Skip to main content
In legislatureNIS2

NIS2 in France

France has not completed transposition. The projet de loi résilience (covering NIS2, CER and DORA together) passed the Senate in March 2025 but still awaits final adoption and implementing decrees. The Commission referred France to the CJEU on 8 July 2026.

Transposition law
Projet de loi relative à la résilience des infrastructures critiques et au renforcement de la cybersécurité (loi résilience) — not yet in force
In force since
Pending
Competent authority
ANSSI: Agence nationale de la sécurité des systèmes d'information
Max fine (Essential)
€10 million or 2% of global annual turnover
Max fine (Important)
€7 million or 1.4% of global annual turnover
Law adopted
Not adopted

Key Deadlines

Senate adopts the loi résilience
12 March 2025
Referred to the Court of Justice of the EU
8 July 2026
Final adoption and implementing decrees
Pending

Competent Authority

ANSSI: Agence nationale de la sécurité des systèmes d'information
Lead NIS2 supervisory authority for all sectors
https://www.ssi.gouv.fr

ANSSI adopts a risk-based approach with a phased onboarding. Entities self-declare via MonEspaceANSSI, after which ANSSI assigns a supervision tier. Audits are conducted on a rolling schedule starting with critical infrastructure.

Registration Process

Mandatory registration begins only once the loi résilience is in force. ANSSI's MesServicesCyber platform is already live and lets entities self-identify and pre-register voluntarily. Prepare your SIREN number, sector and sub-sector classification, and a designated NIS2 contact.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Expected once in force: declaration to ANSSI within 3 months of becoming in-scope (voluntary pre-registration is already open)
  • 2Cyber incident notification within 24 hours (early warning) and 72 hours (full notification)
  • 3Annual cybersecurity audit for Essential Entities every 3 years
  • 4Cyber crisis management plan (PCA/PRI) mandatory
  • 5CISO designation required for Essential Entities
  • 6Supply chain security assessments
  • 7Employee cybersecurity training programme

National Additions

France retains specific sectors from OIV (Opérateurs d'importance vitale) status under SAIV legislation, which adds physical security obligations on top of NIS2
Public administrations at regional and local level are included from 2026
France has introduced specific deadlines for the healthcare sector following major ransomware attacks

FAQ: NIS2 in France

What is MesServicesCyber?
MesServicesCyber is ANSSI's platform where French entities can already check whether they fall in scope and pre-register voluntarily, ahead of the loi résilience entering into force. Mandatory declaration begins only once the law applies.
Does NIS2 apply in France yet?
No. The loi résilience is not yet in force, so NIS2 obligations do not legally bind French entities. Existing OIV/LPM obligations continue to apply. On 8 July 2026 the European Commission referred France, alongside Ireland, Spain and the Netherlands, to the Court of Justice of the EU seeking daily fines. An estimated 15,000 to 18,000 French entities will be in scope once the law commences.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.