NIS2 France: No Law Yet, ANSSI's ReCyF & the Draft Penalties
France has not transposed NIS2. The projet de loi Résilience passed the Senate in March 2025, cleared an Assemblée nationale commission on 10 September 2025 and has not been scheduled for a sitting since. On 8 July 2026 the European Commission referred France to the Court of Justice. This page sets out what that means, what ANSSI's ReCyF already asks of you, and which obligations bind French entities today.
Introduction: NIS2 Directive & the French context
France already had a mature cybersecurity framework built around operators of vital importance (opérateurs d’importance vitale, OIV) and essential service operators (OSE) under the original NIS Directive and national law. That framework is still the one in force. NIS2 would broaden it considerably — more sectors, far more entities, and new governance and incident-reporting duties — but the law that would do so has not been adopted.
The vehicle is the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité — the loi Résilience — which would jointly transpose three European texts: NIS2, the Critical Entities Resilience Directive (EU) 2022/2557 and DORA. That triple scope is part of why it has moved slowly.
The loi Résilience: what it is
France launched transposition on 15 October 2024 — two days before the EU deadline — when the bill was presented in the Council of Ministers and tabled in the Senate as text n° 33. The Government engaged the procédure accélérée the same day, which limits each chamber to a single reading. Nearly two years later the bill has still not completed that single reading.
The bill is structured in several titles. Title I rewrites the OIV regime in the code de la défense, transposing the Critical Entities Resilience Directive and introducing a 24-hour incident notification for operators of vital importance. Title II transposes NIS2 itself: scope, risk-management requirements, the reporting chain, supervision and sanctions. A further title covers DORA.
Two provisions are worth knowing before the law exists. Article 14 is the hook for the security requirements, and its sixth paragraph is what ReCyF implements. Article 16 bis, added by the Senate, prohibits requiring encryption providers and qualified trust service providers to build in master decryption keys or any other mechanism permitting non-consented access to protected data — a French addition with no equivalent in the Directive.
Status
Not transposed. Adopted by the Senate in first reading on 12 March 2025; an Assemblée nationale commission adopted its version on 10 September 2025. No sitting has been scheduled since. No decree exists.
Legal structure
One bill, three directives: NIS2, CER and DORA. The security requirements themselves will sit in decrees taken under article 14, with ReCyF as their reference framework — so the law alone will not tell you what to implement.
Who supervises
The bill never writes “ANSSI”. It refers throughout to l’autorité nationale de sécurité des systèmes d’information, to be designated by decree. ANSSI is the obvious candidate and runs the preparatory work, but the designation is not yet law.
Where the bill actually stands
This is the question the French market gets wrong most often, so here is the parliamentary record in full, taken from the Assemblée nationale's own legislative dossier.
| Date | Step | Reference |
|---|---|---|
| 15 October 2024 | Tabled in the Senate; accelerated procedure engaged the same day | Text n° 33 |
| 4 March 2025 | Senate special commission reports and adopts its text | Report n° 393, text n° 394 |
| 12 March 2025 | Senate adopts the bill in first reading | T.A. n° 78 |
| 13 March 2025 | Transmitted to the Assemblée nationale, referred to a special commission | Text n° 1112 |
| — | 505 amendments tabled on text n° 1112 | — |
| 10 September 2025 | Assemblée nationale special commission adopts its text (published 16 September) | Report n° 1779, text n° 1779-A0 |
| Since then | Nothing. No public sitting has been scheduled at the Assemblée nationale | — |
France at the EU Court of Justice
On 8 July 2026 the European Commission referred France to the Court of Justice of the European Union for failing to notify measures transposing NIS2. France was referred alongside Ireland, Spain and the Netherlands. The French case is INFR(2024)0274.
What binds you right now
“No NIS2 law” is not “no cybersecurity obligations”. For most French organisations this is the section that actually matters, because several regimes already apply and none of them is waiting for the loi Résilience.
The NIS1 regime, still in force
The original NIS Directive was transposed in 2018 and has not been repealed in France. If you were designated an OSE (opérateur de services essentiels), your security and notification obligations continue exactly as before.
The OIV regime
Operators of vital importance remain subject to the code de la défense rules on systèmes d’information d’importance vitale (SIIV). This is the strictest regime in France and it is unaffected by the delay.
DORA
For banks, insurers, investment firms and their critical ICT providers, DORA has applied since 17 January 2025 as a directly applicable EU regulation. It needs no French transposition and is already enforceable.
Contractual spillover
Twenty-three Member States have transposed NIS2. Their in-scope entities must manage supply-chain risk, so French suppliers are already receiving NIS2 security clauses, questionnaires and audit rights from German, Italian, Belgian and Nordic customers. This is currently the most common way NIS2 reaches a French company.
Am I in scope in France?
France will apply the NIS2 model of entités essentielles (EE) and entités importantes (EI) across 18 sectors, far beyond the earlier OIV/OSE perimeter. ANSSI's own wording is “plusieurs milliers d’entités” — several thousand. It publishes no entity count, and the figures circulating in the French advisory market are not ANSSI's. The thresholds below are ANSSI's, as stated on its NIS2 portal.
The two categories, as ANSSI states them
- Entité essentielle (EE) — at least 250 staff, or turnover above EUR 50 million and a balance sheet total above EUR 43 million.
- Entité importante (EI) — not an EE, and at least 50 staff or the corresponding financial test.
- Certain entities are in scope regardless of size, including trust service providers, DNS service providers, TLD name registries and providers of public electronic communications.
- ANSSI states the population is mostly medium and large companies plus local authorities and administrations.
The 18 sectors, as ANSSI lists them
Secteurs hautement critiques: administrations publiques, eaux potables, eaux non potables, énergies, espace, gestion des services TIC (interentreprises), infrastructures des marchés financiers, infrastructures numériques, santé, secteur bancaire, transport.
Autres secteurs critiques: fabrication, production et distribution de produits chimiques; fournisseurs numériques; gestion des déchets; industries manufacturières; production, transformation et distribution de denrées alimentaires; recherche; services postaux et d’expédition.
An important carve-out
The bill excludes entities already subject, under an EU legal act, to sectoral security and incident-notification requirements of at least equivalent effect — provided the equivalent regime gives immediate access to notifications. This is how DORA-regulated financial entities avoid being governed twice. Check whether a sectoral regime already covers you before building a separate NIS2 programme.
ReCyF: the 20 security objectives
ReCyF — the Référentiel Cyber France — is the one concrete thing ANSSI has published. Version 2.5 is dated 17 March 2026 and runs to 48 pages. It is the référentiel referred to at the sixth paragraph of article 14 of the bill, and it is the closest thing available to an answer to “what will we actually have to do?”
Objectifs de sécurité — the “what”
A security objective is the obligation that will be fixed by the decree taken under article 14. Attainment is mandatory. There are 20.
Moyens acceptables de conformité — the “how”
For each objective, ANSSI proposes acceptable means of compliance. These are not mandatory (outside the specific cases in article 16), but an entity that implements them can rely on them to demonstrate it has met the objective.
Who each objective applies to
By default, objectives apply to EI, EE and OIV on their non-SIIV systems. Under the proportionality principle, objectives 16 to 20 apply only to essential entities.
Certification and qualified providers
ReCyF sets out how an entity may rely, during a supervisory check, on ANSSI-qualified services or on certification to international or European standards to demonstrate all or part of an objective.
| # | Objectif de sécurité | Applies to |
|---|---|---|
| 1 | Recensement des systèmes d’information | EI + EE |
| 2 | Mise en oeuvre d’un cadre de gouvernance de la sécurité numérique | EI + EE |
| 3 | Maîtrise de l’écosystème | EI + EE |
| 4 | Intégration de la sécurité numérique dans la gestion des ressources humaines | EI + EE |
| 5 | Maîtrise des systèmes d’information | EI + EE |
| 6 | Maîtrise des accès physiques aux locaux | EI + EE |
| 7 | Sécurisation de l’architecture des systèmes d’information | EI + EE |
| 8 | Sécurisation des accès distants aux systèmes d’information | EI + EE |
| 9 | Protection des systèmes d’information contre les codes malveillants | EI + EE |
| 10 | Gestion des identités et des accès des utilisateurs | EI + EE |
| 11 | Maîtrise de l’administration des systèmes d’information | EI + EE |
| 12 | Identification et réaction aux incidents de sécurité | EI + EE |
| 13 | Continuité et reprise d’activité | EI + EE |
| 14 | Réaction aux crises d’origine cyber | EI + EE |
| 15 | Exercices, tests et entrainements | EI + EE |
| 16 | Mise en oeuvre d’une approche par les risques | EE only |
| 17 | Audit de la sécurité des systèmes d’information | EE only |
| 18 | Sécurisation de la configuration des ressources | EE only |
| 19 | Administration des systèmes d’information depuis des ressources dédiées | EE only |
| 20 | Supervision de la sécurité des systèmes d’information | EE only |
Pre-registration: MesServicesCyber
ANSSI's NIS2 portal is MesServicesCyber, at messervices.cyber.gouv.fr/nis2. If you have the older MonEspaceNIS2 address bookmarked, it now redirects there — the service was renamed.
Pre-registration is voluntary
The portal's call to action is “Pré-enregistrer mon entité”. ANSSI states that transposition “est en cours” and that future essential and important entities are “invitées à s’engager dès à présent”. That is an invitation, not a legal duty. No entity can currently be penalised for not registering.
What the law will require
Under the bill, the national authority establishes and updates at least every two years the list of essential entities, important entities and registration offices, based on the information those entities supply to it. So the duty is to declare yourself into an authority-maintained list — closer to the Belgian and German model than to Bulgaria's, where the register is built without you.
Incident reporting under the draft law
Article 17 of the bill sets the reporting chain. It is not in force, but unlike the security measures it is written out in full in the statute rather than delegated to a decree — so it is the part of the future regime you can plan against with most confidence.
An incident is important if it has caused or is liable to cause a serious operational disruption of services or financial loss for the entity, or if it has affected or is liable to affect other natural or legal persons by causing considerable material, bodily or moral damage.
The authority owes you a response
Article 17 requires the national authority to respond to the entity that filed, without undue delay and if possible within 24 hours of receiving the first notification. Few readers know they are entitled to this.
Public disclosure
To prevent or handle an incident, or where disclosure is in the public interest, the authority may — after consulting the entity — require it to inform the public, or do so itself.
Telling your customers
Entities must also notify, without undue delay, recipients of their services affected by an important incident, and critical vulnerabilities affecting or potentially affecting those services.
A separate OIV clock
Title I imposes its own duty on operators of vital importance: notify any incident liable to compromise the continuity of vital activities within 24 hours, under conditions set by decree in Conseil d’État. If you are an OIV, you will run two regimes.
NIS2 timeline & key dates (France)
Sector-specific notes for France
- Energy: electricity, gas and nuclear-related infrastructures will face strict resilience, security and reporting obligations.
- Transport: aviation, rail, maritime and road operators are in scope under NIS2 and the resilience framework.
- Finance: DORA already applies directly, and the bill's equivalence carve-out is designed to stop the two regimes overlapping. The AMF, Banque de France and ACPR are the only sectoral bodies the bill names, and their role is information exchange with the national authority.
- Healthcare: hospitals and critical health-service providers are a major focus due to recent large-scale cyberattacks.
- Public administration: key State and local authorities fall under the extended NIS2 perimeter.
- Digital infrastructure: data centres, cloud providers, major ICT operators and trust services are in scope regardless of size. Trust service providers file the 72-hour intermediate incident notification within 24 hours instead — the only reporting derogation in the bill.
- Encryption and trust services: article 16 bis prohibits requiring these providers to build in master decryption keys or any other mechanism allowing non-consented access to protected data.
Penalties in the draft law
| Category | Maximum fine | Basis |
|---|---|---|
| Entité essentielle | EUR 10,000,000 or 2 % of total worldwide annual turnover excluding tax for the previous financial year | Whichever amount is higher |
| Entité importante | EUR 7,000,000 or 1.4 % of total worldwide annual turnover excluding tax for the previous financial year | Whichever amount is higher |
| Obstructing a supervisory check | EUR 10,000,000 or 2 % | A separate, freestanding breach — supplying incomplete or inaccurate information, or producing incomplete or distorted documents, is sanctionable in its own right at the highest tier |
| Registration offices (offices d’enregistrement) | EUR 7,000,000 or 1.4 % | Can be cumulated with the essential-entity fine in defined cases |
Public bodies are exempt from fines
The fine provisions expressly exclude State administrations and their public administrative establishments, local authorities, their groupings and their public administrative establishments. Public entities are in scope for the obligations, but not for the administrative fine. Spain's draft does the same; most member states do not.
A GDPR fine blocks the NIS2 fine
Where the same facts give rise to a CNIL administrative fine under the GDPR, the commission des sanctions may not impose an administrative fine at all. A genuine non bis in idem bar, and one no competitor publishes.
Directors can be banned
As a last resort, where the breach persists after a fine has been imposed, the commission may prohibit an individual exercising management functions in an essential entity from holding management responsibilities in that entity.
Cumulation is capped
Where the commission also contemplates the separate article 28 fine against the same person, the combined total may not exceed the maximum of the single applicable fine.
How France differs
Five features that will not be obvious to anyone applying a group-level NIS2 programme built in Germany, Italy or the Nordics.
- One bill, three directives. NIS2, CER and DORA travel together in the loi Résilience. That is a large part of why it has taken two years — and it means the NIS2 timetable is hostage to negotiations on the other two.
- Sanctions sit with an independent commission, not the regulator. ANSSI's agents investigate; a commission des sanctions decides. Most member states let the cybersecurity authority both supervise and fine.
- Public bodies are exempt from administrative fines while remaining fully in scope for the obligations.
- A GDPR fine on the same facts bars the NIS2 fine entirely. Not a reduction, a bar.
- Encryption backdoors are prohibited by name. Article 16 bis, added by the Senate, has no equivalent in the Directive and no equivalent on any other country page we have written.
| French | English / meaning |
|---|---|
| loi Résilience / projet de loi Résilience | The bill transposing NIS2, CER and DORA |
| ReCyF — Référentiel Cyber France | ANSSI's reference framework of 20 security objectives |
| Entité essentielle (EE) / entité importante (EI) | Essential entity / important entity |
| OIV — opérateur d’importance vitale | Operator of vital importance, the pre-existing French regime |
| OSE — opérateur de services essentiels | Essential service operator, the NIS1 designation |
| SIIV — système d’information d’importance vitale | Vitally important information system |
| Commission des sanctions | The body that decides fines |
| Moyens acceptables de conformité | Acceptable means of compliance, ReCyF's non-mandatory “how” |
| MesServicesCyber | ANSSI's portal, formerly MonEspaceNIS2 |
| Procédure accélérée | Accelerated procedure: one reading per chamber |
How to prepare for NIS2 in France
- Settle whether you are in scope against the EE/EI thresholds. These come from the Directive, not from the contested French text, so this work will survive the final law.
- Check the equivalence carve-out first. If a sectoral EU regime such as DORA already covers you, you may be outside these obligations entirely — establish that before building anything.
- Gap-assess against ReCyF, not against the Directive. ANSSI's 20 objectives are what its inspectors will use. If you are likely to be an essential entity, look hard at objectives 16 to 20 — risk-based approach, audit, hardened configuration, dedicated administration resources and security monitoring are the longest-lead items on the list.
- Deal with what already binds you. NIS1 duties if you are an OSE, the SIIV regime if you are an OIV, DORA if you are in financial services, and the NIS2 clauses your EU customers are already putting in contracts.
- Decide on pre-registration. It is voluntary and unpenalised either way; it puts you on ANSSI's distribution list and forces useful information-gathering.
- Draft the reporting runbook, but do not freeze it. Article 17's 24h / 72h / one-month chain is written into the statute rather than delegated, so it is the most stable part of the future regime. Note the 24-hour derogation if you are a trust service provider, and the separate OIV clock if you are one.
- Brief the board. The draft allows a persistent breach to end in a management ban, and the reason the timetable is uncertain is a live case at the EU Court — both are board-level facts.
- Watch two things only: a sitting scheduled at the Assemblée nationale, and publication of the decrees under article 14. Nothing else changes your position.
Official links & resources
FAQ: NIS2 in France
Has France fully transposed NIS2?
Who is the NIS2 competent authority in France?
Should we start preparing before the law is fully in force?
Will ISO 27001 certification be mandatory?
Can we be fined today for not complying with NIS2 in France?
Do we have to register on MesServicesCyber?
Is ReCyF mandatory?
Several French guides say the law is already adopted. Who is right?
Sources & verification
Every date and figure on this page was checked against a primary source on 10 August 2026. Where sources conflict, we followed the parliamentary record, the statutory text and ANSSI, in that order.
- Parliamentary record — Assemblée nationale legislative dossier DLR5L17N50731, and the Sénat text adopted in first reading (T.A. n° 78, 12 March 2025). All dates, text numbers and the 505 amendments come from these.
- Fines, incident reporting, authorities, article 16 bis — the text of the bill as adopted by the Senate. Article and amount references are to that text.
- ReCyF — Référentiel Cyber France, version 2.5 dated 17 March 2026, published by ANSSI. The 20 objectives and the essential-entity-only application of objectives 16 to 20 are stated there.
- Scope thresholds, sector list, portal status — ANSSI's NIS2 portal at MesServicesCyber.
- Court referral — European Commission press release IP/26/1499, 8 July 2026, including the case number INFR(2024)0274 and the wording on financial sanctions.
