LPM, OIV, OSE: who is covered and what the obligations are

Operators of vital importance, operators of essential services, NIS 2: who must do what, since when, and what is about to change.

· 11 min read
Illustration: a columned building with one column glowing orange

In cybersecurity, the LPM refers to France's military programming law of 18 December 2013, whose Article 22 required operators of vital importance (OIV) to protect their most critical systems. In 2018, the transposition of the NIS directive added a second regime, for operators of essential services (OSE). The NIS 2 directive is about to extend this framework to thousands of entities. Here is who each regime covers, which obligations apply today, and what is about to change.

01

The LPM and cybersecurity: from 2013 to today

A military programming law sets France's defence resources and priorities for several years. Since 2013, each has included a cyber component.

  • LPM 2014-2019 (law of 18 December 2013): its Article 22 created the cybersecurity obligations of OIVs in the Defence Code. This is what people usually mean by “the LPM”.
  • LPM 2019-2025 (law of 13 July 2018): its Article 34 allows electronic communications operators to deploy detection devices based on technical markers, and ANSSI to install its own when facing a threat, as the Conseil d'État notes.
  • LPM 2024-2030 (law of 1 August 2023): it gives ANSSI the power to require blocking or redirection of malicious domain names, and requires software vendors to report significant vulnerabilities and incidents affecting their products to ANSSI and then inform their users, according to ANSSI's FAQ.

These texts came on top of those derived from EU law. The timeline below shows how the two tracks overlapped.

From the LPM to NIS 2: overlapping regimes OIV and LPM OSE, NIS and NIS 2
  1. 2006

    SAIV scheme

    Creation of the vital activities security scheme and of OIVs.

  2. 2013

    LPM 2014-2019, Article 22

    Law of 18 December 2013: cyber obligations for OIVs' vital information systems.

  3. 2016

    NIS directive

    Adopted on 6 July 2016: operators of essential services and digital service providers.

  4. 2016

    First sector orders

    In force on 1 July 2016 for the first sectors.

  5. 2018

    NIS transposition

    Law of 26 February, decree of 23 May, order of 14 September 2018 (23 rules).

  6. 2018

    LPM 2019-2025

    Law of 13 July 2018: detection on electronic communications operators' networks.

  7. 2022

    NIS 2 and CER

    Two directives of 14 December 2022, to be transposed by 17 October 2024.

  8. 2023

    LPM 2024-2030

    Law of 1 August 2023: domain name filtering, obligations for software vendors.

  9. 2026

    Resilience bill · Pending

    Still not passed on 9 October 2026.

02

OIV: operators of vital importance

The vital activities security scheme (SAIV), created in 2006, protects operators deemed essential to the nation's survival against malicious acts and natural, technological or health risks. OIVs are identified by their supervising ministry and designated by order. They belong to 12 sectors of vital importance:

  • food;
  • water management;
  • health;
  • civil State activities;
  • judicial activities;
  • military State activities;
  • energy;
  • finance;
  • transport;
  • electronic communications, broadcasting and information;
  • industry;
  • space and research.

The list of OIVs is protected and not published. The Senate report on the resilience bill puts their number at around 300, operating some 1,500 points of vital importance. Beyond cyber, an OIV must draw up an operator security plan, specific protection plans for each of its sites, and appoint a defence and security officer.

03

OIV cyber obligations under the LPM

Article 22 of the 2013 LPM introduced a section on information systems into the Defence Code. Detailed rules are set by sector orders: the first came into force on 1 July 2016 for health products, water management and food, and the others followed. According to ANSSI, an OIV must:

  • identify and declare its SIIV, the vital information systems whose compromise would have serious consequences for the nation;
  • apply the security rules set by ANSSI: around twenty technical and organisational rules covering governance, risk management, control of systems, protection and incident management;
  • notify incidents affecting its SIIV directly to ANSSI without delay;
  • undergo inspections, carried out by ANSSI, another State service or a qualified audit provider;
  • apply, in a major crisis, the measures the Prime Minister may impose.

The Prime Minister may also require the use of attack detection systems. Breaches carry criminal penalties: up to €150,000 for directors and €750,000 for the legal entity, according to the analysis by law firm Squire Patton Boggs.

04

OSE: the operators of essential services under NIS 1

The EU NIS directive, adopted on 6 July 2016, was transposed in France by the law of 26 February 2018, the decree of 23 May 2018 and several orders. It created two categories:

  • operators of essential services (OSE), designated by order of the Prime Minister because they provide a service essential to society or the economy. The first list was adopted in November 2018, according to CMS Francis Lefebvre;
  • digital service providers: online marketplaces, search engines and cloud services with at least 50 employees or €10m in turnover, which are not designated but apply the rules directly.

An OSE must appoint a representative to ANSSI, declare its essential information systems, notify incidents and undergo inspections. Above all, it applies the 23 security rules of the order of 14 September 2018, within three months to three years of its designation:

  • governance: risk analysis, security policy, security accreditation, indicators, audits;
  • protection: mapping, configuration, segmentation, remote access, filtering, administration accounts and systems, identification, authentication, access rights, security maintenance, physical security;
  • defence: detection, logging, log correlation and analysis, incident response, alert handling;
  • resilience: crisis management.

The logic mirrors the RGS for public bodies: a risk analysis, then accreditation. Under Article 9 of the law of 26 February 2018, breaches expose OSE directors to criminal fines of €75,000 to €125,000.

05

OIV or OSE: which regime applies to you?

The two statuses are independent: an OIV can be designated an OSE for other activities, and most OSEs are not OIVs. Answer the four questions to see which regime applies today and which awaits you under NIS 2.

Orientation · which regime applies to you?
Are you designated an operator of vital importance (OIV)?
Are you designated an operator of essential services (OSE)?
Is your sector covered by NIS 2?
Your size

Large: 250 employees or more, or turnover above €50m and balance sheet above €43m. Medium: from 50 employees, or €10m in turnover and balance sheet.

Today (9 October 2026)

OIV regime under the Defence Code

Declaration of vital information systems (SIIV), security rules set by sector orders, incident notification to ANSSI, inspections.

Once NIS 2 is transposed

Critical entity (CER directive)

The resilience bill updates the OIV regime: operator resilience plan, incident notification.

Essential entity (NIS 2)

Risk management measures, incident notification, ex ante and ex post supervision, heavier penalties.

An orientation tool, not legal advice. As the resilience bill had not been passed on 9 October 2026, the right-hand column reflects the NIS 2 directive; the French text may refine these rules.
06

What NIS 2 changes for OIVs and OSEs

Adopted on 14 December 2022 alongside the CER directive on the resilience of critical entities, NIS 2 changes the scale. France is transposing both texts, along with the DORA component, through a single bill known as the resilience bill, which had still not been passed on 9 October 2026.

  • OSEs disappear in favour of essential and important entities. They are no longer designated one by one: sector and size determine status. The Senate estimates the scope at around 15,000 entities in 18 sectors, including nearly 1,500 local authorities. See From NIS to NIS 2 and the sectors covered by NIS 2.
  • OIVs are updated through the CER transposition: the bill notably provides for an operator resilience plan and notification obligations. In addition, NIS 2 classifies as essential entities, regardless of size, entities identified as critical under CER.
  • Penalties change in nature: NIS 2 provides for administrative fines proportionate to turnover, detailed in our article on NIS 2 penalties.

In the meantime, current obligations still apply: the Defence Code for OIVs, the 2018 texts for OSEs. For organisations new to the subject, ANSSI's NIS 2 simulator (MesServicesCyber) helps check their likely status. Either way, the fundamentals do not change: risk analysis, proportionate measures, detection, incident management and business continuity.

To track your NIS 2 requirements alongside the rules that already apply to your systems, Phinasoft's compliance campaigns bring frameworks, assessments and action plans together.

Summary

01

LPM 2013: the OIVs

Article 22 of France's 2013 military programming law required operators of vital importance to protect their vital information systems: security rules, incident notification, inspections.

02

NIS 1: the OSEs

Since the law of 26 February 2018, designated operators of essential services apply 23 security rules to their essential systems and notify incidents to ANSSI.

03

NIS 2: a change of scale

The directive replaces OSEs with around 15,000 essential and important entities. Its French transposition, the resilience bill, had not been passed on 9 October 2026.

Frequently asked questions

What does LPM mean in cybersecurity?

LPM stands for loi de programmation militaire, France's military programming law. In cybersecurity, it mainly refers to Article 22 of the law of 18 December 2013 (LPM 2014-2019), which created security obligations for the information systems of operators of vital importance (OIV). Later LPMs, in 2018 and 2023, strengthened detection capabilities and ANSSI's powers.

What is an OIV?

An operator of vital importance is an organisation, public or private, designated by the French State because its activities are deemed essential to the nation's survival or hard to replace. It belongs to one of 12 sectors of vital importance. The list of OIVs is not public; the French Senate puts their number at around 300.

What is the difference between an OIV and an OSE?

OIVs fall under the Defence Code and the vital activities security scheme; their cyber obligations come from the 2013 LPM and cover their vital information systems. OSEs come from the 2016 EU NIS directive, transposed in 2018; they are designated by order of the Prime Minister and apply 23 rules to their essential information systems. The same organisation can fall under both regimes.

What penalties does an OIV face for non-compliance?

The Defence Code provides for a fine of up to €150,000 for company directors, and €750,000 for the legal entity, for breaching cyber obligations, generally after formal notice.

Are OIVs covered by NIS 2?

Yes. NIS 2 classifies as essential entities, regardless of size, entities identified as critical under the CER directive, which France is transposing by updating the OIV regime. The two regimes will therefore fit together; the details depend on the resilience bill, still before Parliament.

What happens to OSEs under NIS 2?

The category disappears: NIS 2 replaces it with essential and important entities, determined by sector and size rather than case-by-case designation. Until the resilience bill is passed, the French texts from NIS 1 remain those OSEs apply.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.