NIS2 · National implementation
NIS2 in France
France has not yet transposed NIS2. The implementing bill — the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité, commonly the “loi résilience” — bundles NIS2 with the CER directive and parts of DORA alignment, and has been stuck in parliamentary procedure. The European Commission has referred France to the Court of Justice of the EU for failure to transpose.
- National law
- Projet de loi résilience (pending)
- Resilience and cybersecurity bill, not yet adopted
- Status
- Not transposed
- In force
- Not in force
- Authority
- ANSSI (designated)
Who will supervise
ANSSI (Agence nationale de la sécurité des systèmes d'information) is the designated authority and has been preparing openly: its MonEspaceNIS2 portal lets French organisations pre-assess scope and follow the implementation, and ANSSI has published its intended approach to proportionate supervision.
What applies meanwhile
Directives do not bind companies without national law, so the NIS2 obligations are not yet enforceable against French entities. But two caveats matter. First, the bill's current text tracks the directive closely, so preparing against the directive (scope check, Article 21 measures, reporting readiness) is preparation for the French law. Second, entities regulated under the older French SRI/LPM frameworks keep those obligations.
Official sources
Primary references: the national statute book at www.legifrance.gouv.fr and the national cybersecurity authority at cyber.gouv.fr.
NIS2 in France: frequently asked questions
Last reviewed:
