NIS2 Country Guide

NIS2 France: No Law Yet, ANSSI's ReCyF & the Draft Penalties

France has not transposed NIS2. The projet de loi Résilience passed the Senate in March 2025, cleared an Assemblée nationale commission on 10 September 2025 and has not been scheduled for a sitting since. On 8 July 2026 the European Commission referred France to the Court of Justice. This page sets out what that means, what ANSSI's ReCyF already asks of you, and which obligations bind French entities today.

France NIS2 law: not adopted Referred to the EU Court: 8 July 2026 Expected authority: ANSSI Last updated: 10 August 2026

Introduction: NIS2 Directive & the French context

France already had a mature cybersecurity framework built around operators of vital importance (opérateurs d’importance vitale, OIV) and essential service operators (OSE) under the original NIS Directive and national law. That framework is still the one in force. NIS2 would broaden it considerably — more sectors, far more entities, and new governance and incident-reporting duties — but the law that would do so has not been adopted.

The vehicle is the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité — the loi Résilience — which would jointly transpose three European texts: NIS2, the Critical Entities Resilience Directive (EU) 2022/2557 and DORA. That triple scope is part of why it has moved slowly.

The short answer: as at 10 August 2026 there is no French NIS2 law, no application decree, and no enforceable registration or reporting duty under this bill. Any source telling you otherwise is wrong — and several of the highest-ranking French guides do say otherwise. What exists is a draft with known contents, a published ANSSI reference framework, a voluntary pre-registration portal, and a separate set of obligations that do already bind you.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

The loi Résilience: what it is

France launched transposition on 15 October 2024 — two days before the EU deadline — when the bill was presented in the Council of Ministers and tabled in the Senate as text n° 33. The Government engaged the procédure accélérée the same day, which limits each chamber to a single reading. Nearly two years later the bill has still not completed that single reading.

The bill is structured in several titles. Title I rewrites the OIV regime in the code de la défense, transposing the Critical Entities Resilience Directive and introducing a 24-hour incident notification for operators of vital importance. Title II transposes NIS2 itself: scope, risk-management requirements, the reporting chain, supervision and sanctions. A further title covers DORA.

Two provisions are worth knowing before the law exists. Article 14 is the hook for the security requirements, and its sixth paragraph is what ReCyF implements. Article 16 bis, added by the Senate, prohibits requiring encryption providers and qualified trust service providers to build in master decryption keys or any other mechanism permitting non-consented access to protected data — a French addition with no equivalent in the Directive.

Status

Not transposed. Adopted by the Senate in first reading on 12 March 2025; an Assemblée nationale commission adopted its version on 10 September 2025. No sitting has been scheduled since. No decree exists.

Legal structure

One bill, three directives: NIS2, CER and DORA. The security requirements themselves will sit in decrees taken under article 14, with ReCyF as their reference framework — so the law alone will not tell you what to implement.

Who supervises

The bill never writes “ANSSI”. It refers throughout to l’autorité nationale de sécurité des systèmes d’information, to be designated by decree. ANSSI is the obvious candidate and runs the preparatory work, but the designation is not yet law.

Where the bill actually stands

This is the question the French market gets wrong most often, so here is the parliamentary record in full, taken from the Assemblée nationale's own legislative dossier.

Date Step Reference
15 October 2024 Tabled in the Senate; accelerated procedure engaged the same day Text n° 33
4 March 2025 Senate special commission reports and adopts its text Report n° 393, text n° 394
12 March 2025 Senate adopts the bill in first reading T.A. n° 78
13 March 2025 Transmitted to the Assemblée nationale, referred to a special commission Text n° 1112
505 amendments tabled on text n° 1112
10 September 2025 Assemblée nationale special commission adopts its text (published 16 September) Report n° 1779, text n° 1779-A0
Since then Nothing. No public sitting has been scheduled at the Assemblée nationale
What has to happen next: the Assemblée nationale must debate and vote the text in public session. Because the accelerated procedure is engaged, a commission mixte paritaire can then be convened to reconcile the two chambers' versions, followed by final adoption, promulgation and publication in the Journal officiel. Only then do the application decrees under article 14 become possible. We do not print an expected date, and we would treat any source that does with caution — there is no scheduled sitting to base one on.

France at the EU Court of Justice

On 8 July 2026 the European Commission referred France to the Court of Justice of the European Union for failing to notify measures transposing NIS2. France was referred alongside Ireland, Spain and the Netherlands. The French case is INFR(2024)0274.

17 October 2024 — the deadline for all Member States to transpose NIS2. France misses it.
28 November 2024 — the Commission sends a letter of formal notice, opening the infringement procedure.
7 May 2025 — reasoned opinion, the second stage, giving a further two months to comply.
8 July 2026 — referral to the Court, the third and final stage. The Commission asks the Court to impose financial sanctions “consisting of a lump sum and daily penalties until notification of complete transposition”.
What this does and does not mean for your organisation. The penalties are sought against the French State, not against entities. Nothing about the referral creates an obligation for a company or a local authority. Its practical significance is different: it raises the political cost of further delay, which is the clearest signal available that the timetable will move. It is also worth knowing that the Netherlands appears on the same referral despite its Senate having passed the Cyberbeveiligingswet on 7 July 2026 — the day before the Commission filed — because notification of complete transposition had not yet been made.

What binds you right now

“No NIS2 law” is not “no cybersecurity obligations”. For most French organisations this is the section that actually matters, because several regimes already apply and none of them is waiting for the loi Résilience.

The NIS1 regime, still in force

The original NIS Directive was transposed in 2018 and has not been repealed in France. If you were designated an OSE (opérateur de services essentiels), your security and notification obligations continue exactly as before.

The OIV regime

Operators of vital importance remain subject to the code de la défense rules on systèmes d’information d’importance vitale (SIIV). This is the strictest regime in France and it is unaffected by the delay.

DORA

For banks, insurers, investment firms and their critical ICT providers, DORA has applied since 17 January 2025 as a directly applicable EU regulation. It needs no French transposition and is already enforceable.

Contractual spillover

Twenty-three Member States have transposed NIS2. Their in-scope entities must manage supply-chain risk, so French suppliers are already receiving NIS2 security clauses, questionnaires and audit rights from German, Italian, Belgian and Nordic customers. This is currently the most common way NIS2 reaches a French company.

The legal point, stated plainly. An EU directive that has not been transposed cannot by itself impose obligations on, or be used to sanction, a private party. The remedy for late transposition runs against the Member State — which is precisely what the Court case is. So no French company can be fined today for failing to comply with NIS2. What a company can face is the commercial consequence of being unprepared when the law lands, and the contractual consequence described above, which is already live.

Am I in scope in France?

France will apply the NIS2 model of entités essentielles (EE) and entités importantes (EI) across 18 sectors, far beyond the earlier OIV/OSE perimeter. ANSSI's own wording is “plusieurs milliers d’entités” — several thousand. It publishes no entity count, and the figures circulating in the French advisory market are not ANSSI's. The thresholds below are ANSSI's, as stated on its NIS2 portal.

The two categories, as ANSSI states them

  • Entité essentielle (EE) — at least 250 staff, or turnover above EUR 50 million and a balance sheet total above EUR 43 million.
  • Entité importante (EI) — not an EE, and at least 50 staff or the corresponding financial test.
  • Certain entities are in scope regardless of size, including trust service providers, DNS service providers, TLD name registries and providers of public electronic communications.
  • ANSSI states the population is mostly medium and large companies plus local authorities and administrations.

The 18 sectors, as ANSSI lists them

Secteurs hautement critiques: administrations publiques, eaux potables, eaux non potables, énergies, espace, gestion des services TIC (interentreprises), infrastructures des marchés financiers, infrastructures numériques, santé, secteur bancaire, transport.

Autres secteurs critiques: fabrication, production et distribution de produits chimiques; fournisseurs numériques; gestion des déchets; industries manufacturières; production, transformation et distribution de denrées alimentaires; recherche; services postaux et d’expédition.

An important carve-out

The bill excludes entities already subject, under an EU legal act, to sectoral security and incident-notification requirements of at least equivalent effect — provided the equivalent regime gives immediate access to notifications. This is how DORA-regulated financial entities avoid being governed twice. Check whether a sectoral regime already covers you before building a separate NIS2 programme.

Practical tip: the scope tests are set by the Directive and are not the part of the French text still in dispute, so a scoping exercise done today will almost certainly survive the final law. The same is not true of process design — wait for the decrees before hard-coding deadlines into a runbook. If you want a quick view, our NIS2 eligibility check applies these thresholds.

ReCyF: the 20 security objectives

ReCyF — the Référentiel Cyber France — is the one concrete thing ANSSI has published. Version 2.5 is dated 17 March 2026 and runs to 48 pages. It is the référentiel referred to at the sixth paragraph of article 14 of the bill, and it is the closest thing available to an answer to “what will we actually have to do?”

Objectifs de sécurité — the “what”

A security objective is the obligation that will be fixed by the decree taken under article 14. Attainment is mandatory. There are 20.

Moyens acceptables de conformité — the “how”

For each objective, ANSSI proposes acceptable means of compliance. These are not mandatory (outside the specific cases in article 16), but an entity that implements them can rely on them to demonstrate it has met the objective.

Who each objective applies to

By default, objectives apply to EI, EE and OIV on their non-SIIV systems. Under the proportionality principle, objectives 16 to 20 apply only to essential entities.

Certification and qualified providers

ReCyF sets out how an entity may rely, during a supervisory check, on ANSSI-qualified services or on certification to international or European standards to demonstrate all or part of an objective.

# Objectif de sécurité Applies to
1Recensement des systèmes d’informationEI + EE
2Mise en oeuvre d’un cadre de gouvernance de la sécurité numériqueEI + EE
3Maîtrise de l’écosystèmeEI + EE
4Intégration de la sécurité numérique dans la gestion des ressources humainesEI + EE
5Maîtrise des systèmes d’informationEI + EE
6Maîtrise des accès physiques aux locauxEI + EE
7Sécurisation de l’architecture des systèmes d’informationEI + EE
8Sécurisation des accès distants aux systèmes d’informationEI + EE
9Protection des systèmes d’information contre les codes malveillantsEI + EE
10Gestion des identités et des accès des utilisateursEI + EE
11Maîtrise de l’administration des systèmes d’informationEI + EE
12Identification et réaction aux incidents de sécuritéEI + EE
13Continuité et reprise d’activitéEI + EE
14Réaction aux crises d’origine cyberEI + EE
15Exercices, tests et entrainementsEI + EE
16Mise en oeuvre d’une approche par les risquesEE only
17Audit de la sécurité des systèmes d’informationEE only
18Sécurisation de la configuration des ressourcesEE only
19Administration des systèmes d’information depuis des ressources dédiéesEE only
20Supervision de la sécurité des systèmes d’informationEE only
Read ReCyF for what it is. Every page carries a document de travail watermark. ANSSI states that no definitive version will be published until the legislative and regulatory work is complete and consultation has taken place, and ReCyF becomes operative only as an annex to a decree that does not yet exist. So it is not binding today — but it is written by the body that will supervise you, it is unlikely to change beyond recognition, and objectives 16 to 20 in particular (risk-based approach, audit, hardened configuration, dedicated administration resources, security monitoring) are long-lead items. Treating it as a planning baseline is reasonable. Treating it as current law is not.

Pre-registration: MesServicesCyber

ANSSI's NIS2 portal is MesServicesCyber, at messervices.cyber.gouv.fr/nis2. If you have the older MonEspaceNIS2 address bookmarked, it now redirects there — the service was renamed.

Pre-registration is voluntary

The portal's call to action is “Pré-enregistrer mon entité”. ANSSI states that transposition “est en cours” and that future essential and important entities are “invitées à s’engager dès à présent”. That is an invitation, not a legal duty. No entity can currently be penalised for not registering.

What the law will require

Under the bill, the national authority establishes and updates at least every two years the list of essential entities, important entities and registration offices, based on the information those entities supply to it. So the duty is to declare yourself into an authority-maintained list — closer to the Belgian and German model than to Bulgaria's, where the register is built without you.

Should you pre-register now? There is no penalty either way. The practical arguments for doing it are that it puts you on ANSSI's distribution list for guidance and consultation, and that the information gathering it forces — services, systems, dependencies, named contacts — is work you will have to do regardless. The argument against is simply that nothing obliges you yet.

Incident reporting under the draft law

Article 17 of the bill sets the reporting chain. It is not in force, but unlike the security measures it is written out in full in the statute rather than delegated to a decree — so it is the part of the future regime you can plan against with most confidence.

An incident is important if it has caused or is liable to cause a serious operational disruption of services or financial loss for the entity, or if it has affected or is liable to affect other natural or legal persons by causing considerable material, bodily or moral damage.

Within 24 hours — initial notification, without undue delay, indicating where applicable whether the incident may have been caused by unlawful or malicious acts, or may have a cross-border impact.
Within 72 hours — intermediate notification updating the initial one, with an initial assessment of severity and impact and indicators of compromise where available. Derogation: trust service providers must file this within 24 hours, not 72.
On request — a report on relevant updates to the situation, whenever the authority asks for one.
Within one month of the intermediate notification — the final report, provided the incident has been resolved.
If it is not resolved — a progress report at one month instead, followed by a final report within one month of the incident being handled.

The authority owes you a response

Article 17 requires the national authority to respond to the entity that filed, without undue delay and if possible within 24 hours of receiving the first notification. Few readers know they are entitled to this.

Public disclosure

To prevent or handle an incident, or where disclosure is in the public interest, the authority may — after consulting the entity — require it to inform the public, or do so itself.

Telling your customers

Entities must also notify, without undue delay, recipients of their services affected by an important incident, and critical vulnerabilities affecting or potentially affecting those services.

A separate OIV clock

Title I imposes its own duty on operators of vital importance: notify any incident liable to compromise the continuity of vital activities within 24 hours, under conditions set by decree in Conseil d’État. If you are an OIV, you will run two regimes.

Competent authorities & CSIRTs

France will use a centralised model. One point deserves care: the bill never names ANSSI. It refers throughout to l’autorité nationale de sécurité des systèmes d’information, a function to be designated by decree. ANSSI runs all the preparatory work and is the only realistic candidate, but until the decree exists the designation is an expectation rather than a legal fact.

Role Authority Notes
National competent authority & Single Point of Contact L’autorité nationale de sécurité des systèmes d’information — expected to be ANSSI Supervision, control, and the national point of contact for EU partners. Receives incident notifications and owes a response within 24 hours where possible. Establishes the list of entities at least every two years.
Sanctions Commission des sanctions (article L. 1332-15, code de la défense) Fines are not imposed by ANSSI. Sworn, specially designated State agents investigate and refer; an independent sanctions commission decides and sets the amount. This separation is a French design choice and is unusual across the member states we have reviewed.
National CSIRT CERT-FR, operated by ANSSI Coordinates technical response, shares threat intelligence and supports entities in scope.
Financial sector coordination Autorité des marchés financiers, Banque de France, Autorité de contrôle prudentiel et de résolution These three and the national authority must exchange, without delay, information useful to their respective information-security missions. Note the role is information exchange, not sectoral supervision — and these are the only sectoral bodies the bill names.

NIS2 timeline & key dates (France)

15 October 2024 — bill tabled in the Senate as text n° 33; accelerated procedure engaged the same day.
17 October 2024 — EU transposition deadline. France misses it.
28 November 2024 — European Commission sends a letter of formal notice.
12 March 2025 — the Senate adopts the bill in first reading (T.A. n° 78); it is transmitted to the Assemblée nationale the following day.
7 May 2025 — reasoned opinion from the Commission, with a further two months to comply.
10 September 2025 — the Assemblée nationale special commission adopts its text (n° 1779-A0) after 505 amendments. No public sitting has been scheduled since.
20 January 2026 — the Commission proposes targeted amendments to NIS2 itself, as part of a cybersecurity package, to improve legal clarity.
17 March 2026 — ANSSI publishes ReCyF version 2.5, the reference framework for the future security requirements.
8 July 2026 — the Commission refers France to the Court of Justice, INFR(2024)0274, seeking a lump sum and daily penalties.
Next — a public sitting at the Assemblée nationale, then potentially a commission mixte paritaire, final adoption, promulgation, and only then the application decrees. No date is scheduled, and we do not publish a prediction.

Sector-specific notes for France

  • Energy: electricity, gas and nuclear-related infrastructures will face strict resilience, security and reporting obligations.
  • Transport: aviation, rail, maritime and road operators are in scope under NIS2 and the resilience framework.
  • Finance: DORA already applies directly, and the bill's equivalence carve-out is designed to stop the two regimes overlapping. The AMF, Banque de France and ACPR are the only sectoral bodies the bill names, and their role is information exchange with the national authority.
  • Healthcare: hospitals and critical health-service providers are a major focus due to recent large-scale cyberattacks.
  • Public administration: key State and local authorities fall under the extended NIS2 perimeter.
  • Digital infrastructure: data centres, cloud providers, major ICT operators and trust services are in scope regardless of size. Trust service providers file the 72-hour intermediate incident notification within 24 hours instead — the only reporting derogation in the bill.
  • Encryption and trust services: article 16 bis prohibits requiring these providers to build in master decryption keys or any other mechanism allowing non-consented access to protected data.

Penalties in the draft law

None of this is in force. The figures below are in the bill as adopted by the Senate. They bind nobody today, and they can still change in the Assemblée nationale. They are worth knowing because they are the basis on which the final regime will be built — and because several French guides present them as though they already applied.
Category Maximum fine Basis
Entité essentielle EUR 10,000,000 or 2 % of total worldwide annual turnover excluding tax for the previous financial year Whichever amount is higher
Entité importante EUR 7,000,000 or 1.4 % of total worldwide annual turnover excluding tax for the previous financial year Whichever amount is higher
Obstructing a supervisory check EUR 10,000,000 or 2 % A separate, freestanding breach — supplying incomplete or inaccurate information, or producing incomplete or distorted documents, is sanctionable in its own right at the highest tier
Registration offices (offices d’enregistrement) EUR 7,000,000 or 1.4 % Can be cumulated with the essential-entity fine in defined cases

Public bodies are exempt from fines

The fine provisions expressly exclude State administrations and their public administrative establishments, local authorities, their groupings and their public administrative establishments. Public entities are in scope for the obligations, but not for the administrative fine. Spain's draft does the same; most member states do not.

A GDPR fine blocks the NIS2 fine

Where the same facts give rise to a CNIL administrative fine under the GDPR, the commission des sanctions may not impose an administrative fine at all. A genuine non bis in idem bar, and one no competitor publishes.

Directors can be banned

As a last resort, where the breach persists after a fine has been imposed, the commission may prohibit an individual exercising management functions in an essential entity from holding management responsibilities in that entity.

Cumulation is capped

Where the commission also contemplates the separate article 28 fine against the same person, the combined total may not exceed the maximum of the single applicable fine.

How France differs

Five features that will not be obvious to anyone applying a group-level NIS2 programme built in Germany, Italy or the Nordics.

  • One bill, three directives. NIS2, CER and DORA travel together in the loi Résilience. That is a large part of why it has taken two years — and it means the NIS2 timetable is hostage to negotiations on the other two.
  • Sanctions sit with an independent commission, not the regulator. ANSSI's agents investigate; a commission des sanctions decides. Most member states let the cybersecurity authority both supervise and fine.
  • Public bodies are exempt from administrative fines while remaining fully in scope for the obligations.
  • A GDPR fine on the same facts bars the NIS2 fine entirely. Not a reduction, a bar.
  • Encryption backdoors are prohibited by name. Article 16 bis, added by the Senate, has no equivalent in the Directive and no equivalent on any other country page we have written.
French English / meaning
loi Résilience / projet de loi RésilienceThe bill transposing NIS2, CER and DORA
ReCyF — Référentiel Cyber FranceANSSI's reference framework of 20 security objectives
Entité essentielle (EE) / entité importante (EI)Essential entity / important entity
OIV — opérateur d’importance vitaleOperator of vital importance, the pre-existing French regime
OSE — opérateur de services essentielsEssential service operator, the NIS1 designation
SIIV — système d’information d’importance vitaleVitally important information system
Commission des sanctionsThe body that decides fines
Moyens acceptables de conformitéAcceptable means of compliance, ReCyF's non-mandatory “how”
MesServicesCyberANSSI's portal, formerly MonEspaceNIS2
Procédure accéléréeAccelerated procedure: one reading per chamber

How to prepare for NIS2 in France

  1. Settle whether you are in scope against the EE/EI thresholds. These come from the Directive, not from the contested French text, so this work will survive the final law.
  2. Check the equivalence carve-out first. If a sectoral EU regime such as DORA already covers you, you may be outside these obligations entirely — establish that before building anything.
  3. Gap-assess against ReCyF, not against the Directive. ANSSI's 20 objectives are what its inspectors will use. If you are likely to be an essential entity, look hard at objectives 16 to 20 — risk-based approach, audit, hardened configuration, dedicated administration resources and security monitoring are the longest-lead items on the list.
  4. Deal with what already binds you. NIS1 duties if you are an OSE, the SIIV regime if you are an OIV, DORA if you are in financial services, and the NIS2 clauses your EU customers are already putting in contracts.
  5. Decide on pre-registration. It is voluntary and unpenalised either way; it puts you on ANSSI's distribution list and forces useful information-gathering.
  6. Draft the reporting runbook, but do not freeze it. Article 17's 24h / 72h / one-month chain is written into the statute rather than delegated, so it is the most stable part of the future regime. Note the 24-hour derogation if you are a trust service provider, and the separate OIV clock if you are one.
  7. Brief the board. The draft allows a persistent breach to end in a management ban, and the reason the timetable is uncertain is a live case at the EU Court — both are board-level facts.
  8. Watch two things only: a sitting scheduled at the Assemblée nationale, and publication of the decrees under article 14. Nothing else changes your position.

Official links & resources

FAQ: NIS2 in France

Has France fully transposed NIS2?
No. As at 10 August 2026 the loi Résilience has not been adopted. It passed the Senate on 12 March 2025 and an Assemblée nationale commission on 10 September 2025, and no public sitting has been scheduled since. On 8 July 2026 the European Commission referred France to the EU Court of Justice over the delay.
Who is the NIS2 competent authority in France?
In practice ANSSI. Strictly, the bill does not name it — it refers to l’autorité nationale de sécurité des systèmes d’information, to be designated by decree. Note also that fines will be imposed not by that authority but by an independent commission des sanctions.
Should we start preparing before the law is fully in force?
Yes, and ANSSI says so itself — it invites future entities to engage now. Scoping work and a gap assessment against ReCyF will survive the final law. Process design is the part worth holding: wait for the decrees before freezing deadlines into a runbook. Note too that obligations under NIS1, the OIV regime, DORA and your customers' contracts already apply.
Will ISO 27001 certification be mandatory?
No certification is mandated by name. ReCyF does set out how an entity may rely on ANSSI-qualified services, or on certification to international or European standards, to demonstrate all or part of a security objective during a check — so ISO/IEC 27001 is useful evidence rather than a requirement. ANSSI publishes a separate correspondence table between ReCyF and ISO 27001.
Can we be fined today for not complying with NIS2 in France?
No. There is no French NIS2 law in force, and an untransposed directive cannot by itself impose obligations on or sanction a private party — the remedy for late transposition runs against the State, which is what the Court case is. The fines in the draft (EUR 10m or 2 % for essential entities, EUR 7m or 1.4 % for important entities) bind nobody yet.
Do we have to register on MesServicesCyber?
Not yet. ANSSI's portal offers pre-registration and describes it as an invitation, not a duty. Under the bill the national authority will build and update the list of entities at least every two years from information those entities supply, so a declaration duty is coming — but it does not exist today, and nobody can be penalised for not having pre-registered.
Is ReCyF mandatory?
Not today. ReCyF v2.5 carries a document de travail watermark and becomes operative only as an annex to a decree under article 14 that has not been made. When it does bind, its 20 security objectives will be mandatory, while the moyens acceptables de conformité beneath each one will remain optional ways of demonstrating you have met them. Objectives 16 to 20 apply only to essential entities.
Several French guides say the law is already adopted. Who is right?
The Assemblée nationale's own legislative dossier is the authority, and it records no reading of the text in public session. Some widely-read French guides state that the loi Résilience has been approved by Parliament, that application decrees are being published and that entities must already register. None of that is correct. ANSSI's own portal says transposition “est en cours”.

Sources & verification

Every date and figure on this page was checked against a primary source on 10 August 2026. Where sources conflict, we followed the parliamentary record, the statutory text and ANSSI, in that order.

  • Parliamentary record — Assemblée nationale legislative dossier DLR5L17N50731, and the Sénat text adopted in first reading (T.A. n° 78, 12 March 2025). All dates, text numbers and the 505 amendments come from these.
  • Fines, incident reporting, authorities, article 16 bis — the text of the bill as adopted by the Senate. Article and amount references are to that text.
  • ReCyFRéférentiel Cyber France, version 2.5 dated 17 March 2026, published by ANSSI. The 20 objectives and the essential-entity-only application of objectives 16 to 20 are stated there.
  • Scope thresholds, sector list, portal status — ANSSI's NIS2 portal at MesServicesCyber.
  • Court referral — European Commission press release IP/26/1499, 8 July 2026, including the case number INFR(2024)0274 and the wording on financial sanctions.
A claim worth checking before you repeat it. ARCEP is widely named among French sectoral regulators for NIS2. It appears nowhere in the bill. The only sectoral bodies the text names are the Autorité des marchés financiers, the Banque de France and the Autorité de contrôle prudentiel et de résolution, and their role is information exchange rather than supervision.
What we deliberately do not state. A date for entry into force — no sitting is scheduled, so any date would be a guess. An entity count — the figures circulating in the French market are not ANSSI's; ANSSI says only “plusieurs milliers”. That ReCyF or the draft fines currently apply — they do not. A detailed ReCyF-to-ISO 27001 mapping — ANSSI publishes one as a separate document, and we would rather link it than paraphrase it.
Information provided for general guidance and current at 10 August 2026, when France had not yet transposed NIS2. Always consult the official French legislation, ANSSI publications and legal counsel for definitive NIS2 compliance requirements.