Cybersecurity is becoming a governance issue. It’s now a matter of resilience and risk control, not just technical defense. The latest OpinionWay barometer for CESIN confirms this shift: three regulatory frameworks now dominate corporate priorities in France.
Overall, 59% of French companies say they’re in scope for NIS2, 32% for DORA, and 30% for the CRA (CESIN, 2026). But those averages hide a sharp divide by company size. That divide is where the real story is.
1. NIS2: the new center of gravity
70% of large enterprises rank NIS2 as a top priority. Among small and mid-sized businesses (TPE/PME), that figure drops to just 44%.
The gap makes sense. Large groups already went through NIS1, so they know the drill: risk management, incident notification, board-level accountability. Smaller structures, on the other hand, are still discovering the real scope of the requirements — including obligations that reach into their supply chain, not just their own systems.
2. DORA: operational resilience at the heart of finance
DORA remains a strong priority for large enterprises, at 38%. That number reflects its scope: financial institutions and their critical ICT providers.
Resilience testing, third-party risk management, governance: DORA demands a rigorous discipline. And because it reaches ICT providers as well as financial firms directly, its impact spreads well beyond the finance sector itself.
3. The CRA: securing products by design
With the CRA, the logic shifts. Security has to be built in from the start, not bolted on later. That’s the core of Secure by Design and Secure by Default.
Large enterprises are ahead here too: 37% are already anticipating the CRA, compared to just 23% of mid-sized companies (ETI). That 14-point gap matters, because the CRA’s core requirements — software bills of materials (SBOM) and patch management — take real time to operationalize. Waiting until the deadline isn’t really an option.
What sets the top-performing organizations apart
We’re convinced the organizations that progress fastest will share three habits:
- They pool controls and reference frameworks across regulations, instead of running separate compliance programs for NIS2, DORA, and the CRA side by side.
- They prioritize action by actual risk level, not by how easy it is to produce evidence. The easiest compliance box to tick isn’t always the risk that matters most.
- They give cyber GRC teams the tools to industrialize assessments, produce reliable evidence, and manage several regulations at once — without multiplying the effort every time.
This isn’t a small opportunity. As we discussed in an earlier post, 76% of CISOs already say that managing multiple frameworks in parallel hurts their ability to stay compliant. Convergence isn’t a nice-to-have; it’s how compliance stays sustainable.
Turning compliance into a lever, not an obligation
That’s precisely the approach we’re building with SharpenCISO, our AI-native GRC platform, automated in real time.
Our goal is simple: turn compliance into a genuine lever for managing cyber risk — one that durably strengthens security posture — instead of a string of regulatory obligations to tick off, one framework at a time.
So, what have you put in place?
We’re curious: what have you put in place to improve the performance and impact of your cyber GRC teams?
Are you still running NIS2, DORA, and the CRA as separate tracks, or have you already started pooling the effort? Let us know in the comments.
#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA






