(DT02) (CFI) NIS2, CRA : VRAI ou FAUX ?

(DT02) (CFI) NIS2, CRA : VRAI ou FAUX ?

🎙 Marc-Antoine Lodieu 👥 7K 📅 April 10, 2026 ⏱ 34 min 👁 92 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

NIS2CRAcybersecuritycomplianceregulations

Summary

In this video, Marc-Antoine Lodieu, a cybersecurity lawyer, presents a true/false quiz on the NIS2 directive and the Cyber Resilience Act (CRA). He clarifies that NIS2 is not directly applicable to companies until transposed into national law, and emphasizes the self-designation process based on sector and size criteria. He debunks the myth that ISO 27001 certification ensures full NIS2 compliance, noting that the French draft decree includes 103 security measures for important entities and 213 for essential ones. He also addresses the legal responsibility of CISOs, stating they are not personally liable under NIS2, but company directors can face suspension of their mandates for non-compliance. For the CRA, he explains that it applies to almost all software, including SaaS, and imposes 13 cybersecurity requirements and 8 vulnerability management measures, including mandatory SBOM and 5-year support. He discusses the timeline, with notification obligations starting September 2025 and full compliance by December 2027, and the concept of ‘substantial modification’ that triggers full compliance. He also covers potential sanctions, including market withdrawal, and notes that the French authority for CRA enforcement is ANFR, not ANSSI.

182 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the practical implications of NIS2 and CRA for businesses, clarifying common misconceptions and highlighting key compliance requirements. The speaker’s expertise as a lawyer adds credibility, and he supports his arguments with references to legal texts and official publications. However, the presentation is largely opinionated and lacks detailed citations, which could be a limitation for viewers seeking verifiable sources. The argumentation is coherent and well-structured, but some claims, such as the exact number of security measures, should be verified with official documents.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates a good understanding of the legal texts and provides a detailed analysis. He references the NIS2 directive, the CRA, and French draft decrees, but does not provide specific citations or links to these documents. The title accurately reflects the content, as the video is structured as a true/false quiz. The lack of explicit sources may reduce the overall rigor, but the information appears to be based on current regulatory developments. No comments were provided for analysis.

181 words

Title / Content Match

The title accurately reflects the content: a true/false quiz format addressing common misconceptions about NIS2 and CRA.

Quality & Reliability

7/10

The speaker is a lawyer specializing in cybersecurity, providing a detailed and practical analysis of NIS2 and CRA. The content is based on legal texts and official publications, but the presentation is opinionated and lacks citations to specific sources. The information is generally accurate but should be verified with official texts.

Key Moments

Cited Sources

Concurring Sources

Dissenting Sources

  • ANSSI official guidance — The speaker suggests ANFR as the CRA authority, but ANSSI is the primary cybersecurity authority in France; this may be a point of divergence.

Contribution & Novelties

The video provides a practical, lawyer’s perspective on NIS2 and CRA, clarifying common misconceptions and offering actionable insights for compliance. It highlights the self-designation process, the limited role of ISO 27001, and the broad scope of CRA, including SaaS. The discussion on substantial modification and the role of ANFR adds unique value.

Pour aller plus loin :

91 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, indicating a dense and detailed presentation. The quality and reliability scores are slightly lower, reflecting the lack of explicit citations and the opinionated nature of the content.

Reliability 7/10