Implementation in France
Current status
The French NIS2 implementation law is called Loi relatif à la resilience des activités d’importance vitale, à la protection des infrastructures critiques, à la cybersécurité et à la résilience opérationnelle numérique du secteur financier
.
France is one of the few Member States to implement three EU directives NIS2, RCE and DORA in a single legislative proposal on resilience.
The national implementation in France is overseen by the National Agency for the Security of Information Systems ANSSI, Agence nationale de la sécurité des systèmes d'information. Art. 5 The bill is divided into three titles: Resilience of vital activities, Cybersecurity and Digital operational resilience of the financial sector for a joint implementation of NIS2, DORA and RCE.
Since the government tabled the bill in October 2024 under an accelerated procedure, it passed the first chamber, the Sénat, and is currently partway through the second, the Assemblée nationale. Throughout this legislative process, the draft bill has undergone changes: the Sénat adopted the bill following 61 amendments in its special committee on 12 March 2025.
The bill, marked as n° 1112, was transmitted to the Assemblée nationale. Subsequently, the Assemblée nationale, after a 6-month committee review, adopted 244 out of 505 discussed amendments, producing an amended committee text on 10 September 2025 (n° 1779-A0).
The bill has since stalled: it was not scheduled for the July 2026 extraordinary session, pushing plenary examination in the Assemblée to Autumn 2026 at the earliest. France has fallen behind – By 2026, 20 of 27 member states had already transposed NIS2, and on 8 July 2026 the Commission referred France to the CJEU for failure to transpose, alongside Ireland, Spain and the Netherlands.
National NIS2 differences
Compared to the original EU Directive, the scope has been extended in France to more local authorities: all departments, communes with more than 30,000 inhabitants, communautés urbaines, communautés d'agglomération, métropoles, and overseas collectivities. The scope extends to include educational institutions that carry out research activities as well as to software publishers.
In addition to the entities categorized under Art. 8 and 9 the French Prime Minister may decide to exclude some educational entities from the scope or to designate an entity as essential if its service is essential for society, public security or economic stability, poses systemic risks or is vital for its sector or interdependent sectors. Art. 10
Scope
Entities and sectors
The French implementation law defines classification criteria for essential entities (entités essentielles) in Art. 8(I) and for important entities (entités importantes). Art. 9 The thresholds for entities operating in (highly) critical sectors, telco providers and public inter-municipal cooperation establishments are now set directly in the amended text, rather than deferred to regulation.
The coverage of regulated entities will possibly increase from 500 under NIS1 to 15,000-20,000 entities with the implementation of NIS2, while the number of sectors increases from six to 17. Art. 7
According to the Minister of Economy and Minister of Education, the scope retained in the NIS2 Directive specifically targets the sectors and types of entities with the greatest potential impact on the economy and society, whereas the NIS1 Directive provided for a national procedure for identifying operators of essential services
.
While the draft law lists the sectors in Art. 7 (see list below), the definitions of the sub-sectors and entity types will be elaborated on in the décret en Conseil d'État.
Highly critical sectors Art. 7 I
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water
- Wastewater
- Digital infrastructure
- ICT service management
- Space
Critical sectors Art. 7 II
- Postal and courier services
- Waste management
- Chemicals manufacturing, production and distribution
- Food production, processing and distribution
- Manufacturing of certain goods
- Provision of certain digital services
- Research
| Type | Criteria essential | Criteria important |
|---|---|---|
| Highly Critical Sectors (Art. 7, I) |
At least 250 employees Annual turnover exceeds €50 million Total annual balance sheet >€43 million |
At least 50 employees Annual turnover total annual balance sheet >€10 million |
| Critical Sectors (Art. 7, II) |
- | - |
| Telco providers Electronic comms |
At least 50 employees Annual turnover and balance sheet each total >€10 million |
size-independent (telco providers which are not essential entities) |
| qTSP, TLD, DNS, software publishers | size-independent | if not essential, size-independent |
| Public Administration | Regions, departments, communes with more than 30,000 inhabitants and their public administrations in (highly) critical sectors Management centers Art. L. 452-1 Fire and rescue services Art. L. 1424-1 |
Exceptions apply: Prime Minister determines which public entities are exempt from the Act due to their minor economic and social impact |
| Communautés urbaines, communautés d'agglomération, métropoles | size-independent, if activities fall within one of the highly critical or critical sectors | --- |
| "Communautés de communes" | --- | size-independent, if activities fall within one of the highly critical or critical sectors |
| Public inter-municipal establishments | workforce (tbd) | If designated as important entities by decree of the Prime Minister |
| Public health establishments, social and medico-social establishments | essential | if not essential |
| Operators presumably EU CER critical entities |
size-independent | --- |
| Previously identified operators of critical services | size-independent | --- |
| Educational Institutions Art. 8 and 9 | conducting research monopoly position or critical societal or economic functions, significant impact on public safety, significant systemic risk, particular importance for the sector by criteria of Art. 10 |
if not essential and conducting research size-independent |
| monopoly position impact on public safety system risk national or local importance |
operating in (highly) critical sector identified by Prime Minister size-independent |
operating in (highly) critical sector identified by Prime Minister size-independent |
For public administration entities, several exceptions apply. State administrations in national security, public safety, defense and law enforcement are not classified as essential entities. Art. 8(I) no. 7a However, they are covered by risk management obligations in Art. 14. Communities with a population of less than 30,000 and other entities operating on a regional level are also not classified as essential entities as well as . Art. 8 no. 7b
An exception applies to entities whose activities are subject to nuclear-defense authorization: under Art. L. 1333-2 of the Code de la défense, those activities are excluded from several essential- and important-entity categories (operators, previously identified operators, and companies in highly critical sectors).
Requirements
Resilience from EU CER
EU CER Directive (2022/2557) is also transposed through Title I of the French Resilience bill.
Art. 1 replaces the current Chapter II of Title III, Book III, Part 1 of the Defence Code onProtection of installations of vital importance
(L. 1332-1 to L. 1332-7) with a new chapter titledResilience of activities of vital importance,
consisting of three sections and 22 articles.
The first section of the new chapter is concerned with general provisions relating to activities of vital importance. This new section contains eleven articles of which most are dedicated to definitions: it articulates the already existing national definitions with the definitions provided by the European directive, concerning activities of vital importance and critical infrastructures.
Art. L. 1332-2 governs the system for designating the different categories of operators of vital importance, distinguishing between:
- operators who carry out one or more activities of vital importance;
- operators whose destruction or damage could present a serious danger to the population and the environment.
The second part of article (II) aims to take account of the communities which have decided to grant an activity of vital importance by providing them with information:
Art. L. 1332-4 provides for the obligation of vital services operators to identify their dependencies, particularly in terms of supplies and sub-contractors, but also with regard to their own service providers. Within this analysis, a specific requirement targets dependency on proprietary software and hardware suppliers, which must be assessed regarding service continuity, long-term cost, and independent audit capability.
Art. L. 1332-5 lays down specific obligations for critical points, which must be provided with a specific resilience plan drawn up by the operator, replacing the current specific protection plan.
Art. L. 1332-6 extends the cases of access to points of vital importance and information systems of vital importance and functions which may be subject to administrative security investigations at the request of the operators in accordance with the Directive.
Art. L. 1332-7 requires operators to notify the administrative authority, no later than 24 hours after becoming aware, of incidents likely to jeopardise the continuity of their essential activities.
Art. L. 1332-9 makes it possible to distinguish, among the operators of vital importance providing essential services, critical entities of particular European importance for which the European Commission may carry out advisory missions, on a reasoned request and subject to the agreement of the Member States.
Title I's provisions take effect only once a decree is issued, and no later than one year after promulgation of the law (Art. 4) — unlike Title III (which enters into force the day after promulgation), and Title II (whose obligations phase in article by article, as each of its own implementing decrees is published).
Cybersecurity from EU NIS2
EU NIS2 (2022/2555) is transposed with Title II (Cybersecurity) of the Resilience bill.
On the National Authority for the Security of Information Systems
(Chapter I Title II) establishes ANSSI’s role and sets out a national cybersecurity strategy:
- Art. 5 provides that ANSSI is responsible for implementing the government's policy on the security of information systems as well as for supporting the cybersecurity industry and public cyber-hygiene education (see details in next section).
- Art. 5 bis requires the Prime Minister to adopt a national cybersecurity strategy, updated at least every three years. The strategy must include, among others, national objectives in cybersecurity and digital strategic autonomy, information-sharing on risks, threats and incidents, public awareness measures, and support for local authorities and their groupings.
On Cyber Resilience
(Chapter II Title II) provides definitions under Art. 6. Furthermore:
- Art. 7 lists the critical and highly critical sectors of activity in the statute, while the definitions of sub-sectors and entity types within them are set by decree in the Council of State.
- Art. 8-9 define, on the basis of NIS2 Directive, the essential and important entities which will be affected by the measures as well as those which are explicitly excluded from its scope, in particular under clauses relating to national security.
- Art. 10 provides for the possibility for the Prime Minister to designate certain essential and important entities and they define the articulation of the bill with national and sectoral regulations also having an impact on cybersecurity.
- Art. 11-17 harmonize and simplify the existing legal framework for the protection of information systems (NIS1) by establishing a set of rules harmonized for different types of entities, adapted to each level of threat, as well as to sectoral and thematic specificities, and applicable to the largest number of entities in order to protect them against the cybercriminal threat. They bring the additional security requirements of the system of information systems of vital importance (les systèmes d'information d'importance vitale, SAIV), designed to protect the most critical French organizations against strategic threats, into line with those foreseen by the implementation of the NIS2 directive.
- Art. 17 provides for an obligation for essential and important entities to notify significant incidents, subject to a defined threshold and a staged notification timeline, to the national authority, as well as to the recipients of services in certain cases.
Government authorities
ANSSI, the French Cybersecurity authority, will be authorized to monitor and supervise the law. This includes detection of breaches, violations of the obligations and on-site and remote inspections, regular and targeted security audits, security scans and audits in the event of an incident or breach, with a supporting role in developing the cybersecurity industry and public cyber education.
ANSSI's designated agents (Art. 26) are authorized to investigate breaches, and the Sanctions Commission is granted authority to impose administrative fines of up to €10 million or 2% of annual worldwide turnover on essential entities, and €7 million or 1.4% on important entities (Art. 37 I).
The Commission may also require public disclosure of a breach (Art. 37 VI), and must weigh the entity's good faith and financial capacity when setting a sanction (Art. 37 VII).
Art. 5 allows the Prime Minister to designate another authority for activities related to defence.
ANSSI launched several online tools in preparation for the NIS2 transposition:
- An eligibility self-assessment tool to determine whether an entity falls within NIS2's scope.
- A pre-registration and diagnostic service, MesServicesCyber, including a free diagnostic conducted by an “Aidant cyber”.
- A comparison tool mapping the Référentiel Cyber France (ReCyF) against other standards, such as ISO 27001, ISO 27002, or HDS.
Security
Risk Management
The French NIS2 law addresses risk management measures in Art. 14 and Art. 15.
Essential and important entities as well as several state administrations will need to implement appropriate and proportionate technical, operational and organizational measures
to manage risks to the security of their networks and information systems (NIS).
The choice of measures must also account for their auditability, transparency, interoperability, and resilience, with the explicit aim of minimising technological dependency on third-party providers that don't offer sufficient guarantees of compliance with cybersecurity and digital sovereignty requirements.
Measures should ensure a level of NIS security appropriate and proportionate to the existing risks:
Art. 14
- Governance of NIS security: management bodies must approve and supervise these measures, including cybersecurity training for members of management bodies and staff exposed to risk
- Protect NIS, even when outsourced
- Tools and procedures to defend NIS
- Incident management
- Resilience of activities, networks, and information systems
Further risk management measures will follow in a separate decree by the Council of State (Art. 14) which will further determine the conditions for the development, modification and publication of a reference framework of technical and organizational requirements
.
Entities holding an ANSSI-approved trust label (“label de confiance”) are presumed compliant with Art. 14's objectives, unless proven otherwise (Art. 15).
Security measures
ANSSI published the Référentiel Cyber France (ReCyF) on 17 March 2026. It remains a working document until NIS2 is formally transposed into French law, though entities are encouraged to begin implementing it regardless. ReCyF structures 20 security objectives across four pillars: Gouvernance, Protection, Défense, and Résilience.
For each objective, it distinguishes a mandatory “what” (the objective itself) from a recommended “how” (acceptable means of compliance).
Objectives 1 to 15 apply to both essential and important entities, and cover:
- Governance and steering (objectives 1-5) — inventory of information systems, a digital security governance framework, control of the ecosystem (third parties and supply chain), integration of digital security into HR management, and control of information systems
- Protection of information systems (objectives 6-10) — control of physical access to premises, secure architecture, secure remote access, protection against malicious code, and management of user identities and access
- Defence and detection (objectives 11-12) — control of information systems administration, and identification of and response to security incidents
- Resilience and crisis management (objectives 13-15) — business continuity and recovery, response to cyber crises, and exercises, tests and drills
Objectives 16 to 20 apply to essential entities only: a risk-based approach, auditing the security of information systems, secure configuration of information system resources, administration of information systems from dedicated resources, and security monitoring of information systems.
Information and authorities
Registration
Registration obligations are defined in Art. 12. Essential and important entities, as well as DNS registration services and agents acting on their behalf, will have to register at ANSSI. Further details such as deadlines and necessary information will be defined by decree. Registration is available via MesServicesCyber (see Government authorities above).
Reporting
Reporting obligations are defined in Art. 17.
Essential and important entities, as well as state administrations and their public administrative establishments, as defined in Art. 14, must notify the recipients of their serviceswithout delay
where an incident causes or risks causing data extraction, harm to a person’s health, or unauthorized network access with the potential for serious operational disruption, as well as the measures or corrections as soon as they become aware of them, in order for the recipients to respond to vulnerabilities or threats Art. 17.
Operators must notify ANSSI within 24 hours of becoming aware of any incident likely to compromise the continuity of its activities of vital importance
Art. L 1332-7 Code de la défense
ANSSI may require an entity to disclose an incident to the public or do so itself Art. 17
Incident notification deadlines are now set directly in the statute (24 hours for an initial notification, 72 hours for an intermediate notification, and a final report within one month); a decree of the Council of State will follow specifying only the criteria to classify incidents as important.
Sanctions
The draft law defines regulatory offenses (measures after checks) under Art. 31, 33 and 34. They provide for the procedures for initiating a procedure following checks and the enforcement measures that the national authority may decide on and attach to them daily penalty payments, including warnings, binding instructions, compliance injunctions and information obligations.
Sanctions are defined under Art. 35 to 37. The penalty amounts are closely aligned with EU NIS2. The Sanctions Committee Article L. 1332-15 of the Defense Code rules on any breaches of obligations arising from the application to the the NIS2 implementation law (Chapter II + III) Art. 35.
In the case breaches of the implementation law (Chapter II + III), the Sanctions Committee is composed of one coordinating minister of a vitally important sector (Article L. 1332-16 of the Defense Code) as well as three qualified persons, nominated respectively by the Prime Minister, the President of the National Assembly, and the President of the Senate. Art. 36
For companies that obstruct requests necessary to investigate violations and enforce rights, the Sanctions Commission may impose ten million euros or 2% of the company's annual worldwide turnover, excluding tax, for the preceding financial year, whichever is greater, for essential entities, or seven million euros or 1.4%, whichever is greater, for important entities. Art. 28
Regulatory offenses
The ANSSI designates one or more rapporteurs to conduct an investigation pursuant under Art. 31 in case of violations or suspected violations. In the case of regulatory offenses revealed by investigation, the ANSSI is authorized to:
- issue a warning
- take the necessary measures to avoid or remedy an incident, and define the deadlines for implementing these measures and reporting on this implementation
- order the entity to comply with the obligations within a period which the ANSSI determines (> one month, except in the event of serious or repeated failure)
- order the entity to inform the natural or legal persons to whom it provides services or carries out activities that may be affected by a significant cyber threat, of the nature of that threat and of any preventive or remedial measures that those natural or legal persons may take in response to that threat
- order the entity to implement within the time limit it sets the recommendations made following a security audit
Art. 33 provides that:
- in the case that the ANSSI's investigation finds that the entity complied with the enforcement measure within the time limit, the ANSSI will not continue the procedure. In the case of non-adherence with one of the enforcement measures addressed to him, the ANSSI will notify the entity of the grievances and refer the matter to the sanctions committee (Art. L. 1332-15).
- If the entity concerned is an essential entity and does not provide evidence of compliance with the implementing measures referred to above within the time limit, the ANSSI may suspend the certification or authorization for all or part of the services or activities provided by the entity until the essential entity has remedied the non-compliance.
- If that certification or authorization has been issued by a certification or authorization body of another entity, it shall instruct that body to suspend it until the essential entity has remedied the non-compliance.
A decree will specify the investigation process further Art. 34.
Audits
Audit obligations for operators are defined in Art. 15 to 17, official audit powers in Art. 27-30. Audits are led by specially appointed and sworn agents empowered by ANSSI, with independent bodies or experts able to assist under their supervision. Art. 26 also now extends ANSSI's investigative scope to the Cyber Resilience Act, covering product-security obligations along entity cybersecurity.
According to Art. 29 the agents conducting the audits may have the authority to:
- conduct on-site inspections and remote controls
- conduct regular and targeted audits, either run by ANSSI itself at ANSSI's cost, or by an independent organisation ANSSI designates, generally at the entity's cost
- security scans
- audits in the event of a significant incident or a violation of the provisions of EU directives and regulations Art. 26
More details on audits will follow in a separate decree of the Council of State Art. 30.
ReCyF's objective 17 (“Auditing the security of information systems”), applicable to essential entities only, obliges essential entities to conduct audits of their networks and information systems, carried out by qualified security audit providers. The audit must:
- verify compliance
- assess security levels
- include penetration tests
- audit configuration, architecture, and code
- include organizational and physical audits
The outcomes of an audit must include an audit report summarizing compliance, identifying non-conformities and providing recommendations. Furthermore, the essential entity must establish an action plan to address non-conformities and vulnerabilities, with deadlines and designated responsible parties. The guideline document excludes important entities from audit obligations.
Territoriality
The territorial provisions are established in accordance with Art. 26, NIS2 Directive. In line with Art. 11, Section I of the implementing legislation, essential and important entities are subject to the provisions of the law if they are established on national territory or, in the case of electronic communications operators, if they provide their services on the national territory.
DNS, registrars, cloud computing service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, e-commerce providers, online search engines, and social media networking platforms are considered exceptions and special cases. They fall under the provisions of the implementing law if:
- their principal place of business (établissement principal) is on French national territory (Art. 11, Section III clarifies the definition of "principal place of business" as the place where decisions regarding cybersecurity risk management measures are primarily made or, in the absence of such a place, the place where cybersecurity operations are carried out or, in the absence of such a place, the establishment with the largest number of employees in the European Union.)
- they are established outside the European Union but offering their services on national territory when they have appointed a representative established on national territory;
Furthermore, the conditions of establishment on national territory do not apply to state administrations and public establishments.
Art. 11, section II clarifies the obligations of these registration offices and the agents acting on their behalf. The territorial obligations apply to those:
- who have their main establishment in the national territory;
- who have appointed a representative established on the national territory, if they are established outside the European Union but offer their services on the national territory.
Art. 40 provides for the arrangements for applying the French implementation of NIS2 in overseas countries and territories (Wallis and Futuna, French Polynesia, New Caledonia and the French Southern and Antarctic Lands).
Entry into Force
Transitional Provisions
(Chapter III Title I) includes Art. 4 which provides for the obligations applicable to operators of vital importance designated before the entry into force of the law.