NIS2 in France
France has not completed transposition. The projet de loi résilience (covering NIS2, CER and DORA together) passed the Senate in March 2025 but still awaits final adoption and implementing decrees. The Commission referred France to the CJEU on 8 July 2026.
Key Deadlines
Competent Authority
ANSSI adopts a risk-based approach with a phased onboarding. Entities self-declare via MonEspaceANSSI, after which ANSSI assigns a supervision tier. Audits are conducted on a rolling schedule starting with critical infrastructure.
Registration Process
Mandatory registration begins only once the loi résilience is in force. ANSSI's MesServicesCyber platform is already live and lets entities self-identify and pre-register voluntarily. Prepare your SIREN number, sector and sub-sector classification, and a designated NIS2 contact.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Expected once in force: declaration to ANSSI within 3 months of becoming in-scope (voluntary pre-registration is already open)
- 2Cyber incident notification within 24 hours (early warning) and 72 hours (full notification)
- 3Annual cybersecurity audit for Essential Entities every 3 years
- 4Cyber crisis management plan (PCA/PRI) mandatory
- 5CISO designation required for Essential Entities
- 6Supply chain security assessments
- 7Employee cybersecurity training programme
National Additions
FAQ: NIS2 in France
What is MesServicesCyber?
Does NIS2 apply in France yet?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.