\u00a0system behavior.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">It is therefore essential to:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li style=\"text-align: justify;\"><span data-contrast=\"auto\">Provide employees,\u00a0suppliers\u00a0and customers with a\u00a0<\/span><b><span data-contrast=\"auto\">mechanism enabling them to report suspicious events<\/span><\/b><span data-contrast=\"auto\">. Multiple reporting channels should be provided and made easy to access and use<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><b><span data-contrast=\"auto\">Train employees<\/span><\/b><span data-contrast=\"auto\">\u00a0on how to use the incident reporting mechanism and\u00a0<\/span><b><span data-contrast=\"auto\">communicate<\/span><\/b><span data-contrast=\"auto\">\u00a0the reporting process to suppliers and customers<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><b><span data-contrast=\"auto\">Define suspicious events<\/span><\/b><span data-contrast=\"auto\">\u00a0according to non-exhaustive criteria and list the information to be included in reports<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Define an incident management process<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Regardless of the source of an incident, whether it comes from an employee report or from an alert raised by a detection tool, it must be handled according to a defined process. This is why ANSSI requires an incident handling procedure to be defined :<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Define an incident management policy including:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span>\n<ul>\n<li><span data-contrast=\"auto\">an\u00a0<\/span><b><span data-contrast=\"auto\">incident categorization system<\/span><\/b><span data-contrast=\"auto\">: severity, type, etc., as well as criteria enabling categorization, such as operational impact, criticality of the affected scopes, regulatory impact, etc., and the criteria for classifying events as incidents. Ensure that the incident management policy covers\u00a0<\/span><b><span data-contrast=\"auto\">different types\u00a0of incidents<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">an incident\u00a0<\/span><b><span data-contrast=\"auto\">triage<\/span><\/b><span data-contrast=\"auto\">\u00a0and escalation plan<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">the\u00a0<\/span><b><span data-contrast=\"auto\">roles and responsibilities<\/span><\/b><span data-contrast=\"auto\">\u00a0of stakeholders in handling the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<\/li>\n<li><b><span data-contrast=\"auto\">Regularly review<\/span><\/b><span data-contrast=\"auto\">\u00a0the incident management policy and\u00a0response\u00a0playbooks.\u00a0In particular, review\u00a0roles,\u00a0responsibilities\u00a0and procedures at least once a year<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Define a\u00a0<\/span><b><span data-contrast=\"auto\">communication plan<\/span><\/b><span data-contrast=\"auto\">\u00a0for communicating incidents to the relevant stakeholders and personnel<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Align the policy with local requirements<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Article 23 of the NIS 2\u00a0directive\u00a0requires entities to report incidents to the competent authorities. This illustrates the need to ensure that the incident management policy is consistent with applicable laws,\u00a0regulations\u00a0and standards, as well as with business needs:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\">Ensure that the procedure\u00a0<\/span><b><span data-contrast=\"auto\">complies with\u00a0applicable laws,\u00a0regulations\u00a0and industry standards<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Align the incident management procedure with business needs and the business continuity and disaster recovery plan<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Define a communication plan that\u00a0complies with\u00a0regulations, including in particular:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">A procedure for notifying the CSIRT and competent authorities<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">A procedure for communicating with customers and suppliers<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\" aria-level=\"3\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Anticipate the response to the main incident types<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The incident management policy must be comprehensive and enable all types of incidents to be handled. It can be supplemented with documents targeting incidents identified as likely or critical:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li style=\"text-align: justify;\"><span data-contrast=\"auto\">Set up\u00a0<\/span><b><span data-contrast=\"auto\">response playbooks<\/span><\/b><span data-contrast=\"auto\">\u00a0and incident response procedures covering containment,\u00a0eradication\u00a0and service restoration (return to normal) after the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><span data-contrast=\"auto\">Define the\u00a0<\/span><b><span data-contrast=\"auto\">roles and responsibilities<\/span><\/b><span data-contrast=\"auto\">\u00a0for the actions\u00a0identified\u00a0in the response playbooks<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 style=\"text-align: justify;\" aria-level=\"3\">\u00a0<\/h2>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Retain incident records<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The\u00a0objectives\u00a0set by ANSSI emphasize the need to\u00a0retain\u00a0incident records, both for internal traceability and for potential legal use.\u00a0Therefore, organizations should:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><b><span data-contrast=\"auto\">Retain technical records<\/span><\/b><span data-contrast=\"auto\">\u00a0that enabled the incident to be detected<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Retain records of the actions taken<\/span><\/b><span data-contrast=\"auto\">\u00a0in response to the incident:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Time of detection and closure of the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Indicators of compromise and description of the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Actions taken to investigate, qualify and resolve the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Communications to customers,\u00a0suppliers\u00a0and stakeholders during and after incident resolution<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Notifications to the CSIRT and authorities<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Post-incident\u00a0analysis\u00a0report<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Retain records from tests of incident response procedures<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Set up an infrastructure for\u00a0<\/span><b><span data-contrast=\"auto\">storing\u00a0&amp;\u00a0retaining\u00a0technical records<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Restrict access<\/span><\/b><span data-contrast=\"auto\">\u00a0to technical records, in particular write access, to prevent any\u00a0unauthorized\u00a0access or modification<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">It should nevertheless be recalled that these records must be stored in compliance with applicable regulations, particularly those relating to the protection of personal data.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\">\u00a0<\/h2>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Conduct\u00a0post-incident\u00a0analyses<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">While\u00a0retaining\u00a0incident records may serve legal purposes, it is also valuable for improving incident response processes\u00a0through post-incident analyses, and organizations should:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\">Conduct\u00a0<\/span><b><span data-contrast=\"auto\">post-incident analyses<\/span><\/b><span data-contrast=\"auto\">\u00a0to\u00a0determine\u00a0root causes and\u00a0identify\u00a0the actions needed to prevent recurrence of the incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Ensure that post-incident analysis reports are\u00a0considered\u00a0when defining security policies<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Regularly review recent incidents to ensure that post-incident analyses have been carried out where relevant<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h1 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Detection policy<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h1>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">While incident response procedures guide the entity once an incident has been detected, it is also crucial to define a detection policy, aimed at setting out the detection strategy and the types of events to be detected.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Define a detection strategy<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The detection policy must first define\u00a0<\/span><b><span data-contrast=\"auto\">the detection strategy<\/span><\/b><span data-contrast=\"auto\">, namely:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span data-contrast=\"auto\">Identify\u00a0the\u00a0<\/span><b><span data-contrast=\"auto\">scopes to be\u00a0monitored<\/span><\/b><span data-contrast=\"auto\">, the\u00a0<\/span><b><span data-contrast=\"auto\">detection\u00a0objectives<\/span><\/b><span data-contrast=\"auto\">, and the data, algorithms and\u00a0<\/span><b><span data-contrast=\"auto\">tools\u00a0required<\/span><\/b><span data-contrast=\"auto\">\u00a0for detection<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Rely on detection tools to\u00a0<\/span><b><span data-contrast=\"auto\">automate detection<\/span><\/b><span data-contrast=\"auto\">\u00a0and\u00a0minimize\u00a0false positives and false negatives<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Ensure that\u00a0<\/span><b><span data-contrast=\"auto\">alert handling is carried out\u00a0in accordance with\u00a0documented procedures<\/span><\/b><span data-contrast=\"auto\">\u00a0and within controlled\u00a0timeframes<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Conduct\u00a0<\/span><b><span data-contrast=\"auto\">exercises to test incident response procedures<\/span><\/b><span data-contrast=\"auto\">\u00a0at least once a year<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Leverage on\u00a0<\/span><b><span data-contrast=\"auto\">post-incident analyses<\/span><\/b><span data-contrast=\"auto\">\u00a0to\u00a0identify\u00a0areas for improvement in processes, record the actions taken to resolve the incident and\u00a0identify\u00a0the actions needed to improve the response to this type of incident<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Regularly review recent incidents to ensure that post-incident analyses have been carried out where relevant<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Update the detection policy regularly<\/span><\/b><span data-contrast=\"auto\">\u00a0and after every major incident,\u00a0organizational change, or change in the security strategy, also taking post-incident reports into account<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<h2 style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Collect\u00a0the\u00a0appropriate\u00a0logs<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Once the detection strategy has been defined, it should be implemented as follows:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li style=\"text-align: justify;\"><span data-contrast=\"auto\">Ensure the\u00a0<\/span><b><span data-contrast=\"auto\">collection of monitoring data<\/span><\/b><span data-contrast=\"auto\">\u00a0across the relevant scopes, for example: network, user management, system access, authentication, security events such as antivirus alerts, physical access, etc.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><span data-contrast=\"auto\">Implement\u00a0<\/span><b><span data-contrast=\"auto\">analysis of the collected logs<\/span><\/b><span data-contrast=\"auto\">\u00a0in terms of volume,\u00a0type\u00a0and other relevant indicators to detect any unusual or undesirable trend. Where\u00a0appropriate, alerts may be set up\u00a0in the event of\u00a0anomalies, such as an interruption in log collection, together with\u00a0appropriate response\u00a0actions<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><b><span data-contrast=\"auto\">Protect logs and data<\/span><\/b><span data-contrast=\"auto\">\u00a0against unauthorized access and modification<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li style=\"text-align: justify;\"><b><span data-contrast=\"auto\">Retain backups<\/span><\/b><span data-contrast=\"auto\">\u00a0of monitoring data and protect them against unauthorized access and modification. Regularly test the completeness and reliability of backups, as well as recovery processes<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h1 style=\"text-align: justify;\" aria-level=\"2\"><span data-contrast=\"none\">Conclusion<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h1>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">NIS 2 compliance requires a comprehensive approach that spans all aspects of cybersecurity.\u00a0Operational security and the role of the SOC must not be overlooked, particularly when addressing incident response requirements.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Because the SOC involves many teams and, in some cases, service providers, its strategy can be difficult to steer. This is why we have detailed here the main points to ensure\u00a0SOC compliance with the NIS 2\u00a0directive. We therefore recommend that entities subject to the regulation\u00a0anticipate\u00a0its implementation in France and assess, as of now, the level of compliance of their incident response capabilities with the regulation,\u00a0in order to\u00a0define a compliance action plan where necessary.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the&#8230;<\/p>\n","protected":false},"author":1605,"featured_media":30532,"comment_status":"open","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2777,3977],"tags":[5142,3034,3156,3126],"coauthors":[5139,5140,5141],"class_list":["post-30524","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-digital-trust","category-focus","tag-operational-security","tag-reglementation-en","tag-risk-management-en","tag-soc-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight<\/title>\n<meta name=\"description\" content=\"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-22T15:50:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-22T16:05:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Antoine Destalenx, Martin Gregoire, Louis Rideau\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Antoine Destalenx, Martin Gregoire, Louis Rideau\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\"},\"author\":{\"name\":\"Antoine Destalenx\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/6b0bdcf4bf49fc297c4114ae2f7f654a\"},\"headline\":\"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0\",\"datePublished\":\"2026-07-22T15:50:43+00:00\",\"dateModified\":\"2026-07-22T16:05:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\"},\"wordCount\":2145,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png\",\"keywords\":[\"Operational security\",\"r\u00e8glementation\",\"risk management\",\"SOC\"],\"articleSection\":[\"Cybersecurity &amp; Digital Trust\",\"Focus\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\",\"name\":\"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png\",\"datePublished\":\"2026-07-22T15:50:43+00:00\",\"dateModified\":\"2026-07-22T16:05:22+00:00\",\"description\":\"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png\",\"width\":1536,\"height\":1024,\"caption\":\"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/6b0bdcf4bf49fc297c4114ae2f7f654a\",\"name\":\"Antoine Destalenx\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/antoine-destalenx\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight","description":"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/","og_locale":"en_US","og_type":"article","og_title":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight","og_description":"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/","og_site_name":"RiskInsight","article_published_time":"2026-07-22T15:50:43+00:00","article_modified_time":"2026-07-22T16:05:22+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png","type":"image\/png"}],"author":"Antoine Destalenx, Martin Gregoire, Louis Rideau","twitter_misc":{"Written by":"Antoine Destalenx, Martin Gregoire, Louis Rideau","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/"},"author":{"name":"Antoine Destalenx","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/6b0bdcf4bf49fc297c4114ae2f7f654a"},"headline":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0","datePublished":"2026-07-22T15:50:43+00:00","dateModified":"2026-07-22T16:05:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/"},"wordCount":2145,"commentCount":0,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png","keywords":["Operational security","r\u00e8glementation","risk management","SOC"],"articleSection":["Cybersecurity &amp; Digital Trust","Focus"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/","name":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0 - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png","datePublished":"2026-07-22T15:50:43+00:00","dateModified":"2026-07-22T16:05:22+00:00","description":"With the transposition of NIS 2 into French law approaching, organizations must prepare for a significant strengthening of cybersecurity requirements.\u00a0For the entities concerned, the question is no longer whether operational security will be affected, but how. This article explains the main impacts of NIS 2 on SOCs, whose missions, processes and expected standards are set to evolve.\u00a0","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/Designer-1.png","width":1536,"height":1024,"caption":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/nis-2-what-impact-on-the-soc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"NIS 2: What\u00a0impact on\u00a0the SOC ?\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/6b0bdcf4bf49fc297c4114ae2f7f654a","name":"Antoine Destalenx","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/antoine-destalenx\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/30524","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1605"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=30524"}],"version-history":[{"count":5,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/30524\/revisions"}],"predecessor-version":[{"id":30543,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/30524\/revisions\/30543"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/30532"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=30524"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=30524"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=30524"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=30524"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}