OIV and OSE are the two French-law categories for organizations that carry heightened cybersecurity obligations. OIV (Opérateur d'Importance Vitale, operator of vital importance) predates NIS2 and applies under the 2013 Military Programming Law (LPM). OSE (Opérateur de Services Essentiels, operator of essential services) is the French transposition of the original NIS Directive, now extended under NIS2. Both are supervised by ANSSI, the French national cybersecurity agency, but OIV obligations are older and stricter.
What is the difference between OIV and OSE?
OIV status is assigned by government decree to operators whose disruption would seriously threaten the military or economic potential, the security, or the survival of the nation. The list of OIVs is classified. OIVs must implement the Règles de Sécurité des Systèmes d'Information d'Importance Vitale (SIIV), a set of technical and organizational rules that predate NIS2 and exceed it in several areas.
OSE status is broader and public. It applies across the sectors named in the NIS2 Directive: energy, transport, banking, financial markets, health, drinking water, digital infrastructure, public administration, space, postal services, waste management, food, chemicals, research, and manufacturing. OSEs are regulated under the French NIS2 transposition law and supervised by ANSSI or by sector-specific authorities.
What must OIVs do?
The SIIV rules span 20 topic areas, including identity management, network segmentation, incident detection, audit logging, and supply-chain security. Three features set OIV obligations apart from the general NIS2 baseline:
- Mandatory audit by ANSSI-qualified assessors (PASSI). Self-assessment is not accepted.
- Sovereign-infrastructure constraint. Sensitive French data classifications must stay in qualified sovereign infrastructure, not general-purpose public cloud.
- Annual attestation to ANSSI. Formal, recurring reporting rather than voluntary disclosure.
What must OSEs do under NIS2?
The NIS2 baseline for OSEs follows Article 21 of the Directive: risk management, incident handling, business continuity, supply-chain security, vulnerability handling, cryptography, access control, multi-factor authentication, and secure development. France layers its own reporting deadlines and penalty structures on top through the transposition law.
NIS2 also splits regulated operators into entités essentielles (essential entities) and entités importantes (important entities). Essential entities face stricter, proactive supervision and include most former OSEs plus the new sectors NIS2 added.
Why does this matter for OT?
Because most OIV and OSE sectors run substantial OT footprints: power transmission, water treatment, rail signalling, and manufacturing controls. The obligations map directly onto the OT layer, network segmentation, identity-based access, audit logging, and incident detection, and that is exactly where they are hardest to satisfy. Critical infrastructure protection in France is not only an IT problem, and cloud-only security products rarely meet the sovereign-data and on-premise-control expectations ANSSI enforces on OIVs.
How is OIV different from NIS2's essential-entity category?
They overlap but are not identical. NIS2's entité essentielle is a directive-level classification applied broadly across the EU. OIV is a French national designation that existed before NIS2, is assigned by classified decree, and comes with the SIIV rules and PASSI audits. An organization can be both, but OIV status carries the older, more prescriptive, sovereignty-focused regime that NIS2's general baseline does not fully replicate.
How Access Gate helps
Access Gate runs entirely on-premise, produces audit evidence aligned with ANSSI SIIV requirements, and meets the sovereign-infrastructure expectations OIV and critical-sector OSE operators face, because nothing has to leave the site for the control plane to work. An independent IMR feasibility study mapped that evidence directly to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness. See NIS2 Compliance On-Premise.

