[{"data":1,"prerenderedAt":113},["ShallowReactive",2],{"seo-verification":3,"blog-nis2-hebergement-obligations-clients-2026-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"id":7,"slug":8,"title":9,"excerpt":10,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":15,"categories":20,"featuredImage":22,"bgImage":23,"posterImage":24,"relatedSolution":22,"intro":25,"sections":26,"ctaTitle":70,"ctaBody":71,"ctaButton":72,"ctaUrl":73,"relatedPosts":74},211,"nis2-hebergement-obligations-clients-2026","NIS2: what the directive requires from your hosted clients","NIS2 applies from October 2026 across the EU. Clients in essential sectors must choose providers that meet the same security standards.",7,0,false,"2026-08-02T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":18},10,"Compliance & Regulation","conformite","bg-amber-500\u002F10 text-amber-400",[21],{"id":16,"name":17,"slug":18,"color":19,"icon":18},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fnis2-hebergement-obligations-clients-2026-poster.svg","The European NIS2 directive (EU 2022\u002F2555) has been applicable in national law across most EU Member States since October 2024, with a compliance ramp-up period through summer 2026. It covers 18 sectors and approximately 160,000 entities across Europe. For agencies and service providers delivering websites or applications to clients in these sectors, the choice of hosting provider now falls within the scope of the supply chain audit.",[27,31,41,44,63,67],{"type":28,"title":29,"body":30},"h2","Why NIS2 affects your clients and your projects","NIS2 does not apply only to operators themselves — it extends to their supply chain. An essential entity (hospital, energy network, transport operator, public authority) must evaluate and document the security of every provider that touches its digital infrastructure. This includes the website host, the application platform and integrated SaaS tools. An agency delivering a project to a NIS2-subject client is therefore indirectly in scope: if it cannot provide documented guarantees about the chosen hosting, its client cannot satisfy its supply chain monitoring obligation.",{"type":32,"title":33,"items":34},"ul","What NIS2 concretely requires",[35,36,37,38,39,40],"**Ten minimum cybersecurity measures** — including incident management, supply chain security, access control policies and encryption.","**Early warning within 24 h** — any significant cyberattack must be notified to the competent authority within 24 hours of discovery.","**Full report within 72 h** — detailed incident report to the national authority within three days.","**Documented supply chain audit** — each critical supplier must be assessed and security commitments formalized contractually.","**Regular resilience testing** — penetration tests, vulnerability assessments and continuity exercises at defined intervals.","**Governance at board level** — executives can be held personally liable for failure to meet NIS2 obligations.",{"type":28,"title":42,"body":43},"Who is affected: essential and important entities","NIS2 distinguishes two categories. 'Essential entities' (EE) operate in the highest-criticality sectors: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure. 'Important entities' (IE) cover adjacent sectors: postal services, waste management, manufacturing, chemicals, food, digital providers. The general threshold: any medium-sized entity (50 employees or EUR 10 M turnover) in these sectors is in scope. Smaller organizations may be included if they play a critical role in their sector. The first registration deadline for essential entities was set at 30 June 2026 in several Member States.",{"type":45,"title":46,"steps":47},"steps","Preparing for NIS2 compliance",[48,51,54,57,60],{"title":49,"body":50},"Identify whether you or your clients are in scope","Check the sector and applicable thresholds (headcount, turnover) for each client. National transposition texts specify the exact perimeters.",{"title":52,"body":53},"Inventory digital assets and suppliers","List systems, applications and third-party services that process critical data. For each supplier, document available security commitments: data location, certifications, incident procedures.",{"title":55,"body":56},"Set up incident management","Define a detection, escalation and notification circuit: who triggers the 24 h early warning, who drafts the 72 h report, which channel to use to notify the competent national authority.",{"title":58,"body":59},"Choose providers with documented commitments in the EU","Prefer hosting providers whose servers are located in the European Union, who can produce security documentation (ISO 27001 or equivalent) and whose contracts clearly define responsibilities in the event of an incident.",{"title":61,"body":62},"Test and verify regularly","Schedule penetration tests and security reviews at regular intervals. Retain the reports: they constitute the documentary evidence required during a NIS2 audit.",{"type":64,"title":65,"body":66},"tip","Your hosting provider is part of the NIS2 supply chain","For a NIS2-subject client, the hosting provider is not just any supplier. Server location in the EU, contractual security commitments and documented incident notification procedures count directly in its compliance audit. Choosing a provider able to produce these elements simplifies your client's process and strengthens your agency's position as a trusted partner.",{"type":28,"title":68,"body":69},"NIS2: a constraint that builds client trust","NIS2 compliance is not purely a regulatory exercise. For agencies delivering projects to essential or important entities, it represents a concrete commercial argument: being able to demonstrate that the chosen hosting meets the standards required by the directive — data location, security, incident management — distinguishes a serious offer from a generic one. Entities subject to NIS2 need providers who understand their constraints. Penalties for non-compliance: up to EUR 10 M or 2% of global annual turnover for essential entities.","Your infrastructure meets NIS2 standards","Servers in the European Union, documented security commitments, contractually defined incident procedures: the elements your NIS2-subject clients need to verify in their supply chain audit.","Our security commitments","\u002Fpourquoi\u002Fsecurite",[75,85,94],{"id":76,"slug":77,"title":78,"excerpt":79,"readTime":11,"views":12,"isPinned":13,"publishedAt":80,"category":81,"categories":82,"featuredImage":22,"bgImage":23,"posterImage":84,"relatedSolution":22},200,"cyber-resilience-act-ce-qui-change-pour-vos-clients","Cyber Resilience Act: what changes for your clients","The CRA requires vulnerability disclosure in 24 h from September 2026. What it means in practice for agencies and developers.","2026-08-01T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":18},[83],{"id":16,"name":17,"slug":18,"color":19,"icon":18},"\u002Fblog\u002Fcovers\u002Fcyber-resilience-act-ce-qui-change-pour-vos-clients-poster.svg",{"id":86,"slug":87,"title":88,"excerpt":89,"readTime":11,"views":12,"isPinned":13,"publishedAt":80,"category":90,"categories":91,"featuredImage":22,"bgImage":23,"posterImage":93,"relatedSolution":22},205,"data-act-portabilite-cloud-frais-sortie","Data Act: cloud exit fees banned from 2027","From January 12, 2027, the EU Data Act prohibits cloud exit fees. What this changes for your hosting strategy and contracts.",{"id":16,"name":17,"slug":18,"color":19,"icon":18},[92],{"id":16,"name":17,"slug":18,"color":19,"icon":18},"\u002Fblog\u002Fcovers\u002Fdata-act-portabilite-cloud-frais-sortie-poster.svg",{"id":95,"slug":96,"title":97,"excerpt":98,"readTime":99,"views":100,"isPinned":13,"publishedAt":101,"category":102,"categories":107,"featuredImage":22,"bgImage":23,"posterImage":109,"relatedSolution":110},108,"securiser-vps-crowdsec","Securing your VPS with CrowdSec","Deploy CrowdSec on your VPS to block attacks thanks to behavioral detection and a shared community blocklist.",8,596,"2026-03-04T00:00:00+00:00",{"id":99,"name":103,"slug":104,"color":105,"icon":106},"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[108],{"id":99,"name":103,"slug":104,"color":105,"icon":106},"\u002Fblog\u002Fcovers\u002Fsecuriser-vps-crowdsec-poster.svg",{"categorySlug":111,"appSlug":112},"securite","crowdsec",1785671421826]