NIS2 in France
What binds you in France is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Referred to the Court of Justice
The European Commission referred this member state to the Court of Justice of the European Union in its July 2026 infringement package for failing to fully transpose NIS2, asking the Court to impose a lump sum and daily penalty payments.
This does not suspend your obligations. The directive still binds the member state, and entities are expected to be working to article 21(2) regardless of how late the national text is.
Status of the national text · Not yet promulgated
Loi relative à la résilience des activités d'importance vitale, à la protection des infrastructures critiques, à la cybersécurité et à la résilience opérationnelle numérique du secteur financier ("loi résilience")
Adopted at first reading by the Sénat on 12 March 2025; the special committee of the Assemblée nationale finished its examination on 10 September 2025. A public session was announced for July 2026 and promulgation was widely expected over the summer — but at re-check on 16 August 2026 the Assemblée nationale legislative file still showed that committee report as its most recent step, and nothing had been promulgated. A session being announced is not a session being held, and commentary that reported the July date has largely not been corrected since. The European Commission opened an infringement procedure against France at the end of November 2024 for missing the 17 October 2024 deadline.
This is not the article you read in the directive
The law delegates most technical requirements to implementing decrees and to ANSSI reference documents, so the operative obligations are not yet fixed in national law. Do not plan against article numbers that do not exist yet.
MonEspaceNIS2 (ANSSI)
ANSSI opened a pre-registration portal in November 2025, ahead of the law. Registering early costs nothing and fixes your entity classification.
Référentiel Cyber France — ReCyF
first publication, published by Agence nationale de la sécurité des systèmes d'information (ANSSI). Built on The security objectives of NIS2, restated as graduated measures.
A label is not compliance
ReCyF is a recommendation framework, not a certification scheme: there is no ReCyF label to hold. It also sits on a law that is not yet promulgated — the loi résilience was still before Parliament in July 2026 — so the binding obligations remain to be fixed by implementing decree. Treat ReCyF as the best available statement of what ANSSI will expect, not as settled law.
ReCyF in full — levels, controls and what it does not cover →
Who supervises you
ANSSI is the competent authority designated by France. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CERT-FR, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, France legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
Transposition is not complete here
That is not a reason to wait. The article 21 measures are fixed and will not change; only the procedural detail is pending. Organisations that waited are now compressing an 18-month programme into whatever time the national law leaves them. The European Commission opened infringement procedures in 2025 against member states that missed the 17 October 2024 deadline.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.