Resilience bill: where does the NIS 2 transposition stand in France?
Passed by the Senate, stuck in the National Assembly: where the bill that must transpose NIS 2 stands on 8 October 2026.
As of 8 October 2026, the resilience bill, which must transpose NIS 2 in France, has still not been passed. The Senate voted for it on 12 March 2025 and the National Assembly's special committee in September 2025, but its floor debate, planned from 7 October 2026, was postponed once again the day before, with no new date. Implementing decrees and the final version of ANSSI's framework will then follow. Here is where the bill stands, what it contains, and why you should not wait for the vote to prepare.
The resilience bill: one bill for three EU texts
Behind the shorthand “resilience bill” lies the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, tabled in the French Senate on 15 October 2024 under the accelerated procedure. Rather than passing one law per directive, the government bundled three EU workstreams adopted on the same day, 14 December 2022. The summary of the Senate special committee's report sets out its structure:
- Title I, the CER Directive (2022/2557) on the resilience of critical entities: it modernises France's system for operators of vital importance, which covers about 300 operators, and widens its scope from 2 to 11 sectors.
- Title II, the NIS 2 Directive (2022/2555): about 15,000 essential and important entities across 18 sectors, including nearly 1,500 local authorities.
- Title III, the DORA part: the DORA regulation (2022/2554) has applied directly since 17 January 2025; the bill transposes the accompanying directive 2022/2556 and adapts French law (competent authorities, inspections, penalties).
This article does not go back over the content of the directive: for the definition, read From NIS to NIS 2; to find out whether your organisation is covered, see the sectors concerned by NIS 2.
- Title I CER Directive (EU) 2022/2557 Resilience of critical entities ≈ 300 operators of vital importance, from 2 to 11 sectors
- Title II NIS 2 Directive (EU) 2022/2555 Cybersecurity of essential and important entities ≈ 15,000 entities, 18 sectors
- Title III DORA Directive (EU) 2022/2556 The “directive” part of DORA, financial sector Regulation 2022/2554 applicable since 17 Jan 2025
NIS 2 transposition: the resilience bill's journey since 2024
In the Senate: passed in March 2025
The Senate referred the bill to a special committee (rapporteurs Michel Canévet, Patrick Chaize and Hugues Saury), which adopted 61 amendments. After two days of debate, senators passed it on 12 March 2025 and sent it to the National Assembly the next day. Their additions include a trust label for compliant entities, a cap on the cost of inspections charged to entities, and a provision on encryption that would become the main sticking point.
In the National Assembly: a special committee in September 2025
In the National Assembly, a special committee examined the bill in turn. Its report, presented by Mickaël Bouloux, Catherine Hervieu and Anne Le Hénanff, who has since become minister for digital affairs, was tabled on 10 September 2025 together with the committee's text. Since then, nothing has happened on the floor for more than a year.
Article 16 bis: encryption at the heart of the deadlock
Introduced in the Senate, Article 16 bis prohibits requiring encryption service providers to use techniques that deliberately weaken security, such as master decryption keys (“backdoors”). According to LCP and Localtis, the DGSI domestic intelligence agency and other intelligence services want it removed. Yet the Assembly's special committee kept it and even broadened it. On 18 March 2026, France's Higher Commission for Digital Affairs and Postal Services (CSNP) was already denouncing “a situation of unjustifiable uncertainty”. In early October 2026, according to LCP, minister Anne Le Hénanff announced that the government would support deleting the article, which she calls a “legislative rider”.
6 October 2026: another postponement
The bill was finally due on the floor on 7 October 2026. The day before, the Conference of Presidents removed it from the agenda, citing a busy schedule, notably the comprehensive bill on sexist and sexual violence, Next reports. Rapporteur Éric Bothorel said, according to Maire-info, that he was hopeful the text could be put back on the agenda “within a fortnight or three weeks”. No date has been set. After the MPs' vote, and since the bill is under the accelerated procedure, a joint committee may be convened to reconcile the two houses' versions.
- 14 Dec 2022 NIS 2 Directive adopted
- 15 Oct 2024 Bill tabled in the Senate
- 17 Oct 2024 Transposition deadline
- 12 Mar 2025 Passed by the Senate
- 10 Sep 2025 Special committee text (National Assembly)
- 8 Jul 2026 France referred to the CJEU
- 6 Oct 2026 Floor debate postponed We are here
- Next Floor debate, then implementing decrees
NIS 2 in France: two years late and a referral to the Court of Justice
The NIS 2 Directive gave Member States a clear deadline: transpose by 17 October 2024, the same date applying to the CER Directive. France only tabled its bill two days before that deadline.
The European Commission sent letters of formal notice on 28 November 2024, then reasoned opinions on 7 May 2025. On 8 July 2026, it announced it was referring to the Court of Justice of the EU four countries that had not notified full transposition: Ireland, Spain, France and the Netherlands. It is asking the Court to impose a lump sum and daily penalty payments until transposition is complete. According to Le Monde Informatique, the 19 other countries initially targeted have since complied.
For organisations, the main consequence is prolonged uncertainty: until the law and its decrees are published, neither the exact scope, nor the registration procedure, nor the compliance timetable is set in stone.
A situation of unjustifiable uncertainty.
CSNP, 18 March 2026, quoted by Localtis
After the vote: decrees, ANSSI's framework and MonEspaceNIS2
When will NIS 2 apply in France?
The vote will not be enough. The Senate special committee had already counted 40 references to Conseil d'État decrees in the text. According to Localtis, minister Anne Le Hénanff mentioned more than thirty decrees, to be published within 7 to 9 months, and full compliance targeted for the end of 2028. These timeframes have not been confirmed by an official document: they give an order of magnitude, not an enforceable date.
ReCyF, ANSSI's framework
On 17 March 2026, ANSSI released the Référentiel Cyber France (ReCyF), which corresponds to the framework provided for in Article 14 of the bill. It lists the measures recommended to meet the security objectives of NIS 2. It is a working document that will only be finalised after transposition and a consultation. It is not mandatory by default, but an entity that applies it will be able to rely on it during an inspection. The agency is also announcing a baseline measures framework for the least mature organisations, and offers a tool to compare the ReCyF with the standards already in place.
MonEspaceNIS2 and pre-registration
The MonEspaceNIS2 portal offers an “Am I concerned?” simulator. ANSSI has also opened voluntary pre-registration on ClubSSI, currently reserved for companies, to make registration easier once the rules apply. As for local authorities, the current text excludes them from fines, according to Maire-info, without exempting them from the obligations; the amounts planned for other entities are detailed in our article on NIS 2 penalties.
Why you should not wait for the resilience bill to prepare
The legislative timetable is uncertain, but the substance much less so. The directive, published at the end of 2022, already sets out the minimum requirements that the law will have to include:
- risk-management measures that are “appropriate and proportionate”, based on an all-hazards approach, starting with policies on risk analysis (Article 21);
- reporting of significant incidents in three stages: early warning within 24 hours, notification within 72 hours, final report within a month (Article 23);
- management involvement: management bodies approve the measures, oversee their implementation and follow training (Article 20);
- supply chain security, meaning the relationships with direct suppliers (Article 21).
ANSSI's Director General, Vincent Strubel, also urges entities to apply the ReCyF without waiting. The context gives his call weight: since the summer, data leaks have followed one another in government departments (see our article on State data leaks). Before MPs, he argued, according to Localtis, that transposing NIS 2 and complying with the ReCyF would have “prevented most of these attacks”.
Finally, compliance cannot be improvised in a few months: inventorying your systems, analysing your risks, organising incident management and assessing your suppliers all take time. Starting now means being ready when the resilience bill and its decrees are published, rather than chasing deadlines.
- Check whether you are in scope ANSSI · MonEspaceNIS2 simulator
- Pre-register (companies) ANSSI · ClubSSI
- Carry out a risk analysis NIS 2 · Art. 21(2)(a)
- Benchmark against the ReCyF ANSSI · comparison tool
- Prepare reporting: 24 h, 72 h, 1 month NIS 2 · Art. 23(4)
- Have management approve the measures NIS 2 · Art. 20
- Assess your critical suppliers NIS 2 · Art. 21(2)(d)
How to prepare with a tool-supported approach
Most of the actions above rest on a common foundation: an up-to-date risk analysis, a set of requirements tracked over time, and evidence of compliance to show during an inspection. With Phinasoft, you carry out your risk analyses using EBIOS RM with software labelled by ANSSI, then track your requirements through compliance campaigns and manage your third-party assessments.
Frequently asked questions about the resilience bill and NIS 2
When will the resilience bill be passed?
No date has been set as of 8 October 2026. The floor debate in the National Assembly, planned from 7 October, was postponed on 6 October; rapporteur Éric Bothorel hopes it will be rescheduled within two to three weeks. As the bill is under the accelerated procedure, a joint committee of both houses may then be convened if they disagree.
Does NIS 2 already apply in France?
Not yet: a directive must be transposed into national law before it creates obligations for companies and local authorities. Until the resilience bill and its decrees are published, NIS 2 obligations cannot be enforced in France. The previous regime derived from NIS 1 still applies to operators already designated.
What does the critical infrastructure resilience bill contain?
It brings together three EU workstreams: the CER Directive on the resilience of critical entities (Title I), the NIS 2 Directive on cybersecurity (Title II) and the directive that accompanies the DORA regulation for the financial sector (Title III).
What is ANSSI's ReCyF?
The Référentiel Cyber France lists the measures ANSSI recommends to meet the security objectives of NIS 2. Published on 17 March 2026 as a working document, it is not mandatory by default, but an entity that applies it will be able to rely on it during an inspection.
Will local authorities face penalties?
According to Maire-info and Localtis, the current text excludes local authorities from administrative fines, even though they remain subject to the same substantive obligations. This depends on the final version of the law.
Summary
A bill still on hold
Passed by the Senate in March 2025 and by the National Assembly's special committee in September 2025, the resilience bill has still not been debated on the floor: the debate planned for 7 October 2026 was postponed with no new date.
A costly delay
The EU deadline was 17 October 2024. In July 2026 the European Commission referred France to the Court of Justice of the EU, asking for a lump sum and daily penalty payments.
Requirements already known
The directive already sets out the essentials (risk management, incident reporting, management's role) and ANSSI has published its ReCyF framework. Risk analysis can start today.
Sources (17)
- Sénat — Dossier législatif : résilience des infrastructures critiques et renforcement de la cybersécurité
- Sénat — Synthèse du rapport de la commission spéciale n° 393 (2024-2025)
- EUR-Lex — Directive (UE) 2022/2555 (NIS 2)
- EUR-Lex — Directive (UE) 2022/2557 (REC)
- European Commission — Referral of Ireland, Spain, France and the Netherlands to the CJEU (8 July 2026)
- ANSSI — La directive NIS 2 (ReCyF, MonEspaceNIS2)
- ANSSI — NIS 2 : l'ANSSI poursuit et renforce sa dynamique d'accompagnement (18 mars 2026)
- ANSSI — NIS 2 simulator (MesServicesCyber)
- Next — S. Gavois, la transposition de NIS2 de nouveau repoussée (6 octobre 2026)
- Next — S. Gavois, l'ANSSI publie son ReCyF (19 mars 2026)
- Banque des territoires (Localtis) — O. Devillers, Cybermois et report de NIS2 (6 octobre 2026)
- Banque des territoires (Localtis) — V. Fauvel, la CSNP presse le Parlement (18 mars 2026)
- LCP — R. Marchal, pourquoi la France a-t-elle autant tardé (4 octobre 2026)
- Maire-info — Directive NIS 2 : deux ans de retard pour les collectivités
- Le Monde Informatique — D. Filippone, l'UE poursuit la France (9 juillet 2026)
- Conseil national des barreaux — État des lieux NIS2, REC et DORA (27 août 2026)
- Phinasoft — From NIS to NIS 2
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.