France

← All Member States
In legislative procedure
NIS2 status
In legislative procedure
National law
Projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité ('Resilience Bill') — combines NIS2 + CER + DORA
Competent authority
Agence nationale de la sécurité des systèmes d'information (ANSSI)
CSIRT
CERT-FR (ANSSI)
Last verified
2026-07-16

France

🔴 NIS2 still in the national legislative procedure.

NIS2 transposition

  • National law: Projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité (‘Resilience Bill’) — combines NIS2 + CER + DORA
  • Status / entry into force: Final adoption expected during the July 2026 extraordinary session; ANSSI implementing decrees expected Q2 2026 ⚠️ VERIFY

Competent authority & CSIRT

  • Competent authority: Agence nationale de la sécurité des systèmes d’information (ANSSI)
  • CSIRT / incident response: CERT-FR (ANSSI)
  • Registration: MonEspaceNIS2 platform (once enacted)

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

One bill transposes NIS2, CER and DORA together. ANSSI published Référentiel Cyber France (ReCyF) on 2026-03-17 as a preparatory reference. Referred to the CJEU for late transposition.

Sources