Checked on September 27, 2026
NIS2 in France
How France applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- Draft law, not yet adopted
- National law
- Bill on the resilience of critical infrastructure and strengthening cybersecurity (transposes NIS2, CER, DORA) · Projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité
- Competent authority
- National Cybersecurity Agency of France (ANSSI) (Agence nationale de la sécurité des systèmes d'information (ANSSI))
- National CSIRT
- CERT-FR (ANSSI)
- Registration
- See note
ANSSI's MonEspaceNIS2 portal is open for pre-registration; binding obligations apply only once the law, decrees and orders are promulgated.
- Incident reporting
- Not yet applicable; the bill designates ANSSI as authority for incident notification once in force.
- National specifics
- Senate adopted 2025-03-12; National Assembly special committee adopted 2025-09-10; plenary debate scheduled from 2026-10-07.
- Commission referred France to the CJEU on 2026-07-08 for non-transposition.
- ANSSI published its reference framework ReCyF on 2026-03-17.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
- www.assemblee-nationale.fr/dyn/17/dossiers/DLR5L17N50731
- aide.monespacenis2.cyber.gouv.fr/fr/article/avancement-de-la-transposition-de-la-directive-nis-2-1b3j1da/
- www.cyberattaque.org/nis2-enfin-a-lassemblee-nationale-pres-de-deux-ans-apres-la-date-limite/
- directive-nis2.fr/loi-resilience/
- www.legiscope.com/blog/transposition-nis2-france.html
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.