Press: NIS 2 physical security requirements

by SPAC Alliance | June 2026 | News, Press Publications

NIS 2: the steps to comply with the new physical security requirements - Journal du Net - June 6 2026 (translated by SPAC Alliance)

The NIS 2 Directive imposes access control measures for the sites and premises of the organizations it covers, combining appropriate technological solutions with suitable security policies.

While the NIS 2 Directive is mainly known for the cybersecurity obligations it imposes on essential and important entities, it also includes a lesser-known dimension: physical security requirements. These requirements will have to be met by more than 15,000 small and medium-sized enterprises, as well as by their suppliers, according to Mickaël Wajnglas, Secretary General of SPAC Alliance, an alliance bringing together physical and cyber security stakeholders.

“These security obligations will be reflected in contracts with suppliers. The NIS 2 Directive does indeed require organizations to assess the security level of their suppliers. More broadly, the market itself will expect companies to comply with physical security obligations.”

The issue is that companies often do not know what these physical security obligations actually cover, or even that they exist. “Companies that want to comply with the Directive now regularly ask me what they should do from a physical security standpoint,” adds Mickaël Wajnglas.

This is understandable, as the Directive remains vague on this point. It merely states that organizations must protect the “physical environment” of their network and information systems “against incidents”. However, more detailed recommendations already exist to meet this requirement today, without waiting for the legislative transposition of the Directive, which is still pending. Here are the steps to follow.

Understanding the physical security obligations

Published in March 2026 by the French National Cybersecurity Agency, ANSSI, the French Cybersecurity Framework, known as ReCyF, provides a set of best practices designed to help organizations comply with the NIS 2 Directive. At this stage, it is it is still a draft version. The final version will be published after the Directive has been transposed into national law.

Of the twenty cybersecurity objectives included in ReCyF, the sixth deals with physical security obligations. This objective sets out four “acceptable means of compliance” to “ensure that only authorized persons have access to the organization’s premises”:

  • “The entity implements security measures to restrict access by unauthorized persons to its premises, server rooms and technical rooms.”
  • “The entity ensures the physical protection of its premises, server rooms and technical rooms. This physical protection makes it possible to prevent, monitor and respond to unauthorized access to these premises.”
  • “The entity ensures that physical access rights are granted strictly on the basis of what is necessary for individuals to carry out their duties.”
  • “The entity ensures that external persons accessing the entity’s technical rooms and server rooms are accompanied or duly authorized.”

Although some of these measures are reserved for essential entities, Mickaël Wajnglas also advises important entities and their suppliers to implement all of them. “ReCyF explains that the second and third measures are not mandatory for important entities. But an important entity is very likely to be part of the supply chain of an essential entity, so it should implement all these measures. Everyone is concerned.”

Carrying out a risk analysis

To implement these means of compliance properly, the organization must carry out a risk analysis. “This is a mandatory prerequisite,” stresses Dominique Gueguen, Cybersecurity Engineer at Axis Communications, a company specializing in surveillance technologies.

“Indeed, the physical security measures to be implemented will depend on this risk mapping,” adds Mickaël Wajnglas.

This risk mapping must identify all the elements needed to determine which controls should be put in place, including:

  • The sites to be protected and controlled, taking into account their specific characteristics: address, function and nature of the site, natural risks that may affect it, number of people who visit it, and so on.
  • The business assets and supporting assets to be protected on these sites. Business assets are the information, activities or services whose compromise could harm the organization’s missions. This could include, for example, a hospital’s patient care service. Supporting assets are the resources that allow business assets to function, such as a server or data center. A protection level must be assigned to these business and supporting assets located on the sites, according to their criticality.
  • The zones to be secured within the identified sites. These may include office areas, reception areas or server rooms. Their level of criticality depends on the assets they contain. The more critical these assets are, the higher the level of protection must be.

Adapting technological systems

Once the criticality level of each site, zone and business asset has been established, physical security measures compliant with ReCyF can be implemented. To do this, Mickaël Wajnglas recommends referring to the ANSSI guide dedicated to physical access control and video protection systems.

This guide provides detailed recommendations on the most appropriate technological systems to deploy, such as access badges, video protection systems, intercoms and more. Each of these systems must include certain protective features, the level of which varies according to the zone to be secured.

Access badges must be unique, non-clonable and must not contain sensitive information other than the identifier. They must also provide cryptographic authentication. Badge readers must have a maximum reading distance of five centimeters, must not store access rights, must be equipped with tamper detection, and so on. For highly critical zones, they must include a keypad in order to enable multi-factor authentication through an access code.

As for video protection, cameras must be physically protected. In critical zones, they must be within the field of view of at least one other camera, in accordance with the principle of cross-surveillance. The video management center must be installed in a secure room and must not be shared with the office IT system.

“I recommend following the recommendations in this guide to the letter, as it really goes into detail,” stresses Mickaël Wajnglas.

Updating the security policy

Security systems alone are not enough. ReCyF also requires organizations to adopt “measures” to assign appropriate physical access rights, for example. These must be defined in a security policy, generally by the security manager, explains Dominique Gueguen.

This policy must notably define badge validity periods adapted to whether the badge holder is an employee or a service provider. Access rights must also be differentiated according to hierarchical level.

“Badge rules may also cover the color of the lanyard. If the lanyard is red, it indicates that the holder is a visitor and must be accompanied at all times. If it is green, it may indicate that the person is an employee who can move around freely,” adds Dominique Gueguen.

To go further, consult our guide to NIS 2 compliance in France and our presentation of the ReCyF compliance framework.