NIS2 · National implementation

NIS2 in France

France has not yet transposed NIS2. The implementing bill — the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité, commonly the “loi résilience” — bundles NIS2 with the CER directive and parts of DORA alignment, and has been stuck in parliamentary procedure. The European Commission has referred France to the Court of Justice of the EU for failure to transpose.

National law
Projet de loi résilience (pending)
Resilience and cybersecurity bill, not yet adopted
Status
Not transposed
In force
Not in force
Authority
ANSSI (designated)

Who will supervise

ANSSI (Agence nationale de la sécurité des systèmes d'information) is the designated authority and has been preparing openly: its MonEspaceNIS2 portal lets French organisations pre-assess scope and follow the implementation, and ANSSI has published its intended approach to proportionate supervision.

What applies meanwhile

Directives do not bind companies without national law, so the NIS2 obligations are not yet enforceable against French entities. But two caveats matter. First, the bill's current text tracks the directive closely, so preparing against the directive (scope check, Article 21 measures, reporting readiness) is preparation for the French law. Second, entities regulated under the older French SRI/LPM frameworks keep those obligations.

Official sources

Primary references: the national statute book at www.legifrance.gouv.fr and the national cybersecurity authority at cyber.gouv.fr.

NIS2 in France: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states